Lomia · Privacy

Privacy notice

This notice explains how Peregrin AB processes personal data on lomia.se and in the Lomia service.

Effective
23 August 2026
Version
2026-08-23.1

1. Controller and contact

Peregrin AB is controller for its own purposes and means relating to accounts, authentication, security, operation, support, payment, legal records and abuse prevention.

Peregrin AB
Company registration no. 559260-5777
VAT no. SE559260577701
Framnäsvägen 1
SE-186 95 Vallentuna
Sweden
support@lomia.se

Contact support@lomia.se with privacy questions or rights requests.

2. Private care spaces and responsibility

The Main Coordinator decides why a private care space is used, what relevant content is added and who is invited. Peregrin AB processes care content to deliver the user-directed storage and coordination service and does not reuse it for ads, unrelated analytics, profiling, model training, diagnosis or treatment recommendations.

The Main Coordinator's authority attestation and contributors' use acknowledgements document instructions and responsibility but are not, by themselves, the Care Recipient's consent. Lomia does not normally verify identity, family ties, power of attorney or representation. The Main Coordinator is responsible for ensuring lawful support before collecting or sharing another person's data.

3. Data we process

  • Account and security: name, email, language, password hash, sessions, verification, recovery, security events and IP address used in security controls.
  • Care Recipient and relationships: name, municipality, portrait, relationships, roles, invitations, permissions and deceased status.
  • Coordination content: calendars, tasks, shopping, transport, messages, contacts, documents, economy, family support, later-life planning and other user content.
  • Health and care content: for example medicines, health journal, wellbeing/status, sleep, meals, care profile, aids and notes. This may be special-category health data.
  • Files and private records: uploaded documents, images, audio and user-stored password or code records.
  • Technical data and logs: device/browser data, bounded operational logs, delivery and access events.
  • Billing: plan, subscription, invoice/transaction references, tax data and payment status. Stripe receives payment method and billing details.
  • Support and email: contact address, support content and necessary account, invitation, security and billing messages.

4. Sources

Data comes from you, the Main Coordinator and other invitees, is generated through service use, or comes from Stripe for payment processing. A family-created managed-recipient login is product access, not verification of identity or legal consent.

5. Purposes and legal bases

PurposeLegal basis
Create accounts, deliver requested features, support and ordinary subscription administration.Contract, Article 6(1)(b) GDPR.
Accounting, tax, mandatory consumer notices and other legal requirements.Legal obligation, Article 6(1)(c).
Secure the service, prevent intrusion and abuse, and operate reliably.Legitimate interests, Article 6(1)(f), after balancing.
Private care and health content users instruct us to store and display.The user-directed service contract and documented instructions. Because content may fall under Article 9, an applicable exception is also required for the concrete situation. The Lomia attestation is not, by itself, the Care Recipient's consent.

We do not send marketing without a separately assessed basis. We do not use data for automated decisions producing legal or similarly significant effects.

6. Health information and non-medical purpose

Lomia collects, organises and displays what authorised users enter. It may show dates, averages and changes against the same person's earlier entries to help a household prepare questions for healthcare or social care.

Lomia does not diagnose, determine medical normality, recommend treatment, triage urgency, continuously monitor or send physiological alarms. A non-medical purpose does not stop health information from being special-category data.

7. Recipients and providers

  • Peregrin AB and Scaleway: operation, API, database and storage in Sweden and the Netherlands.
  • Cloudflare: DNS, TLS, protection and delivery of the public site and network traffic.
  • Microsoft 365/Graph: account-related email delivery.
  • Stripe: Checkout, payment, tax, invoices, refunds and subscriptions.
  • Authorised account and family members: content under roles and permissions set by the Main Coordinator.
  • Authorities and advisers: only when required by law or needed for legal claims.

We do not sell personal data. New analytics, AI, transcription or marketing providers require assessment and notice before receiving care content.

8. Processing outside the EU/EEA

Primary product operation and database storage are in Sweden and the Netherlands. Cloudflare, Microsoft and Stripe are international groups and may process some account, network, email or billing data outside the EU/EEA. Such transfers must rely on a valid adequacy decision or the European Commission's Standard Contractual Clauses with supplementary safeguards where needed. Contact us for current information about a specific flow.

9. Retention and erasure

  • Account and ordinary account content is erased or deidentified when a valid erasure can be completed. Shared content may remain for other authorised members.
  • Care content remains while the care space is used or until an authorised person deletes it. A space without a live member may be cleaned up as orphaned.
  • Versioned contributor acknowledgements are deleted with the account. Authority evidence is deleted with the care space; if only the attesting account is erased, its identifier is detached while version and time may remain for other members.
  • Sessions and verification/recovery records are removed when expired. Certain security/access events are retained for 24 months.
  • Detached billing and accounting records are retained to the conservative boundary of 1 January in the erasure year plus eight years. Processed webhook records are retained for 90 days.
  • A browser onboarding draft expires after 24 hours.
  • Encrypted recovery backups are retained for no more than six months and used only for recovery. Erasure reaches each backup when it expires.

Withdrawal or cancellation does not automatically erase an account or content. Request erasure separately in app settings.

10. Your rights

Depending on the circumstances, you may request access, correction, erasure, restriction, portability or object to processing based on legitimate interests. Where processing relies on consent, it may be withdrawn without affecting earlier processing.

Use export and erasure in app settings or email support@lomia.se. We may need to verify identity and authority and consider others in a shared space. You may complain to the Swedish Authority for Privacy Protection (IMY).

11. Security

We use permission controls, personal accounts, encrypted transport, access restrictions, security logging and other technical and organisational safeguards appropriate to risk. No service can guarantee absolute security. Contact us immediately if you suspect unauthorised access.

12. Changes and version

We update this notice when processing, providers or legal requirements change. Material changes receive a new version and reasonable notice. When rules for care content change, the app may require new active acknowledgement.

Effective: 23 August 2026 · Version 2026-08-23.1