SkjoldCyber

Privacy notice

Draft: requires legal review

This notice is a working draft. It has not been reviewed by a lawyer and it is not yet in force. Items in [square brackets] must be confirmed before launch.

The company details are placeholders until they are confirmed.

Draft of

Who is responsible

The controller of your personal data is:

Company
SkjoldCyber
Address
Denmark
CVR
[to be confirmed]

What we collect

We collect only what is needed to run your case and the service.

  • Account data: your name, email address and a password, which is stored only as a one-way hash.
  • Intake answers: the type of incident, dates, how contact was made, payment method, amount and currency, recipient details if you know them, what you have reported to your bank or the police, and the free-text account you write.
  • Case data: the case reference, status, updates we write to you, and internal notes by case handlers.
  • Technical data: a session cookie that keeps you logged in, a language preference, and records of login attempts used to limit abuse [exact fields to be confirmed against the implementation].

Why we use it, and the legal basis

  • To provide the service you ask for: creating your account, handling your case and writing to you about it. Basis: contract and steps taken at your request (GDPR Article 6(1)(b)).
  • To keep the service secure and prevent abuse. Basis: our legitimate interest (Article 6(1)(f)).
  • To meet legal obligations, such as accounting rules. Basis: Article 6(1)(c).
  • [Legal review: whether intake answers about being a victim of a criminal offence need an additional basis under the Danish Data Protection Act.]

How long we keep it

[Retention period to be decided, for example a fixed period after a case is completed, with the reason stated.] Data that is no longer needed is deleted.

Who receives it

Our case handlers, and the service providers that host the site and send email on our behalf [providers to be named].

Banks, the police, insurers and Datatilsynet receive information only when your case needs it and you have asked us to share it.

[Transfers outside the EU/EEA: none planned. To be confirmed.]

Your rights

Under the GDPR you have the right to:

  • see the data we hold about you, and get a copy;
  • have incorrect data corrected;
  • have data deleted, where the law allows;
  • restrict how we use it, and object to uses based on our legitimate interest;
  • receive your data in a portable format;
  • withdraw consent, where we rely on it.

Complaints

If you think we handle your data wrongly, tell us first. You also have the right to complain to Datatilsynet (datatilsynet.dk), the Danish Data Protection Agency.

How we protect it

Measures in place in the service:

  • Passwords are hashed with a modern one-way algorithm.
  • Sessions use HttpOnly cookies and expire.
  • Every case can be read only by its owner and by staff, and every staff action on a case is logged.
  • Login attempts are rate limited.
  • [Encryption in transit and at rest, backups and access control at the hosting provider: to be confirmed at deployment.]

Cookies

We use only cookies the service needs to work: your login session and your language choice. [No analytics or advertising cookies are used. To be confirmed.]

Changes

When this notice changes in a way that matters, we will say so here and, if you have an account, tell you.