GDPR Compliance Statement
SimpleSecurity is currently in pre-launch. The operating Swedish company (aktiebolag) is under registration — org.nr [ORG-NR] will be inserted here once registration completes.
1. Our Commitment
SimpleSecurity is committed to processing personal data in accordance with the EU General Data Protection Regulation (GDPR). Our role depends on the data in question:
- For customer platform data — the asset inventory, monitoring configuration, compliance records, and other data customers enter into the SimpleSecurity platform — SimpleSecurity acts as processor, and the customer is the controller.
- For SimpleSecurity's own account and billing records — customer contact details, subscription status, and invoicing data — SimpleSecurity acts as controller.
2. Lawful Processing
Processing is carried out on the following legal bases, consistent with our Privacy Notice:
- Contract (GDPR Art. 6(1)(b)) — processing account data and platform data is necessary to provide the Service the customer has signed up for.
- Legitimate interest (GDPR Art. 6(1)(f)) — operational and security logging is used to keep the platform secure, debug issues, and detect abuse.
3. EU Data Residency
All customer data is processed and stored exclusively in AWS eu-north-1 (Stockholm, Sweden). By design, there are no third-country transfers of personal data.
4. Data Processing Agreement (Art. 28)
SimpleSecurity offers a signable Data Processing Agreement covering the requirements of GDPR Art. 28 for customers who require one for their vendor assessment. See Data Processing Agreement.
5. Security Measures (Art. 32)
SimpleSecurity maintains technical and organisational measures appropriate to the risk, including tenant-isolated data storage, encryption in transit and at rest, Cognito-backed authentication with enforced MFA options, AWS WAF and API throttling, CloudTrail/CloudWatch audit logging, and DynamoDB point-in-time recovery. The full set of measures is documented in Technical and Organisational Measures (TOMs).
6. Breach Notification (Art. 33/34)
SimpleSecurity notifies affected customers of a personal data breach without undue delay and in any case within 72 hours of becoming aware of it, with the information required by GDPR Art. 33(3). Full process detail is in Incident Response & Breach Notification.
7. Data Subject Rights
Data subjects have the right to access, rectify, erase, and receive a portable copy of their personal data. In practice:
- Organization admins can permanently delete an entire organization — all users, assets, monitors, incidents, policies, vendor records, and settings — self-service from the dashboard ("Danger Zone" in User Management → Security), with typed confirmation.
- Erasure and other data subject requests are also honored on written request to security@simplesecurity.se within 30 days.
8. Retention
Data is retained for as long as an account is active and as needed for the purposes described in our Privacy Notice. Retention periods by data category are set out in Data Retention.
9. Sub-Processors
The current list of sub-processors that receive personal data on SimpleSecurity's behalf is maintained at Sub-Processors.