Product
Security Privacy About Careers Contact Book a demo Login

CATALSY PRIVACY NOTICE

Effective: April 2026

1. Introduction

This Privacy Notice explains how Catalsy AB ("Catalsy", "we", "us", or "our") collects, uses, shares, and retains personal data about individuals who interact with us, including prospective customers, leads, customer representatives and contact persons, business partners, and visitors to our website and other digital properties.

Catalsy provides an AI-powered risk intelligence and workflow automation platform for Legal, Compliance, and Security teams. In the course of running our business, we act as an independent data controller for the personal data described in this notice. Where we process personal data on behalf of our customers as a data processor, that processing is governed separately by our Data Processing Agreement (DPA).

Please read this notice carefully. If you have any questions, you can contact us at any time using the details in Section 13.

2. Who We Are

The data controller responsible for your personal data is Catalsy AB, registration number 559568-6600, with registered address Ängstigen 13, 82453 Hudiksvall, Sweden. The relevant supervisory authority is Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Data Protection, imy.se

3. Who This Notice Covers

This notice applies to the following categories of external data subjects:

  • Leads and prospects: Individuals at organisations that have expressed an interest in Catalsy's products or with whom we have initiated contact for commercial purposes.

  • Customer representatives and contact persons: Employees, officers, or authorised contacts at companies that have contracted with Catalsy ("Subscribers"), including named users of our platform.

  • Business partners and suppliers: Contact persons at partner organisations, resellers, referral partners, and vendors.

  • Website and marketing channel visitors: Individuals who visit our website, download resources, attend our events or webinars, or otherwise interact with our marketing communications.

  • Correspondence contacts: Individuals who contact us by email, phone, or other channels for any reason not covered above.

5. Special Category and Sensitive Data

We do not intentionally collect or process special category personal data (such as health data, racial or ethnic origin, political opinions, religious beliefs, or biometric data) about external data subjects. If you disclose such information to us voluntarily, for example in a support communication, we will treat it with the highest level of confidentiality and will not use it for any purpose other than responding to your communication.

6. How We Collect Your Personal Data

We collect personal data through the following channels:

  • Directly from you; when you fill in a form on our website, request a demo, sign a contract, contact our support team, or communicate with us by email or phone.

  • From your employer or organisation; when an organisation contracts with us and provides your details as a named contact, authorised user, or billing contact.

  • From publicly available sources; such as company websites, LinkedIn, professional directories, and published corporate filings, for the purpose of B2B outreach.

  • From technology partners; such as marketing automation tools, event platforms, or referral partners, subject to their own privacy notices and applicable data protection requirements.

7. Who We Share Your Personal Data With

We do not sell or rent your personal data to third parties. We may share your personal data with third parties without further notice to you, unless required by law, in the following circumstances:

Vendors and Service Providers

To operate our business and deliver our services, we engage vendors and service providers across a range of functions, including cloud hosting and infrastructure, customer relationship management, email and communications, payment processing, product analytics, and customer support tooling. These parties access or process personal data solely on our instructions and are bound by appropriate data processing agreements.

Affiliates

We may share personal data with other entities within the Catalsy corporate group, where relevant to operating our business. Any affiliate receiving personal data will use it only in a manner consistent with this Privacy Notice.

Business Transfers

If Catalsy is involved in a merger, acquisition, reorganisation, asset sale, financing, or similar strategic transaction, personal data may be shared with counterparties and advisers as part of the due diligence process and transferred to a successor entity as part of that transaction. We will notify affected individuals if such a transfer results in a material change to how their data is processed, to the extent required by applicable law.

Professional Advisers

We may share personal data with our lawyers, accountants, auditors, insurers, and other professional advisers where necessary in connection with the services they provide to us, subject to appropriate confidentiality obligations.

Legal Requirements and Protection of Rights

We may disclose personal data where we believe disclosure is necessary or appropriate to: (i) comply with a legal obligation or binding order of a court or regulatory authority, including to meet national security or law enforcement requirements; (ii) protect and defend our legal rights or property; (iii) prevent, investigate, or take action regarding fraud, security incidents, or other illegal activity; or (iv) protect the vital interests of any person.

