Legal

Data Protection & GDPR

How BARK approaches data protection

BARK provides AI-powered services to financial institutions and other professional organisations. We recognise that our customers operate in highly regulated environments where data protection, confidentiality and transparency are fundamental requirements.

Our approach is to minimise unnecessary personal data, clearly define how data is used, and apply appropriate safeguards as BARK and our technology continue to develop.

1. Our Role

BARK may have different roles depending on how personal data is processed.

For information relating to our website, business contacts, user accounts and certain operational activities, Regulatory Knowledge Europe AB may act as the data controller.

When BARK processes personal data contained in Customer Content or institutional data on behalf of a customer, BARK will generally act as a data processor, with the customer remaining the data controller.

Processing performed by BARK as a data processor is governed by the applicable Data Processing Agreement (DPA).

2. Data Minimisation

BARK's services are designed primarily for professional and institutional information.

Our objective is to minimise the personal data required to use BARK and to avoid collecting personal or sensitive information where it is not necessary for the relevant service.

Customers remain responsible for determining what information they provide to BARK and for ensuring that they have the appropriate rights and lawful basis for doing so.

3. Customer Content and AI

BARK uses artificial intelligence and other computational technologies to provide regulatory research, analysis, explanations and related functionality.

Customer Content may be processed where necessary to provide these services.

BARK does not use Customer Content to train its own general-purpose AI models.

BARK may use selected technology and AI providers as part of delivering the Service. Where those providers process personal data on behalf of BARK, appropriate data-protection arrangements apply.

4. Access to Customer Information

Access to Customer Content by authorised BARK personnel should be limited to situations where it is reasonably necessary for purposes such as:

5. European Data Protection

BARK is a Swedish company primarily serving customers in Europe and the Nordic region.

We seek to use European hosting and processing locations where appropriate.

Some technology providers or technical functions may involve processing outside the European Economic Area. Where required, appropriate safeguards are used in accordance with applicable data-protection law.

Customer-specific requirements regarding processing locations and international transfers may also be addressed through contractual arrangements and the applicable DPA.

6. Data Protection by Design

We aim to consider data protection throughout the development and operation of BARK.

This includes principles such as:

7. Customer Responsibilities

Data protection is a shared operational responsibility.

Customers determine what Customer Content they provide to BARK and remain responsible for their own compliance obligations, including determining the lawful basis for personal data they instruct BARK to process on their behalf.

Where BARK acts as a processor, BARK processes such personal data in accordance with the applicable contractual arrangements and documented instructions.

8. Individual Rights

Individuals may have rights under GDPR including access, correction, deletion, restriction, objection and data portability.

Where BARK is the data controller, requests can be directed to:

info@barktechnologies.se

Where BARK processes personal data on behalf of a customer, the relevant customer will generally be responsible for handling the request as data controller, with BARK providing assistance where required.

9. Data Processing Agreements

Where BARK processes personal data on behalf of a customer, the processing should be governed by an applicable Data Processing Agreement.

The DPA defines the respective responsibilities of BARK and the customer and addresses matters including processing instructions, confidentiality, security, subprocessors, international transfers, assistance with data-subject rights and the handling of personal data when the relationship ends.

10. More Information

For detailed information about how Regulatory Knowledge Europe AB processes personal data, please see our Privacy Policy.

Our General Terms and Conditions govern the general use of BARK products and services.

For data-protection questions or DPA enquiries, contact:

info@barktechnologies.se