CRA PROCESS
Compliance workspace
Security · Privacy · GDPR
How your compliance data is protected
This page is maintained by iThing AB (org. nr 559153-5397) to answer common security and privacy questions about CRA PROCESS. It describes controls that are in place in the product today — it is not an independent audit, certification or attestation.
Last reviewed: July 2026
Access
Who can see your data
Access requires a personal account with e-mail and password. There is no anonymous access to the workspace.
- Every product/project, clause status, task and assistant thread belongs to exactly one company.
- Database-level row security rules allow only members of that company to read or write those records — isolation is enforced in the database, not only in the interface.
- A new account and its company start in a read-only pending state until we approve it. Pending users can browse, but cannot create, edit or use the assistant.
- A company owner controls the seat roster (default five seats) and can remove a member at any time, which immediately ends that person's access to the shared data.
- Administrative functions are limited to a named superadmin account, and internal database helper functions are not callable from the public API.
Protection
In transit and at rest
- All traffic is served over HTTPS/TLS.
- Data is stored in a managed PostgreSQL database with encryption at rest and automated backups.
- Hosting and data storage are located within the EU.
- Passwords are never stored in clear text; they are hashed by the authentication provider, and new or changed passwords are checked against known breached-password lists.
Data
What we collect and why
We only process what the service needs in order to work for you:
- Account e-mail address (identification and sign-in).
- Company name, seat roster, licence/trial status and internal administrative notes.
- The content you create: product/project names, clause progress, assessment-criteria ticks, tasks, assignees, due dates, notes and evidence links.
- Assistant conversations you start inside a clause.
We do not collect payment card data in the app, and we do not use advertising or third-party tracking cookies — only the session cookie/token required to keep you signed in.
AI
Assistant processing
When you use the AI assistant, the text involved in that request — the clause context and your question — is sent to a third-party model provider for processing so a response can be generated. Your content is not used to train models, and the assistant is only invoked when you explicitly ask for an explanation, a chat reply or task suggestions.
Treat the assistant as guidance, not as legal or certification advice, and avoid pasting secrets or personal data you do not need to share.
GDPR
Your rights and our role
Controller: iThing AB, org. nr 559153-5397, Sweden. Contact: conny@ithing.se.
Lawful basis: processing of account and workspace data is necessary to perform our agreement with your company (Art. 6(1)(b)), with a legitimate interest basis (Art. 6(1)(f)) for securing and operating the service.
Your rights: access, rectification, erasure, restriction, portability and objection. Write to conny@ithing.se and we will respond within one month. You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority.
Retention: your data is kept for as long as the company's licence or trial is active. After termination it is deleted on request, and otherwise removed in the course of routine clean-up of inactive accounts. Backups age out on their own rotation schedule.
Sub-processors: we use cloud hosting and database services located in the EU, an e-mail-delivery service for account e-mails, and an AI model provider for assistant features. A current sub-processor list and a Data Processing Agreement are available on request.
Transfers: where a sub-processor may process data outside the EU/EEA, that transfer relies on Standard Contractual Clauses or an adequacy decision.
Shared responsibility
What is yours and what is ours
We are responsible for the platform: authentication, tenant isolation, encryption, backups and keeping the hosting stack patched.
You are responsible for your own use: who you invite into your company's seats, the strength and confidentiality of your password, what content and evidence you upload, and validating that your CRA / prEN 40000-1-2 conclusions are correct. This tool structures the process — it does not by itself make a product compliant.
Contact
Report a vulnerability or ask a question
Found a security issue? Please report it privately to conny@ithing.se before disclosing it publicly, and include steps to reproduce. We acknowledge reports as quickly as we can.
For general questions, use the same address or our Discord support channel.