Privacy Policy - Crystal Alarm

1. Introduction
Crystal Alarm AB (reg. no. 556822-8034) provides personal alarm services and security solutions. We are committed to protecting your privacy and ensuring that all processing of personal data is carried out in accordance with the General Data Protection Regulation (GDPR). This document describes how we collect, use, and protect your personal data when you use our services or visit our website.
Important notice
Crystal Alarm acts in two distinct roles with respect to personal data:
- When you use the personal alarm as an end user: Your employer is the data controller, and Crystal Alarm acts as the data processor. This means we process your personal data in accordance with your employer's instructions.
- For business contacts, website visitors, and marketing purposes: Crystal Alarm acts as the data controller for our own processing of personal data related to customer management, marketing, and website usage.
2. Where Crystal Alarm Acts as Data Processor (End Users of the Alarm)
2.1 What data is collected?
When you use Crystal Alarm as an end user, we collect the following data:
Basic information:
- Name, phone number, email address
- Alarm group and any role as an alarm recipient
- Information about your device (model, operating system, mobile carrier)
Upon alarm activation:
- Time and date of the alarm
- Location (GPS, Wi-Fi, Bluetooth beacons for indoor positioning)
- Audio recordings during the alarm (if the appropriate settings have been configured)
- Video (if the feature has been enabled)
- Alarm status and action plan
Technical information:
- Device identifiers and network information
- Technical logs for troubleshooting
- App usage and configuration status
- Aggregated statistics (without individual identification)
Profile images:
- Optional upload of a profile picture for visual identification during an alarm
- We do not use facial recognition or biometric authentication
2.2 Why is this data processed?
The data is processed in order to:
- Enable alarm functionality and ensure safety
- Locate you in emergency situations (including indoors where GPS is unavailable)
- Dispatch assistance in accordance with the action plan
- Assess alarm situations (audio/video)
- Provide technical support and resolve issues
- Ensure the security and stability of the service
- Detect misconfigurations and assist users
- Send functional safety notifications (onboarding, alerts, test alarm reminders)
- Send consolidated reports to administrators at your employer
- Comply with the requirements of occupational health and safety legislation
2.3 Legal basis
Your employer is the data controller, and Crystal Alarm processes data as data processor on the basis of:
- Performance of a contract – to provide the security service
- Legitimate interests – for security and occupational health and safety purposes
- Vital interests – in acute emergency situations involving audio/video recording (Article 9(2)(c) GDPR)
- Legal claims – for the storage of audio/video recordings following an alarm (Article 9(2)(f) GDPR)
2.4 Who has access to your data?
Upon alarm activation, the following parties may have access:
- Alarm monitoring centre (if you use an external monitoring centre)
- Colleagues designated as alarm recipients
- Your employer's administrators (via the self-service portal)
- Crystal Alarm's technical staff (only for troubleshooting purposes)
Functional email communications: You will receive functional safety messages from us via Mautic (self-hosted within the EU), including:
- Welcome emails and activation assistance
- Alerts regarding misconfigurations (e.g. GPS disabled, notifications disabled)
- Test alarm reminders
- Security updates
These communications are critical to the functioning of the alarm service and cannot be opted out of.
Reports to administrators: Your employer's administrators receive consolidated reports covering:
- Users with misconfigurations
- Inactive users
- Test alarm statistics
- System status
Important: These reports do not enable individual tracking of working hours or locations outside of alarm events.
Positioning and tracking: Crystal Alarm does not continuously track your location. Positioning (including indoor positioning via Bluetooth beacons and Wi-Fi) is activated only when you trigger an alarm function such as Emergency Alarm, Timed Alarm, Safe Return Home, Man Down, or any other alarm function that requires location data. Positioning never occurs in the background without an alarm function being active.
2.5 How long is data retained?
- Basic data: For as long as you are an active user
- Alarm data and recordings: In accordance with your employer's settings in the self-service portal
- System logs: Configurable per customer
- Backup: Retained for a limited period for disaster recovery purposes, after which data is deleted automatically
When you no longer require the service, all data will be deleted or returned to your employer in accordance with their instructions.
3. Where Crystal Alarm Acts as Data Controller
3.1 Business contacts and customer management (CRM)
Data processed:
- Name, email address, phone number
- Company affiliation, role/title
- Billing address
- Contact history and pipeline status (for prospective customers)
Purpose and legal basis:
- Existing customers: Contract management, invoicing, self-service portal (Article 6(1)(b) GDPR – Performance of a contract)
- Prospective customers (leads): Sales process management, documentation of contact history (Article 6(1)(f) GDPR – Legitimate interests)
Retention period:
- Existing customers: Up to 7 years following the termination of the agreement (in accordance with the Swedish Accounting Act)
- Prospective customers: For as long as an active business interest exists
3.2 Support and technical assistance
Data processed:
- Name, email address, phone number
- Company affiliation
- Technical information relating to the issue
Legal basis: Performance of a contract (Article 6(1)(b) GDPR)
Retention period: Closed support cases are retained for up to 7 years to enable handling of recurring issues.
3.3 Marketing and prospecting
3.3.1 Customer Match / Retargeting
We use Customer Match technology to display relevant advertisements to business contacts at existing and prospective customer organisations on Google, Meta (Facebook/Instagram), LinkedIn, Microsoft, and Gartner Digital Markets (Capterra).
What this means:
- Email addresses are hashed using SHA-256 before any matching takes place
- Advertisements are displayed on Google, Facebook, Instagram, LinkedIn, Microsoft, and Capterra
- Only B2B contacts are targeted — end users of the alarm service are never included
Exclusion lists (suppression of end users): We also upload end users' email addresses to advertising platforms for the sole purpose of excluding them from seeing our advertisements. This protects end users from irrelevant advertising and optimises our advertising spend. Email addresses are used exclusively for suppression purposes — never for targeted advertising directed at end users.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR)
Opt-out: Contact us at support@crystalalarm.se
Retention period: 12 months following the end of the customer relationship or active CRM engagement.
