Privacy Notice

Last updated: 15 June 2026

1. Who we are

iThing AB, a company registered in Sweden, operates Zybercomply ("the Service") and is the data controller for personal data processed in connection with the Service. Contact: conny@zyber.se.

2. Personal data we collect

  • Account data: name, email address, login credentials, organisation.
  • Service content: product descriptions, threat models, comments and other content you submit.
  • Support data: messages you send us and related metadata.
  • Usage and telemetry: pages visited, features used, errors, device and browser identifiers, IP address, approximate location.
  • Billing reference data: a customer reference and subscription status returned to us by Paddle. Full payment details are collected and stored by Paddle, not by us.

3. Why we use it (purposes & legal bases)

  • To provide the Service (account creation, authentication, generating threat models and reports) — performance of a contract.
  • To process payments and subscriptions via Paddle — performance of a contract and legal obligation (tax, invoicing).
  • Security, fraud prevention and abuse monitoringlegitimate interests in protecting the Service and users.
  • Product improvement and analyticslegitimate interests in improving the Service.
  • Customer supportperformance of a contract and legitimate interests.
  • Marketing communications — only with your consent, which you can withdraw at any time.
  • Legal compliancelegal obligation.

4. AI processing

Content you submit to AI features is sent to our underlying AI providers solely to generate responses for you. We do not use your content to train foundation models.

5. Who we share data with

  • Service providers / sub-processors: hosting, database, AI inference, analytics, error monitoring and support tooling, acting on our instructions.
  • Merchant of Record: Paddle.com Market Limited, which handles sale of the product, subscription management, payments, tax compliance and invoicing as an independent controller.
  • Professional advisers: legal, accounting and audit, where necessary.
  • Authorities: where required by law or to protect our rights.

6. International transfers

Some of our service providers are located outside the EEA/UK. Where this is the case, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or adequacy decisions to protect your data.

7. Retention

We keep personal data only as long as needed for the purposes described above: account and service content for the lifetime of your account and a reasonable period afterwards to handle disputes and legal obligations; billing records for the period required by tax law (typically 7 years); support tickets for up to 3 years; usage logs for up to 12 months. After that, data is deleted or anonymised.

8. Your rights

Under the GDPR you have the right to:

  • access your personal data and obtain a copy;
  • rectify inaccurate data;
  • request erasure ("right to be forgotten");
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent at any time, without affecting prior lawful processing;
  • lodge a complaint with a supervisory authority — in Sweden this is the Integritetsskyddsmyndigheten (IMY, imy.se).

To exercise these rights, contact conny@zyber.se. We will respond within one month.

9. Security

We apply appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS), encryption at rest, role-based access controls, audit logging and regular review of our security practices.

10. Cookies

We use strictly necessary cookies for authentication and session management, and may use analytics cookies to understand how the Service is used. You can manage cookie preferences through your browser. Where required, we will ask for your consent before using non-essential cookies.

11. Changes

We may update this Privacy Notice from time to time. Material changes will be communicated through the Service or by email.