Privacy Policy
Version 1.1, last updated 27 August 2026
1. What this policy does not cover
Most of what our software does happens on the user's own device. Email analysed there is never transmitted to us, and we hold no copy of any mailbox.
Some of the data that does reach us is processed on the instructions of the organisation that deployed the software. For that data the organisation is the controller and is responsible for informing its own people; our obligations to it are in the Data Processing Agreement. Every category is listed at skeptiva.com/data, which states our role, the retention period and what each category contains.
This policy covers the categories that page marks as processed by us as an independent controller, together with our own business contacts and our website.
2. Software data we use in our own right
For the categories marked as ours at skeptiva.com/data, we process the data in order to:
- meter licences and confirm that installations and updates worked;
- diagnose faults and measure service quality;
- improve our detection models, using reported messages and feedback;
- where an administrator has turned on extended telemetry, correct our detection rules and maintain sender domain reputation.
We rely on our legitimate interests in maintaining and improving a network and information security product, which Recital 49 GDPR recognises. Our written assessment is available on request.
Extended telemetry is optional. The categories listed under Extended telemetry at skeptiva.com/data are sent only if an administrator turns the setting on. It can be turned off again at any time, and the protection works without it.
We do not use this data to profile, evaluate, score or report on individual people. We do not tell an employer how any individual behaves. We do not sell, rent or license the data, and we do not use it for advertising.
If you sent a message to someone whose organisation uses Skeptiva and they reported it, your message may have reached us that way. You can ask us what we hold and ask us to delete it. See Section 6.
3. Our customers, contacts and website visitors
| Data | Why |
|---|---|
| Business contact details of customer contacts and prospects | Managing the relationship, support, sales |
| Billing contacts, addresses, organisation numbers, invoice and payment records | Invoicing and accounting |
| Payment instrument data | Taking payment. Handled by Stripe; we do not store card numbers. |
| Website enquiries: name, email address, message and IP address | Answering the enquiry and handling abuse of the form |
| Website analytics | Understanding how the site is used |
We process this data to perform our contract with the customer, to comply with the Swedish Bookkeeping Act, and on our legitimate interests in managing business relationships.
We use no tracking cookies, advertising pixels or third-party trackers. Our analytics tool, Plausible, is self-hosted, sets no cookies and does not follow visitors between sites. We may use strictly necessary cookies to keep you signed in to the Admin Portal.
4. Retention, recipients and location
Retention periods are stated at skeptiva.com/data.
Our suppliers, and where data is stored, are listed at skeptiva.com/subprocessors.
5. Automated decisions
Our software assesses automatically whether an email looks like a threat and shows the result to the recipient with an explanation. It does not block or delete anything and it does not make decisions about people; the recipient decides what to do. This is not automated decision-making producing legal or similarly significant effects under Article 22 GDPR.
6. Your rights
You have the right to ask us for a copy of your data, to correct it, to have it deleted, to restrict how we use it, to receive it in a portable form, and, where we rely on legitimate interests, to object to our using it at all. If you object, we stop unless we can show compelling legitimate grounds that override your interests.
Email info@skeptiva.com. We respond within one month. We may need enough information to identify your records, such as the organisation you work for and the device concerned. Where we act as a processor for an organisation, we refer you to them and tell you that we have done so.
You may complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten), Box 8114, 104 20 Stockholm, imy@imy.se, or to the supervisory authority where you live or work.
7. Changes and contact
We update this policy when our processing changes, and make material changes clear rather than quietly amending the text. The version and date at the top show the current version. Enquiries: info@skeptiva.com.
Data Processing Agreement Data We Process Security Measures Subprocessors Privacy Policy