Privacy
Privacy policy
Pressmatch is operated by Politek AB (org.nr 556869-0423), Box 11032, 100 61 Stockholm. We are the controller for the processing described below unless stated otherwise. Questions: privacy@pressmatch.io.
Who this policy covers
- Journalists and media contacts in our database (section 1).
- Customers and users of the service (section 2).
- Visitors to pressmatch.io (section 3).
- Followers of a customer's press room (section 4).
- For a customer's own contact lists, the customer is the controller and we are the processor (section 4).
1. Journalists and media contacts
- Data
- Name, employer and job title, subjects covered, and professional contact details. We also keep the link to your public profile or author page and when you last appeared on a byline — that is how we judge whether the data is still current.
- Source
- The data is not collected from you directly. It comes from public editorial sources — publishers' websites, bylines and similar.
- Purpose
- To pass relevant press releases to journalists whose subjects match, and to keep the database current.
- Legal basis
- Legitimate interest (article 6(1)(f)) — our and our customers' interest in reaching the right journalists, weighed against your privacy. Matching reduces irrelevant sendouts, which is in your interest too.
- Matching
- We match a subject against the subjects you cover to judge relevance. It has no legal or similarly significant effect on you, so it is not automated decision-making under article 22. Data may also be used in aggregate to assess our subject coverage.
- Your choices
- You may object to the processing and unsubscribe at any time (section 6).
If you sign in to the journalist portal
The portal is not a sign-up but a door into what we already hold about you: a sign-in link is only ever sent to an address that is already in our database as a journalist. You sign in with a one-time link to your email address — it expires shortly, works once, and we keep only a cryptographic fingerprint of it, never the link itself. There is no password.
The account carries what you set yourself: which subjects you want prioritised or declined, whether to pause sendouts until a date you choose, your display name and your language. We also note when you last signed in. The purpose is to let you govern what reaches you; the basis is legitimate interest (article 6(1)(f)) — yours in deciding, ours in being able to honour what you decided. If you stop everything (section 6), that decision is kept; otherwise the block would be lost.
If the sender measures opens and clicks
Measurement is off to begin with, and it takes two deliberate choices by the sender: one for the account and one for the individual sendout. With both on, we record that an email was opened or a link was clicked, which link it was, when it happened and which recipient row it belonged to. We store no IP address and no browser information for those events. They are used for that sendout's statistics — never to build a profile of you. The same applies when a customer sends to their own contacts (section 4).
2. Customers and users
- Data
- Account and contact details (name, email, organisation, role), and login and usage data. Failed sign-in attempts are stored with the IP address and the address that was typed — that is how we stop password guessing. The brake applies to the guessing IP address only, never to an account: otherwise someone else could lock you out.
- Purpose
- To provide and secure the service, billing, support, and improving the service.
- Legal basis
- Performance of a contract (article 6(1)(b)) for the service itself; legitimate interest (article 6(1)(f)) for security and improvement; legal obligation (article 6(1)(c)) for accounting and similar.
3. Visitors to pressmatch.io
No page here contains analytics, measurement or advertising scripts, and the pages you can read — this one, the start page — set no cookies at all. We do not measure you while you read, which is why there is no consent banner to dismiss.
The pages with a form are the exception, and they set the cookie when the page opens rather than when you send anything: it carries the token that proves the form came from us and not from somewhere else. Logging in to the service sets the same session cookie. It is strictly necessary for the function, is not used for anything else, and needs no consent for exactly that reason. Our web server also keeps ordinary operational logs.
If you try the match
When you try the match on the site we keep what you fill in — your email address and the text you paste — together with the result we showed you, a keyed hash of your IP address and your browser's user-agent string. We need the text to produce the match: it is classified by subject, compared against what journalists cover, and it yields one short writing suggestion. An AI provider processes the text for us, as our processor. The result is stored in the form you see it — without the journalists' names and addresses.
Your address is checked by an address-validation processor before anything runs, and a copy of the result is emailed to you. The purpose is to show you the result, to keep bots and abuse out, and to understand how the test is used; the basis is our legitimate interest (article 6(1)(f)). Submissions that are refused are kept too, as a record of how much of this traffic is automated — we never market to them. Tips and offers are sent only if you tick that box yourself. If you want the text and the address removed sooner than that, ask us (section 6).
