Privacy Policy
Secure State Cyber develops information security from both a technical and legal perspective, with the goal of creating security for everyone in the digital society. Secure State Cyber is a European-Canadian company and therefore complies with the General Data Protection Regulation (GDPR). We take data protection seriously and ensure that personal data is handled lawfully, fairly, transparently and securely.
This privacy policy describes how Secure State Cyber processes personal data when acting as a data controller, including what personal data we collect, for what purposes, on what legal grounds, how long data is stored, who may access it, and what rights you have as a data subject.
Our policy applies to all Secure States Cyber services and other interactions with Secure State Cyber, including but not limited to:
• Customers and potential costumers
• Participants in surveys, e-learning activities, events and training
• Security-related activities such as penetration testing
• Website visitors
• Newsletter subscribers
• Recruitment candidates
• Other contacts via email, forms and meeting
The privacy policy will be updated periodically. All changes to the policy will be published on this page, and in the event of significant changes, we will clearly state this on our website.
Although we will do our best to notify you of changes to our privacy policy, we encourage you to review this policy periodically.
Data Controller and Data Processor
Secure State Cyber consists of two companies: Secure State Cyber AB, established in Sweden, and Secure State Cyber Inc., established in Canada. The companies are sister companies within the same corporate group, and each constitutes a separata legal entity. Each company acts as an independent data controller for the processing of personal data that takes place within its own operations.
Secure State Cyber AB provides technical tools to Secure State Cyber Inc. Secure State Cyber AB acts as a data processer on behalf of Secure State Cyber Inc. In such cases, the companies have entered into a data processing agreement in accordance with Article 28 GDPR.
Where the companies engage one another as subcontractors in connection with customer assignments, each company acts as an independent data controller for the personal data it processes in that context. Each company is responsible for its own processing and ensures that data subject is informed accordingly.
In some cases, we process your personal data on behalf of a customer, such as when carrying out our services. When doing so, we act solely as data processors. In those situations, please contact the data controller responsible, usually our customer. If you are unsure of who is the responsible data controller, feel free to contact us and we will assist you.
Purposes of Processing
Secure State Cyber processes personal data in order to:
Customers and Business Contacts:
• Administer customer relationships
• Enter into, manage and fulfill contracts
• Deliver services, including security consulting, training, e-learning and penetration testing
• Provide support and communicate regarding services
• Handle invoicing and accounting
• Comply with applicable laws and regulations
Surveys, E-learning and Events
• Administer and evaluate surveys
• Provide and manage access to e-learning platforms and training materials
• Register and manage participation in events, webinars and training sessions
• Follow up participation and measure outcomes for quality and improvement purposes
Penetrations Testing and Security Services
• Plan, perform and document security tests
• Communicate findings and results
• Fulfill contractual obligations related to information security services
Depending on the assignment, personal data may be processed either as part of Secure State Cybers’ own operations or on behalf of a customer.
Newsletter and Marketing
• Communicate offers, invitations to event and other information about Secure State Cybers’ services
• Conduct targeted marketing, where permitted by law
Website Visitors
• Enable website functionality
• Analyze website usage and improve user experience and usability
• Compile statistics on how our website and services are used
Recruitment
• Manage recruitment processes
• Communicate with candidates
• Evaluate applications, CVs and interview information
• Store candidate information for future recruitment, where permitted
Categories of Personal Data
Depending on the context, Secure State Cyber may process the following categories of personal data:
• Identification data (e.g. name)
• Contact details (e.g. email address, phone number)
• Professional information (e.g. role, organization, CV, references)
• Account and login information for e-learning platforms
• Communication data (e.g. emails, survey responses, feedback)
• Technical data (e.g. IP address, browser type, website usage via cookies)
• Other information necessary to deliver agreed services
Personal data is primarily collected directly from you, but may also be obtained from:
• Your employer or organization
• Customers when Secure State Cyber acts as a data processor
• Publicly available sources (e.g. LinkedIn, where relevant for recruitment)
• Technical systems used in the delivery of services
Legal Basis for Processing
Secure State Cyber processes personal data based on one or more of the following legal grounds:
• Contract – when processing is necessary to perform a contract or take steps prior to entering a contract
• Legal obligation – when processing is required to comply with applicable laws, such as accounting legislation
• Legitimate interest – when processing is necessary for Secure State Cybers’ legitimate interests, provided such interests are not overridden by your fundamental rights and freedoms (e.g. business communication, recruitment, service improvements)
• Consent – when you have given explicit consent, for example for newsletters, certain cookies, surveys or storage of recruitment data
When processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.