3.3.2 AI-assisted prospecting
We use lead enrichment and AI tools to identify and analyse relevant business contacts (see Section 7.1 for a list of suppliers).
Data processed:
- Name, job title, email address, phone number
- Company affiliation
- Publicly available information from LinkedIn and company websites
Legal basis: Legitimate interests (Article 6(1)(f) GDPR)
Retention period: 12 months from the date of last contact attempt
Opt-out: At the time of first contact, you will always be given the opportunity to unsubscribe from future marketing communications.
3.3.3 Email marketing via Mautic
We send B2B marketing communications via Mautic (self-hosted within the EU), including:
- Newsletters about product improvements
- Information about new features
- Invitations to webinars
Legal basis: Legitimate interests (Article 6(1)(f) GDPR)
Opt-out: Every email contains an unsubscribe link.
Please note: Functional safety emails sent to end users (onboarding, alerts, test alarm reminders) cannot be opted out of, as they are critical to the functioning of the alarm service. These are processed under the data processor arrangement described in Section 2.
3.4 Website usage and tracking
We use several tools to analyse and optimise our website:
Tools used:
- Google Analytics (GA4) – Visitor statistics and user flows
- Mautic Tracking – Visitor tracking and lead scoring (self-hosted within the EU)
- Meta Pixel (Facebook) – Measuring advertising performance and retargeting
- LinkedIn Insight Tag – Measuring advertising performance and retargeting
- Microsoft UET Tag – Measuring advertising performance in Microsoft Ads
- Gartner Digital Markets (Capterra) – Measuring advertising performance and retargeting
Legal basis: Consent (Article 6(1)(a) GDPR) via Cookiebot. All tracking tools are blocked until you actively provide your consent via the Cookiebot widget. You may accept or decline cookies and may withdraw your consent at any time.
Safeguards:
- IP anonymisation in Google Analytics
- Mautic self-hosted within the EU (data does not leave the EU)
- Standard Contractual Clauses (SCCs) in place with Google, Meta, LinkedIn, Microsoft, and Gartner Digital Markets
Chat function: Our chat provider uses cookies to enable you to continue a conversation as you navigate between pages.
4. Special Provisions Regarding Sensitive Personal Data
Crystal Alarm does not process special categories of personal data as defined under Article 9 GDPR (such as health data, biometric data, or data relating to ethnic origin). Location data is not classified as sensitive personal data under GDPR; however, we treat it with particular care and restrict its collection to active alarm situations.
4.1 Audio and video recordings during alarms
When you activate an alarm, audio is recorded automatically if the appropriate settings have been configured. If you have enabled the video feature, video will also be recorded.
Purpose: To assist the alarm monitoring centre and colleagues in assessing the situation and responding promptly.
Crystal Alarm's role: We act as data processor — your employer is the data controller.
Legal basis (your employer is responsible for):
- During an active alarm: Vital interests (Article 9(2)(c) GDPR) — necessary to protect life and health
- Storage after the alarm: Legal claims (Article 9(2)(f) GDPR) — may be required as evidence in investigations
Access:
- Alarm monitoring centre (during an active alarm)
- Alarm recipients/colleagues (during an active alarm)
- Your employer (after the alarm, via the self-service portal)
- You (via the app)
- Crystal Alarm's technical staff (only for troubleshooting purposes)
Security measures:
- Encryption of stored recordings
- Restricted access — authorised personnel only
- Access logging (Audit Log)
- Automatic deletion in accordance with configured settings
- We do not use facial recognition or biometric authentication
Retention period: In accordance with your employer's settings. Backup copies are retained for a limited period for disaster recovery purposes.
5. Your Rights
You have the following rights under GDPR:
- Right to information: You have the right to be informed about how your personal data is processed.
- Right of access: You may request a copy of the personal data we hold about you.
- Right to rectification: You may request the correction of inaccurate data.
- Right to erasure: You may request the deletion of your data under certain conditions.
- Right to restriction of processing: You may request that the processing of your data be restricted.
- Right to data portability: You may request your data in a machine-readable format.
- Right to object: You may object to processing based on legitimate interests.
- Right not to be subject to automated decision-making: We do not use automated decisions that have a legal or similarly significant effect on you.
How to exercise your rights:
- End users: Please contact your employer in the first instance, as they are the data controller. If you do not receive assistance, you may contact us at support@crystalalarm.se.
- Business contacts: Contact us directly at support@crystalalarm.se.
- Complaints: You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) at www.imy.se.
6. Data Security
We take security seriously and have implemented comprehensive protective measures.
Technical measures:
- Encryption of stored personal data
- Secure transmission (TLS/HTTPS)
- Two-factor authentication for staff access
- Network security and monitoring
- Automatic deletion in accordance with defined retention periods
- Backup for disaster recovery
- Strict tenant isolation (each customer's data is stored separately)
Organisational measures:
- Restricted access — authorised personnel only
- Confidentiality agreements for all staff
- Regular security training
- Documented procedures for handling GDPR requests
- Annual review of security measures
In the event of a data breach: In the event of a serious breach, all affected customers will be notified promptly, including information about the scope of the breach.