If you apply for a beta place
We keep what you type in the form — organisation, website, your name, role, work address and your description of what you send out — together with a keyed hash of your IP address and your browser's user-agent string. The hash lets us tell repeated submissions apart without storing the address itself. The purpose is to assess the application and to answer you; the basis is our legitimate interest (article 6(1)(f)) in handling enquiries about our own service.
Your address is checked for deliverability by an address-validation processor before we store the application, so that we do not accept an application we could never answer. Submissions our spam protection refuses are kept too, as a record of how much of this traffic is automated — we never market to them. Tips and offers are sent only if you tick that box yourself, and you can withdraw that at any time.
4. A customer's own contact lists
When a customer uploads or builds their own contact lists in the service, the customer is the controller and Politek AB (org.nr 556869-0423) is the processor. The processing is governed by a data processing agreement.
Followers of a press room
Anyone can follow a customer's press room with their email address. The subscription must be confirmed through a link in an email before anything is sent, so the basis is your consent — and you can withdraw it at any time through the link in every sendout. We keep the address, the times of the request, the confirmation and any unsubscribe, and a cryptographic fingerprint of the one-time links, never the links themselves. An unsubscribe is not deleted: the row stays as proof that you said no — without it the block can be lost. The customer decides their press room and what goes out from it; we run the mechanism.
5. Recipients and processors
We share data with processors who help us run the service: email delivery, address validation, hosting and operations, and AI-based text processing. All are bound by data processing agreements and process data only on our instructions. Our customers see journalists' professional data when they prepare a sendout.
What you write is not used to train AI models. Neither customers' text nor journalists' data becomes training material — our AI provider's terms forbid it without our permission, and we have given no such permission.
We aim to process data within the EU/EEA. Where any processing takes place outside the EU/EEA, appropriate safeguards apply, such as the EU standard contractual clauses (SCCs). If you want to know which processors we use, ask us and we will tell you.
6. Your rights
You have the right to request access, rectification, erasure, restriction and to object to processing; the right to data portability where that basis applies; and to withdraw consent where processing relies on it.
If you are a journalist and want the sendouts to stop, there are two routes, and they do different things:
- The unsubscribe link in a sendout stops that sender. Other customers can still reach you.
- The journalist portal — or an email to privacy@pressmatch.io — stops all press releases through Pressmatch. You sign in with a one-time link sent to your address; the same place lets you choose which subjects you want, and pause everything until a date you choose.
You have the right to complain to the Swedish Authority for Privacy Protection (IMY), imy.se. Contact us at privacy@pressmatch.io.
7. Retention
We state the criteria for how long data is kept:
- Journalist and media contacts: for as long as you are an active journalist and the data is current.
- Account and customer data: for the duration of the customer relationship and for as long as the law requires.
- A journalist portal account: for as long as the account is used, and after that for as long as your choices need honouring.
- Followers of a press room: for as long as the subscription is active. An unsubscribe stays as proof.
- Open and click events: they belong to their sendout and are kept for its statistics.
- Match tests and beta applications: for as long as they are needed to answer you and to understand how the service is used.
- Proof of an unsubscribe or block: kept so that we can keep honouring your request. Deleting the proof would mean losing the block.
The criteria are ours, but automated deletion jobs do not yet enforce them for every category — that work is under way, and it is listed among the open points. If you ask us to erase something, we do (section 6).
8. Changes
We may update this policy. The current version is always at https://pressmatch.io/about/privacy, with the date it was last changed.
Open points
The following is not settled yet and will be filled in:
- Processors by name. We list categories today, not names. Ask us and we will tell you.
- Where each processor handles data. We do not state a country per processor until we have confirmed it against that processor's own documentation.
- Data protection officer. Whether we fall under the article 37 requirement is being assessed.
- Responsibility for a press room's follower list. Who is controller and who is processor when someone follows a customer's press room is for the legal review to settle. The processing is described in section 4 either way.
- Automated deletion. The criteria in section 7 apply, but the jobs that are to enforce them are not yet running for every category.
- The last-changed date will be set when the policy is final.