Privacy Policy
Last updated: 30 July 2026
Atlas Lejon AB, org. nr 559446-0015, Drottninggatan 15, 702 10 Örebro, Sweden (“OnlyCEO”, “we”) is the data controller for personal data processed on the OnlyCEO platform. This policy explains what we collect, why, and your rights under the EU General Data Protection Regulation (GDPR). Discretion is the foundation of this house. This policy is written to be read, not skimmed.
1. What we collect
Account and application data
Name, email, phone number, company, title, photograph, and the information you provide when applying for membership.
Identity verification data
Verification is performed through Stripe Identity, which processes your identity document and a selfie (including biometric comparison) to confirm you are who you say you are. Stripe acts as our processor for this; we receive the verification outcome and limited document metadata, we do not store copies of your identity documents on our own systems. Stripe's processing is further described in Stripe's privacy documentation. We may additionally check your role against public sources and corporate registries.
Content you create
Signals, Threads, Ideas and Questions, comments, event participation, saved items, and your profile.
Private communications
Your Messages and your discussions in Rooms are stored encrypted at rest and transmitted encrypted. No one at OnlyCEO reads them. They are accessed by a human only if a participant reports a specific item, and then only the reported item, never the surrounding conversation. Every such access is logged.
Butler and Privileges data
Requests you make to the Butler, and the details needed to fulfil them (for example travel dates or booking preferences), which are shared with the relevant Partner only when you confirm a request.
Technical data
Log data, device and browser information, IP address, and security events. The minimum needed to run and protect the service. We do not use advertising trackers.
2. Why we process it
| Purpose | Legal basis |
|---|---|
| Assessing your application and verifying identity and role | Contract (Art. 6.1.b); legitimate interest in a verified community (Art. 6.1.f); consent for biometric verification where required (Art. 9.2.a) |
| Operating the Platform, showing your content to the audiences you choose, delivering messages, running Chambers and Events | Contract (Art. 6.1.b) |
| Fulfilling Butler requests and Privileges via Partners, at your request | Contract (Art. 6.1.b) |
| Billing and invoicing | Contract (Art. 6.1.b); legal obligation (Art. 6.1.c, bookkeeping) |
| Safety: handling reports, enforcing the Code of Conduct, preventing abuse | Legitimate interest (Art. 6.1.f); legal obligation where reporting is mandated (Art. 6.1.c) |
| Security, logging, fraud prevention | Legitimate interest (Art. 6.1.f) |
| Service communications (approval, receipts, changes to terms) | Contract (Art. 6.1.b) |
We do not sell personal data, we do not use your data for third-party advertising, and we do not build advertising profiles. Members are never the product.
3. Anonymity on the Platform
Signals may be published anonymously. Anonymity applies toward other members. The connection between an anonymous Signal and its author exists in our systems, is access-restricted, and is used only for safety enforcement and legal obligations. We never reveal an anonymous author to other members.
4. Who we share data with
Processors who run the service under contract with us: hosting and infrastructure providers, Stripe (identity verification and payments), email delivery, and error monitoring. Processors act only on our instructions.
Partners, only when you ask the Butler to arrange something or claim a Privilege, and only the details needed to fulfil that specific request. Partners act as independent controllers for their own service.
Authorities, where the law requires it (for example, content involving minors, or a valid order from police or courts). We disclose the minimum required and, where legally permitted, inform you.
No one else. We do not share member lists, and we never confirm or deny anyone's membership publicly.
5. International transfers
We keep data in the EU/EEA where feasible. Where a processor transfers data outside the EEA (for example Stripe, to the United States), the transfer is protected by the European Commission's adequacy decisions or Standard Contractual Clauses.
6. How long we keep data
| Data | Retention |
|---|---|
| Account and profile | For the life of your membership + 12 months |
| Verification outcome | Life of membership; verification session data held by Stripe per its retention terms |
| Content in shared spaces | While published; deleted content is removed from view immediately and from backups on backup rotation |
| Messages and Rooms | Until you delete them or your account is deleted |
| Report and enforcement records | Duration of the case + 90 days, then purged (longer only if law requires) |
| Invoices and bookkeeping records | 7 years (Swedish Bookkeeping Act) |
| Security logs | 12 months |
7. Your rights
Under the GDPR you may: access your data; correct it; delete it; restrict or object to processing based on legitimate interest; receive a portable copy; and withdraw consent at any time where processing is based on consent. Write to privacy@onlyceo.app. We respond within 30 days.
You may also complain to the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY), imy.se, or to your local authority if you are elsewhere in the EU.
Note: deleting your account deletes your profile and private communications, and anonymizes or removes your contributions in shared spaces, except where we must retain records by law (Section 6).
8. Security
All data is encrypted in transit (TLS) and at rest. Internal access follows least-privilege: private communications are inaccessible to staff except through the report-review process described above, and all such access is logged and auditable. We review access rights regularly and will notify you and IMY of any personal-data breach as the GDPR requires.
9. Cookies
The Platform uses only strictly necessary cookies (session, security). No advertising or third-party tracking cookies. If this changes, we will ask for consent first.
10. Changes
We will notify you of material changes to this policy before they take effect. The current version always lives at onlyceo.app/legal.