Privacy notice 2026-07-26

How the public website uses personal data.

How Saga Compliance processes personal data on the public website, how long contact requests are kept, and how to exercise your rights.

Who is responsible

Saga Compliance publishes this notice for the public website at https://saga-compliance.com. Formal legal-entity details other than Sweden as the country of operation will appear here when the authoritative company record is available for publication.

Contact the team through https://saga-compliance.com/contact or info@saga-compliance.com. The form records a request for human triage and does not promise a response time. Vulnerability reports use the same paths, as described in /.well-known/security.txt.

What the public website processes

The public pages are marketing, documentation, and intake. They are not a customer workspace. Customer compliance records live behind sign-in and are governed by that organisation’s workspace and contract, not by this notice.

When you submit the contact form we store the name, work email, organisation, how you heard about us, and any optional message you typed, together with a request identifier, the privacy-notice version you acknowledged, and the time of submission. A hidden website field is a honeypot: if it is filled, the submission is treated as automated noise.

The public site also records coarse first-touch attribution (channel and source, such as search or a referring site) and anonymous page, call-to-action, and form-start events. Those events use a random session identifier stored in the browser’s session storage. They are not used to build a profile of you across other sites, and they are not sold.

Why we process it

Contact-form data is processed so a human can review a request to talk about the product, a partnership, or a security disclosure. The lawful bases we rely on for that intake are steps at your request before a contract and our legitimate interest in answering serious enquiries without opening an unmonitored mailbox.

Anonymous public telemetry is processed on legitimate interest: it tells us whether a public page is reached and whether someone started or submitted the contact form. It is not a condition of reading the guides.

How long we keep it

Contact-form records are retained for up to 90 days for human triage, then purged. The privacy-notice version this page and the contact form share is 2026-07-26.

Do not include confidential incident details, special-category data, or another person’s personal data in the public form. If you need to report a concern inside a customer organisation, use that organisation’s speak-up channel.

Your rights

If we hold personal data about you from this website, you can ask for access, correction, erasure, restriction, or objection, and you can complain to a supervisory authority. For people in Sweden that authority is Integritetsskyddsmyndigheten (IMY). Send the request through the contact form or info@saga-compliance.com and say that it is a privacy request so it is triaged as one.

Customer-workspace data is handled under that customer’s instructions. A request about a record inside a signed-in workspace should go to that organisation; we will point you there rather than answering from this public notice.

Who else sees it

The public site and the protected review inbox run on Saga’s production host. We do not sell public-site personal data. Hosting, backup, and edge delivery process the data as processors on our documented instructions. No automated decision that produces legal or similarly significant effects is taken from the public contact form or public telemetry.

Send a privacy request