Legal · Privacy

    Privacy Policy

    SYDERA.io Technologies AS — sydera.io
    Version 1.0 · Effective: 29 May 2026

    1. Data controller

    The data controller for personal data collected via sydera.io and Sydera Policy Scan is:

    SYDERA.io Technologies AS
    Subsidiary of STÖ GROUP AS
    ALEAP / Forskningsparken, Gaustadalléen 21, 0349 Oslo
    Email: hello@sydera.io

    This policy covers processing in connection with the sydera.io website and the Sydera Policy Scan service. When a customer uploads policy documents, the customer is the data controller for the document content and Sydera acts as data processor (see section 6).

    2. What personal data we process

    2.1 Contact and lead form (Policy-check funnel)

    When you complete the qualification form on /policyscan/test and choose to receive our regulatory guide, we process:

    DataPurposeLegal basis
    Email addressSend the regulatory guide and relevant updatesGDPR Art. 6(1)(a) (consent)
    Role, organisation size, pain pointTailor the guide and understand the audienceGDPR Art. 6(1)(a) (consent) and (f) (legitimate interest in product improvement)
    Consent text and timestampDocument valid consent, cf. GDPR Art. 7GDPR Art. 6(1)(c) (legal obligation)

    2.2 Authenticated users

    When you register an account to use Sydera Policy Scan, we process email, name, organisation and sign-in events. Legal basis: GDPR Art. 6(1)(b) (contract).

    2.3 Policy documents

    On upload, the customer confirms that the document is a governance document and contains no personal data. This attestation is the primary mechanism for keeping personal data out of the service. Sydera Policy Scan analyses policy and OHS documents, not people.

    As a supplementary control, a GDPR Pre-scan looks for national identity numbers, diagnoses, sick-leave language and other indicators of special categories (GDPR Art. 9). If the threshold is hit, the document is rejected and deleted immediately with the message "The document was not analysed. Upload the governance document instead."

    2.4 Technical logs

    We process IP address, browser type and timestamp for technical purposes (operational security, abuse protection) based on GDPR Art. 6(1)(f).

    3. Cookies

    Sydera uses only strictly necessary cookies for sign-in and language preferences, cf. the Norwegian Electronic Communications Act § 2-7b. We do not use marketing or tracking cookies, nor third-party analytics cookies.

    4. Data processors and sub-processors

    CategoryVendorPurposeTransfer outside EEA
    Database and authenticationSupabase (EU region)User accounts, scan results, RLS isolationNo
    Form intake (lead funnel)Formspree (USA)Receipt and forwarding of /policyscan/test form submissionsYes — SCC + EU-U.S. Data Privacy Framework
    Hosting / edgeCloudflare Workers (global edge, EU PoPs)Serving the site and server functionsLimited — SCC where applicable
    AI mapping (engine)EU-hosted model vendors (see DPA)Automatic mapping between policy text and control points; human validates final outputNo

    We have entered into data processing agreements (DPAs) under GDPR Art. 28 with all processors. The DPA and current sub-processor list are available on request at hello@sydera.io.

    5. Transfers to third countries

    The bulk of processing happens within the EU/EEA. Where transfers to third countries occur (Formspree, any edge nodes outside the EEA), they are based on the European Commission's Standard Contractual Clauses (SCC) under GDPR Art. 46(2)(c) and, where applicable, the EU-U.S. Data Privacy Framework. We perform Transfer Impact Assessments where needed.

    6. Roles in policy scanning

    The customer is the data controller for content in documents uploaded to Sydera Policy Scan. Sydera is the data processor and processes the documents solely on the customer's documented instructions (DPA). Sydera never sells data, never uses customer data to train general models, and never combines data across customers.

    7. Retention

    • Lead data from /policyscan/test is deleted 24 months after last interaction, or immediately on withdrawal of consent.
    • User accounts are deleted on request, and at the latest 90 days after account closure.
    • Policy documents and scan results follow the customer DPA — default is deletion within 30 days after contract end.
    • Technical logs are retained for a maximum of 90 days.

    8. Security

    We encrypt data at rest and in transit (TLS). Access is enforced with row-level security per organisation, and the production environment is protected by MFA and least-privilege principles. The security measures also support the employer's internal control under the Internal Control Regulation § 5. Incidents are handled under GDPR Art. 33–34; breaches affecting data subjects are notified to the Norwegian Data Protection Authority within 72 hours.

    9. Your rights

    You have the right to access, rectification, erasure, restriction, data portability and to object to processing (GDPR Art. 15–22). Where processing is based on consent, you may withdraw it at any time (GDPR Art. 7(3)) — this does not affect the lawfulness of processing before withdrawal.

    Requests can be sent to hello@sydera.io. We respond within 30 days (GDPR Art. 12(3)). You may also lodge a complaint with the Norwegian Data Protection Authority — datatilsynet.no.

    10. Changes to this policy

    We may update this policy when the service or applicable law changes. Material changes are notified by email to authenticated users and published here with a new effective date.