7. Sharing Data with Third Parties
7.1 Data processors
We engage the following external suppliers who may process personal data on our behalf:
Advertising platforms (Customer Match and exclusion lists):
- Google LLC (USA) – Standard Contractual Clauses (SCCs) in place
- Meta Platforms Inc (USA) – Standard Contractual Clauses (SCCs) in place
- LinkedIn Corporation (USA) – Standard Contractual Clauses (SCCs) in place
- Microsoft Corporation (USA) – Standard Contractual Clauses (SCCs) in place
- Gartner Digital Markets / Capterra (USA) – Standard Contractual Clauses (SCCs) in place
Lead enrichment and AI:
- Clay (USA) – GDPR-compliant
- Apollo (USA) – GDPR-compliant
- Anthropic / Claude (USA) – GDPR-compliant
Email automation:
- Mautic (self-hosted within the EU)
Web analytics:
- Google Analytics (USA) – with consent via Cookiebot
- Meta Pixel (USA) – with consent via Cookiebot
- LinkedIn Insight Tag (USA) – with consent via Cookiebot
- Microsoft UET Tag (USA) – with consent via Cookiebot
- Gartner Digital Markets / Capterra (USA) – with consent via Cookiebot
All of our data processors have signed Data Processing Agreements (DPAs) and are GDPR-compliant.
7.2 When are we required to share data?
We may be required to share data:
- During an alarm (with the alarm monitoring centre, colleagues, or employer)
- Where required by law or court order
- With law enforcement agencies in the context of criminal investigations
We never sell your personal data to third parties.
8. International Transfers
Some of our suppliers are based in the United States. When we transfer personal data to the US, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Suppliers that are GDPR-compliant
- SHA-256 hashing of email addresses prior to any matching
- Encrypted transmission (TLS/HTTPS)
9. Mobile Device Permissions
The Crystal Alarm app requires the following permissions in order to function:
Android:
- SMS_RECEIVE – Receive SMS from the service
- SMS_SEND – Send SMS for positioning and alarm purposes
- CALL_PHONE – Automatically call the alarm monitoring centre
- MODIFY_AUDIO_SETTINGS – Sound the alarm even when the device is on silent mode
- ACCESS_FINE_LOCATION – Determine location during an alarm
- Notifications – Deliver alarms and updates
iPhone:
- Always allow location – Determine location during an alarm
- Microphone – Transmit audio during an alarm
- Notifications – Deliver alarms and updates
You may deny certain permissions; however, Crystal Alarm will then not function as intended.
10. Contact Us
Data controller: Crystal Alarm AB Org. no.: 556822-8034
Addresses:
- Första Magasinsgatan 5, 803 10 Gävle, Sweden
- Gamla Brogatan 32, 111 20 Stockholm, Sweden
Privacy enquiries: Email: support@crystalalarm.se Phone: +46 26 840 06 23 (Gävle) | +46 8 55 118 990 (Stockholm)
Technical support: Phone: +46 8 55 118 993 Support form: [available on our website]
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be published on this page with an updated date. In the event of material changes, we will notify you by email or via the app.
Change log
Date Description
2026-03-03
Added Gartner Digital Markets (Capterra) as an advertising and tracking platform. Clarified that no special categories of personal data under Article 9 GDPR are processed. Extended description of alarm functions that activate positioning. Simplified hashing description. Generalised technical details relating to infrastructure and logging. Updated retention period to "up to 7 years".
2025-02-12
Major update: Clarified the distinction between data processor and data controller roles. Added information on Customer Match with exclusion lists, AI-assisted prospecting, extended web tracking (Meta Pixel, LinkedIn, Microsoft), indoor positioning, system logs, and profile images. Updated information on audio/video recordings, hashing, and legal bases.
2024-06-13
Added information on the collection of personal data in connection with marketing activities.
2024-03-14
Removed reference to: "Crystal Alarm and Crystal Code are hereinafter jointly referred to as Crystal Alarm."
2020-04-15
Added information on website statistics.
2019-02-20
Added information on mobile device permissions.
2017-06-27
First version published.
12. Cookie Declaration
This website uses cookies. We use device identifiers to personalise content and advertisements, provide social media features, and analyse our traffic. We also share such identifiers and other information from your device with the social media, advertising, and analytics companies with whom we work. These companies may in turn combine that information with other data you have provided to them or that they have collected in connection with your use of their services.
Cookies are small text files that may be used by websites to make a user's experience more efficient.
The law states that we may store cookies on your device if they are strictly necessary for the operation of this website. For all other purposes, your consent is required.
This website uses different types of cookies. Some cookies are placed by third-party services that appear on our pages.
You may change or withdraw your consent to the cookie declaration on our website at any time.
Please read our Privacy Policy for more information about who we are, how to contact us, and how we process personal data. Please include your consent ID and the date on which you contacted us regarding your consent.
Your consent applies to the following domains: www.crystalalarm.no, www.crystalalarm.dk, www.crystalalarm.de, www.crystalalarm.fr, www.crystalalarm.fi, www.personalalarm.app, www.personlarm.app, www.crystalalarm.com, www.crystalalarm.se
Your current status: Allow all.
Cookie declaration last updated: 01/12/25 by Cookiebot.
2. When Crystal Alarm is a data processor (end user of the alarm)
2.1 What data is collected?
When you use Crystal Alarm as an end user, we collect the following data:
Basic information:
- Name, phone number, email address
- Alarm group and any role as alarm recipient
- Information about your phone (model, operating system, mobile carrier)
In the event of an alarm:
- Time and date of the alarm
- Location (GPS, WiFi, Bluetooth beacons for indoor positioning)
- Audio recordings during the alarm (if the correct settings are configured)
- Video (if the feature is enabled)
- Alarm status and action plan
Technical information:
- Device identifiers and network information
- Technical logs for troubleshooting
- App usage and configuration status
- Aggregated statistics (without individual identification)
Profile pictures:
- Optional upload of a profile picture for visual identification during an alarm
- We do NOT use facial recognition or biometric authentication
2.2 Why is this data processed?
The data is processed in order to:
- Enable alarm functionality and safety
- Locate you in emergency situations (including indoors where GPS does not work)
- Send help according to the action plan
- Assess alarm situations (audio/video)
- Provide technical support and troubleshoot issues
- Ensure the security and stability of the service
- Detect misconfigurations and help users
- Send functional safety notifications (onboarding, warnings, test alarm reminders)
- Send summary reports to administrators at your employer
- Comply with workplace health and safety legislation
2.3 Legal basis
Your employer is the data controller and Crystal Alarm processes data as a data processor based on:
- Performance of a contract (to provide the safety service)
- Legitimate interest (for safety and the work environment)
- Vital interests (in acute emergencies with audio/video recording – Art. 9.2.c GDPR)
- Legal claims (storage of audio/video after an alarm – Art. 9.2.f GDPR)
