Privacy Policy
Last updated: [2026-06-15]
In this privacy policy we, DALESEC AB, org. no. [registration number], describe how and why we process personal data in our business and when we provide our services. DALESEC is the data controller for the processing we carry out under this policy.
We process personal data in accordance with this policy, the General Data Protection Regulation (EU 2016/679) ("GDPR"), and the national legislation that supplements it. It is important to us that you feel confident in how we handle your personal data.
Our role when delivering security testing
When we perform penetration tests and related security services, we may process personal data contained in our clients' systems and environments. In those cases we act as a data processor and the client is the data controller. That processing is governed by a separate data processing agreement between us and the client, and we only process such data according to the client's documented instructions. We treat all findings, test data, and client information as strictly confidential.
1. Categories of data subjects and personal data
We process personal data that you provide to us and that we collect when you use our services or contact us:
- Clients (a person who uses our services or represents an organisation that does): name, email, phone number, postal address, company name, title and role, details in agreements, billing and payment details, username, personal data contained in emails and our CRM, and other information relevant to the purpose of the contact.
- Business contacts, suppliers, consultants and other visitors (anyone who contacts us or visits our website or social media): name, email, phone number, company name, title and role, personal data in emails and CRM, and other relevant information. When you visit our website we may also collect limited visit statistics and device information through cookies, plus any details you choose to provide.
- Job applicants: name, email, phone number, postal address, personal identity number, age, work experience, education history, references, and other information provided in a CV or cover letter.
We may also receive personal data from third parties, such as professional business-information providers and web-service providers (for example LinkedIn or Google), as well as from publicly available sources. This mainly concerns potential clients (a person representing an organisation we believe may be interested in our services): name, email, phone number, postal address, company name, title and role, and personal data in emails.
2. Purposes and legal basis
We process personal data for the following purposes:
- Clients — to administer and deliver our services, contact the client's representatives, invoice and carry out administration, improve and tailor our services, and send information and marketing about DALESEC. Legal basis: performance of a contract where we have an agreement directly with the data subject; otherwise our legitimate interest.
- Business contacts, suppliers, consultants and visitors — to assist those who contact us, establish and maintain business relationships, enter into agreements, and adapt our website to your device. Legal basis: performance of a contract, or our legitimate interest.
- Potential clients — to establish new client relationships and send relevant information and marketing. Legal basis: our legitimate interest.
- Job applicants — to manage recruitment and hiring (legitimate interest), and to keep your details for future recruitment (consent).
- All categories — to establish, exercise or defend legal claims (legitimate interest), and to meet statutory requirements such as accounting (compliance with a legal obligation).
Where we rely on legitimate interest, we have assessed that our interest in running our business, delivering our services, and maintaining contact outweighs any limited privacy impact. You may object to processing for direct marketing at any time.
3. Retention
We keep personal data only as long as necessary for the purpose:
- Clients: for as long as there is an ongoing relationship, and for up to 12 months thereafter.
- Business contacts, suppliers and consultants: for as long as the business relationship lasts.
- Visitors: for the duration of the website visit, or as long as needed to assist you if you contact us.
- Job applicants: until the position is filled, or for as long as consent remains for future recruitment.
- Marketing: for as long as we send such information, unless you object.
- Test data and engagement material: handled under the client data processing agreement and securely deleted or returned after the engagement, unless a longer period is agreed.
- Legal and statutory requirements: longer where required, for example seven years under the Swedish Bookkeeping Act, or to protect our legal interests.
When data no longer needs to be stored, it is deleted or anonymised.
4. Disclosure and sharing
We may share personal data with trusted suppliers who help us deliver our services and run our business, for example software and data-storage providers (such as Microsoft), payment providers, IT service providers, advisers (for example legal and accounting), and other administrative providers. We share data only where necessary and where required by law. When a supplier processes personal data on our behalf, we enter into a data processing agreement to ensure the processing follows our instructions and applicable law.
5. Security and location of processing
We take appropriate technical and organisational measures to ensure a level of security suited to the risk, including measures appropriate for a security-focused business. Our services are mainly provided from data centres within the EU and EEA, and we primarily process your data within the EU and EEA. If we ever process data outside the EU and EEA, we put appropriate safeguards in place in line with the GDPR.
6. Cookies
A cookie is a small text file that a website places on your device. We use cookies and similar technologies on dalesec.com to make the site work, to understand how it is used, and, where you consent, for marketing. This section explains the cookies we use and how you can control them.
Types of cookies we use
- Functional cookies are necessary for the site to work and to remember your preferences. Because the site cannot function properly without them, these may be placed without your consent.
- Statistics cookies help us understand how visitors use the site, for example device type, pages viewed, and time of visit, so we can improve it. We ask for your permission before placing these.
- Marketing and tracking cookies may be used to build a profile of your interests and to show relevant advertising on this and other websites. These are only placed with your consent.
Social media and other third parties
If we embed content from social networks such as LinkedIn, those providers may place their own cookies through that content. We do not control these third-party cookies, so please review the relevant provider's privacy policy to understand how they process your data. Such providers may be located outside the EU and EEA.
Consent
The first time you visit dalesec.com we ask for your consent through a cookie banner. You can accept or refuse non-essential cookies, and you can change or withdraw your choice at any time.
Managing and removing cookies
You can accept, refuse, or delete cookies through your browser settings, and you can set your browser to notify you whenever a cookie is placed. If you disable cookies, some parts of the site may not work as intended. If you delete cookies, they will be placed again, with your consent, the next time you visit.
7. Your rights
Under the GDPR you have the right to:
- Access your personal data and information about how it is processed.
- Rectification of inaccurate or incomplete data.
- Erasure ("the right to be forgotten") in certain cases.
- Data portability where processing is based on a contract or consent.
- Restriction of processing in certain cases.
- Object to processing based on our legitimate interest.
- Object to direct marketing at any time.
You also have the right to lodge a complaint about our processing with the Swedish Authority for Privacy Protection (IMY, Integritetsskyddsmyndigheten).
8. Changes to this policy
We may update this policy from time to time. The latest version is always available on our website.
DALESEC AB
Kungstensgatan 42, 113 57, Stockholm, Sweden
Email: privacy@dalesec.com