Legal
Privacy Notice
How KASP Solutions collects, uses, and protects personal data, the lawful basis for each purpose, and how to exercise your rights.
Who we are
KASP Solutions AB (“KASP”, “we”, “us”, or “our”) is a cybersecurity and technology advisory firm registered in Sweden.
- Company name: KASP Solutions AB
- Organisation number: 559501-3508
- Registered municipality: Östersund, Sweden
KASP Solutions AB is the data controller for the personal data described in this notice, unless we are engaged by a client as a data processor under a separate agreement, in which case the client’s own privacy notice and our data processing agreement with them will govern.
For any questions about this notice or how we handle personal data, please contact us at contact@kaspsolutions.com.
What personal data we collect
Depending on our relationship with you, we may collect and process the following categories of personal data:
- Contact details. Name, job title, employer, business email address, phone number.
- Client and prospect data. Information shared in the course of advisory, mentoring, coaching, or assessment engagements, including names and roles of individuals we work with.
- Communications. Records of emails, calls, and meetings related to our services.
- Website and enquiry data. Information you submit through contact forms or provide when enquiring about our services.
- Supplier and partner data. Contact details of individuals at organisations we work with as vendors, partners, or referral contacts.
We do not knowingly collect personal data relating to children, and our services are directed at business professionals and organisations.
Why we process personal data (purposes and legal basis)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Delivering advisory, coaching, and consulting services under a signed engagement | Performance of a contract |
| Responding to enquiries and providing quotes or proposals | Legitimate interest / pre-contractual steps |
| Maintaining business relationships with clients, partners, and vendors | Legitimate interest |
| Meeting legal, tax, and accounting obligations | Legal obligation |
| Sending marketing or thought-leadership content, where permitted | Consent or legitimate interest (with opt-out available) |
Where we rely on legitimate interest, we have considered that our processing is proportionate and does not override your rights and freedoms.
How long we keep personal data
We retain personal data only for as long as necessary for the purposes set out above, typically:
- For the duration of an active client engagement, plus a period afterward to meet contractual, accounting, and legal obligations (generally up to 7 years for financial records, in line with Swedish accounting law).
- Enquiry and prospect data that does not lead to an engagement is retained for a limited period and then deleted or anonymised.
Who we share personal data with
We do not sell personal data. We share personal data only where necessary, with the following categories of recipients:
Service providers (data processors) we currently use:
| Provider | Purpose |
|---|---|
| Microsoft 365 (Outlook, SharePoint, Teams, OneDrive) | Business email and document storage |
| Cloudflare | Website hosting |
| FortNox (Swedish online accounting system) | Invoicing and accounting |
| Calendly (online calendaring and appointment system) | Arranging online and physical meetings |
Each provider processes personal data on our behalf under a data processing agreement or the provider’s own standard contractual terms, and only for the purposes we specify. Where a provider is located outside the EU/EEA, transfers are safeguarded through mechanisms such as the EU Standard Contractual Clauses.
We may also disclose personal data where required by law, regulation, or a valid legal request.
AI-assisted tools
In delivering our advisory services, KASP Solutions AB uses a limited number of third-party artificial intelligence platforms to support drafting, research, analysis, and documentation. Where personal data is processed through these tools, they act as sub-processors on our behalf, under the same principles of data minimisation, confidentiality, and lawful processing described in this notice.
The AI platforms we currently use are:
| Provider | Function |
|---|---|
| Anthropic (Claude) | AI-assisted analysis, drafting, and advisory support |
| OpenAI | AI-assisted analysis, drafting, and research support |
| Perplexity | AI-assisted research and information retrieval |
| Gamma | AI-assisted presentation and document generation |
| Granola | AI-assisted meeting notes and transcription |
We do not submit client personal data to these platforms unless it is necessary for delivering the specific engagement, and we take reasonable steps to minimise the personal data included in any such use. Where our agreements with these providers permit it, we opt out of having submitted data used to train underlying models. We require these providers to maintain appropriate technical and organisational security measures.
Clients with a signed data processing agreement with KASP will be notified of these sub-processors in accordance with the terms of that agreement.
Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request erasure, where applicable.
- Object to or restrict certain processing.
- Request data portability, where applicable.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with the Swedish Authority for Privacy Protection (IMY), www.imy.se, or your local supervisory authority.
To exercise any of these rights, contact us at contact@kaspsolutions.com.
Security
We operate security controls aligned with NIST CSF 2.0 principles, including access management, encryption of data in transit and at rest, and incident response procedures, to protect personal data against unauthorised access, loss, or misuse.
Changes to this notice
We may update this notice from time to time to reflect changes in our practices or legal requirements. The date below reflects the most recent update.
This notice applies to personal data processed by KASP Solutions AB in the course of its business. It does not cover personal data processed by KASP on behalf of a client under a separate data processing agreement, which is governed by the terms of that agreement and the client’s own privacy notice.
Last revised: 3 August 2026