Privacy policy
Effective from August 26, 2026. Describes how CO Mitt AB processes personal data within Nisenta.
Data controller
CO Mitt AB (Swedish org. no. 559191-9765) is the data controller for personal data processed within Nisenta. Questions about this policy or your data can be sent to support@nisenta.com.
What data we collect
At registration: company name, organization number, contact person, phone number, invoice address, invoice email, number of employees, and the email/password used to log in. During use of the service: the information you enter yourselves into the gap analysis, incident handling, supplier follow-up, and security training. The self-test at nisenta.com/sjalvtest requires no account and stores no data tied to your identity.
Why we process the data
We process the data to deliver the service under our agreement with you, handle invoicing, send important information and reminders about your compliance, and respond to support requests. The legal basis is mainly performance of a contract, in some cases a legal obligation (e.g. Swedish bookkeeping law) or legitimate interest.
How long we keep the data
Data is kept for as long as the customer relationship lasts. Data required for bookkeeping is kept for seven years under Swedish bookkeeping law, even after the relationship ends. You may request deletion of your data at any time, to the extent this doesn't conflict with other legislation.
Who we share data with
We share data with the processors required to run the service: Supabase (database and file storage, within the EU in Sweden), Vercel (application hosting), and Resend (transactional email delivery). We never sell your data or share it for marketing purposes. If a processor is based outside the EU/EEA, we ensure appropriate safeguards, such as standard contractual clauses, under GDPR.
Cookies
Nisenta uses necessary cookies for login and session handling, plus cookie-free visitor analytics (Vercel Web Analytics) that sets no cookies and collects no personal data. We use no tracking or analytics that would require consent.
Your rights
You have the right to request an extract of the data we hold about you, correct inaccurate data, request deletion, request restriction of processing, object to processing, and request data portability. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) if you believe we're processing your data incorrectly.
Changes to this policy
We may update this policy when needed, for example if we change a provider or add a feature that affects how data is processed. The date at the top shows when the policy was last updated.
If you need a Data Processing Agreement (DPA) for your own documentation, see our Trust page or contact us.