2.4 Who has access to your data?
In the event of an alarm, the following may have access:
- Alarm receiving centre (if you use an external alarm receiving centre)
- Colleagues who are alarm recipients
- Your employer's administrators (via the self-service portal)
- Crystal Alarm's technical staff (only for troubleshooting)
Functional emails:
You receive functional safety notifications from us via Mautic (self-hosted in the EU):
- Welcome email and activation help
- Warnings about misconfigurations (GPS off, notifications off)
- Test alarm reminders
- Security updates
These notifications are critical for the alarm to function and cannot be opted out of. Reports to administrators:
Your employer's administrators receive summary reports on:
- Users with misconfigurations
- Inactive users
- Test alarm statistics
- System status
Important: The reports do NOT enable individual mapping of working days or locations outside of alarms. Positioning and tracking: Crystal Alarm does NOT track your location continuously. Positioning (including indoor positioning via Bluetooth beacons and WiFi) takes place when you activate an alarm feature such as Emergency Alarm, Timer Alarm, Safe Arrival Home, Man Down or any other alarm feature that requires positioning. Positioning never takes place in the background without an alarm feature being activated.
2.5 How long is the data retained?
- Basic data: As long as you are an active user
- Alarm data and recordings: According to your employer's settings in the self-service portal
- System logs: Configurable per customer
- Backup: For a limited period for disaster recovery, after which the data is automatically deleted
When you no longer need the service, all data is deleted or returned to your employer in accordance with their instructions.
3. When Crystal Alarm is the data controller
3.1 Business contacts and customer management (CRM)
Data processed:
- Name, email address, phone number
- Company affiliation, role/title
- Billing address
- Contact history and pipeline status (for prospective customers)
Purpose and legal basis:
- Existing customers: Contract management, invoicing, self-service portal (Art. 6.1.b GDPR – Performance of a contract)
- Prospective customers (leads): Managing the sales process, documenting contact history (Art. 6.1.f GDPR – Legitimate interest)
Retention period:
- Existing customers: Up to 7 years after termination of the contract (Accounting Act)
- Prospective customers: As long as an active business interest exists
3.2 Support and technical assistance
Data processed:
- Name, email address, phone number
- Company affiliation
- Technical information about the issue
Legal basis: Performance of a contract (Art. 6.1.b GDPR) Retention period: Closed cases are kept for up to 7 years in order to manage recurring issues
3.3 Marketing and prospecting
3.3.1 Customer Match / Retargeting
We use Customer Match technology to show relevant ads to business contacts at existing and prospective customers on Google, Meta (Facebook/Instagram), LinkedIn, Microsoft and Gartner Digital Markets (Capterra).
What this means:
- Email addresses are hashed with SHA-256 before matching takes place
- Ads are shown on Google, Facebook, Instagram, LinkedIn, Microsoft and Capterra
- Only B2B contacts, never end users of the alarm
Suppression lists (excluding end users): We also upload end users' email addresses to the ad platforms in order to EXCLUDE them from seeing our ads. This protects end users from irrelevant advertising and optimises our ad budget. Email addresses are used solely for exclusion – never for targeted advertising to end users.
Legal basis: Legitimate interest (Art. 6.1.f GDPR)
How to opt out: Contact us at support@crystalalarm.se
Retention period: 12 months after the customer relationship or CRM engagement has ended
3.3.2 AI-assisted prospecting
We use lead enrichment tools and AI tools to identify and analyse relevant business contacts (see section 7.1 for a list of providers).
Which data:
- Name, job title, email address, phone number
- Company affiliation
- Public information from LinkedIn and company websites
Legal basis: Legitimate interest (Art. 6.1.f GDPR)
Retention period: 12 months from the most recent contact attempt
Opt-out: At the first point of contact you will always be given the opportunity to opt out of future marketing.
3.3.3 Email marketing via Mautic
We send B2B marketing via Mautic (self-hosted in the EU):
- Newsletters about product improvements
- Information about new features
- Invitations to webinars
Legal basis: Legitimate interest (Art. 6.1.f GDPR)
Opt-out: Every email contains an unsubscribe link.
Please note: Functional safety emails to end users (onboarding, alerts, test alarms) cannot be opted out of, as they are critical to the alarm functioning properly. These are handled as data processor activities (see section 2).
3.4 Website usage and tracking
We use several tools to analyse and optimise our website:
Tools used:
- Google Analytics (GA4) – Visitor statistics and user flows
- Mautic Tracking – Visitor tracking and lead scoring (self-hosted in the EU)
- Meta Pixel (Facebook) – Measuring ad performance and retargeting
- LinkedIn Insight Tag – Measuring ad performance and retargeting
- Microsoft UET Tag – Measuring ad performance in Microsoft Ads
- Gartner Digital Markets (Capterra) – Measuring ad performance and retargeting
Legal basis: Consent (Art. 6.1.a GDPR) via Cookiebot. All tracking tools are blocked until you actively consent via the Cookiebot widget. You can accept or decline cookies and can withdraw your consent at any time.
Safeguards:
- IP anonymisation in Google Analytics
- Mautic self-hosted in the EU (data does not leave the EU)
- Standard Contractual Clauses (SCCs) with Google, Meta, LinkedIn, Microsoft and Gartner Digital Markets
Chat feature: Our chat provider uses cookies so that you can continue chatting as you navigate between pages.
4. Specific information on sensitive personal data
Crystal Alarm does not process any sensitive personal data as defined in GDPR Article 9 (such as health data, biometric data, or information about ethnic origin). Location data is not classified as sensitive personal data under the GDPR, but we handle it with extra care and limit collection to active alarm situations.
