Data We Process
Version 1.1, last updated 27 August 2026
1. From the endpoint client
Sent by the installer and the background client on each protected device. Our role: independent controller.
| Category | Description |
|---|---|
| User identity on device | Windows account SID and Windows display name of the interactive user |
| Installed version | Installed product version and the customer release the installer was built for |
| Device specifications | Operating system identifier and version, Outlook version and update channel, and the client build version |
| Locale and time zone | BCP-47 locale string and the device time zone |
| Analysis events | Outcome and duration of each analysis, and the presence of errors and warnings such as mail parse or signature verification failures |
| Aggregate counters | Counts of analyses by outcome, and opaque identifiers for what the analysis system reacted to in the content |
| Installation events | Whether an install was fresh or an upgrade |
| Outlook layout dumps | Sanitised snapshot of the Outlook interface layout, sent on first conversation click and used to keep the interface integration working across Outlook versions. Deleted automatically 90 days after receipt. |
The endpoint client transmits no message content, subject lines, attachments, or sender or recipient addresses. Errors and warnings are recorded as categories and codes, and cannot carry message content.
2. Data reported by users
Users can report any message they choose, whether or not it is a threat, and can send feedback with a report or on its own. Reporting a message allows dashboard administrators to view its content. Our role: processor, on the customer's instructions. Skeptiva may also use reported messages and feedback to improve the Software, and acts as an independent controller for that use.
| Category | Description |
|---|---|
| Original message | The complete message, including headers, body, attachments and all sender and recipient addresses |
| Submission time | When the report was submitted and which seat it is attributed to |
| Feedback | Any feedback a user provides, with a reported message or separately |
A reported message may contain any category of personal data, including special category data under Article 9 GDPR, depending on what the message contains. We cannot assess a message before it is sent to us.
3. Extended telemetry
Extended telemetry is optional. It is off unless an administrator turns it on, it can be turned off again at any time, and the protection works without it. Turning it on sends additional data that improves the accuracy of link and sender detection. Our role: independent controller.
| Category | Description |
|---|---|
| Flagged links | A URL that a detection rule flagged, after email addresses and token patterns are stripped from the query parameters on the device, together with the verification verdict |
| Sender domain | The domain part of the sender address for messages classified as suspicious or malicious. Not the part before the @, and nothing from the message itself. |
4. From the dashboard
Our role: processor, on the customer's instructions.
| Category | Description |
|---|---|
| Sign-in email address | The email address an administrator signs in with, and whether it has been verified |
| Account timestamps | Account creation, last update and last-seen times |
| Organisation details | User-supplied information about the organisation, such as name and website |
| Membership and roles | Which person belongs to which organisation, and in what role, administrator or viewer |
| Product configuration | User-supplied options, for example package configuration |
5. Website contact form
Our role: independent controller.
| Category | Description |
|---|---|
| Enquiry details | Sender name, contact email address, message body and enquiry type, demo booking or general |
| Network identifier | Client IP address, included with the enquiry for abuse handling |
6. What never leaves the device
Email analysed locally and not transmitted under the tables above is never received by us. That is the bulk of all mail the software sees. We hold no copy of any mailbox, and the software provides no facility by which we could retrieve one.
7. Who the data is about
The data subjects are the customer's employees and other authorised users of the software and the dashboard and, where a message is reported or a link is flagged, the senders and recipients of that message and any individuals referred to in it. For the website contact form, the data subject is the person making the enquiry.
8. Retention
Outlook layout dumps are deleted automatically 90 days after receipt.
Everything else in Sections 1 to 4 is retained while the customer's subscription is in force and deleted within 90 days after it ends. Website enquiries are retained for the duration of any customer relationship that results, or for 24 months from the last contact where none does. Invoice and accounting records are kept for seven years, as the Swedish Bookkeeping Act (bokföringslagen 1999:1078) requires.
Data reduced to a form that no longer identifies any person or organisation, such as a link pattern, a domain reputation score or a trained detection model, is no longer personal data and is retained without time limit.
9. What the roles mean
Where our role is processor, the data is Customer Personal Data under the DPA. The customer is the controller, decides why the data is processed, and is responsible for informing its own people.
Where our role is independent controller, the data is not Customer Personal Data. Skeptiva decides why it is processed and is responsible for it; the purposes are in the Privacy Policy. Skeptiva does not use it to profile, evaluate or report on any individual user.
10. Changes and contact
We give at least thirty days' notice before adding a category or extending a retention period, and the customer may object under Section 7.3 of the DPA. Enquiries: info@skeptiva.com.
Data Processing Agreement Data We Process Security Measures Subprocessors Privacy Policy