Privacy Notice
Last updated: 2026-10-08
GDPR & EU compliance: SUMS Compliance is operated from the European Union and is designed to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Swedish Data Protection Act (Dataskyddslagen, SFS 2018:218), and applicable EU/EEA data protection law. Where we offer the Service to users in the United Kingdom, we also comply with the UK GDPR and the Data Protection Act 2018.
1. Who we are
iThing AB (org.nr 559153-5397, VAT SE559153536901) ("we", "us") provides SUMS Compliance (the "Service"). For personal data processed in connection with the Service, we act as the data controller.
2. Personal data we collect
- Account data: name, email address, organization, login credentials.
- Profile data: display name, role, preferences.
- Content: documents, assessment data, evidence files and notes you upload.
- Support communications: messages you send us.
- Usage and telemetry: pages visited, actions taken, error logs.
- Device data: IP address, browser type, device identifiers.
3. How we use it
- To create and operate your account.
- To provide the Service, including assessments, evidence storage, and reporting.
- To secure the Service and prevent fraud and abuse.
- To improve the product and troubleshoot issues.
- To respond to support requests.
- To send service-related communications (and, with your consent, marketing).
4. Legal basis
We rely on the following legal bases: performance of the contract with you (providing the Service), our legitimate interests (security, product improvement), your consent (where required, e.g. for marketing), and compliance with legal obligations.
5. Who we share data with
- Service providers / subprocessors: hosting, database, email, analytics, and customer support tools, acting on our instructions.
- Paddle, our Merchant of Record, for the sale of subscriptions, payments, billing, tax compliance, invoicing and subscription management.
- Professional advisers (legal, accounting) where necessary.
- Authorities where required by law.
6. International transfers
Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
7. Data retention
We retain personal data for as long as your account is active and for a reasonable period afterwards to comply with legal obligations and to resolve disputes. After that, data is deleted or anonymised.
8. Your rights
Depending on your location, you may have rights to access, rectify, erase, restrict or object to processing of your personal data, to data portability, and to withdraw consent. You also have the right to lodge a complaint with a supervisory authority. We will respond to requests within one month.
9. Security
We use appropriate technical and organisational measures, including encryption in transit, access controls and audit logging, to protect your personal data.
10. Cookies
We use cookies and similar technologies that are strictly necessary to operate the Service (e.g. to keep you signed in), and limited analytics cookies to understand product usage. You can manage cookie preferences in your browser.
11. Contact
For privacy questions or to exercise your rights, contact us via the Service.