Get our free PCI DSS cost-reduction guide cut costs by up to 10× Download free PDF Download free

Privacy Policy

Effective date: 20 April 2026
Last updated: 20 April 2026

1. Controller Information

This Privacy Policy explains how 7Security GmbH ("we", "us", "our") collects, uses, stores and protects Personal Data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR").
Data Controller:
7Security GmbH
Hiessgasse 12/3, 1030 Vienna, Austria
Registration Number: FN561824m
VAT Number: ATU77298229
Website: https://pci.7sec.com
Email: contact@7sec.com

2. Personal Data We Collect

2.1 Information You Provide

We may collect the following information when you contact us or use our services:

  • Full name

  • Business email address

  • Phone number

  • Company name

  • Job title

  • Country

  • Information submitted through contact forms

  • Information provided during consultations, meetings or certification projects

2.2 Information Collected Automatically

When you visit our website, we may automatically collect:

  • IP address

  • Browser type and version

  • Device information

  • Operating system

  • Approximate geographic location

  • Website usage data (pages visited, time spent on pages, referring website)

  • Cookies and similar tracking technologies

3. Purpose of Processing

We process Personal Data for the following purposes:

  • Responding to enquiries

  • Providing requested information and services

  • Scheduling consultations and meetings

  • Performing contractual obligations

  • Managing customer relationships

  • Improving our website, products and services

  • Measuring website performance and analytics

  • Sending marketing communications (where permitted or with your consent)

  • Detecting fraud and maintaining website security

  • Complying with applicable legal and regulatory obligations

4. Legal Basis for Processing

We process Personal Data on one or more of the following legal bases under Article 6 GDPR:

  • Consent (Art. 6(1)(a)) — marketing communications and non-essential cookies.

  • Performance of a Contract (Art. 6(1)(b)) — providing consultations, certification services and fulfilling contractual obligations.

  • Legal Obligation (Art. 6(1)(c)) — complying with applicable laws and regulations.

  • Legitimate Interests (Art. 6(1)(f)) — improving our services, analysing website usage, ensuring business development, maintaining security and preventing fraud, provided these interests do not override your rights and freedoms.

5. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Ensure the website functions properly

  • Remember user preferences

  • Analyse website traffic

  • Improve user experience

  • Measure advertising effectiveness

  • Deliver relevant marketing content

We use the following categories of cookies:

  • Necessary Cookies (always active)

  • Functional Cookies

  • Analytics Cookies

  • Marketing Cookies

The retention period depends on the type of cookie. Some cookies expire when your browsing session ends, while persistent cookies may remain on your device for up to 24 months.
You can manage your cookie preferences through our Cookie Banner or your browser settings.

6. Sharing of Personal Data

We may share Personal Data with:

  • Cloud infrastructure providers

  • CRM providers

  • Analytics providers

  • Advertising platforms

  • Meeting scheduling providers

  • IT service providers

  • Professional advisers (lawyers, accountants and auditors)

  • Government authorities where required by law

All third parties process Personal Data under contractual obligations and appropriate security safeguards.

7. Third-Party Services

We currently use or may use the following third-party services:

  • Google Analytics

  • Google Ads

  • Meta (Facebook) Pixel and Meta Ads — operated by Meta Platforms Ireland Limited

  • LinkedIn Ads and LinkedIn Insight Tag — operated by LinkedIn Ireland Unlimited Company

  • Microsoft Clarity

  • Calendly

  • NetHunt CRM

  • Zapier

  • Cloudflare

  • Microsoft 365 and/or Google Workspace

These providers may process Personal Data on our behalf in accordance with applicable Data Processing Agreements and their own privacy policies.

8. International Data Transfers

Some of our service providers may process Personal Data outside the European Economic Area (EEA).
Whenever Personal Data is transferred internationally, we ensure appropriate safeguards are in place, including:

  • European Commission Adequacy Decisions

  • Standard Contractual Clauses (SCCs)

  • Other transfer mechanisms permitted under the GDPR

9. Data Retention

We retain Personal Data only for as long as necessary to fulfil the purposes described in this Privacy Policy.
Typical retention periods include:

  • Contact requests — Up to 12 months

  • Client data — Duration of the contract plus 5 years (or longer where legally required)

  • Marketing communications — Until consent is withdrawn or retention is no longer necessary

  • Analytics and cookie data — Up to 24 months

10. Your Rights Under GDPR

Under the GDPR, you have the right to:

  • Access your Personal Data (Art. 15)

  • Rectify inaccurate Personal Data (Art. 16)

  • Request erasure ("Right to be Forgotten") (Art. 17)

  • Restrict processing (Art. 18)

  • Receive your Personal Data in a portable format (Art. 20)

  • Object to processing (Art. 21)

  • Withdraw consent at any time where processing is based on consent

To exercise any of these rights, please contact us at: contact@7sec.com
You also have the right to lodge a complaint with your local supervisory authority or with the Bulgarian Commission for Personal Data Protection (CPDP).

11. Data Protection Officer

We have not appointed a Data Protection Officer because we are not legally required to do so under Article 37 GDPR.
For any privacy-related enquiries, please contact: contact@7sec.com

12. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects.

13. Data Security

We implement appropriate technical and organisational measures to protect Personal Data, including:

  • SSL/TLS encryption

  • Secure cloud infrastructure

  • Access controls based on the principle of least privilege

  • Authentication and authorization mechanisms

  • Regular software updates

  • Internal security policies

  • Protection against unauthorized access, alteration, disclosure or destruction of Personal Data

While we take appropriate measures to safeguard Personal Data, no method of transmission over the Internet or electronic storage can be guaranteed to be completely secure.

14. Confidentiality

Information shared with us during consultations, pre-sales discussions, certification projects or other business communications is treated as confidential and handled in accordance with our internal security procedures and applicable legal obligations.

15. Third-Party Websites

Our website may contain links to third-party websites.
We are not responsible for the privacy practices or content of those websites. We encourage you to review their privacy policies before providing any Personal Data.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.
Any changes will be published on this page together with the updated effective date.

17. Contact

If you have any questions regarding this Privacy Policy or the processing of your Personal Data, please contact us:
7Security GmbH
Hiessgasse 12/3, 1030 Vienna, Austria
Website: https://pci.7sec.com
Email: contact@7sec.com

Get a free consultation

Sign up for the webinar

Leave your contact details and we'll send you the next available webinar dates.

Every Wednesday · New York 9 a.m. · Europe 3 p.m. · Singapore 7 p.m.

Get your project cost estimate

30 minutes with our QSA team — leave your details to confirm the slot.

Your slot:

Download the free guide

Leave your details and the guide will be emailed to you right away.

Free estimate

Get Your Free PCI DSS Cost Estimate in 60 Seconds

Answer a few quick questions, and our PCI DSS experts will prepare a personalized estimate.

You will receive:

  • Estimated project cost
  • Expected PCI DSS Level
  • Initial scope assessment
  • Recommended implementation approach
  • Suggestions on how to reduce PCI DSS costs

We will send your estimate within one business day.