Privacy Notice
Last updated: 15 June 2026
1. Who we are
iThing AB, a company registered in Sweden, operates Zybercomply ("the Service") and is the data controller for personal data processed in connection with the Service. Contact: conny@zyber.se.
2. Personal data we collect
- Account data: name, email address, login credentials, organisation.
- Service content: product descriptions, threat models, comments and other content you submit.
- Support data: messages you send us and related metadata.
- Usage and telemetry: pages visited, features used, errors, device and browser identifiers, IP address, approximate location.
- Billing reference data: a customer reference and subscription status returned to us by Paddle. Full payment details are collected and stored by Paddle, not by us.
3. Why we use it (purposes & legal bases)
- To provide the Service (account creation, authentication, generating threat models and reports) — performance of a contract.
- To process payments and subscriptions via Paddle — performance of a contract and legal obligation (tax, invoicing).
- Security, fraud prevention and abuse monitoring — legitimate interests in protecting the Service and users.
- Product improvement and analytics — legitimate interests in improving the Service.
- Customer support — performance of a contract and legitimate interests.
- Marketing communications — only with your consent, which you can withdraw at any time.
- Legal compliance — legal obligation.
4. AI processing
Content you submit to AI features is sent to our underlying AI providers solely to generate responses for you. We do not use your content to train foundation models.
5. Who we share data with
- Service providers / sub-processors: hosting, database, AI inference, analytics, error monitoring and support tooling, acting on our instructions.
- Merchant of Record: Paddle.com Market Limited, which handles sale of the product, subscription management, payments, tax compliance and invoicing as an independent controller.
- Professional advisers: legal, accounting and audit, where necessary.
- Authorities: where required by law or to protect our rights.
6. International transfers
Some of our service providers are located outside the EEA/UK. Where this is the case, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or adequacy decisions to protect your data.
7. Retention
We keep personal data only as long as needed for the purposes described above: account and service content for the lifetime of your account and a reasonable period afterwards to handle disputes and legal obligations; billing records for the period required by tax law (typically 7 years); support tickets for up to 3 years; usage logs for up to 12 months. After that, data is deleted or anonymised.
8. Your rights
Under the GDPR you have the right to:
- access your personal data and obtain a copy;
- rectify inaccurate data;
- request erasure ("right to be forgotten");
- restrict or object to certain processing;
- data portability;
- withdraw consent at any time, without affecting prior lawful processing;
- lodge a complaint with a supervisory authority — in Sweden this is the Integritetsskyddsmyndigheten (IMY, imy.se).
To exercise these rights, contact conny@zyber.se. We will respond within one month.
9. Security
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS), encryption at rest, role-based access controls, audit logging and regular review of our security practices.
10. Cookies
We use strictly necessary cookies for authentication and session management, and may use analytics cookies to understand how the Service is used. You can manage cookie preferences through your browser. Where required, we will ask for your consent before using non-essential cookies.
11. Changes
We may update this Privacy Notice from time to time. Material changes will be communicated through the Service or by email.