Privacy notice 2026-09-29
How the public website uses personal data.
How Saga Compliance processes personal data on the public website, how long contact requests are kept, and how to exercise your rights.
Cookie choices
Optional analytics and ad measurement, including Meta, run only if you allow them. Forms and downloads work either way.
Optional measurement is off for this browser.
Who is responsible
TicTech AB (organisation number 556278-4297), with business address Askims Utsiktsväg 8 B, 436 42 Askim, Sweden, operates Saga Compliance and is responsible for the public website at https://saga-compliance.com.
Contact the team through the protected form at https://saga-compliance.com/contact. The form records a request for human triage and does not promise a response time. Vulnerability reports use the same monitored path, as described in /.well-known/security.txt.
What the public website processes
The public pages are marketing, documentation, and intake. They are not a customer workspace. Customer compliance records live behind sign-in and are governed by that organisation’s workspace and contract, not by this notice.
When you submit a contact form we store your name, work email, organisation, any phone number provided, the page, bounded campaign parameters and any Meta click parameter in the visited URL, or self-reported source of the request, and any priority or message you entered, together with a request identifier, the privacy-notice version you acknowledged, and the time of submission. A hidden website field is a honeypot: if it is filled, the submission is treated as automated noise.
When you request a practical resource we store the email address, exact campaign and resource version, source page, bounded campaign parameters, any Meta click parameter in the visited URL, and the privacy-notice version you acknowledged. Optional consent to receive further Saga guidance is recorded separately and is never required to receive the resource.
Optional visitor measurement (page, call-to-action, and form-start events with a random session identifier) runs only after you accept measurement on a public page. Declining or withdrawing it does not block reading, contact forms, or resource delivery. Aggregate cookieless landing views, form starts, and accepted submissions are totals per published version and day — they are not unique or consented experiment visitors. Only after you accept measurement does a Meta (Facebook) pixel load for campaign measurement; without that consent no third-party pixel fires from these pages.
Why we process it
Contact-form data is processed so a human can review a request to talk about the product, a partnership, or a security disclosure. Resource-request data is processed to provide the requested download and understand which practical material is useful. Further guidance is sent only when the separate optional marketing consent was granted. The lawful bases are steps at your request, legitimate interest in answering serious enquiries and improving public material, and consent for optional marketing.
Optional visitor measurement is processed on consent. Aggregate cookieless landing funnel totals contain no cookie, session, or person identifier. Neither is a condition of reading the guides or sending a form.
How long we keep it
Contact-form and resource-request records are retained for up to 90 days, then purged. The privacy-notice version this page and both public forms share is 2026-09-29.
Do not include confidential incident details, special-category data, or another person’s personal data in the public form. If you need to report a concern inside a customer organisation, use that organisation’s speak-up channel.
Your rights
If we hold personal data about you from this website, you can ask for access, correction, erasure, restriction, or objection, and you can complain to a supervisory authority. For people in Sweden that authority is Integritetsskyddsmyndigheten (IMY). Send the request through the contact form and say that it is a privacy request so it is triaged as one.
Customer-workspace data is handled under that customer’s instructions. A request about a record inside a signed-in workspace should go to that organisation; we will point you there rather than answering from this public notice.
Who else sees it
The public site and the protected review inbox run on Saga’s production host. We do not sell public-site personal data. Hosting, backup, and edge delivery process the data as processors on our documented instructions. No automated decision that produces legal or similarly significant effects is taken from the public contact form or public telemetry.
Only after you accept optional measurement does Meta Platforms process limited measurement data as a processor so we can see which campaigns reach people. This includes page events and accepted conversion events, plus Meta browser identifiers (`_fbp` and `_fbc`) and the browser user-agent to match campaign measurement and deduplicate browser and server events. Those browser identifiers are not anonymous data, and the browser Pixel receives ordinary network-request metadata when it loads. Saga’s server-side conversion payload excludes form email, name, phone, message, and IP address. Without that consent no Meta pixel loads, and we send no conversion event to Meta.