4.1 Audio and video recordings during alarms
When you trigger an alarm, audio is automatically recorded if the correct settings are configured. If you have enabled the video function, video is also recorded.
Why: To help the alarm centre and colleagues assess the situation and act quickly.
Crystal Alarm's role: We are the data processor – your employer is the data controller.
Legal basis (your employer's responsibility):
- During an active alarm: Vital interests (GDPR Article 9.2.c) – necessary to protect life and health
- Storage afterwards: Legal claims (GDPR Article 9.2.f) – may be required as evidence in investigations
Who has access:
- Alarm centre (during an active alarm)
- Alarm recipients/colleagues (during an active alarm)
- Your employer (after the alarm, via the self-service portal)
- You (via the app)
- Crystal Alarm's technical staff (only for troubleshooting)
Security:
- Encryption of stored recordings
- Restricted access – authorised personnel only
- Access is logged (AuditLog)
- Automatic deletion according to settings
- We do NOT use facial recognition or biometric authentication
Retention period: As determined by your employer's settings. Backups are kept for a limited period for disaster recovery purposes.
5. Your rights
You have the following rights under GDPR:
Right to information: You have the right to be informed about how your personal data is processed.
Right of access (data extract): You can request a copy of the personal data we hold about you.
Right to rectification: You can request that inaccurate data be corrected.
Right to erasure: You can request that your data be deleted under certain conditions.
Right to restriction: You can request that the processing of your data be restricted.
Right to data portability: You can request to receive your data in a machine-readable format.
Right to object: You can object to processing based on legitimate interest.
Right not to be subject to automated decision-making: We do not use automated decisions that have legal or significant effects on you.
How do you exercise your rights?
If you are an end user: First contact your employer, who is the data controller. If you do not receive assistance, you can contact us at support@crystalalarm.se
If you are a business contact: Contact us directly at support@crystalalarm.se
Complaints: You always have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) at www.imy.se
6. Data Security
We take security seriously and have implemented comprehensive safeguards: Technical measures:
- Encryption of stored personal data
- Secure transmission (TLS/HTTPS)
- Two-factor authentication for staff access
- Network security and monitoring
- Automatic deletion according to defined retention periods
- Backups for disaster recovery
- Strict tenant isolation (each customer's data is stored separately)
Organisational measures:
- Restricted access – authorised personnel only
- Confidentiality agreements for all staff
- Regular security training
- Documented procedures for GDPR requests
- Annual review of security measures
In the event of a data breach: If a serious breach is detected, all customers will be notified immediately about the scope of the breach.
7. Sharing of data with third parties
7.1 Data processors
We use the following external providers who may process personal data on our behalf:
Advertising platforms (Customer Match and negative lists):
- Google LLC (USA) – with Standard Contractual Clauses (SCC)
- Meta Platforms Inc (USA) – with Standard Contractual Clauses (SCC)
- LinkedIn Corporation (USA) – with Standard Contractual Clauses (SCC)
- Microsoft Corporation (USA) – with Standard Contractual Clauses (SCC)
- Gartner Digital Markets / Capterra (USA) – with Standard Contractual Clauses (SCC)
Lead enrichment and AI:
- Clay (USA) – GDPR-compliant
- Apollo (USA) – GDPR-compliant
- Anthropic/Claude (USA) – GDPR-compliant
Email automation:
- Mautic (self-hosted in the EU)
Web analytics:
- Google Analytics (USA) – with consent via Cookiebot
- Meta Pixel (USA) – with consent via Cookiebot
- LinkedIn Insight Tag (USA) – with consent via Cookiebot
- Microsoft UET Tag (USA) – with consent via Cookiebot
- Gartner Digital Markets / Capterra (USA) – with consent via Cookiebot
All our data processors have signed data processing agreements (DPAs) and are GDPR-compliant.
7.2 When do we have to share data?
We may need to share data:
- In the event of an alarm (to alarm centre, colleagues, employer)
- If required by law or court order
- To the police in criminal investigations
We NEVER sell your personal data to third parties.
8. International Transfers
Some of our providers are located in the United States. When we transfer personal data to the US, we use:
- Standard Contractual Clauses (SCC) approved by the European Commission
- GDPR-compliant providers
- SHA-256 hashing of email addresses before matching takes place
- Encrypted transfer (TLS/HTTPS)
9. Mobile device permissions
The Crystal Alarm app requires the following permissions to function: Android:
- SMS_RECEIVE – Receive SMS from the service
- SMS_SEND – Send SMS for positioning and alarms
- CALL_PHONE – Automatically call the alarm response centre
- MODIFY_AUDIO_SETTINGS – Play the alarm signal even in silent mode
- ACCESS_FINE_LOCATION – Determine position when an alarm is triggered
- Notifications – Deliver alarms and updates
iPhone:
- Always allow location – Determine position when an alarm is triggered
- Microphone – Transmit audio during an alarm
- Notifications – Deliver alarms and updates
You can decline certain permissions, but Crystal Alarm will not work as intended if you do.
10. Contact us
Data controller: Crystal Alarm AB Company reg. no.: 556822-8034
Addresses: Första Magasinsgatan 5, 803 10 Gävle Gamla Brogatan 32, 111 20 Stockholm
Contact for privacy matters: Email: support@crystalalarm.se Phone: 026 840 06 23 (Gävle) or 08 55 118 990 (Stockholm)
Technical support: Phone: 08 55 118 993 Support form
11. Changes to the privacy policy
We may update this privacy policy from time to time. Any changes will be published on this page with an updated date. In the event of significant changes, we will notify you by email or through the app.
