Privacy policy
Last updated: 12 August 2026
This policy describes how Ren Labs Stockholm AB (reg. no. 5595948539), operating SuperRen, handles your personal data when you submit your phone number, are called by our AI, get help creating a CV and are matched with jobs. The processing follows the EU GDPR.
1. Controller
Ren Labs Stockholm AB, reg. no. 5595948539, Stockholm, Sweden. Contact: hej@superren.ai.
2. What we collect
Job seekers: phone number, name, city, language, work experience, skills, availability, desired role and what you tell our AI during the call (including a recording and/or transcript of the call). Your CV is created from this. Employers/customers: contact person, phone number, email, company name and the staffing need you describe. Technical data: timestamp, source form, chosen language and browser user-agent. We never ask for national ID numbers, card details, or data about health, union membership, religion or ethnicity. Please do not share such data with our AI.
3. Why we process it
To call you after your approval, help you create and update a CV, match you with open jobs, present anonymised or — with your approval — full candidate profiles to employers, and to handle introductions, support and invoicing. We never sell your data and do not use it for third-party marketing.
4. Age requirement
The service is intended for people who are at least 18 years old. We do not knowingly collect data about anyone under 18. If we learn that a user is under 18, the data is deleted.
5. Legal basis
Consent under GDPR Art. 6(1)(a) for AI calls, call recording and for sharing your profile with employers. Performance of a contract under Art. 6(1)(b) to deliver the matching and to invoice customers. Legitimate interest under Art. 6(1)(f) for security, abuse prevention and service improvement. You may withdraw consent at any time by replying STOP to a text, saying so on the call, or emailing hej@superren.ai.
6. Calls with our AI
Our AI only calls after you have submitted your number and approved contact. At the start of the call you are told that it may be recorded and transcribed to build your CV and to ensure quality. You can end the call or decline recording — in that case we only note what you explicitly ask us to save. The logic at a high level: the AI summarises what you told us into a profile and ranks open assignments based on role, experience, city and availability. The AI makes no hiring decisions — suggestions are recommendations reviewed by a human, and the employer decides on an interview or assignment.
7. Sharing with employers and providers
Your profile or CV is shared with an employer only once you have approved it for that specific request. We also use processors: database and hosting provider (EU region), voice-AI and speech providers, an SMS provider and an email provider. All process data under data processing agreements and only on our instructions. Where a provider processes data outside the EU/EEA, it is based on the European Commission’s standard contractual clauses. We maintain an up-to-date register of our processors and sub-processors. A full list of named providers is available on request — email hej@superren.ai.
8. Retention
Candidate profiles and CVs are kept while you are active in the service and at most 24 months after your last contact with us, then deleted. Call recordings are deleted within 6 months; transcripts underlying your CV are kept with the profile. Accounting records for customer invoices are kept for 7 years as required by Swedish bookkeeping law. If you withdraw consent we delete your data within 30 days, except what we must keep by law.
9. Your rights
You have the right to access, rectify or erase your data, to restrict or object to processing, and to data portability. You also have the right not to be subject to solely automated decisions with legal effect — matching suggestions from our AI are always reviewed before an employer proceeds, and you can always request a human assessment. Complaints can be lodged with the Swedish Authority for Privacy Protection (IMY, imy.se) or your local supervisory authority.
10. Security
Data is protected with encryption in transit (TLS) and at rest with our providers. Access is limited to the people and systems that need it to deliver the service, and access to data is logged. We maintain procedures for handling security incidents and report personal data breaches to the Swedish Authority for Privacy Protection (IMY) within 72 hours, and inform you where a breach poses a high risk to you.
11. Cookies and tracking
Necessary cookies are used to make the site work and to store your choice in the cookie banner. For web analytics we use PostHog (EU hosting, eu.i.posthog.com) to measure visits and usage — the analytics script only loads after you consent in the cookie banner, and you can change or withdraw your choice there at any time. We do not sell data to ad networks. Marketing cookies are only loaded if you explicitly consent to the Marketing category in the banner; if you do not, no such cookies are set.
12. Changes
Material changes to this policy are reflected by an updated date above and apply going forward.