Privacy Policy
Last updated: 15 September 2026
1. Who Is the Data Controller?
The data controller for the processing of personal data is:
CyberResilient AB
Org.nr: 556702-0200
Email: info@cyberresilient.se
Questions about information security, or a vulnerability you want to report, go to security@cyberresilient.se. More about how we protect data is in our Trust Center.
2. What Personal Data Do We Collect?
Information you provide when registering:
- Name
- Email address
- Telephone number, if you provide it
- Organisation name
- Position or role in the organisation
Information about your organisation that you provide when getting started:
- Organisation number, sector, size, turnover band and countries of operation
- A description of the business, if you write one
Data that arises when you use the Service:
- Login and account information (for example time of registration and last login)
- Technical logs (for example IP address, browser type and time of access)
- Your answers in assessments and the notes you write alongside them
- Documents you upload as evidence
- Reports, action plans and risk registers
Information you provide on our website:
- Name, email address, organisation and message when you fill in a form, for example to request documents, become a partner or subscribe to news
3. Why Do We Process Your Personal Data and on What Legal Basis?
To create and administer your account
- Purpose: Create a user account, enable login and access to the Service, manage permissions
- Information: Name, email address, phone number, organisation name, login details
- Legal basis: Performance of contract (Article 6(1)(b) GDPR) to provide services to your organisation
To provide and develop the Service
- Purpose: Conduct assessments, produce reports and recommendations, link uploaded evidence to the right question, improve features, user experience and security, follow usage at an aggregate level (statistics)
- Information: Your answers and notes, uploaded evidence, organisation details, usage data, technical logs
- Legal basis: Legitimate interest (Article 6(1)(f) GDPR) in providing, developing and improving the Service and ensuring IT and information security
AI processing
The Service uses language models to read uploaded evidence, link it to the right question, and write the report's observations and recommendations. Processing takes place at our AI provider in Sweden.
- Information sent: Text from uploaded evidence, your answers and notes, and sector, size band and business description from the organisation profile. Organisation number and turnover are not sent.
- No training: We do not train or fine-tune any model on your data.
- Legal basis: The same as for providing the Service above
For customer service and support
- Purpose: Answer questions, handle bug reports, help you use the Service
- Information: Contact information (name, email, telephone), information about your organisation, the content of your question or case
- Legal basis: Legitimate interest in providing service and support (Article 6(1)(f) GDPR)
To handle requests from the website
- Purpose: Respond to requests for documents, partnerships and demonstrations, and send newsletters you have signed up for
- Information: Name, email address, organisation, role and the content of the request
- Legal basis: Legitimate interest (Article 6(1)(f) GDPR) in responding to requests you sent yourself. For newsletters: consent (Article 6(1)(a) GDPR), which you can withdraw at any time
For sending information and marketing communications (optional)
- Purpose: Send information about updates to the Service, news, tips or invitations to webinars and events about cybersecurity
- Information: Name, email address, organisation
- Legal basis: Legitimate interest (Article 6(1)(f) GDPR) in communicating with existing users in a professional role about services and information relevant to their activities
- Your right to object: You may object to marketing communications by clicking the unsubscribe link in emails or contacting info@cyberresilient.se
4. How Long Do We Keep Your Personal Data?
User accounts and account information
Information linked to your user account is kept as long as the account is active and you use the Service. If your account is inactive (no login) for 36 months, we may contact you to confirm whether you still want to keep it. If we do not receive a response within 30 days, the account may be deleted.
Deleted accounts
If you actively choose to delete your account:
- You have 30 days from the deletion request to export your data
- After these 30 days, your personal data is permanently deleted or anonymised
- Data in backups may remain for up to 30 additional days, after which it is deleted
Assessments, evidence and reports
Your answers, notes, uploaded evidence and generated reports are kept as long as your account is active. If you delete your account, they are deleted according to the timeframes above.
Technical logs and backups
Technical logs (IP addresses, login attempts, system events) are kept for at most 12 months for IT security, troubleshooting and traceability. Backups are kept for at most 90 days so that the Service can be restored.
Requests from the website
Data from website forms is kept while the request is being handled and for as long as there is ongoing contact between us. Newsletter sign-ups are kept until you unsubscribe.
Marketing communications
Data for marketing communications (name, email, organisation) is kept as long as you are an active user or until you opt out. If you opt out, your choice is kept permanently. If your account is inactive for 36 months and you have not interacted with marketing communications, we may remove you from the marketing list.
Accounting documents and legal requirements
Data that must be kept under the Swedish Accounting Act (for example invoices, payment information and agreements) is kept for 7 years from the end of the financial year. Data retained under other legal obligations is kept for as long as the obligation persists.
Anonymised and aggregated data
Anonymised and aggregated data that does not identify you or your organisation may be kept indefinitely for statistics, benchmarking and product development.
5. To Whom Do We Disclose Personal Data?
Where the Service runs
The Service is operated within the EU. The database and uploaded evidence are stored with Hetzner in Germany, and AI processing takes place at Berget AI in Sweden.
Encryption
All traffic to the Service is encrypted in transit with TLS. Selected data is also encrypted at application level with AES-256-GCM, using keys only we have access to. This includes two-factor secrets, IP addresses and browser details in sessions, security logs and the processed results reports are built from.
