Effective date: 20 April 2026
Last updated: 20 April 2026
1. Controller Information
This Privacy Policy explains how 7Security GmbH ("we", "us", "our") collects, uses, stores and protects Personal Data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR").
Data Controller:
7Security GmbH
Hiessgasse 12/3, 1030 Vienna, Austria
Registration Number: FN561824m
VAT Number: ATU77298229
Website: https://pci.7sec.com
Email: contact@7sec.com
2. Personal Data We Collect
2.1 Information You Provide
We may collect the following information when you contact us or use our services:
Full name
Business email address
Phone number
Company name
Job title
Country
Information submitted through contact forms
Information provided during consultations, meetings or certification projects
2.2 Information Collected Automatically
When you visit our website, we may automatically collect:
IP address
Browser type and version
Device information
Operating system
Approximate geographic location
Website usage data (pages visited, time spent on pages, referring website)
Cookies and similar tracking technologies
3. Purpose of Processing
We process Personal Data for the following purposes:
Responding to enquiries
Providing requested information and services
Scheduling consultations and meetings
Performing contractual obligations
Managing customer relationships
Improving our website, products and services
Measuring website performance and analytics
Sending marketing communications (where permitted or with your consent)
Detecting fraud and maintaining website security
Complying with applicable legal and regulatory obligations
4. Legal Basis for Processing
We process Personal Data on one or more of the following legal bases under Article 6 GDPR:
Consent (Art. 6(1)(a)) — marketing communications and non-essential cookies.
Performance of a Contract (Art. 6(1)(b)) — providing consultations, certification services and fulfilling contractual obligations.
Legal Obligation (Art. 6(1)(c)) — complying with applicable laws and regulations.
Legitimate Interests (Art. 6(1)(f)) — improving our services, analysing website usage, ensuring business development, maintaining security and preventing fraud, provided these interests do not override your rights and freedoms.
5. Cookies and Tracking Technologies
We use cookies and similar technologies to:
Ensure the website functions properly
Remember user preferences
Analyse website traffic
Improve user experience
Measure advertising effectiveness
Deliver relevant marketing content
We use the following categories of cookies:
Necessary Cookies (always active)
Functional Cookies
Analytics Cookies
Marketing Cookies
The retention period depends on the type of cookie. Some cookies expire when your browsing session ends, while persistent cookies may remain on your device for up to 24 months.
You can manage your cookie preferences through our Cookie Banner or your browser settings.
6. Sharing of Personal Data
We may share Personal Data with:
Cloud infrastructure providers
CRM providers
Analytics providers
Advertising platforms
Meeting scheduling providers
IT service providers
Professional advisers (lawyers, accountants and auditors)
Government authorities where required by law
All third parties process Personal Data under contractual obligations and appropriate security safeguards.
7. Third-Party Services
We currently use or may use the following third-party services:
Google Analytics
Google Ads
Meta (Facebook) Pixel and Meta Ads — operated by Meta Platforms Ireland Limited
LinkedIn Ads and LinkedIn Insight Tag — operated by LinkedIn Ireland Unlimited Company
Microsoft Clarity
Calendly
NetHunt CRM
Zapier
Cloudflare
Microsoft 365 and/or Google Workspace
These providers may process Personal Data on our behalf in accordance with applicable Data Processing Agreements and their own privacy policies.
8. International Data Transfers
Some of our service providers may process Personal Data outside the European Economic Area (EEA).
Whenever Personal Data is transferred internationally, we ensure appropriate safeguards are in place, including:
European Commission Adequacy Decisions
Standard Contractual Clauses (SCCs)
Other transfer mechanisms permitted under the GDPR
9. Data Retention
We retain Personal Data only for as long as necessary to fulfil the purposes described in this Privacy Policy.
Typical retention periods include:
Contact requests — Up to 12 months
Client data — Duration of the contract plus 5 years (or longer where legally required)
Marketing communications — Until consent is withdrawn or retention is no longer necessary
Analytics and cookie data — Up to 24 months
10. Your Rights Under GDPR
Under the GDPR, you have the right to:
Access your Personal Data (Art. 15)
Rectify inaccurate Personal Data (Art. 16)
Request erasure ("Right to be Forgotten") (Art. 17)
Restrict processing (Art. 18)
Receive your Personal Data in a portable format (Art. 20)
Object to processing (Art. 21)
Withdraw consent at any time where processing is based on consent
To exercise any of these rights, please contact us at: contact@7sec.com
You also have the right to lodge a complaint with your local supervisory authority or with the Bulgarian Commission for Personal Data Protection (CPDP).
11. Data Protection Officer
We have not appointed a Data Protection Officer because we are not legally required to do so under Article 37 GDPR.
For any privacy-related enquiries, please contact: contact@7sec.com
12. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
13. Data Security
We implement appropriate technical and organisational measures to protect Personal Data, including:
SSL/TLS encryption
Secure cloud infrastructure
Access controls based on the principle of least privilege
Authentication and authorization mechanisms
Regular software updates
Internal security policies
Protection against unauthorized access, alteration, disclosure or destruction of Personal Data
While we take appropriate measures to safeguard Personal Data, no method of transmission over the Internet or electronic storage can be guaranteed to be completely secure.
14. Confidentiality
Information shared with us during consultations, pre-sales discussions, certification projects or other business communications is treated as confidential and handled in accordance with our internal security procedures and applicable legal obligations.
15. Third-Party Websites
Our website may contain links to third-party websites.
We are not responsible for the privacy practices or content of those websites. We encourage you to review their privacy policies before providing any Personal Data.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
Any changes will be published on this page together with the updated effective date.
17. Contact
If you have any questions regarding this Privacy Policy or the processing of your Personal Data, please contact us:
7Security GmbH
Hiessgasse 12/3, 1030 Vienna, Austria
Website: https://pci.7sec.com
Email: contact@7sec.com