Change history
2026-03-03 – Added Gartner Digital Markets (Capterra) as an advertising and tracking platform. Clarified that no sensitive personal data as defined by GDPR Article 9 is processed. Expanded the description of alarm features that activate positioning. Simplified the hashing description. Generalised technical details regarding infrastructure and logging. Changed the retention period to "up to 7 years".
2025-02-12 – Comprehensive update: Clarified the distinction between data processor and data controller. Added information about Customer Match with negative lists, AI prospecting, expanded web tracking (Meta Pixel, LinkedIn, Microsoft), indoor positioning, system logs, and profile pictures. Updated information about audio/video recordings, hashing, and legal bases.
2024-06-13 – Added information about the collection of personal data in connection with marketing.
2024-03-14 – Removed: "Crystal Alarm and Crystal Code are hereinafter jointly referred to as Crystal Alarm."
2020-04-15 – Added information about statistics on the website
2019-02-20 – Added information about mobile phone permissions
2017-06-27 – First version
12. Cookie Declaration
This website uses cookies. We use device identifiers to personalise content and ads for users, provide social media features and analyse our traffic. We also share such identifiers and other information from your device with our social media, advertising and analytics partners. They may in turn combine this information with other information you have provided to them or that they have collected from your use of their services.
Cookies are small text files that can be used by websites to make a user's experience more efficient.
The law states that we can store cookies on your device if they are strictly necessary for the operation of this website. For all other types of cookies, we need your permission.
This website uses different types of cookies. Some cookies are placed by third-party services that appear on our pages.
You can change or withdraw your consent to the Cookie Declaration on our website at any time.
Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.
Please state your consent ID and date when you contact us regarding your consent.
Your consent applies to the following domains: www.crystalalarm.no, www.crystalalarm.dk, www.crystalalarm.de, www.crystalalarm.fr, www.crystalalarm.fi, www.personalalarm.app, www.personlarm.app, www.crystalalarm.com, www.crystalalarm.se
Your current state: Allow all.
Your consent ID:
Consent date:
Change your consent | Withdraw your consent
Cookie declaration last updated on 12/1/25 by Cookiebot :
Last updated: 2026-03-03
Privacy
Cookie declaration
This website uses cookies and similar technologies to provide essential functionality, improve the experience, analyse traffic, and support relevant marketing.
Necessary cookies are stored without consent. We ask for your consent before storing cookies for any other purpose. Some cookies are set by third-party services used on our pages.
Necessary (17)
Necessary cookies help make the website usable by enabling basic functions.
| Cookie | Provider | Purpose | Expiry | Type |
|---|---|---|---|---|
| __cf_bm | calendly.com | This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website. | 1 day | HTTP Cookie |
| __stripe_mid | calendly.com | This cookie is necessary for making credit card transactions on the website. The service is provided by Stripe.com which allows online transactions without storing any credit card information. | 1 year | HTTP Cookie |
| __stripe_sid | calendly.com | This cookie is necessary for making credit card transactions on the website. The service is provided by Stripe.com which allows online transactions without storing any credit card information. | 1 day | HTTP Cookie |
| _calendly_session | calendly.com | If consent is given by the visitor, this cookie allows the website to add events into the visitor's calendar. | 21 days | HTTP Cookie |
| _cfuvid | calendly.com | This cookie is a part of the services provided by Cloudflare - Including load-balancing, deliverance of website content and serving DNS connection for website operators. | Session | HTTP Cookie |
| test_cookie | doubleclick.net | Used to check if the user's browser supports cookies. | 1 day | HTTP Cookie |
| rc::a | gstatic.com | This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website. | Persistent | HTML Local Storage |
| rc::c | gstatic.com | This cookie is used to distinguish between humans and bots. | Session | HTML Local Storage |
| __cf_bm | linkedin.com | This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website. | 1 day | HTTP Cookie |
| bcookie | linkedin.com | Used in order to detect spam and improve the website's security. | 1 year | HTTP Cookie |
| li_gc | linkedin.com | Stores the user's cookie consent state for the current domain | 180 days | HTTP Cookie |
| m | m.stripe.com | Determines the device used to access the website. This allows the website to be formatted accordingly. | 400 days | HTTP Cookie |
| _ab | m.stripe.network | This cookie is necessary for making credit card transactions on the website. The service is provided by Stripe.com which allows online transactions without storing any credit card information. | Session | HTML Local Storage |
| _mf | m.stripe.network | This cookie is necessary for making credit card transactions on the website. The service is provided by Stripe.com which allows online transactions without storing any credit card information. | Session | HTML Local Storage |
| id | m.stripe.network | — | Session | HTML Local Storage |
| CookieConsent | www.crystalalarm.com | Stores the user's cookie consent state for the current domain | 1 year | HTTP Cookie |
| wpEmojiSettingsSupports | www.crystalalarm.com | This cookie is part of a bundle of cookies which serve the purpose of content delivery and presentation. The cookies keep the correct state of font, blog/picture sliders, color themes and other website settings. | Session | HTML Local Storage |
Preferences (3)
Preference cookies remember information that changes how the website looks or behaves.
| Cookie | Provider | Purpose | Expiry | Type |
|---|---|---|---|---|
| lidc | linkedin.com | Registers which server-cluster is serving the visitor. This is used in context with load balancing, in order to optimize user experience. | 1 day | HTTP Cookie |
| 1 | m.stripe.network | This cookie is used in conjunction with the payment window - The cookie is necessary for making secure transactions on the website. | Session | HTML Local Storage |
| chatlio-#-#-#-#-#-isClosed | w.chatlio.com | — | Persistent | HTML Local Storage |
Statistics (12)
Statistics cookies help us understand how visitors interact with the website.
