RAVNSecurity

Privacy policy

Last updated: 25 August 2026

This policy describes how JBANORDIC processes personal data — what we collect, why, how long we keep it and what rights you have.

RAVN Security is a trading name of JBANORDIC (org. no. 199312274658). JBANORDIC is the data controller and the party you contract with — which is why the text below says JBANORDIC.

Data controller

JBANORDIC (Swedish org. no. 199312274658) is the data controller for the processing described in this policy. If you have questions about how we handle your personal data, or want to exercise any of your rights, contact us at hi@ravnsec.com.

What we process — and why

We only collect data needed to answer enquiries and carry out penetration tests. We never sell personal data and never use it for third-party marketing.

  • Quote request: name, company name, email address, phone number (optional) and your description of the application. Purpose: answering your enquiry and preparing a quote. Legal basis: Article 6(1)(b) GDPR — steps taken at your request prior to entering into a contract.
  • Scoping form (before an engagement): contact details, technical contact person, who authorised the testing, technical information about your environment and which systems are in scope. Purpose: planning and carrying out the agreed penetration test. Legal basis: Article 6(1)(b) GDPR — performance of a contract.
  • Test accounts: login credentials for test accounts that you provide for the engagement. They are encrypted (AES-256-GCM) before storage and are never shown in the browser again. Legal basis: Article 6(1)(b) GDPR.
  • Uploaded files: documentation, source code or other material you choose to share for the engagement. Files are stored in a private bucket and are only accessible to JBANORDIC staff. Legal basis: Article 6(1)(b) GDPR.
  • Quote acceptance: name, role, email address, IP address, browser information and the time of acceptance for whoever accepts a quote. Purpose: to be able to show that an agreement was entered into and by whom. Legal basis: article 6(1)(f) GDPR, our legitimate interest in being able to evidence agreements entered into.
  • Visitor measurement: when you visit the site, the page view is recorded together with the page address, approximate geographic region, device and browser type, and where you arrived from. The data is collected as aggregated statistics — no cookies are set, no identifier is stored in your browser, and we cannot link one visit to the next or to an identifiable person. Purpose: to know how many people find the site and which pages are read. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in understanding how the site is used.
  • Email: when you contact us at hi@ravnsec.com we process your email address and the content of your message in order to reply. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in handling correspondence.
  • Analytics and advertising measurement via Google Analytics and Google Ads, only if you have consented: if you choose to accept analytics or marketing cookies in the cookie banner, we record your visit, which pages you read and, for marketing, your interaction with our ads, linked to an identifier in your browser. Purpose: understanding how the website is used and measuring ad effectiveness. Legal basis: Article 6(1)(a) GDPR — your consent, which you can withdraw at any time via "Manage cookies" at the bottom of the page.

Recipients and sub-processors

We never share your data with third parties for their own purposes. The following providers process data on our behalf as data processors:

  • A cloud provider for database and file storage — all data is stored in the Stockholm region (EU). Covers everything you submit through our forms.
  • A website hosting, CDN and visitor-measurement provider — processes technical data such as your IP address when you visit the site. The same provider supplies the cookie-free visit statistics; the IP address is used to derive an approximate region and is not retained in the statistics.
  • A Swedish AI infrastructure provider — our default sovereign AI track. Processes scoping data and engagement material when AI analysis runs.
  • A US AI provider (frontier models) — only if you have explicitly chosen the frontier track for your engagement. See the section on third-country transfers below.
  • Google Ireland Limited — only if you have consented to analytics or marketing cookies in the cookie banner. Processes visit data for traffic statistics (Google Analytics) and ad measurement (Google Ads).

Transfers outside the EU

With the sovereign default, your engagement material is processed in Sweden and the EU. If you choose the frontier track, engagement data (for example technical documentation and test results) is transferred to a US AI provider. The transfer relies on the European Commission adequacy decision (EU-U.S. Data Privacy Framework, Article 45 GDPR) or the European Commission standard contractual clauses (Article 46 GDPR).

In the interest of transparency: our infrastructure providers have US parent companies. The data is stored within the EU, but the companies may be subject to US legislation such as the CLOUD Act.

If you accept analytics or marketing cookies, some visit data is transferred to Google Ireland Limited, which may forward it to Google LLC in the US. The transfer relies on the European Commission adequacy decision (EU-U.S. Data Privacy Framework, Article 45 GDPR) or standard contractual clauses (Article 46 GDPR) — the same legal basis as the frontier track's AI provider above.

How long we keep your data

  • Quote requests that do not lead to an engagement are deleted no later than 12 months after our last contact.
  • All material submitted in the scoping form — technical details about your environment, uploaded files and test accounts — is deleted no later than 30 days after the engagement ends. Test account credentials are deleted promptly as soon as testing is complete.
  • Contact details and contract information are kept for 24 months after the engagement ends, for follow-up and to handle any legal claims.
  • Data in invoicing records is kept for seven years under the Swedish Bookkeeping Act. Legal basis: Article 6(1)(c) GDPR — legal obligation.
  • Visit data from Google Analytics is kept according to the retention period we have set in our Google Analytics account (Google's default is 14 months for user-level data).

Security

Security is our core business, and we treat your data accordingly. All data is encrypted in transit and at rest, sensitive data such as test accounts is additionally encrypted separately with AES-256-GCM, and access is restricted to authorised staff through row-level access control in the database.

Your rights

Under the GDPR you have the right to:

  • access the personal data we process about you (Article 15)
  • have inaccurate data corrected (Article 16)
  • have your data erased (Article 17)
  • request that processing be restricted (Article 18)
  • receive your data in a machine-readable format and move it to another provider, known as data portability (Article 20)
  • object to processing based on legitimate interest (Article 21)

Contact us at hi@ravnsec.com and we will help you — we reply within one month at the latest. You also always have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), www.imy.se.

Automated decision-making

We make no automated decisions that produce legal effects or similarly significantly affect you (Article 22 GDPR). JBANORDIC AI agents work as tools directed by our penetration testers — assessments and reports are always reviewed by humans.

Changes to this policy

We may update this policy, for example as the service evolves or legislation changes. The latest version is always available on this page, and the date at the top shows when it was last changed. If we make material changes, we inform active customers directly.