Privacy policy
Updated August 2026
This policy describes how Jonatan Kilefors collects and uses information in connection with independent Human Design analyses. It is written for launch and should be reviewed with appropriate Swedish GDPR guidance before production use on a public domain.
Who is responsible
Jonatan Kilefors is the controller of personal data collected through this website and through the analysis process. Contact: the email address published in the site footer.
What is collected, and when
The public request form collects your name, email, the analysis you are considering, familiarity with Human Design, and a short description of what you would like help understanding. Optional fields include birth date, birthplace, previous-analysis context, and how you heard about this work. The form also records the consents you give.
Birth time and remaining chart details are requested only after an analysis has been accepted, through a private intake link. If birth date and birthplace were not given on the request, they can be provided there.
If you become a client, session recordings are made with explicit consent. Payment details are handled by the payment provider; this site does not store card numbers.
Why it is used
Request data is used to assess fit, correspond with you, and — if the request is accepted — to prepare, deliver, and follow up the analysis. Intake and chart notes are used only to prepare and deliver the work you asked for, and, if you consent, to retain context for a later Integration Reading.
The legal bases we rely on are your consent (for the request, recording, and optional retention) and the performance of a contract (for accepted, paid analyses). Accounting records are kept where Swedish law requires it.
What is not done
Birth data is never placed in analytics, URLs, public logs, or email subject lines. Analysis material is not reused publicly without a separate, explicit consent. This site does not use advertising pixels at launch.
Retention
Declined or expired requests are deleted after 30 days. Pending requests expire after 30 days if they are not reviewed. Client chart and intake notes are deleted 12 months after the final session unless you opt into retention for future integration work. Payment and accounting records are retained according to Swedish legal requirements, separately from analysis notes.
These periods are a starting point and will be confirmed with appropriate Swedish GDPR and accounting guidance.
Your rights
You may request access to, correction of, or deletion of personal data, and you may withdraw consent where processing is based on consent. You may also lodge a complaint with Integritetsskyddsmyndigheten (IMY) in Sweden, or with your local supervisory authority.
To request export or deletion, write from the email address associated with your request or analysis.
Processors
Depending on configuration, requests may be stored with a database provider, emails sent through a transactional email provider, payments processed by Stripe, and scheduling handled by Cal.com. Each processor is used only for the purpose described above.