Skip to content

Legal

Privacy notice

What data INTYGA collects on this website and in the product, why, how long it is kept, and the rights you have over it.

Who we are

This website and the INTYGA service are operated by Janbjer Technologies AB (org. no. 559602-1757), a Swedish aktiebolag with its registered office at Rickards plan 3, 791 47 Falun, Sweden. For questions about this notice or about data we hold, contact privacy@intyga.com.

This website

When configured, this public website loads Plausible Analytics automatically to count page views and aggregate interactions. Plausible uses no cookies or persistent visitor identifiers and does not build a cross-site profile. We send fixed event names and labels, not names, email addresses, or contact-form answers. Plausible is not used in the signed-in Ops Console.

Optional campaign or advertising tracking, if configured, remains off until you choose. It may set cookies or share data with an advertising provider. This choice is independent of Plausible.

If an optional tracker is configured, its consent banner appears before that script loads. Declining keeps it off; accepting it does not change Plausible's operation. You can change or withdraw that optional consent using the cookie preferences link in the footer.

If you submit the contact form, we process the name, email address, company, and description you provide, for the sole purpose of responding to you. The lawful basis is our legitimate interest in answering enquiries about our product.

Cookies in the Ops Console

The Ops Console — the signed-in application you use once you have an account — does not ask for cookie consent, because nothing its cookies do is optional: every cookie it sets is required to sign you in. A person creating a new workspace separately accepts the Terms of Service; that is agreement to the customer contract, not consent to tracking. The console measures nothing about how you use it. There is no analytics of any kind, no advertising, no third-party scripts, and nothing is stored in your browser's local storage beyond remembering that you have seen its data notice. Its content security policy confines scripts and network requests to our own origin, so a tracker added there by mistake would be blocked by your browser rather than run quietly.

That is a deliberate choice rather than an omission. The witness log already records every governed action, because recording them verifiably is what the product is for — so measuring the same events a second time, in a separate analytics system, would mean holding your activity somewhere it is not needed and telling you about it in a paragraph like this one. We would rather not hold it.

The cookies it does set are strictly necessary to sign you in and to keep that sign-in safe — the category European cookie rules exempt from consent, because refusing them is the same as refusing to log in. Every one is HttpOnly, so no script can read it, and Secure wherever the console is served over HTTPS. In production each also carries the __Host- prefix, which instructs your browser to reject it outright unless it came from exactly this hostname over HTTPS — so no other site of ours, and no subdomain, can plant one. None of them profile you, follow you between sites, or are shared with anyone.

CookieWhat it is forLifetime
__Host-intyga_sessionKeeps you signed in. Holds your account identifier, an identifier for this sign-in session and the company you are currently viewing, signed so it cannot be altered. The session can be ended from our side (sign out, sign out everywhere, removing a passkey), not only by deleting the cookie.8 hours
__Host-intyga_login_bindTies a sign-in attempt to the browser that started it, so a challenge cannot be completed somewhere else.5 minutes
__Host-intyga_webauthn_login, __Host-intyga_webauthn_regCarries the one-time challenge your passkey or security key signs while signing in or enrolling a credential.5 minutes
intyga_oauth_ssoCross-site request forgery protection and one-time values for verifying your identity with your organization's single sign-on before you enroll a passkey. Set only if you use it.10 minutes

Logging out ends the session on our servers and deletes the session cookie. The rest expire on their own within minutes and are deleted as soon as the flow they belong to finishes.

The product

When you use INTYGA, we process account data (email address, authentication credentials, organizational membership) and approval records. An approval record contains the action description, its structured parameters, the identity of the requester and approver, and the cryptographic signature material.

Policy documents you store with us are encrypted in your browser before transmission. Our servers hold ciphertext and your organization's public key; decryption happens client-side with a key we do not possess.

Approval notifications contain an opaque request reference and link, not action descriptions, amounts or document names. Individually addressed notifications may include an expiring token that allows the recipient to view the request; approval still requires a valid signing credential. Delivery uses the recipient’s contact or subscription information. Enrollment and account-security messages may also include account information, an IP address and browser details where needed for their purpose.

Retention

Evidence retention depends on your plan: 14 days on Developer, 90 days on Starter, 1 year on Team, 3 years on Business, and 7 years plus legal hold on Enterprise. These periods govern access to readable evidence and scheduled erasure of its content and signer identities. Expired terminal approval requests and platform signing records are deleted, including their duplicate signatures and identity links. A negotiated retention period or a documented lawful hold may extend preservation. Upgrading cannot restore content already redacted. When termination is recorded, evidence still within the retention window is preserved for the 30-day export period.

Account data is retained while needed to provide the account. At customer termination, accounts belonging only to that customer are erased with its workspace under the agreed DPA. Accounts still used by another customer remain for that purpose. Any legally required continued storage is limited to the necessary records, purpose and duration.

Server logs

Like every website, our servers keep access logs. Each entry records the IP address the request came from, the date and time, the address requested, the response status, and the browser's user-agent string. An IP address counts as personal data under the GDPR, so we say plainly that we hold it rather than treating logs as too mundane to mention. We do not use these logs to build a profile, we do not combine them with your account, and they are never sold or shared for advertising. The lawful basis is our legitimate interest in keeping the service running and secure — logs are what let us investigate an outage or an attack after the fact. They are kept for 30 days and then deleted.

These logs are written by the providers who host us, not by our own application code. If you want to know what we hold about you, or want it deleted, write to privacy@intyga.com — see "Your rights" below, which applies to log data exactly as it applies to everything else on this page.

Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing based on legitimate interest. To exercise any of these, contact privacy@intyga.com. You also have the right to lodge a complaint with a supervisory authority. Ours is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se; you may also complain to the authority where you live or work.

Changes

We will post material changes to this notice on this page and update the date above. Where a change materially affects how we process your personal data, we will notify account holders directly.