Table of content
This Privacy Policy explains how Zendev collects, uses, stores, and shares your personal data when you visit our website at https://www.zendev.se, contact us, or apply for a role with us. We take the protection of your personal data seriously – please read this carefully. If you do not agree with it, we kindly ask that you refrain from using our website.
1. Who we are (data controller)
Zendev operates as a group of two companies:
- Zendev AB – Kungsportsavenyn 21, 411 36 Gothenburg, Sweden. Our Swedish client-facing company.
- Zendev d.o.o. – our software delivery company, with development offices in Mostar (Dr. Ante Starčevića bb, 88000 Mostar) and Sarajevo (Džavida Haverića 6, Sarajevo Tower, 71000 Sarajevo), Bosnia & Herzegovina.
Zendev AB and Zendev d.o.o. are joint controllers for personal data collected through this website. Zendev AB determines the purposes of the processing in its role towards our clients and market, while Zendev d.o.o. carries out most of the day-to-day processing, in particular software delivery and recruitment for engineering roles.
For any privacy matter, you can reach us at [email protected]
2. The law we follow
Because we offer services to individuals in the EU/EEA and operate a Swedish company, we process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and applicable Swedish law. Processing carried out by Zendev d.o.o. is additionally subject to the law of protection of personal data of Bosnia and Herzegovina.
3. What personal data do we collect
Data you give us:
- Contact details – such as your name and email address – when you submit a form or make an inquiry
- Recruitment data – the information in your CV and application: name, contact details, work history, qualifications, skills, education, and anything else you choose to share (for example, a photo, references, or social media profiles). Applications are handled through our external recruitment platform, TalentLyft.
Data we collect automatically:
- Technical and usage data – IP address, device and browser type, operating system, referring URLs, language preference, approximate location, and how you interact with the site. This is used mainly to secure and operate the site and for our own analytics.
We collect some of this through cookies and similar technologies. How that works and how you control it are described in our separate Cookie Policy.
4. Sensitive personal data
We do not seek to collect special categories of data (such as health, religion, ethnicity, sexual orientation, or political opinions). Please do not include such information in your application. We are aware that a CV or photo may incidentally reveal such data; where it does, we treat it as incidental and do not use it in our decision-making.
5. Why we process your data and our legal basis
We only process your data where we have a lawful basis. Depending on the situation, that basis is:
- Consent – for our marketing communications and non-essential cookies. You can withdraw consent at any time.
- Legitimate interests – to respond to inquiries, run and secure our website, understand how it is used, and support our marketing, where this does not override your rights.
- Steps prior to a contract – to handle your job application or a request for our services.
- Legal obligation – where the law requires us to keep or disclose data.
6. Who we share your data with
We share personal data only where necessary, with the following categories of recipients:
- Group companies – Zendev AB and Zendev d.o.o. share data within the group to deliver our services and manage recruitment.
- Service providers (processors) – acting only on our instructions and under a data processing agreement: website hosting (WordPress), our recruitment platform (TalentLyft), website analytics (Google, Microsoft), B2B visitor identification (Dealfront), and email delivery.
- Professional advisers – such as legal, accounting, and audit firms, where needed.
- Authorities – where we are legally required to disclose.
- Business transfers – in connection with a merger, acquisition, or sale of assets.
For our business-to-business marketing, we may obtain limited professional contact details (such as name, role, company, and business email) about individuals at companies that have shown interest in us, from business data providers and enrichment tools. We use this only for B2B outreach relevant to their professional role.
7. International data transfers
Some of our recipients are located outside the EU/EEA – including our own delivery teams in Bosnia & Herzegovina, which does not have an EU adequacy decision. When we transfer your data outside the EU/EEA, we rely on an appropriate safeguard, as set out below.
| Why we transfer the data
|
Recipient category
|
Transfer mechanism
|
Region or country
|
|---|---|---|---|
| Software delivery, engineering, and support
|
Zendev d.o.o. (group delivery company)
|
Standard Contractual Clauses + supplementary measures
|
Bosnia & Herzegovina
|
| Recruitment / applicant (CV) data
|
TalentLyft (recruitment platform)
|
EU provider – no third-country transfer
|
EU
|
| Website hosting and web inquiries
|
Hetzner (hosting provider)
|
EU provider – no third-country transfer
|
EU
|
| Website analytics and behaviour insights
|
Google (GA4), Microsoft (Clarity, LinkedIn)
|
EU-US Data Privacy Framework / SCCs
|
EU / USA
|
| B2B website visitor identification
|
Dealfront (Leadfeeder)
|
EU provider – no third-country transfer
|
EU
|
8. How long we keep your data
- Inquiries and contact data – kept for as long as needed to handle your request and a reasonable period afterward.
- Applicant / CV data – stored in our recruitment platform (TalentLyft) and kept for 6 months after the relevant role closes, so we can handle any follow-up or legal claim. If you agree, we may keep your details in our talent pool for future opportunities beyond that period; you can withdraw that consent at any time, and we will delete your data. This retention period is configured in TalentLyft.
9. How we keep your data safe
We use technical and organisational measures to protect your personal data, and we are certified to ISO 27001 (information security) and ISO 9001 (quality management). No method of transmission or storage is ever completely secure, but we work continuously to protect your information and to respond appropriately if a problem occurs.
10. Your rights
Under the GDPR you have the right to: access your data; correct it; erase it; restrict or object to processing; withdraw consent at any time; receive your data in a portable format; and opt out of marketing at any time via the unsubscribe link. To exercise any of these, contact us at [email protected].
You also have the right to lodge a complaint with a supervisory authority. In Sweden this is the Swedish Authority for Privacy Protection (IMY, imy.se), and in Bosnia and Herzegovina, Personal Data Agency in Bosnia and Herzegovina.
11. Automated decision-making
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
12. Children
Our website and services are directed at businesses and professionals, not children. We do not knowingly collect personal data from anyone under 18.
13. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the date above and, where appropriate, notify you. We encourage you to review this page periodically. The most recent version is always the one published here.
14. Contact
Questions, requests, or complaints about your personal data: [email protected].