Privacy Policy

Last updated: 26 September 2026

1. Introduction

Venor AB (org. nr 559116-3695), referred to as "we", "our" or "us", is committed to protecting your privacy. This Privacy Policy explains how we handle personal data when you:

  • visit our websites;
  • contact us;
  • use Tveir, our AI-assisted security operations service (the "Service").

2. Our role

  • As controller. We decide how your data is used when you visit our websites, contact us, or sign in to and use the Service. This policy describes that processing.
  • As processor, for our customers. The Service analyses security alerts from our customers' own systems. Those alerts can contain personal data, such as user names, email addresses, device names and IP addresses. For that data our customer (usually your employer) is the controller, and we process it only on their instructions under our agreement with them. That agreement includes the data protection terms in section 8 of our Terms of Service, at https://venor.se/terms. Section 5 describes this processing. Questions about it are best sent to the organisation that uses the Service; we will help them answer.

3. Information we collect

When you visit our websites or contact us:

  • Contact information: name, email address, phone number, company name and your message, when you use our contact form or email us.
  • Usage and technical data: pages visited, time spent, IP address, browser and device type, and operating system.
  • Company identification: with your consent, a visitor identification service uses your IP address to identify the company you are visiting from (see section 6).

When you use the Service:

  • Account data: your email address, your role in your organisation's environment, and when your account was created and last used. If you sign in with a password, we store only a secure hash of it, never the password itself.
  • Sign-in data: if you sign in with a Google or Microsoft account, we receive your name and email address from that provider when you sign in, so we can confirm who you are.
  • Activity and security data: actions you take in the Service, such as changing settings or overriding an assessment, recorded in an audit log together with your IP address. We also record sign-in attempts, which we use to detect and block abuse.

4. How we use your information, and our legal basis

  • Responding to inquiries and providing support: our legitimate interest in answering you, or steps before entering into a contract.
  • Sending information about our services to your work email address: our legitimate interest in business-to-business marketing. You can opt out at any time with the unsubscribe link or by contacting us.
  • Website analytics and company identification: your consent, given through our cookie banner.
  • Giving you access to the Service your organisation has contracted: our legitimate interest in providing that Service to our customer.
  • Keeping the Service and its users secure, including audit logs and abuse detection: our legitimate interest in security, and legal obligations where they apply.
  • Complying with the law: legal obligation.

5. Customer data processed in the Service

To triage a security alert, the Service may:

  • read the alert and related information from the customer's connected security platforms;
  • analyse it with AI models;
  • run public web searches using details from the alert, such as file names, domains and hashes, and in some cases the name of a person who appears in it.

The results are shown to the customer's users and, depending on the customer's settings, written back to the customer's platforms or sent to destinations the customer chooses.

We process this data only to provide the Service to our customer, under our agreement with them. We do not sell it, and we do not use it to train AI models. It is stored in the European Union, unless the customer has agreed another region with us in writing.

6. Cookies and similar technologies

Our websites use:

  • Essential cookies, needed for the websites to work. These do not require consent.
  • Analytics and company identification. With your consent, we use Dealfront (formerly Leadfeeder), which identifies the company you visit from (based on IP address) and records which pages were visited, and similar analytics. These run only after you accept them in our cookie banner.

You can withdraw your consent at any time through the "Cookie settings" link at the bottom of every page, or by clearing cookies in your browser; the cookie banner will then ask you again. Withdrawing consent does not affect processing that took place before.

The Service itself uses only the cookies needed to keep you signed in and to protect sign-in. These do not require consent.

7. Who we share data with

We do not sell personal data. We share it only with service providers that process it on our behalf under contracts that protect it, and when the law requires it.

For our websites and contact with you:

  • Lovable: website hosting
  • Supabase: contact form processing
  • HubSpot: customer relationship management and email
  • Dealfront (formerly Leadfeeder): visitor company identification, with consent

For the Service:

  • Google: hosting and infrastructure (Google Cloud), AI analysis (Gemini) and Google sign-in
  • Anthropic: AI analysis
  • Microsoft: Microsoft sign-in
  • SerpApi: public web search

8. Transfers outside the EU/EEA

Some of the providers above process data outside the EU/EEA, for example in the United States. When they do, the transfer relies on the European Commission's Standard Contractual Clauses or, where the provider is certified under it, the EU–U.S. Data Privacy Framework. You can contact us for more information about these safeguards.

9. How long we keep data

  • Contact and inquiry data: up to 24 months after our last contact, unless we enter into a business relationship.
  • Analytics and company identification data: up to 13 months.
  • Service accounts: for as long as your organisation's environment exists.
  • Audit and security logs: up to 400 days, so that security events can be investigated.
  • Sign-in: our sign-in service keeps no record of the sign-ins made through it. It holds sign-in details only briefly, while a sign-in is completed.
  • When a customer's agreement ends: within 30 days we delete the customer's environment, including its accounts, logs and customer data. Our infrastructure provider then completes permanent deletion under its own deletion process. We keep only what we need for our own accounting and legal obligations.

10. Data security

As a cybersecurity company, we take data protection seriously. We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction. Access to data is limited to personnel who need it, and they are bound by confidentiality.

11. Your rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the right to:

  • Access: request a copy of your personal data.
  • Rectification: request correction of inaccurate data.
  • Erasure: request deletion of your personal data.
  • Restrict processing: request that we limit how we use your data.
  • Data portability: receive your data in a structured, machine-readable format.
  • Object: object to processing based on our legitimate interests, including direct marketing.
  • Withdraw consent: at any time, where we rely on your consent.
  • Lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se, or with the supervisory authority where you live.

For data we process on behalf of a customer (section 5), please contact that organisation. If you contact us, we will pass your request on to them.

12. Automated assessments

The Service assesses security alerts automatically. These assessments are about security events, not decisions about individuals. They are decision support for our customers, and the customer decides what action to take.

13. Contact

Venor AB

Org. nr 559116-3695

Stockholm, Sweden

firstcontact@venor.se

+46 (0) 8 38 88 67

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the new version on this page and update the "Last updated" date. If we make material changes that affect how we process your data in the Service, we will also tell our customers.

15. Signing in to Tveir with Google or Microsoft

When you sign in to a Tveir console with your Google or Microsoft work account, Venor's sign-in service at auth.bjoern.service.venor.se sends you to Google or Microsoft to sign in, and receives back a signed identity token.

  • What we receive: your email address, your first and last name, and, from Microsoft, whether your organisation has verified the domain of that email address. We ask only for basic sign-in scopes (openid, email, profile). We do not receive your password, and we do not read your mailbox, files, calendar or directory.
  • What we keep, and for how long: to finish the sign-in, we briefly store your email address, your name, and a per-console user identifier derived from your account. It is stored only until your console collects it, normally within seconds, and is deleted at that moment. If a sign-in is abandoned, the record expires after 60 seconds and is deleted automatically, typically within 24 hours. After deletion, our database provider can still technically serve the record for up to one hour; after that no copy remains. We keep no backups of this data.
  • Where: Google Cloud Firestore, in the europe-north1 (Finland) region.
  • What is passed on: your email address and name are passed only to the Tveir console you are signing in to, which uses them to decide whether your account may sign in.
  • Logs: our load balancer records the IP address, browser user agent and requested web address of each request, for security and abuse prevention. Our sign-in service never writes your email address to its logs.
  • Who processes it: Google (as the sign-in provider for Google accounts, and as our cloud host) and Microsoft (as the sign-in provider for Microsoft Entra ID work accounts).
  • Your organisation decides: whether Google or Microsoft sign-in is used, and which email domain may sign in to a console, is configured by your organisation's administrators.