Effective: April 2026
This Privacy Notice explains how Catalsy AB ("Catalsy", "we", "us", or "our") collects, uses, shares, and retains personal data about individuals who interact with us, including prospective customers, leads, customer representatives and contact persons, business partners, and visitors to our website and other digital properties.
Catalsy provides an AI-powered risk intelligence and workflow automation platform for Legal, Compliance, and Security teams. In the course of running our business, we act as an independent data controller for the personal data described in this notice. Where we process personal data on behalf of our customers as a data processor, that processing is governed separately by our Data Processing Agreement (DPA).
Please read this notice carefully. If you have any questions, you can contact us at any time using the details in Section 13.
The data controller responsible for your personal data is Catalsy AB, registration number 559568-6600, with registered address Ängstigen 13, 82453 Hudiksvall, Sweden. The relevant supervisory authority is Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Data Protection, imy.se
This notice applies to the following categories of external data subjects:
Leads and prospects: Individuals at organisations that have expressed an interest in Catalsy's products or with whom we have initiated contact for commercial purposes.
Customer representatives and contact persons: Employees, officers, or authorised contacts at companies that have contracted with Catalsy ("Subscribers"), including named users of our platform.
Business partners and suppliers: Contact persons at partner organisations, resellers, referral partners, and vendors.
Website and marketing channel visitors: Individuals who visit our website, download resources, attend our events or webinars, or otherwise interact with our marketing communications.
Correspondence contacts: Individuals who contact us by email, phone, or other channels for any reason not covered above.
The table below sets out the categories of personal data we collect for each group of data subjects, the purposes for which we use it, and the legal basis under Article 6 of the GDPR.
| Data Category | Purpose | Legal Basis |
|---|---|---|
| Name, job title, business email, business phone, employer / organisation name | Sales and business development outreach Maintaining our CRM and contact records Sending information about our products, services, and relevant content | Legitimate interests (Art. 6(1)(f)); pursuing commercial opportunities and growing our customer base. We send B2B communications only and assess that our interests are not overridden by the individual's rights. |
| Records of prior interactions and engagement (e.g., email opens, event attendance, content downloads) | Personalising and improving the relevance of our outreach Understanding interest in specific topics or products | Legitimate interests (Art. 6(1)(f)); improving the quality and relevance of our commercial communications. |
| Marketing consent records (where applicable) | Recording and honouring opt-in / opt-out preferences for marketing communications | Compliance with legal obligation (Art. 6(1)(c)) and/or consent (Art. 6(1)(a)) where required under applicable law. |
| Data Category | Purpose | Legal Basis |
|---|---|---|
| Name, job title, work email, work phone | Contract administration and management Onboarding, provisioning of platform access, and account management Sending contractual and operational communications (e.g., invoices, change notices, security alerts) | Performance of a contract / steps prior to entering into a contract to which the data subject's organisation is party (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)). |
| Platform usage data; login timestamps, feature usage, user-generated configurations, audit logs | Providing, operating, and securing the platform Troubleshooting and support Product analytics and improvement (aggregated / anonymised where possible) | Legitimate interests (Art. 6(1)(f)); operating a secure, reliable service and improving our products. |
| Customer support communications (emails, tickets, chat transcripts) | Resolving support requests Maintaining a record of our service interactions | Legitimate interests (Art. 6(1)(f)) and performance of a contract (Art. 6(1)(b)). |
| Financial and billing information (name, billing contact details, payment references) | Invoicing and collection of fees Financial record-keeping | Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)); e.g., Swedish accounting and tax law. |
| Marketing and event communications (where the individual has been opted in or has opted in themselves) | Newsletters, product updates, and thought leadership content Invitations to events, webinars, and product demos | Legitimate interests (Art. 6(1)(f)) for existing customer contacts, or consent (Art. 6(1)(a)) where separately obtained. Opt-out available at any time. |
| Data Category | Purpose | Legal Basis |
|---|---|---|
| Name, job title, work email, work phone, organisation name | Managing and administering partner and supplier relationships Sending contractual notices and operational communications Maintaining due diligence and vendor records | Legitimate interests (Art. 6(1)(f)); managing our business relationships; and performance of a contract / pre-contractual steps (Art. 6(1)(b)) where applicable. |
| Financial and payment details (for individuals operating as sole traders or named billing contacts) | Processing payments and maintaining financial records | Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)). |
| Data Category | Purpose | Legal Basis |
|---|---|---|
| Form submission data (name, email, company, job title, query) — e.g., contact forms, demo requests, content downloads | Responding to inbound enquiries Qualifying and following up on sales leads | Legitimate interests (Art. 6(1)(f)) / pre-contractual steps (Art. 6(1)(b)) where the individual has proactively requested contact. |
We do not intentionally collect or process special category personal data (such as health data, racial or ethnic origin, political opinions, religious beliefs, or biometric data) about external data subjects. If you disclose such information to us voluntarily, for example in a support communication, we will treat it with the highest level of confidentiality and will not use it for any purpose other than responding to your communication.
