Privacy Policy

1. Who We Are

Sysarb AB (org. nr 556681-8828), Järntorget 12A, 732 30 Arboga, Sweden, is the data controller for the processing of personal data described in this policy.

This privacy policy explains how we collect, use, share, and protect personal data when you interact with us as a website visitor, prospect, customer, job applicant, or business contact. It covers our obligations under the EU General Data Protection Regulation (GDPR) and the EU AI Act (Regulation 2024/1689).

This policy does not cover the processing of customer employee data within the Sysarb platform, which is governed by separate Data Processing Agreements between Sysarb and each customer.

Data Protection Officer: Peter Wäfors

Email: dpo@sysarb.com

2. What Personal Data We Collect

We collect different categories of personal data depending on how you interact with us:

2.1 Website Visitors

•  Device and browser information (IP address, browser type, operating system, screen resolution)

•  Usage data (pages visited, time on site, referring URL, clicks)

•  Cookie identifiers and similar tracking technologies (see Section 8)

2.2 Prospects and Business Contacts

•  Contact information (name, work email, phone number, job title, company)

•  Professional profile information (company size, industry, country)

•  Communication history (emails, form submissions, meeting bookings)

•  Engagement data (email opens, content downloads, webinar attendance)

2.3 Customers and Platform Users

•  Account information (name, work email, role, company)

•  Support interactions (chat conversations, support tickets, feedback surveys)

•  Meeting recordings and transcripts (when enabled and with prior notice)

•  Satisfaction survey responses

2.4 Job Applicants

•  Application data (name, email, phone, CV, cover letter)

•  Interview notes and assessments

•  References (when provided by the applicant)

•  Background screening data (criminal record check, risk pattern analysis — conducted via Svensk Bakgrundsanalys for candidates progressing to the offer stage)

2.5 Office Visitors

•  Visitor name, company, host, and time of visit

3. Why We Process Your Data and Our Legal Basis

We process personal data for the following purposes, each supported by a legal basis under GDPR Article 6:

4. Use of Artificial Intelligence

Sysarb uses AI-powered features in several of its internal tools and services. In compliance with the EU AI Act (Regulation 2024/1689), we are transparent about where AI is used and how it processes personal data.

None of our AI use cases are classified as high-risk under the AI Act. We classify all current AI uses as limited-risk or minimal-risk systems. We do not use AI for automated decision-making that produces legal effects on individuals. This classification is reviewed at least annually and whenever new AI use cases are introduced.

The following AI-powered features may process your personal data:

Key principles for our AI use:

•  Human oversight: All AI-generated content that is sent to external parties is reviewed by a Sysarb employee before sending.

•  No training on your data: Our agreements with AI providers explicitly prohibit the use of your data to train AI models.

•  Data minimisation: We configure AI integrations to process only the data necessary for the intended purpose.

•  Transparency: We inform you when you are interacting with an AI system (e.g., Intercom Fin) or when a meeting is being recorded for AI transcription.

•  Audio and video recordings are personal data but are NOT classified as sensitive data (special categories under GDPR Article 9), as they are not used for biometric identification purposes.

•  Disclosure: Where AI is used to generate content that is sent to external parties (e.g., sales emails, support responses), the communication includes a notice that AI was used in its preparation, in compliance with the EU AI Act (Art. 50, proactively applied ahead of the August 2026 compliance date).

5. Who We Share Your Data With — Sub-Processors

We share personal data with the following categories of service providers (sub-processors) who process data on our behalf under Data Processing Agreements. We do not sell your personal data.

5.1 Hosting and Infrastructure

5.2 Customer Relationship and Sales

5.3 Website and Analytics

5.4 Communication and Productivity

5.5 Recruitment

5.6 Contracts, Finance, and Operations

5.7 Security and Device Management

5.8 AI Providers

The following AI model providers processpersonal data as sub-processors through the integrations described in Section4. Both providers have contractual commitments not to use Sysarb data for modeltraining.

Note on OpenAI: Sysarb does not maintain adirect sub-processor relationship with OpenAI. OpenAI processes data as asub-processor of Microsoft (for Microsoft 365 Copilot and Teams Transcriber)and Atlassian (for Atlassian Intelligence). Personal data transferred to OpenAIin this context is governed by those platform vendors' DPAs with OpenAI, not bya direct Sysarb–OpenAI agreement. OpenAI is not used in any Sysarb-controlledintegration that processes personal data.

6. International Data Transfers

Some of our sub-processors are basedoutside the EU/EEA, primarily in the United States. Where personal data istransferred to a third country, we ensure appropriate safeguards are in place:

•  EU-US Data Privacy Framework (DPF): For USproviders that are certified under the DPF (e.g., Google, Microsoft, HubSpot,Atlassian).

