Our approach
AWISEE handles information relating to clients, creators, campaigns, employees, contractors and business partners. We aim to use technical and organisational measures appropriate to the nature of the information, the way it is used and reasonably foreseeable risks.
This page is a public overview. It does not disclose confidential technical security information and it is not a guarantee that a security incident can never occur.
Collect only what is needed
We aim to minimise unnecessary collection and retention. In particular, the standard /creators registration flow should avoid special-category information and unnecessary identity, banking, tax or follower-level sensitive data. Separate processes should be used if those details later become genuinely necessary for payments, tax or compliance.
Control access
Access to personal and confidential business information should be limited to people who reasonably need it for their role. AWISEE’s operational practices should support individual accounts, appropriate permissions and timely adjustment or removal of access when responsibilities change.
Secure authentication
Where supported and appropriate, AWISEE uses or encourages controls such as strong passwords, multi-factor authentication, OTP verification and managed credential practices. The exact security features depend on the systems and providers in use.
Work with established service providers
AWISEE uses third-party systems for functions such as hosting, cloud storage, CRM, communications, e-signatures, payments, accounting and analytics. When providers process personal data, AWISEE should assess relevant security and data-protection terms and put appropriate contractual safeguards in place where required.
Protect creator data
- Creator-submitted personal data is not sold or licensed as a standalone database in the initial /creators version.
- Optional consent-based sharing should be recorded separately from acceptance of Creator Terms.
- Consent records should capture the date/time and version of the wording accepted.
- Creators should have a clear mechanism to withdraw consent and request access, correction or deletion.
- Audience or follower information should be handled in aggregate where reasonably possible.
Confidentiality and internal handling
People who have access to confidential or personal information should be subject to appropriate confidentiality obligations. Internal access should reflect role and business need rather than broad availability.
Security awareness
Security depends on people as well as technology. Relevant personnel should receive practical guidance on phishing, account security, confidential data handling, access management and incident escalation.
Security incidents
Suspected information-security incidents should be escalated, assessed, contained and documented. Where a personal-data breach triggers regulatory or individual notification obligations, AWISEE will assess and respond to those requirements under applicable law.
Retention and deletion
Personal data should not be kept indefinitely without a valid purpose. Retention should take into account operational need, contractual commitments, accounting and tax requirements, legal claims and privacy rights. Information that is no longer required should be deleted, anonymised or appropriately restricted where feasible and lawful.
International operations
AWISEE works internationally. When applicable data-protection law requires safeguards for an international transfer, AWISEE will use an appropriate recognised transfer mechanism.
Privacy by design
New services involving personal data should consider privacy and security before launch. For /creators this includes deciding which fields are necessary, whether data is public or private, who can access it, which lawful basis applies, how consent is recorded, how long information is kept and how creators can exercise their rights.
Report a concern
AWISECO AB
Utsiktsvägen 16, 591 35 Motala, Sweden
[email protected]



