| Cookie | Provider | Purpose | Expiry | Type |
|---|---|---|---|---|
| c.gif | c.clarity.ms | Collects data on the user’s navigation and behavior on the website. This is used to compile statistical reports and heatmaps for the website owner. | Session | Pixel Tracker |
| ajs_anonymous_id | calendly.com | This cookie is used to identify a specific visitor - this information is used to identify the number of specific visitors on a website. | 1 year | HTTP Cookie |
| dd_cookie_test_# | calendly.com | Registers data on visitors' website-behaviour. This is used for internal analysis and website optimization. | 1 day | HTTP Cookie |
| ajs_anonymous_id | cdn.segment.io | This cookie is used to count how many times a website has been visited by different visitors - this is done by assigning the visitor an ID, so the visitor does not get registered twice. | Persistent | HTML Local Storage |
| userleap.ids | cdn.sprig.com | This cookie is set to make split-tests on the website, which optimizes the website's relevance towards the visitor – the cookie can also be set to improve the visitor's experience on a website. | Persistent | HTML Local Storage |
| _clck | crystalalarm.com | Collects data on the user’s navigation and behavior on the website. This is used to compile statistical reports and heatmaps for the website owner. | 1 year | HTTP Cookie |
| _clsk | crystalalarm.com | Registers statistical data on users' behaviour on the website. Used for internal analytics by the website operator. | 1 day | HTTP Cookie |
| _ga | crystalalarm.com | Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels. | 2 years | HTTP Cookie |
| _ga_# | crystalalarm.com | Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels. | 2 years | HTTP Cookie |
| _cltk | scripts.clarity.ms | Registers statistical data on users' behaviour on the website. Used for internal analytics by the website operator. | Session | HTML Local Storage |
| number(#) | w.chatlio.com | Used to track user’s interaction with embedded content. | Persistent | HTML Local Storage |
| _clsk | www.crystalalarm.com | Registers statistical data on users' behaviour on the website. Used for internal analytics by the website operator. | Session | HTTP Cookie |
Marketing (42)
Marketing cookies are used to track visitors across websites and show relevant advertising.
| Cookie | Provider | Purpose | Expiry | Type |
|---|---|---|---|---|
| _uetsid | bing.com | Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences. | Persistent | HTML Local Storage |
| _uetsid_exp | bing.com | Contains the expiry-date for the cookie with corresponding name. | Persistent | HTML Local Storage |
| _uetvid | bing.com | Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences. | Persistent | HTML Local Storage |
| _uetvid_exp | bing.com | Contains the expiry-date for the cookie with corresponding name. | Persistent | HTML Local Storage |
| MR | bing.com | Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences. | 7 days | HTTP Cookie |
| MUID | bing.com | Used widely by Microsoft as a unique user ID. The cookie enables user tracking by synchronising the ID across many Microsoft domains. | 1 year | HTTP Cookie |
| SRM_B | bing.com | Tracks the user’s interaction with the website’s search-bar-function. This data can be used to present the user with relevant products or services. | 1 year | HTTP Cookie |
| ANONCHK | c.clarity.ms | Registers data on visitors from multiple visits and on multiple websites. This information is used to measure the efficiency of advertisement on websites. | 1 day | HTTP Cookie |
| MR | c.clarity.ms | Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences. | 7 days | HTTP Cookie |
| SM | c.clarity.ms | Registers a unique ID that identifies the user's device during return visits across websites that use the same ad network. The ID is used to allow targeted ads. | Session | HTTP Cookie |
| __tld__ | calendly.com | Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences. | Session | HTTP Cookie |
| MUID | clarity.ms | Used widely by Microsoft as a unique user ID. The cookie enables user tracking by synchronising the ID across many Microsoft domains. | 1 year | HTTP Cookie |
| lastExternalReferrer | connect.facebook.net | Detects how the user reached the website by registering their last URL-address. | Persistent | HTML Local Storage |
| lastExternalReferrerTime | connect.facebook.net | Detects how the user reached the website by registering their last URL-address. | Persistent | HTML Local Storage |
| mautic_device_id | crm.crystalalarm.com | Used to identify the visitor across visits and devices. This allows the website to present the visitor with relevant advertisement - The service is provided by third party advertisement hubs, which facilitate real-time bidding for advertisers. | Persistent | HTML Local Storage |
| mautic_device_id | crm.crystalalarm.com | Used to identify the visitor across visits and devices. This allows the website to present the visitor with relevant advertisement - The service is provided by third party advertisement hubs, which facilitate real-time bidding for advertisers. | 1 year | HTTP Cookie |
| mautic_referer_id | crm.crystalalarm.com | Collects information on user behaviour on multiple websites. This information is used in order to optimize the relevance of advertisement on the website. | 1 day | HTTP Cookie |
| mtc_id | crm.crystalalarm.com | Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences. | Session | HTTP Cookie |
| mtc_id | crm.crystalalarm.com | Sets a unique ID for the visitor, that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs, which facilitates real-time bidding for advertisers. | Persistent | HTML Local Storage |
| mtc_sid | crm.crystalalarm.com | Sets a unique ID for the visitor, that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs, which facilitates real-time bidding for advertisers. | Persistent | HTML Local Storage |
| mtc_sid | crm.crystalalarm.com | Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences. | Session | HTTP Cookie |
