Privacy Notice
SimpleSecurity is currently in pre-launch. The operating Swedish company (aktiebolag) is under registration and does not yet have an organization number. This notice will be updated with full legal entity details once registration completes.
1. Controller
The data controller for personal data processed through SimpleSecurity is SimpleSecurity (Swedish company under registration — this notice will be updated with legal entity details). Until registration completes, contact us at security@simplesecurity.se for any privacy inquiry.
2. Data We Process
| Category | Examples |
|---|---|
| Account data | Email address and name, managed via AWS Cognito for authentication. |
| Platform data you enter | Asset inventory (CMDB), monitoring configuration, compliance records, and any other data you input into the platform. |
| Notification & audit records | Alert history, notification delivery logs, and audit trails of actions taken in your account. |
| Employee awareness records | Where your organization uses the People & Awareness module: employee name, work email address, role and department, employment start/end dates, security training completions and quiz scores, policy acknowledgments, and onboarding/offboarding checklist status. Entered by your organization about its own staff — your organization is the controller for this data, and the employees concerned are not users of the platform. |
| Payment data | Handled entirely by Stripe. We never receive or store your card number — only subscription/billing status. |
| Operational logs | Application logs (AWS CloudWatch) generated by normal platform operation, used for debugging and security monitoring of our own infrastructure. |
3. Where Data Is Processed
Your platform data — everything you enter into the Service — is processed and stored in the EU, in AWS eu-north-1 (Stockholm, Sweden), and is not replicated to other AWS regions. Email you send to us (for example to our support@ or admin@ addresses) is handled by our email provider OVHcloud in France (EU). All personal-data processing now takes place in the EU, handled by three EU sub-processors — AWS (Stockholm), Stripe Payments Europe, and OVHcloud (France) — as named in our Sub-processor List. A small number of outbound calls retrieve non-personal public data (such as vulnerability feeds) or look up external technical identifiers during an incident investigation; these do not involve your personal data.
4. Sub-Processors
We use the following sub-processors:
- Amazon Web Services (AWS) — infrastructure hosting, under AWS's standard Data Processing Addendum. Data stays within the EU (eu-north-1), so no Standard Contractual Clauses are required for this processing. This includes Amazon SES (eu-north-1), which delivers our transactional email — including the security awareness training and policy-acknowledgment email sent to employee work addresses on your organization's instruction.
- OVHcloud (Zimbra) — hosts our company mailboxes (
support@,admin@). Email you send to us is stored on OVHcloud servers in France (EU), under OVHcloud's Data Processing Agreement. OVHcloud is ISO 27001, 27017, 27018 and 27701 certified. Data stays within the EU/EEA, so no Standard Contractual Clauses are required. - Stripe — payment processing. Stripe acts as an independent controller for payment data; see Stripe's privacy policy.
We do not use any advertising networks, and we do not sell or rent personal data to any third party. We do not currently use any third-party analytics or tracking service on our public pages or platform.
5. Legal Basis
- Contract (GDPR Art. 6(1)(b)) — processing account data and platform data you enter is necessary to provide the Service you've signed up for.
- Legitimate interest (GDPR Art. 6(1)(f)) — operational and security logging (CloudWatch) to keep the platform secure, debug issues, and detect abuse.
- Legitimate interest of your employer (GDPR Art. 6(1)(f)) — where your organization uses the People & Awareness module, we process employee records and send security training and policy-acknowledgment email to work addresses on your organization's instruction. Your organization is the controller and relies on its own legitimate interest as an employer; we act only as its processor. This email is workplace communication, not marketing, so it carries no unsubscribe link — if you are an employee and wish to object, contact your employer.
6. Retention
We retain your account and platform data for as long as your account is active and as long as needed for the purposes described in this notice. On account closure, your data is deleted. Operational logs are kept only as long as needed for debugging and security purposes before being rotated out.
8. Your Rights
Under GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Erase your data ("right to be forgotten") — you can close your account at any time to trigger deletion.
- Restrict or object to certain processing.
- Receive your data in a portable format (data portability).
- Withdraw consent where processing is based on consent.
To exercise any of these rights, contact security@simplesecurity.se.
9. Complaints
If you believe we have processed your personal data unlawfully, you have the right to lodge a complaint with the Swedish data protection authority, the Integritetsskyddsmyndigheten (IMY) — www.imy.se.
10. Changes to This Notice
We will update this notice as the platform and the operating company evolve, in particular once the Swedish company completes registration. Material changes will be reflected by updating the "Last updated" date above.
11. Contact
Privacy questions or data subject requests: security@simplesecurity.se.