Privacy policy

Last updated: 13 August 2026

This policy explains how personal data is handled in the Merlon service (merlon.schotteniuspartners.com) and on this website (www.merlon.se).

1. Who is responsible

The Merlon service is operated by Schottenius & Partners AB (org.nr 556673-1898), registered in Sweden at Norrgatan 10, 432 41 Varberg (“we”, “us”). We act as the data controller for the processing described in this policy.

Where Merlon processes personal data on behalf of a customer organization using the service, that organization may instead be the controller and we act as its processor under a data processing agreement.

Questions about this policy or about your personal data: merlon@schotteniuspartners.com.

2. What data we process

Account and sign-in data

Users sign in with their work account, through their organization's sign-in (single sign-on). From that sign-in we receive and store your name, work email address(es), and your organization identifiers. If you link several work email identities to one Merlon account, each linked identity is stored.

Receipt and expense data

Receipts you submit (as photos, uploaded files, or emails) are stored together with the details extracted from them: supplier, date, amounts, VAT, currency, and similar bookkeeping fields. Receipts are associated with the user who submitted them and the company they belong to.

Transaction data from connected services

When an organization connects its accounting system, company-card provider, or bank, Merlon syncs financial data from those services: booked accounting data, card transactions (which can identify the card holder), and bank account transactions and balances. This data is used for receipt matching and finance reporting.

Email data

Email reaches Merlon in two distinct ways, handled differently:

Technical data

Like most web services, we keep technical logs (such as IP addresses, timestamps, and events in the service) for operating and securing the service. This website (www.merlon.se) is a static site and sets no cookies and uses no analytics. The application at merlon.schotteniuspartners.com uses only strictly necessary session cookies for sign-in.

3. Why we process it, and on what legal basis

Providing the service
Receiving receipts, extracting their details, matching them to transactions, producing finance reports, and exporting finished bookkeeping to the accounting system. Legal basis: performance of a contract with the user's organization and our legitimate interest in operating the service for the organizations that use it (Article 6(1)(b) and (f) GDPR).
Automatic receipt detection in connected mailboxes
Detecting supplier invoices in a mailbox the user has chosen to connect, as described in section 2. Legal basis: the user's consent (Article 6(1)(a) GDPR), given via the mailbox connection flow. Disconnecting the mailbox withdraws the consent.
Bookkeeping and legal obligations
Receipts and accounting records are part of the organization's statutory bookkeeping material. Legal basis: compliance with legal obligations (Article 6(1)(c) GDPR), including retention requirements under the Swedish Bookkeeping Act.
Security and operations
Logging, abuse prevention, troubleshooting, and keeping the service available and secure. Legal basis: our legitimate interest (Article 6(1)(f) GDPR).

4. Who processes data on our behalf

We use a small number of service providers (processors/subprocessors):

In addition, data flows to and from the services an organization itself connects: its accounting system, company-card provider, bank, and identity/mailbox provider. Each of those providers processes data under its own agreement with the organization and its own privacy terms; Merlon exchanges data with them only as needed to provide the service the organization has connected.

We will update this policy if the list of service providers changes.

5. How long we keep data

6. International transfers

The service is hosted in the EU (AWS eu-north-1, Stockholm). The use of OpenAI for receipt data extraction may involve transferring personal data to the United States. Such transfers are made subject to appropriate safeguards, such as the EU Standard Contractual Clauses and, where applicable, the provider's certification under the EU–U.S. Data Privacy Framework.

7. Your rights

Under the GDPR you have the right to:

To exercise these rights, contact merlon@schotteniuspartners.com. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY, www.imy.se) or your local supervisory authority.

8. Changes to this policy

We may update this policy as the service evolves. Material changes will be announced in the service, and the “Last updated” date above always reflects the current version.