| _fbp | crystalalarm.com | Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers. | 3 months | HTTP Cookie |
| _gcl_au | crystalalarm.com | Used to measure the efficiency of the website’s advertisement efforts, by collecting data on the conversion rate of the website’s ads across multiple websites. | 3 months | HTTP Cookie |
| _uetsid | crystalalarm.com | Collects data on visitor behaviour from multiple websites, in order to present more relevant advertisement - This also allows the website to limit the number of times that they are shown the same advertisement. | 1 day | HTTP Cookie |
| _uetvid | crystalalarm.com | Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences. | 1 year | HTTP Cookie |
| pagead/1p-user-list/# | google.com | Tracks if the user has shown interest in specific products or events across multiple websites and detects how the user navigates between sites. This is used for measurement of advertisement efforts and facilitates payment of referral-fees between websites. | Session | Pixel Tracker |
| mautic_device_id | www.crystalalarm.com | Used to identify the visitor across visits and devices. This allows the website to present the visitor with relevant advertisement - The service is provided by third party advertisement hubs, which facilitate real-time bidding for advertisers. | Session | HTTP Cookie |
| mtc_id | www.crystalalarm.com | Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences. | Session | HTTP Cookie |
| mtc_sid | www.crystalalarm.com | Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences. | Session | HTTP Cookie |
| _gcl_ls | www.googletagmanager.com | Tracks the conversion rate between the user and the advertisement banners on the website - This serves to optimise the relevance of the advertisements on the website. | Persistent | HTML Local Storage |
| __Secure-ROLLOUT_TOKEN | youtube.com | Used to track user’s interaction with embedded content. | 180 days | HTTP Cookie |
| __Secure-YEC | youtube.com | Stores the user's video player preferences using embedded YouTube video | Session | HTTP Cookie |
| __Secure-YNID | youtube.com | Used to track user’s interaction with embedded content. | 180 days | HTTP Cookie |
| LAST_RESULT_ENTRY_KEY | youtube.com | Used to track user’s interaction with embedded content. | Session | HTTP Cookie |
| LogsDatabaseV2:V#||LogsRequestsStore | youtube.com | Used to track user’s interaction with embedded content. | Persistent | IndexedDB |
| ServiceWorkerLogsDatabase#SWHealthLog | youtube.com | Necessary for the implementation and functionality of YouTube video-content on the website. | Persistent | IndexedDB |
| TESTCOOKIESENABLED | youtube.com | Used to track user’s interaction with embedded content. | 1 day | HTTP Cookie |
| VISITOR_INFO1_LIVE | youtube.com | Tries to estimate the users' bandwidth on pages with integrated YouTube videos. | 180 days | HTTP Cookie |
| YSC | youtube.com | Registers a unique ID to keep statistics of what videos from YouTube the user has seen. | Session | HTTP Cookie |
| yt-icons-last-purged | youtube.com | Necessary for the implementation and functionality of YouTube video-content on the website. | Persistent | HTML Local Storage |
| ytidb::LAST_RESULT_ENTRY_KEY | youtube.com | Used to track user’s interaction with embedded content. | Persistent | HTML Local Storage |
| YtIdbMeta#databases | youtube.com | Used to track user’s interaction with embedded content. | Persistent | IndexedDB |
Unclassified (27)
Unclassified cookies are still being classified together with their providers.
| Cookie | Provider | Purpose | Expiry | Type |
|---|---|---|---|---|
| _cache | assets.calendly.com | — | Persistent | HTML Local Storage |
| cal_anonymous_id | calendly.com | — | 1 year | HTTP Cookie |
| sprigReplay#chunkUploads | calendly.com | — | Persistent | IndexedDB |
| sprigReplay#events | calendly.com | — | Persistent | IndexedDB |
| sprigReplay#pendingCaptures | calendly.com | — | Persistent | IndexedDB |
| sprig.anon.env.vid.map | cdn.sprig.com | — | Persistent | HTML Local Storage |
| chatlio_at--34e20a49-37dc-43a5-6c6f-024eebaa342a | crystalalarm.com | — | Session | HTTP Cookie |
| chatlio_at--6243f528-0076-4f9e-510a-543b2e0ab6e1 | crystalalarm.com | — | Session | HTTP Cookie |
| chatlio_rt--34e20a49-37dc-43a5-6c6f-024eebaa342a | crystalalarm.com | — | Session | HTTP Cookie |
| chatlio_rt--6243f528-0076-4f9e-510a-543b2e0ab6e1 | crystalalarm.com | — | Session | HTTP Cookie |
| chatlio_uuid--34e20a49-37dc-43a5-6c6f-024eebaa342a | crystalalarm.com | — | Session | HTTP Cookie |
| chatlio_uuid--6243f528-0076-4f9e-510a-543b2e0ab6e1 | crystalalarm.com | — | Session | HTTP Cookie |
| _v-consent | vercel.com | — | 1 year | HTTP Cookie |
| _vercel_sso_nonce | vercel.com | — | Session | HTTP Cookie |
| _v-visitor-id | vercel.com | — | 3 months | HTTP Cookie |
| _v-visitor-id-renewed | vercel.com | — | 1 day | HTTP Cookie |
| chatlio_at--34e20a49-37dc-43a5-6c6f-024eebaa342a | w.chatlio.com | — | Persistent | HTML Local Storage |
| chatlio_at--6243f528-0076-4f9e-510a-543b2e0ab6e1 | w.chatlio.com | — | Persistent | HTML Local Storage |
| chatlio_rt--34e20a49-37dc-43a5-6c6f-024eebaa342a | w.chatlio.com | — | Persistent | HTML Local Storage |
| chatlio_rt--6243f528-0076-4f9e-510a-543b2e0ab6e1 | w.chatlio.com | — | Persistent | HTML Local Storage |
| chatlio_uuid--34e20a49-37dc-43a5-6c6f-024eebaa342a | w.chatlio.com | — | Persistent | HTML Local Storage |
| chatlio_uuid--6243f528-0076-4f9e-510a-543b2e0ab6e1 | w.chatlio.com | — | Persistent | HTML Local Storage |
| chatlio-css-compat-v1--34e20a49-37dc-43a5-6c6f-024eebaa342a | w.chatlio.com | — | Persistent | HTML Local Storage |
| chatlio-css-compat-v1--6243f528-0076-4f9e-510a-543b2e0ab6e1 | w.chatlio.com | — | Persistent | HTML Local Storage |
| lc-impr-cache | widget.leadcaller.com | — | Session | HTML Local Storage |
| leadcaller_tracking_id | widget.leadcaller.com | — | Persistent | HTML Local Storage |
| widgetSession-v1 | widget.leadcaller.com | — | Session | HTML Local Storage |
Cookie declaration last updated: 20/09/2026.