Skip to content

Compliance

Last updated: August 2026

Nudgd AB (company reg. no. 559188-6477, Gothenburg, Sweden) designs Expert Services, the Smart Nudges platform, and Academy so organizations can change everyday behavior lawfully, transparently, and with evidence. This page summarizes how we approach the EU AI Act, GDPR, and related obligations. It is not legal advice. Contracts, data processing agreements, and product documentation govern each engagement.

1. Scope and roles

This statement covers Nudgd as a Swedish company placing digital products and professional services on the EU market, and the public marketing website at nudgd.se.

In many customer programs, the customer (for example a municipality, utility, or employer) is the controller of personal data about end users, and Nudgd acts as a processor under documented instructions. For our own marketing, sales, and support channels, Nudgd is typically the controller. AI Act roles (provider and/or deployer) depend on who places the system on the market or puts it into service under their name. We document roles in the commercial and processing agreements for each delivery.

2. GDPR and data protection

We process personal data in line with Regulation (EU) 2016/679 (GDPR) and Swedish complementary rules. That includes lawful basis, purpose limitation, data minimization, security, retention limits, and support for data-subject rights.

Where we act as processor, we provide data processing terms, limit processing to the customer’s instructions, use appropriate technical and organizational measures, and restrict sub-processors as agreed. Where we act as controller (for example website demo requests), our Privacy policy applies.

International transfers outside the EU/EEA are handled with adequate protection or other lawful safeguards when they occur. Details are in the Privacy policy.

  • Lawful basis, transparency, and purpose limitation for each processing activity
  • Processor commitments and customer instructions for Smart Nudges and related services
  • Support for access, rectification, erasure, restriction, objection, and portability where applicable
  • Complaint path to Integritetsskyddsmyndigheten (IMY)

3. ePrivacy and cookies

On nudgd.se, necessary cookies run the site. Analytics and marketing cookies load only after consent, consistent with the ePrivacy rules as applied in Sweden and our cookie controls.

Product channels may use additional technical measures required to deliver the service. Those are described in the relevant product terms and customer documentation.

4. EU AI Act

Regulation (EU) 2024/1689 (the AI Act) uses a risk-based approach. Nudgd designs and operates its AI-enabled offerings to respect prohibited-practice rules, transparency duties, and the obligations that apply to our role for each system. We keep this work under active review as guidance and timelines evolve.

We do not offer AI systems intended for prohibited practices under Article 5, including subliminal, manipulative, or deceptive techniques designed to materially distort behavior and cause significant harm. Smart Nudges are designed as transparent behavioral support for sustainable choices, with human-designed content and measurement, not covert influence.

Where an AI system interacts with people, or where transparency obligations otherwise apply (including Article 50 where relevant), we work so users and deployers can understand that they are dealing with an AI-supported system and what it is for. Deployers remain responsible for informing end users in their own channels as required.

If a customer use case may qualify as high-risk under the AI Act, we assess that with the customer before go-live, document intended purpose and residual risk, and align delivery, logging, human oversight, and documentation with the applicable requirements and timelines. We do not claim that every deployment is high-risk, and we do not claim a blanket conformity marking for all customer configurations.

  • Risk-based classification with the customer for intended purpose and context of use
  • No prohibited subliminal or harmful manipulative AI practices
  • Transparency and human accountability in design and delivery
  • Documentation and oversight support for deployers where required
  • Ongoing updates as AI Act obligations and official guidance apply

5. Accessibility and public-sector expectations

The public website aims for WCAG 2.2 Level AA with known limitations described in our Accessibility statement. For public-sector buyers, we support procurement conversations on privacy, security, evidence quality, and responsible use of behavioral interventions.

Evidence tiers and method notes on Results and Method pages are part of how we keep claims auditable for leadership and procurement.

6. Security and vendors

We use technical and organizational measures appropriate to the risk, including access control, protected networks, and encryption where suitable. Sub-processors that handle personal data are bound by contract to protect that data and use it only for agreed purposes.

Website tooling (for example demo scheduling or forms) is covered under our Privacy policy and vendor terms. Product environments are governed by the customer agreement.

7. Governing language

This page may exist in Swedish and English. If there is any difference in interpretation, the Swedish version prevails.

Related pages

Compliance and privacy questions: [email protected].