CRA Desk

Draft - pending legal review, not yet legally binding.

Privacy Policy

Version 1 (Draft) Effective date: 24-08-2026

The data controller is Cloudsoft Marcin Malinowski, Ku Słońcu 24E/11, 71-073 Szczecin, Poland, NIP: 599-276-18-15. Contact for data protection matters: contact@cradesk.eu.

1. What personal data we process

CRA Desk's core payload - SBOMs, vulnerability matches and reporting drafts - is technical, not personal. The personal data the service actually holds is limited to:

  • Account email - the email address used to sign up and sign in (Cognito), and the same address as Vendor.contactEmail.
  • Team member email and role - if the account's admin invites a colleague, that person's email address, role and invitation date.
  • Billing contact details - the name, billing address and, for a business buyer, the VAT/tax number collected at checkout and passed to our payment processor and invoicing provider to issue a compliant invoice.
  • Content-set publication metadata - the account identifier of whoever publishes a new version of the classification ruleset or a document template (content administrators only).

2. Legal bases

  • Performance of a contract (Art. 6(1)(b) GDPR) - account provisioning, team membership, service delivery.
  • Legal obligation (Art. 6(1)(c) GDPR) - the data on an issued invoice and its statutory retention.
  • Legitimate interest (Art. 6(1)(f) GDPR) - operating and securing the service.

Where the Operator processes a Customer's team members' email addresses on the Customer's behalf, it acts as a processor under Art. 28 GDPR - see the Data Processing Agreement.

3. Retention

DataRetention
Account and team member dataFor the life of the account; deleted after a 30-day grace period once account deletion is requested (cancellable during that window)
Uploaded SBOM filesKept without a fixed deletion schedule while the account is open - re-parsing an inventory must always be possible - and removed as part of account deletion
Generated documents (readiness reports, CVD policy, security.txt)Cached for 30 days, then recomposed on next access from the underlying data
InvoicesKept for the period required by Polish accounting and EU OSS VAT rules (typically 5–10 years) even after the rest of an account's data is deleted
Point-in-time database backupsRetained for [to be confirmed] on production

4. Recipients and transfers

Personal data is shared only with the sub-processors that support the service - infrastructure, payment processing and invoicing. The current list, including where each one processes data, is published separately at Sub-processors so it can be kept current without amending this policy.

5. Email sign-up on the public site

The homepage offers a one-field email sign-up for a notification when reporting starts. Submitted addresses are processed by the sign-up form provider named on the Sub-processors page, used only to send that notification, and are not combined with any account you may separately create.

6. Browser storage, not cookies

CRA Desk does not use advertising or analytics cookies or trackers of any kind. The browser stores only what the application itself needs to function: sign-in session tokens, a temporary copy of an in-progress scope classification kept only until you sign in, and your chosen display language. None of this is shared with anyone else or used to track you across sites.

7. Your rights

You have the right to access, correct, export and delete your data, and to object to processing based on legitimate interest. For an account you administer, export and account-deletion requests are available directly from Settings in the panel; a deletion request opens a 30-day cancellable grace period before data is removed. You may also lodge a complaint with the Polish data protection authority (UODO).

8. Changes to this Policy

The Operator may amend this Policy by publishing a new version at a new address (the next version of this document), stating its effective date.