•  Standard Contractual Clauses (SCCs): Forproviders not covered by an adequacy decision, we rely on the EuropeanCommission's standard contractual clauses, supplemented by additional technicaland organisational measures where necessary.

•  We conduct Transfer Impact Assessments (TIAs)for transfers that involve higher-risk data or jurisdictions.

7. How Long We Keep Your Data

We retain personal data only as long asnecessary for the purpose it was collected, or as required by law:

•  Website analytics data: Up to 26 months(Google Analytics default), or as configured per tool.

•  Prospect and marketing data: For the durationof the business relationship plus up to 24 months of inactivity, unless youobject earlier.

•  Customer support data: For the duration ofthe customer relationship plus a reasonable period for follow-up.

•  Meeting recordings and transcripts: Retainedfor up to 12 months, then deleted.

•  Job application data: For the duration of therecruitment process. With your consent, we may retain your application for upto 24 months for future opportunities.

•  Visitor logs: Up to 12 months.

•  Accounting and invoicing data: As required bySwedish bookkeeping legislation (generally 7 years).

We delete or anonymise personal data whenthe retention period expires or when you request deletion (see Section 9).

8. Cookies

We use cookies and similar technologies onsysarb.com. Cookies are small files placed on your device that help usunderstand how you use our website, remember your preferences, and deliverrelevant content and advertising.

8.1 Cookie Categories

•  Necessary cookies: Required for the websiteto function (e.g., cookie consent, security). These do not require yourconsent.

•  Statistics cookies: Help us understand howvisitors interact with the website (e.g., Google Analytics, Amplitude). Requireyour consent.

•  Marketing cookies: Used to track visitorsacross websites for advertising purposes (e.g., LinkedIn, Meta, Google Ads).Require your consent.

•  Preference cookies: Remember your settingsand choices. Require your consent.

8.2 Managing Cookies

When you first visit sysarb.com, you areasked to choose which cookie categories to accept via our consent banner(powered by Cookiebot). You can change your preferences at any time by clickingthe cookie settings link in the website footer.

You can also delete cookies from yourbrowser settings. Note that blocking certain cookies may affect websitefunctionality.

9. Your Rights

Under the GDPR, you have the followingrights regarding your personal data:

•  Right of access (Art. 15): Request a copy ofthe personal data we hold about you.

•  Right to rectification (Art. 16): Requestcorrection of inaccurate or incomplete data.

•  Right to erasure (Art. 17): Request deletionof your data when it is no longer necessary, or when you withdraw consent.

•  Right to restriction (Art. 18): Request thatwe limit the processing of your data in certain circumstances.

•  Right to data portability (Art. 20): Receiveyour data in a structured, machine-readable format where processing is based onconsent or contract.

•  Right to object (Art. 21): Object toprocessing based on legitimate interest, including direct marketing. We willstop processing unless we demonstrate compelling legitimate grounds.

•  Right to withdraw consent: Where processingis based on consent, you may withdraw it at any time without affecting thelawfulness of prior processing.

To exercise any of these rights, contact usat dpo@sysarb.com. We will respond within one month. In complex cases, thisperiod may be extended by two months — we will inform you if this is necessary.

Every marketing email includes anunsubscribe link for easy opt-out.

10. Data Security

Sysarb is certified under ISO/IEC27001:2022 and maintains a comprehensive Information Security Management System(ISMS). We implement appropriate technical and organisational measures toprotect your personal data, including encryption in transit and at rest,role-based access controls, regular security assessments, employee securityawareness training, and incident response procedures.

For more information about our securitypractices, visit our Trust Centre at security.sysarb.app.

11. Children

Our services are designed for businessesand professionals. We do not knowingly collect personal data from childrenunder 16. If you believe we have inadvertently collected such data, pleasecontact us at dpo@sysarb.com.

12. Changes to This Policy

We may update this privacy policy from timeto time to reflect changes in our processing activities, technology, legalrequirements, or business practices. The "Last updated" date at thetop of this page indicates when the policy was last revised. For materialchanges, we will take reasonable steps to notify you.

13. Contact and Complaints

If you have questions about this privacypolicy or wish to exercise your rights, please contact:

Sysarb AB
Järntorget 12A, 732 30 Arboga, Sweden
Email: support@sysarb.com
Phone: +46 589-501 60

Data Protection Officer: Peter Wäfors
Email: dpo@sysarb.com

If you believe your data has been processedincorrectly, you have the right to lodge a complaint with the Swedish Authorityfor Privacy Protection (IMY):

Email: imy@imy.se
Postal address: Box 8114, 104 20 Stockholm, Sweden

Ready to book a demo yet, we're waiting for you!

Request demo →