Privacy Policy
Last updated 16 August 2026
This policy explains what personal data FirmoryX collects, why, and the rights you have under the EU General Data Protection Regulation (GDPR).
1. Who we are
FirmoryX ("we", "us") is a service operated by Amandah Klingsten, an enskild firma (a sole proprietorship registered in Sweden), based in Eskilstuna, Sweden. Full business-registration details are available on request. For any privacy question, or to exercise your rights, contact us at privacy@firmoryx.se. For most data our customers upload, we act as a processor on their behalf — see our Data Processing Agreement.
2. What we collect
- Account data — your name (derived from your email) and email address, used to create and secure your account.
- Customer content — the client, device, firmware, and vulnerability data you enter or import to run the service. This may include the names of your own clients.
- Billing data — subscription tier and payment metadata. Card details are collected and stored by our payment processor (Stripe) and never reach our servers.
- Technical data — IP address, browser type, and request logs, processed transiently to operate and secure the service.
We do not use advertising trackers, and we set only cookies that are strictly necessary to keep you signed in.
3. Why we use it (legal bases)
- To provide the service — performance of our contract with you (Art. 6(1)(b)).
- To secure and maintain it — our legitimate interests in a safe, reliable service (Art. 6(1)(f)).
- To bill you — performance of contract and compliance with legal accounting obligations.
4. Sharing & sub-processors
We do not sell personal data. We share it only with the vetted sub-processors that run the service on our behalf (hosting, database, storage, payments), each bound by a data-processing agreement. The current list, including what each one handles and where, is published at firmoryx.se/legal/subprocessors.
5. International transfers
Some sub-processors are located outside the EU/EEA (for example, in the United States). Where that is the case, transfers are protected by the European Commission's Standard Contractual Clauses or an equivalent safeguard.
6. How long we keep it
We keep account and customer content for as long as your account is active. When you delete your organization, we permanently erase its data from our production systems, and it is purged from routine backups within 30 days. Invoicing records are retained as required by law.
7. Your rights
Under the GDPR you have the right to access, correct, export, restrict, object to, and erase your personal data. You can export or permanently delete your organization's data yourself from Settings → Account & data, or contact privacy@firmoryx.se. You also have the right to lodge a complaint with your supervisory authority (in Sweden, the Integritetsskyddsmyndigheten, IMY).
8. Security
We protect data with tenant isolation, encryption in transit, and least-privilege access. Read more on our security page.
9. Changes
We may update this policy; the "last updated" date above always reflects the current version, and we will notify account admins of material changes.