Privacy Policy
Last updated: 23 July 2026
This Privacy Policy explains how ISMS Guide processes personal data when you visit the website, request information or use the platform.
Data controller
The operator of ISMS Guide acts as data controller for account, website and contact data. For customer workspace content, roles may vary depending on the customer's instructions and applicable law.
Data we process
- Account data such as name, email address, language, account status and sign-in timestamps.
- Company membership, roles and workspace records entered by authorized users.
- Contact form, feedback and standard-notification requests.
- Security and technical data such as request metadata, rate-limit identifiers and audit events.
- Analytics data only when optional analytics is enabled and consent has been given.
Purposes and legal bases
We process data to create and secure accounts, provide contracted platform functions, respond to requests, prevent abuse, maintain auditability and comply with legal obligations. Depending on the activity, processing is based on contract performance, legal obligation, legitimate interests or consent.
Recipients and international transfers
Data may be processed by infrastructure, database, email delivery, security and analytics providers only as needed to provide the service. Where data is transferred internationally, we use the transfer mechanism and safeguards required by applicable law.
- Supabase — managed database, authentication, file storage and related infrastructure.
- Mailtrap — transactional email delivery and delivery diagnostics.
- Google Analytics — optional website measurement, only after analytics consent.
- Coolify-managed hosting and the underlying hosting provider — application deployment, runtime, network and backup infrastructure.
No sale or targeted advertising
ISMS Guide does not sell personal data or share it for cross-context behavioural advertising. If this practice changes, the policy and any legally required choice mechanism will be updated before the change takes effect.
Retention and security
Data is retained only for as long as needed for the service, security, dispute resolution and legal obligations. We use access controls, tenant isolation, encryption in transit, logging and restricted administrative access; no system can eliminate every risk.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, portability or information about processing. You may also withdraw consent where processing relies on consent, without affecting earlier lawful processing, and lodge a complaint with the competent data protection authority.
Children
The service is intended for organizations and professional users, not children. We do not knowingly request personal data directly from children.
Use the contact form for privacy questions or rights requests.
Privacy request →ISMS Guide is not affiliated with, endorsed by or approved by ISO, IEC or any certification body. ISO and IEC are trademarks of their respective organisations. All guidance content on this platform is original work and is not a reproduction of any standard.