Privacy Notice

Last updated: 18 July 2026

On this page

  1. Controller
  2. Data We Process
  3. Where Data Is Processed
  4. Sub-Processors
  5. Legal Basis
  6. Retention
  7. Cookies & Local Storage
  8. Your Rights
  9. Complaints
  10. Changes to This Notice
  11. Contact

  SimpleSecurity is currently in pre-launch. The operating Swedish company (aktiebolag) is under registration and does not yet have an organization number. This notice will be updated with full legal entity details once registration completes.

1. Controller

The data controller for personal data processed through SimpleSecurity is SimpleSecurity (Swedish company under registration — this notice will be updated with legal entity details). Until registration completes, contact us at security@simplesecurity.se for any privacy inquiry.

2. Data We Process

Category Examples
Account data Email address and name, managed via AWS Cognito for authentication.
Platform data you enter Asset inventory (CMDB), monitoring configuration, compliance records, and any other data you input into the platform.
Notification & audit records Alert history, notification delivery logs, and audit trails of actions taken in your account.
Payment data Handled entirely by Stripe. We never receive or store your card number — only subscription/billing status.
Operational logs Application logs (AWS CloudWatch) generated by normal platform operation, used for debugging and security monitoring of our own infrastructure.

3. Where Data Is Processed

All data is processed and stored exclusively in AWS eu-north-1 (Stockholm, Sweden). We do not replicate or transfer personal data to other AWS regions or outside the EU/EEA.

4. Sub-Processors

We use the following sub-processors:

  • Amazon Web Services (AWS) — infrastructure hosting, under AWS's standard Data Processing Addendum. Data stays within the EU (eu-north-1), so no Standard Contractual Clauses are required for this processing.
  • Stripe — payment processing. Stripe acts as an independent controller for payment data; see Stripe's privacy policy.

We do not use any advertising networks, and we do not sell or rent personal data to any third party. We do not currently use any third-party analytics or tracking service on our public pages or platform.

5. Legal Basis

  • Contract (GDPR Art. 6(1)(b)) — processing account data and platform data you enter is necessary to provide the Service you've signed up for.
  • Legitimate interest (GDPR Art. 6(1)(f)) — operational and security logging (CloudWatch) to keep the platform secure, debug issues, and detect abuse.

6. Retention

We retain your account and platform data for as long as your account is active and as long as needed for the purposes described in this notice. On account closure, your data is deleted. Operational logs are kept only as long as needed for debugging and security purposes before being rotated out.

7. Cookies & Local Storage

SimpleSecurity does not use tracking or advertising cookies. We use browser localStorage and sessionStorage — not cookies — for the following, strictly necessary purposes:

  • Authentication tokens (e.g. access/ID/refresh tokens, session data) — required to keep you signed in and to authorize requests to our API. Cleared when you sign out.
  • Local UI personalization (e.g. session count, last-visit timestamp, which features you've used) — stored only in your browser to drive in-app elements like "Account Health" and returning-user messaging. This data is never transmitted to us or any third party.

Because none of this is used for tracking, advertising, or cross-site profiling, it falls under "strictly necessary" storage and does not require cookie-consent banner opt-in under EU ePrivacy rules.

8. Your Rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate data.
  • Erase your data ("right to be forgotten") — you can close your account at any time to trigger deletion.
  • Restrict or object to certain processing.
  • Receive your data in a portable format (data portability).
  • Withdraw consent where processing is based on consent.

To exercise any of these rights, contact security@simplesecurity.se.

9. Complaints

If you believe we have processed your personal data unlawfully, you have the right to lodge a complaint with the Swedish data protection authority, the Integritetsskyddsmyndigheten (IMY) — www.imy.se.

10. Changes to This Notice

We will update this notice as the platform and the operating company evolve, in particular once the Swedish company completes registration. Material changes will be reflected by updating the "Last updated" date above.

11. Contact

Privacy questions or data subject requests: security@simplesecurity.se.

  Home Terms of Service Trust Center