Skip to main content
Platform
Platform Overview How It Works
Solutions
AppSec Teams Platform Engineering Pricing Blog
Sign In Request Early Access
Legal

Privacy Policy

Last updated: 28 April 2026

Cybret AI AB ("the Company," "we," "us," or "our") (Regeringsgatan 29, 111 57 Stockholm, Sweden) is the data controller for personal data processed through getcybretai.com. This Privacy Policy explains what personal data we collect in connection with our application security reachability platform, why we process it, and what rights you have under the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Swedish data-protection law.

Cybret AI helps application security and platform engineering teams identify which exposure paths in their software architecture are genuinely reachable by attackers. Understanding how we handle the data you share with us is part of that same transparency we build into our product.

1. Data Controller

Cybret AI AB (Regeringsgatan 29, 111 57 Stockholm, Sweden) is the data controller for personal data processed through getcybretai.com. You can reach us at [email protected] for any data-protection matter, including to exercise the rights described below.

2. Personal Data We Process

The categories of personal data we collect depend on how you interact with the Cybret AI platform and website:

  • Identity and contact data you submit directly: name, work email address, company name, job title, and role (submitted via our contact form, early-access request form, or account registration);
  • Communications content: the content of messages you send us, early-access enquiries, or support requests;
  • Platform usage data: data about how you use the Cybret AI platform once you have an account, including feature interactions, scan configurations, and workflow activity. This data is used solely to operate and improve the service;
  • Technical data collected automatically: IP address, browser type, operating system, pages visited, referrer URL, and session timestamps, collected via server logs and (with consent) analytics cookies;
  • Analytics data: aggregated, anonymised usage statistics, only where you have given prior consent through our cookie banner.

Cybret AI does not process the application code, architectural graph data, or security findings that your team submits to the platform to generate reachability analysis. That data is processed strictly to deliver the service under your team's instructions and is governed by your service agreement, not this Privacy Policy.

3. Purposes and Legal Bases (Article 6 GDPR)

Purpose Legal basis
Responding to early-access enquiries and contact form submissions Pre-contract steps / legitimate interest (Art. 6(1)(b)/(f))
Operating and securing the Cybret AI platform and website Legitimate interest (Art. 6(1)(f))
Managing platform accounts and delivering the reachability analysis service Performance of contract (Art. 6(1)(b))
Legal compliance and maintaining records Legal obligation (Art. 6(1)(c))
Product and security updates to existing contacts (where opted in) Consent (Art. 6(1)(a))
Analytics cookies to understand website usage Consent (ePrivacy Directive + Art. 6(1)(a))

4. Recipients and Transfers

Personal data is shared only with processors acting on the Company's behalf under Article 28 GDPR data-processing agreements. These include infrastructure hosting providers, email-delivery services, and (where you have consented) analytics providers. We select processors that maintain appropriate security standards.

Where data is transferred outside the EU/EEA, we rely on Standard Contractual Clauses (Art. 46 GDPR) and assess additional safeguards as required by the Schrems II ruling. We do not sell personal data to third parties, and we do not use contact data or platform usage data for advertising purposes.

5. Retention

We retain personal data only for as long as necessary for the purposes described:

  • Early-access enquiry and contact form data: 24 months after last contact;
  • Platform account data: for the duration of the account plus 12 months after closure to satisfy any outstanding legal or contractual obligations;
  • Server access logs: 90 days;
  • Analytics data (where consented): up to 13 months, then aggregated or deleted.

6. Your GDPR Rights

Under the GDPR you have the following rights with respect to personal data the Company holds about you:

  • Right of access (Art. 15): confirm whether we process your data and obtain a copy;
  • Right to rectification (Art. 16): ask us to correct inaccurate or incomplete data;
  • Right to erasure / "right to be forgotten" (Art. 17), subject to limited exceptions where we have an overriding legal basis to retain data;
  • Right to restriction of processing (Art. 18): ask us to limit how we use your data while a dispute is resolved;
  • Right to data portability (Art. 20): receive your data in a structured, machine-readable format where processing is based on consent or contract;
  • Right to object (Art. 21), including to direct marketing without further conditions;
  • Right not to be subject to automated decision-making (Art. 22): the Company does not engage in automated decision-making with legal or similarly significant effects.

To exercise any right, email [email protected]. We respond within one month, extendable by two further months for complex requests. We may need to verify your identity before fulfilling a request.

7. Right to Lodge a Complaint

You have the right to lodge a complaint with your national supervisory authority. The Swedish supervisory authority is Integritetsskyddsmyndigheten (IMY), reachable at imy.se. A list of all EU/EEA supervisory authorities is available at edpb.europa.eu.

8. Cookies

See our Cookie Policy for full details. Non-essential cookies (including analytics cookies) are not set until you give prior consent through the cookie banner displayed on your first visit to getcybretai.com. You can withdraw or change your consent at any time through the "Cookie preferences" link in the footer.

9. Security

The Company implements technical and organisational measures appropriate to the risk posed by processing personal data. These include TLS encryption in transit, encrypted storage at rest, role-based access controls limiting who can access personal data, and regular internal security reviews. Given that Cybret AI is itself a security product, we hold our own infrastructure to a high standard.

10. Changes to This Policy

Material changes will be reflected by an updated "Last updated" date at the top of this page. Where required by applicable law, we will request renewed consent before the changes take effect.

11. Contact

Cybret AI AB
Regeringsgatan 29
111 57 Stockholm, Sweden
Email: [email protected]
Phone: +46 8 502 4180