8. International Transfers

Catalsy stores and processes personal data primarily within the European Union and European Economic Area (EU/EEA). Where any transfer to a country outside the EU/EEA is necessary, for example where a third-party service provider is located outside the EU/EEA, we ensure that an appropriate transfer safeguard is in place, such as:

  • A European Commission adequacy decision for the recipient country; or

  • Standard Contractual Clauses (SCCs) as approved by the European Commission (Implementing Decision (EU) 2021/914); or

  • Another valid transfer mechanism recognised under Chapter V of the GDPR.

You may request information about the specific safeguards applicable to any transfer by contacting us at hello@catalsy.com.

9. How Long We Retain Your Data

We retain personal data only for as long as necessary to fulfil the purposes described in this notice, or as required by applicable law. Our standard retention periods are set out below:

Data Subject / Data Category Retention Period Rationale
Lead / prospect contact data (active) For the duration of the commercial relationship or sales process, then up to 3 years from last meaningful interaction Legitimate interests in maintaining a pipeline and re-engaging prospects
Lead / prospect contact data (unengaged or opted out) Suppression list maintained indefinitely to honour opt-out; underlying personal data deleted within 90 days of opt-out Compliance with marketing and communication law
Customer representative and platform user data For the duration of the customer contract, then up to 3 years after termination Contract administration, dispute resolution, and legal claims
Financial and billing records 7 years from the relevant financial year Swedish Bookkeeping Act (Bokföringslagen) and tax law requirements
Support and correspondence records 3 years from resolution of the relevant matter Legitimate interests in maintaining service quality records and handling claims
Business partner and supplier contact data For the duration of the relationship, then up to 3 years after it ends Contract administration and claims

When personal data is no longer required, we delete or anonymise it in a secure manner. In some cases we may retain an anonymised record for statistical or analytical purposes, in which case it will no longer constitute personal data.

10. Your Rights

Subject to applicable law and certain exceptions, you have the following rights in relation to your personal data:

Right What It Means
Access (Art. 15) You have the right to request a copy of the personal data we hold about you and information about how we process it.
Rectification (Art. 16) You have the right to ask us to correct inaccurate or incomplete personal data we hold about you.
Erasure (Art. 17) You have the right to ask us to delete your personal data in certain circumstances, for example where the data is no longer necessary for the purpose for which it was collected.
Restriction (Art. 18) You have the right to ask us to restrict the processing of your personal data in certain circumstances, for example if you contest its accuracy or have objected to processing.
Portability (Art. 20) Where processing is based on your consent or the performance of a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format.
Objection (Art. 21) You have the right to object to processing based on our legitimate interests at any time on grounds relating to your particular situation. You also have an unconditional right to object to direct marketing at any time.
Withdraw consent (Art. 7(3)) Where we process your data based on your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
Lodge a complaint (Art. 77) You have the right to lodge a complaint with Integritetsskyddsmyndigheten (IMY), reachable at imy.se or imy@imy.se.

To exercise any of your rights, please contact us using the details in Section 13 below. We will respond within one month of receiving your request. We may need to verify your identity before processing your request. We will not charge a fee for reasonable requests; however, we may charge a reasonable fee for manifestly unfounded or excessive requests.

11. Automated Decision-Making and Profiling

We do not make decisions about you that produce legal or similarly significant effects solely on the basis of automated processing. Our marketing segmentation and lead scoring activities may involve some automated analysis of contact behaviour (e.g., email engagement, website visits), but a human always reviews outreach decisions. If this changes, we will update this notice and comply with our obligations under Article 22 of the GDPR.

12. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or damage. These measures include encryption in transit, role-based access controls, multi-factor authentication, audit logging, and regular security assessments. While we take data security seriously, no system is completely secure. If you have reason to believe that your interaction with us is no longer secure, please notify us immediately.

13. Contact Us

If you have any questions about this Privacy Notice or wish to exercise your rights, please contact us:

Contact details
Email hello@catalsy.com
Post Catalsy AB, Ängstigen 13, 82453 Hudiksvall, Sweden
Supervisory authority Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, Sweden. imy.se / imy@imy.se

14. Changes to This Notice

We may update this Privacy Notice from time to time to reflect changes in our practices, our services, or applicable law. When we make material changes, we will notify you by updating the "Effective" date at the top of this notice and, where appropriate, by sending a direct notification (e.g., by email to known contacts or by posting a prominent notice on our website). We encourage you to review this notice periodically.