We collect personal data through the following channels:
Directly from you; when you fill in a form on our website, request a demo, sign a contract, contact our support team, or communicate with us by email or phone.
From your employer or organisation; when an organisation contracts with us and provides your details as a named contact, authorised user, or billing contact.
From publicly available sources; such as company websites, LinkedIn, professional directories, and published corporate filings, for the purpose of B2B outreach.
From technology partners; such as marketing automation tools, event platforms, or referral partners, subject to their own privacy notices and applicable data protection requirements.
Catalsy stores and processes personal data primarily within the European Union and European Economic Area (EU/EEA). Where any transfer to a country outside the EU/EEA is necessary, for example where a third-party service provider is located outside the EU/EEA, we ensure that an appropriate transfer safeguard is in place, such as:
A European Commission adequacy decision for the recipient country; or
Standard Contractual Clauses (SCCs) as approved by the European Commission (Implementing Decision (EU) 2021/914); or
Another valid transfer mechanism recognised under Chapter V of the GDPR.
You may request information about the specific safeguards applicable to any transfer by contacting us at hello@catalsy.com.
We retain personal data only for as long as necessary to fulfil the purposes described in this notice, or as required by applicable law. Our standard retention periods are set out below:
| Data Subject / Data Category | Retention Period | Rationale |
|---|---|---|
| Lead / prospect contact data (active) | For the duration of the commercial relationship or sales process, then up to 3 years from last meaningful interaction | Legitimate interests in maintaining a pipeline and re-engaging prospects |
| Lead / prospect contact data (unengaged or opted out) | Suppression list maintained indefinitely to honour opt-out; underlying personal data deleted within 90 days of opt-out | Compliance with marketing and communication law |
| Customer representative and platform user data | For the duration of the customer contract, then up to 3 years after termination | Contract administration, dispute resolution, and legal claims |
| Financial and billing records | 7 years from the relevant financial year | Swedish Bookkeeping Act (Bokföringslagen) and tax law requirements |
| Support and correspondence records | 3 years from resolution of the relevant matter | Legitimate interests in maintaining service quality records and handling claims |
| Business partner and supplier contact data | For the duration of the relationship, then up to 3 years after it ends | Contract administration and claims |
When personal data is no longer required, we delete or anonymise it in a secure manner. In some cases we may retain an anonymised record for statistical or analytical purposes, in which case it will no longer constitute personal data.
Subject to applicable law and certain exceptions, you have the following rights in relation to your personal data:
| Right | What It Means |
|---|---|
| Access (Art. 15) | You have the right to request a copy of the personal data we hold about you and information about how we process it. |
| Rectification (Art. 16) | You have the right to ask us to correct inaccurate or incomplete personal data we hold about you. |
| Erasure (Art. 17) | You have the right to ask us to delete your personal data in certain circumstances, for example where the data is no longer necessary for the purpose for which it was collected. |
| Restriction (Art. 18) | You have the right to ask us to restrict the processing of your personal data in certain circumstances, for example if you contest its accuracy or have objected to processing. |
| Portability (Art. 20) | Where processing is based on your consent or the performance of a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format. |
| Objection (Art. 21) | You have the right to object to processing based on our legitimate interests at any time on grounds relating to your particular situation. You also have an unconditional right to object to direct marketing at any time. |
| Withdraw consent (Art. 7(3)) | Where we process your data based on your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal. |
| Lodge a complaint (Art. 77) | You have the right to lodge a complaint with Integritetsskyddsmyndigheten (IMY), reachable at imy.se or imy@imy.se. |
To exercise any of your rights, please contact us using the details in Section 13 below. We will respond within one month of receiving your request. We may need to verify your identity before processing your request. We will not charge a fee for reasonable requests; however, we may charge a reasonable fee for manifestly unfounded or excessive requests.
We do not make decisions about you that produce legal or similarly significant effects solely on the basis of automated processing. Our marketing segmentation and lead scoring activities may involve some automated analysis of contact behaviour (e.g., email engagement, website visits), but a human always reviews outreach decisions. If this changes, we will update this notice and comply with our obligations under Article 22 of the GDPR.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or damage. These measures include encryption in transit, role-based access controls, multi-factor authentication, audit logging, and regular security assessments. While we take data security seriously, no system is completely secure. If you have reason to believe that your interaction with us is no longer secure, please notify us immediately.
If you have any questions about this Privacy Notice or wish to exercise your rights, please contact us:
| Contact details | |
|---|---|
| hello@catalsy.com | |
| Post | Catalsy AB, Ängstigen 13, 82453 Hudiksvall, Sweden |
| Supervisory authority | Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, Sweden. imy.se / imy@imy.se |
We may update this Privacy Notice from time to time to reflect changes in our practices, our services, or applicable law. When we make material changes, we will notify you by updating the "Effective" date at the top of this notice and, where appropriate, by sending a direct notification (e.g., by email to known contacts or by posting a prominent notice on our website). We encourage you to review this notice periodically.