Data processors within the EU/EEA
- Hetzner Online GmbH (Germany): Hosting, database and storage of uploaded files. Categories: all information stored in the Service. Legal basis: performance of contract (Article 6(1)(b) GDPR).
- Berget AI (Sweden): AI processing with language models. Categories: text from uploaded evidence, answers and notes, sector, size band and business description. Legal basis: legitimate interest (Article 6(1)(f) GDPR).
- Stripe Payments Europe, Ltd. (Ireland): Payments and invoicing. Categories: billing details and billing contact details. Legal basis: performance of contract (Article 6(1)(b) GDPR) and legal obligation (Article 6(1)(c) GDPR). Stripe may transfer data to the US, see section 6.
Data processors outside the EU/EEA
- Resend, Inc. (USA): Sending email from the Service, such as invitations, one-time codes and notifications. Categories: email address, name and the content of messages. Legal basis: performance of contract (Article 6(1)(b) GDPR).
- Slack Technologies, LLC (USA): Internal communication, support and operational alerts. Categories: contact details and the content of support cases, and technical error messages that in exceptional cases can contain excerpts of generated content. Legal basis: legitimate interest (Article 6(1)(f) GDPR).
- Vercel Inc. (USA): Hosting of the website cyberresilient.se. Categories: technical visit data and the content of forms submitted through the website. Legal basis: legitimate interest (Article 6(1)(f) GDPR).
- Attio Ltd (United Kingdom): Customer records for requests and newsletters from the website. Categories: name, email address, organisation, role and the content of the request. Legal basis: legitimate interest or consent, see section 3.
- Google and LinkedIn: Analytics and campaign measurement on the website, only with your consent. See section 10.
A current list of subprocessors is available on request from security@cyberresilient.se.
Sharing with group companies
Personal data is shared with:
- Cyber Defencely Sweden AB (559501-5594)
- Navis Mater AB (559537-7184)
- Internetworking Stockholm AB (556990-8220)
Purpose: joint management of user accounts, support and customer service, monitoring and development of the Service, joint administration and IT operations.
Data shared: name, email, phone, organisation, position or role, account information, support cases.
Legal basis: performance of contract (Article 6(1)(b) GDPR). All companies are in Sweden and subject to GDPR.
Other recipients
- Authorities and regulatory bodies (if required by law)
- Accountants and legal advisors
- Potential buyers (in the event of a sale)
6. Transfer to Countries Outside the EU/EEA
The Service's database, uploaded evidence and AI processing are located within the EU. Personal data can be transferred outside the EU/EEA when we send email, take payment, communicate internally, host the website and handle requests from it, through the suppliers listed in section 5.
For such transfers we ensure a legal basis and adequate protection through:
- European Commission adequacy decisions, including the EU–US Data Privacy Framework and the decision on the United Kingdom, or the EU Standard Contractual Clauses
- Technical and organisational measures, including encryption and access control
- Supplier assessment focused on security and data protection
7. How We Protect Your Personal Data
We work according to a documented information security management system built on ISO/IEC 27001. Technical and organisational measures include:
- Two-factor authentication, strong password requirements and protection against password guessing
- A check on every request that you only reach the organisations you have access to
- Encryption in transit and additional application-level encryption for sensitive data
- Logging of access to uploaded evidence
- Daily backups
- Two-factor authentication and personal accounts for all our staff, and confidentiality agreements for employees and contractors
A fuller description is in our Trust Center.
No internet-based service can be completely secure against all threats. In the event of a personal data breach likely to result in a high risk to you, we will notify you without undue delay in accordance with Article 34 GDPR.
8. Your Rights
Under GDPR you have the right to:
- Access your personal data and information about how it is processed
- Have inaccurate or incomplete data corrected
- Have data deleted in certain circumstances ("right to be forgotten")
- Restrict processing in some cases
- Object to processing based on legitimate interest
- Withdraw consent without affecting processing that took place before
- Receive data you have provided in a portable format
Regarding AI: We do not use automated decision-making within the meaning of Article 22 GDPR. Recommendations are advisory, and you retain the right to information and to express your view.
How to exercise your rights: Contact info@cyberresilient.se.
Response time: Within one month of receiving your request (can be extended to three months in complex cases). Requests are normally handled free of charge.
9. Right to Lodge a Complaint
If you believe your personal data has been processed in violation of GDPR, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY):
- Website: www.imy.se
- Phone: 08-657 61 00
- Email: imy@imy.se
- Address: Box 8114, 104 20 Stockholm
10. Cookies and Similar Technology
Necessary cookies are always active and cover:
- Authentication and sessions
- Security and access control
- Technical operation and basic functionality
Analytics and tracking cookies are only set with your explicit consent. When you opt in, we use:
- Google Analytics: to understand how visitors use the site (anonymised IP).
- Google Ads conversion tracking: to measure whether campaigns lead to meaningful actions such as sign-ups or demo requests.
- LinkedIn Insight Tag: to measure the effectiveness of our campaigns.
You can change or withdraw your consent at any time via the "Cookie Settings" link in the footer. These tools process cookie and usage information on our behalf for analytics and campaign measurement, and only when you have consented.
11. Changes to This Privacy Policy
We may update this Privacy Policy at any time. Material changes will be notified at least 30 days in advance. Minor updates may be made without prior notice and take effect when published. Continued use of the Services after changes take effect constitutes acceptance.