Privacy
What this site does with your data
This site has no analytics, advertising or tracking. It handles what you submit through its three forms, plus the request data its hosting provider logs. Everything below describes what the source and published provider terms establish.
- Controller
- Cryvanta AB
- Trackers
- None
- Cookies
- None
- Updated
- 6 August 2026
Who is responsible
The controller for the personal data described here — the party that decides why and how it is processed (GDPR Art. 4(7)) — is:
- Company
- Cryvanta AB
- Org. number
- 559593-0537
- VAT number
- SE559593053701
- Geographic address
- Hammarbybacken 27, 120 30 Stockholm
- Registered seat (säte)
- Stockholm
- Contact
- hello@cryvanta.io
No data protection officer contact is published here. This repository cannot establish whether one has been appointed or is required: that assessment depends on the controller's core activities across the organisation, not only this marketing site (GDPR Art. 37(1)). The account owner must verify the position before making a broader claim, including for the AI SOC platform that is outside this notice.
What we collect, and why
Four things happen on this site that involve personal data. Each has its own purpose and its own lawful basis (GDPR Art. 13(1)(c), Art. 6).
- Contact form
- Your name, email address, organisation if you give one, the topic you pick and what you write. Used to answer you and to have the conversation you asked for. A service enquiry or early-access request made on your own behalf is processed to take steps you ask for before a possible contract (Art. 6(1)(b)). Other correspondence, such as partnership or speaking enquiries, relies on our legitimate interest in answering correspondence addressed to us (Art. 6(1)(f), Art. 13(1)(d)).
- Incident form
- The affected organisation, how to reach you, and what you tell us you are seeing. Basis: our legitimate interest in responding quickly to a reported security incident so we can help (Art. 6(1)(f)), and, for your own contact details, taking steps at your request toward possible services for you, Art. 6(1)(b). Please give us only what we need to reach you and understand the shape of the problem — the detail belongs on the call, not in a web form (Art. 5(1)(c)).
- Newsletter
- Your email address, and nothing else. Basis: your consent (Art. 6(1)(a)), which you can withdraw at any time by writing to us, or through an unsubscribe link where a message provides one (Art. 7(3)). Withdrawing does not affect anything sent before you did.
- Server logs
- Our hosting provider records the usual request data, including your IP address, in order to serve the page and to keep the site up. Basis: our legitimate interest in operating and securing the site (Art. 6(1)(f)).
There is no profiling and no automated decision-making about you on this site (Art. 13(2)(f), Art. 22). Form and newsletter submissions are voluntary; without the requested fields we cannot answer or add you to the list (Art. 13(2)(e)). Request logs are created automatically when your browser asks the hosting service for a page.
Photographs of our own team appear on the site, published on the basis of our legitimate interest in showing customers who will actually be doing the work (Art. 6(1)(f)). If you are one of them and want yours taken down, write to the address above and we will handle the request under the rights described below.
Who else handles it
We do not sell personal data and we do not share it for anyone else's marketing. Three companies handle it because they run parts of this site for us (GDPR Art. 13(1)(e)):
- Vercel Inc.
- United States. Hosts the site and runs its server code, so it processes every request — including your IP address and anything you submit, in transit. We have configured the site's server code to run in Vercel's Stockholm region, but Vercel routes traffic through points of presence worldwide and does not document where its logs are stored, so we do not claim the request path stays inside the EU.
- Resend
- Plus Five Five, Inc., trading as Resend, United States. Delivers the email our contact and incident forms generate, and holds the newsletter list.
- Telegram
- When an incident report arrives we send a message to a Telegram group to make our phones ring. That message deliberately contains no personal data at all — it says a report has arrived and nothing more. The report itself travels by email and never reaches Telegram.
The web fonts are downloaded from Google when the site is built and then served from our own domain, so your browser never contacts Google and no request of yours is disclosed to them.
What leaves the EU
Vercel and Resend are United States companies, so using them transfers personal data outside the EU/EEA (GDPR Chapter V). This is what each relies on (Art. 13(1)(f)):
- Vercel Inc.
- Vercel's published data processing addendum for eligible paid plans applies the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914). Vercel Inc. is additionally self-certified under the EU–US Data Privacy Framework (Commission Implementing Decision of 10 July 2023).
- Resend
- Resend's published data processing addendum applies the same standard contractual clauses, and Resend states that it is self-certified under the EU–US Data Privacy Framework.
Vercel's plan and contractual coverage are account facts that this repository does not establish. The account owner must verify them; the source code is not evidence that a particular addendum applies. The providers publish their transfer terms in the Vercel DPA and the Resend DPA (Art. 13(1)(f)).
How long we keep it
(GDPR Art. 13(2)(a), Art. 5(1)(e))
- Enquiries
- while needed to answer you and manage any resulting business relationship; this repository does not implement or evidence the required account-side review
- Incident reports
- while needed to respond and handle any resulting engagement or legal claim; this repository does not implement or evidence the required account-side review
- Newsletter
- until you unsubscribe; Resend then suppresses future sends, but the contact remains until it is deleted separately
- Server logs
- according to the Vercel account's plan and logging configuration; no retention period or log drain is set in this repository
This website has no database, deletion job or retention timer. Enquiries and incident reports sit in a mailbox; the newsletter list sits with Resend. Mailbox review and deletion must therefore happen manually outside this codebase, and the source cannot demonstrate that they are happening. We publish criteria rather than promise a fixed period this code does not enforce. An unsubscribe suppresses future newsletters; it does not by itself erase the Resend contact record.
Resend states that it retains email data for thirty days, but does not publicly define whether that covers the body of a message or only the surrounding logs. We would rather tell you that than round it into a promise we cannot stand behind.
Your rights
You can ask us to do any of the following, and we will answer within one month (GDPR Art. 12(3)). Write to hello@cryvanta.io — there is no form and no portal.
- Access
- A copy of what we hold about you (Art. 15).
- Rectification
- Correct anything wrong (Art. 16).
- Erasure
- Ask for erasure where the conditions in Art. 17 are met.
- Restriction
- Ask us to restrict processing in the cases listed in Art. 18.
- Portability
- Receive it in a machine-readable form (Art. 20). This applies to data you provided that we process automatically on consent or under Art. 6(1)(b): here, your newsletter subscription and form data where the request was a step toward services for you. It does not cover correspondence processed only on our legitimate interests.
- Objection
- Object to processing we base on legitimate interests (Art. 21).
- Withdraw consent
- For the newsletter, at any time (Art. 7(3)).
If you think we have got this wrong, you can complain to the Swedish data protection authority, Integritetsskyddsmyndigheten (IMY) — or, if you would rather, to the authority in the EU country where you live or work (Art. 77(1)). We would rather you told us first, but you are not obliged to.
What this site does not do
Stated positively because it is easier to verify than a promise:
- No analytics
- No analytics product of any kind, first- or third-party.
- No advertising
- No advertising pixels, no conversion tracking, no remarketing.
- No embeds
- No third-party fonts, maps, videos, chat widgets or social embeds loading in your browser.
- No CRM
- Contact and incident submissions go to the configured mailbox. They do not enter a sequence and nobody is scored.
You can check most of this yourself: open your browser's network tab on any page here and see what it requests.
Changes
This notice records the implementation and provider information reviewed on 6 August 2026. The date at the top is the point to check when comparing a later version.
Our company details are on the company details page, and the terms covering use of this site are in the terms of use.

Ask us anything about this
If something here is unclear, or you want to exercise one of those rights, write to us and a person will answer.