Guide
Security and data protection
How API keys, traffic, logs, storage and personal data are handled.
This page describes how the service actually runs in production. If you need a data processing agreement, a security annex or answers to your own questionnaire, just get in touch.
Protecting API keys
- The key is never stored in plain text. We keep a SHA-256 hash and compare it in constant time, so a leaked database yields no usable credentials.
- The secret is shown once, when it is issued, and cannot be recovered afterwards.
- A client can hold several active keys at once, so rotation happens without downtime.
- A key can be revoked immediately, and stops working on the next call.
- Keys belong to a machine client. They create no web session, set no cookies, and cannot be used to sign in to firmainfo.se.
Traffic and access
- All traffic goes over HTTPS.
- The API is read-only. There are no endpoints that change data on our side.
- Every resource requires a specific scope, so a key can be limited to exactly the datasets the integration needs.
-
Responses set
Cache-Control: private, no-store, so intermediate caches do not retain the content.
Logs and retention
We log calls for support, debugging and abuse investigation. The log holds the timestamp, method, path, status code, response time, the key's public prefix and the client's IP address.
| Data | Retention | Notes |
|---|---|---|
| IP address in the request log | 30 days | Cleared automatically after that; the row is kept without the IP |
| Other fields in the request log | 90 days | Deleted automatically by a daily job |
| Daily usage counters | Kept | Aggregated figures for billing, no personal data |
Personal data in the dataset
Most resources contain data about legal entities. Four scopes can contain data about natural persons: governance, person_lookup, contacts and market. They are enabled only once your organisation has accepted the current version of our data terms, and person_lookup is granted only after an individual review of the purpose.
- The recipient becomes the data controller for the data retrieved, and is therefore responsible for the legal basis, for informing data subjects and for retention within their own product.
- Sole traders are registered under the owner's personal identity number. The API therefore uses a public token in ordinary flows and shows the identity masked.
- For sole traders the visiting address, coordinates and contact fields are also omitted, because the address is often a home.
-
The
advertising_blockfield mirrors the marketing opt-out in the Statistics Sweden register and must be respected in your own marketing.
Where the data is processed
The service is operated in Sweden and the data comes from Swedish sources: Bolagsverket, Statistics Sweden, Finansinspektionen and PRV, plus GLEIF and ESMA for identifiers. We do not resell your request data and do not use it to profile your customers.
Incident handling
If you suspect a key has leaked, email us and we will revoke it and issue a new one. In an incident affecting your data we contact registered integration owners. Always include the request_id from the response when reporting a technical problem, so we can find the exact call in the log.