Privacy Policy
Version 1 (Draft) Effective date: 24-08-2026
The data controller is Cloudsoft Marcin Malinowski, Ku Słońcu 24E/11, 71-073 Szczecin, Poland, NIP: 599-276-18-15. Contact for data protection matters: contact@cradesk.eu.
1. What personal data we process
CRA Desk's core payload - SBOMs, vulnerability matches and reporting drafts - is technical, not personal. The personal data the service actually holds is limited to:
- Account email - the email address used to sign up and sign in (Cognito), and the
same address as
Vendor.contactEmail. - Team member email and role - if the account's admin invites a colleague, that person's email address, role and invitation date.
- Billing contact details - the name, billing address and, for a business buyer, the VAT/tax number collected at checkout and passed to our payment processor and invoicing provider to issue a compliant invoice.
- Content-set publication metadata - the account identifier of whoever publishes a new version of the classification ruleset or a document template (content administrators only).
2. Legal bases
- Performance of a contract (Art. 6(1)(b) GDPR) - account provisioning, team membership, service delivery.
- Legal obligation (Art. 6(1)(c) GDPR) - the data on an issued invoice and its statutory retention.
- Legitimate interest (Art. 6(1)(f) GDPR) - operating and securing the service.
Where the Operator processes a Customer's team members' email addresses on the Customer's behalf, it acts as a processor under Art. 28 GDPR - see the Data Processing Agreement.
3. Retention
| Data | Retention |
|---|---|
| Account and team member data | For the life of the account; deleted after a 30-day grace period once account deletion is requested (cancellable during that window) |
| Uploaded SBOM files | Kept without a fixed deletion schedule while the account is open - re-parsing an inventory must always be possible - and removed as part of account deletion |
Generated documents (readiness reports, CVD policy, security.txt) | Cached for 30 days, then recomposed on next access from the underlying data |
| Invoices | Kept for the period required by Polish accounting and EU OSS VAT rules (typically 5–10 years) even after the rest of an account's data is deleted |
| Point-in-time database backups | Retained for [to be confirmed] on production |
4. Recipients and transfers
Personal data is shared only with the sub-processors that support the service - infrastructure, payment processing and invoicing. The current list, including where each one processes data, is published separately at Sub-processors so it can be kept current without amending this policy.
5. Email sign-up on the public site
The homepage offers a one-field email sign-up for a notification when reporting starts. Submitted addresses are processed by the sign-up form provider named on the Sub-processors page, used only to send that notification, and are not combined with any account you may separately create.
6. Browser storage, not cookies
CRA Desk does not use advertising or analytics cookies or trackers of any kind. The browser stores only what the application itself needs to function: sign-in session tokens, a temporary copy of an in-progress scope classification kept only until you sign in, and your chosen display language. None of this is shared with anyone else or used to track you across sites.
7. Your rights
You have the right to access, correct, export and delete your data, and to object to processing based on legitimate interest. For an account you administer, export and account-deletion requests are available directly from Settings in the panel; a deletion request opens a 30-day cancellable grace period before data is removed. You may also lodge a complaint with the Polish data protection authority (UODO).
8. Changes to this Policy
The Operator may amend this Policy by publishing a new version at a new address (the next version of this document), stating its effective date.