Storage and Retention
Personal data is stored only for as long as necessary to fulfill the purposes for which it was collected, in accordance with GDPR.
As a general rule:
• Customer and business contact data is stored for the duration of the business relationship and deleted no later than five (5) years after the end of the relationship, unless a longer retention period is requested by law
• Newsletter data is stored until you unsubscribe or withdraw your consent
• Recruitment data is stored for the duration of the recruitment process and, where consent is given, for a limited period thereafter
• Survey and e-learning data is stored as long as necessary for evaluation, follow-up and contractual purposes
Certain personal data may need to be retained for longer periods due to legal obligations, such as accounting of documentation requirements.
Security of Processing
Secure State Cyber protects personal data through appropriate technical and organizational security measures designed to prevent unauthorized access, loss, alteration or disclosure.
Access to personal data is limited to authorized personnel who require the information to perform their work duties. Personal data is processed in Secure State Cybers’ internal IT systems and, where applicable, by external service providers.
Secure State Cyber has entered into data processing agreements with relevant suppliers and service providers, including any sub-processors, to ensure an adequate level of protection for personal data.
Recipients and Disclosure
Personal data may be disclosed to:
• IT and system suppliers providing platforms, CRM systems, e-learning tools or other technical solutions
• Secure State Cyber Inc. (Canada), when Secure State Cyber AB engages its Canadian sister company in connection with subcontracting or service delivery (see further under Transfers Outside the EU/EEA below)
• Professional advisors, where necessary
• Authorities, where required by law
• Customers, when Secure State Cyber acts as a data processor
Personal data is disclosed only to the extent necessary for the relevant purpose and in accordance with applicable data protection laws.
Transfers Outside the EU/EEA
Personal data is primarily processed within the EU/EEA. Where personal data is transferred to countries outside the EU/EEA, Secure State Cyber ensures that appropriate safeguards are in place to ensure an adequate level of protection.
Underribrik: Transfers to Canada
Secure State Cyber AB may transfer contact details (such as name, e-mail address and phone number) to Secure State Cyber Inc. in Canada in connection with subcontracting and the delivery of services. Canada is a third country in relation to the EU/EEA.
Such transfers are based on the European Commissions adequacy decision of 20th of December 2001 (Decision 2002/2/EC) pursuant to Article 45 GDPR. The adequacy decision applies to private commercial organizations subject to Canadas Personal Information Protection and Electronic Documents Act (PIPEDA). Secure State Cyber Inc. is a private commercial entity conducting commercial activity and is subject to PIPEDA, including for international data flows. The adequacy decision was confirmed in full by the European Commission on 15th of January 2024.
Secure State Cyber AB continuously monitors the validity of the adequacy decision, including ongoing legislative developments in Canada. In the event that the adequacy decision is revoked or that the conditions for its application cease to be met, Secure State Cyber AB will without delay transition to Standard Contractual Clauses (SCC) pursuant to Article 46.2 c GDPR as an alternative transfer mechanism.
Where personal data is transferred to other countries outside the EU/EEA in connection with the use of IT services or suppliers, Secure State Cyber ensures that appropriate safeguards are in place, such as standard contractual clauses or other legally recognized transfer mechanics.
Your Rights
You have the following rights under GDPR:
• The right to receive information about how your personal data is processed
• The right of access to your personal data (register extract)
• The right to rectification of inaccurate or incomplete personal data
• The right to erasure of personal data, subject to legal limitations
• The right to restriction of processing
• The right to object to processing based on legitimate interest
• The right to data portability, under certain conditions
• The right to lodge a complaint with the supervisory authority
In Sweden, the supervisory authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
Contact Information
If you have questions about this privacy policy, Secure State Cybers’ processing of personal data, or if you wish to exercise your rights under GDPR, please contact: info@securestatecyber.com
Cookies
Secure State Cyber uses cookies on its website. For more information about how cookies are used and how you can manage preferences, please see our Cookie-policy