Privacy notice
Last updated 9 September 2026
1. Controller and contact
The data controller for ConformOps is Simone Laudani, based in Italy, operating the service under the product name ConformOps. Privacy requests can be sent to privacy@conformops.eu.
2. Data we process
We process account profile names, identifiers, and email addresses; workspace and product names, settings, memberships, invitations, and audit records; selected public or private GitHub repository identifiers; files and project material you upload or authorise us to retrieve; sanitized source snapshots, assessment findings, evidence lineage, reporting-case records, and generated artifacts; and Stripe customer, checkout, subscription, invoice, and payment-status identifiers when billing features are used. Stripe processes payment-card data directly rather than through ConformOps.
ConformOps does not sell customer material or personal data. Data is disclosed only to the service providers and destinations needed for the service path you select, as described below.
3. Purposes and legal bases
We process data to create and secure accounts, provide the assessment and evidence service, retrieve sources you explicitly connect, maintain traceability and audit history, enforce product access, provide support, detect abuse or security incidents, and administer billing. The legal bases are performance of a contract or steps you request before entering one, legitimate interests in operating and securing the service, and compliance with applicable legal obligations. Where processing relies on consent, you may withdraw that consent without affecting processing that was lawful before withdrawal.
4. Service providers and recipients
Cloudflare provides the Worker, D1, R2, Vectorize, and workflow infrastructure. Resend is used for transactional email. Google and Microsoft receive authentication data only when you choose those sign-in methods. GitHub receives and returns authorization and repository data when you connect a repository. Stripe handles payment and billing services. OSV receives package coordinates used for vulnerability matching. OpenAI is the only AI provider and is used only when a workspace Owner or Admin enables both the workspace and product settings. OpenAI receives the limited product, legal-rule, source-path, and sanitized-evidence request described on the AI processing page; raw archives and detected secret values are not sent. OpenAI states API data is not used to train or improve its models unless the API account opts in, and ConformOps does not opt in. Provider calls are blocked unless the deployment confirms optional API data sharing is disabled. Requests use store: false, which is not a Zero Data Retention guarantee. When the deployment gates described below are satisfied, PostHog receives the allowlisted server-side product-usage events through the host configured by the operator. PostHog receives no account identifier, name, email address, repository or file name, source or evidence content, SBOM or vulnerability data, generated document, secret, or token. These providers process data under their own applicable service and data-protection terms.
PostHog retains the server-side measurement for the retention period configured in its project and under its provider terms; that retention setting is part of the operator's activation review. The configured PostHog host determines where that processing occurs. Some providers may process data outside the European Economic Area. Where a transfer requires a GDPR transfer mechanism, the applicable adequacy framework or Article 46 safeguard used by the relevant provider applies. You can request further information about the safeguards relevant to your data through the contact above. Business-customer processor terms are published in the Data processing agreement.
5. Data residency and international processing
ConformOps does not currently promise EU-only data residency or processing. A production infrastructure check on 29 August 2026 reported the D1 primary and R2 bucket in Cloudflare's Eastern Europe region, but neither resource has an EU jurisdiction restriction. The Worker and other service paths retain global processing boundaries, and the OpenAI client does not use the EU regional endpoint. The current facts and limitations are published on the Data residency page.
6. GitHub authorization and source handling
GitHub identity and refresh tokens are encrypted at rest and used to confirm repositories available to you. Repository content is retrieved with a short-lived, read-only installation token restricted to the selected repository and immutable commit. Local ZIP metadata is validated, then accepted entries are extracted in the browser and transferred in bounded packs; the raw archive is not uploaded or stored. Repository input is filtered and sanitized sequentially before persistence. Temporary upload and candidate records are removed after snapshot activation, cancellation, or expiry, with abandoned ingestions expiring within 24 hours. Sanitized active snapshots remain as the versioned evidence the customer asked ConformOps to preserve. Disconnecting GitHub revokes the authorization where possible, erases stored token ciphertext, and disables linked repositories.
7. Retention
Account, workspace, product, assessment, and evidence data are retained while needed to provide the service and preserve the versioned history the customer has chosen to keep. Temporary ingestion objects use the shorter lifecycle described above. Billing and transaction records may be retained for statutory accounting, tax, fraud-prevention, or dispute periods. Security and audit records are retained for as long as reasonably necessary for those purposes. When you request deletion, data is erased or anonymised where applicable unless a legal obligation or overriding lawful reason requires limited continued retention. The product, account, store-by-store verification, and retained-record behavior is described on the Account and product deletion page.
8. Your GDPR rights
Subject to the conditions in applicable law, you may request access to, correction of, deletion of, or restriction of your personal data; object to processing based on legitimate interests; and request portability where the right applies. You may also lodge a complaint with a competent supervisory authority, including the Italian Garante per la protezione dei dati personali. Requests can be sent to privacy@conformops.eu.
9. Cookies and authentication
ConformOps uses session and security mechanisms needed to authenticate users and protect accounts. The application does not use advertising cookies, analytics cookies, device fingerprinting, or session replay. Public pages use the limited first-party measurement described below. No third-party script runs in your browser.
Product usage is measured on the server only. ConformOps records a fixed list of lifecycle events - such as a workspace being created, an assessment starting, completing or failing, and an export finishing - together with internal workspace, product and assessment-run identifiers, the plan, the source type, a bounded duration and a bounded error code. These identifiers are pseudonymous: ConformOps can link them to account and workspace records, while the PostHog sink deliberately omits the internal user identifier. The measurement contains no name, email address, repository or file name, source or evidence content, SBOM or vulnerability data, generated document, secret, or token. The PostHog project must have its project-level IP-discard setting enabled, and each event carries the provider's explicit GeoIP-disable flag, so no location is derived from the request. The operator records the applicable legal-basis or consent decision before enabling the sink; where consent is the selected basis, capture must remain disabled until the required consent mechanism is in place. This notice does not assert that consent is never required. No third-party script runs in your browser.
When separately enabled after the public-site legal-basis or consent decision, a small first-party script measures public marketing pageviews through our server to PostHog. It sends only an explicitly listed canonical page path, reviewed campaign labels from utm_source, utm_medium, utm_campaign and utm_content, the deployment environment, and random visitor and session identifiers. Unrecognised campaign labels, unrelated query parameters, full URLs and referrers are discarded. It does not read page contents or form values. It does not run measurement on account, application, onboarding, billing, invitation or reviewer-share pages.
Public measurement uses local browser storage for a random visitor identifier for up to 30 days and tab session storage for a random session identifier that expires after 30 minutes without a measured public pageview or when the tab session ends. Expired entries are replaced on the next measured visit; clearing site storage removes them. These identifiers are not linked to accounts or product analytics. Person profiles, autocapture, exception capture, session replay and GeoIP enrichment remain disabled. The same PostHog retention and processing-location terms described above apply. Public measurement stays disabled until its separate activation review covers this storage and measurement; where consent is required, it must remain disabled until a consent mechanism is implemented.
10. Security and sensitive content
Do not upload secrets, private keys, production credentials, personal data not needed for the assessment, or source material you are not authorised to process. The service bounds and filters repository inputs, never executes repository code, redacts detected confidential secrets before persistence, isolates workspace ownership, and gates repository ingestion and evidence downloads with server-side authorization and entitlement checks.
11. Automated processing and optional AI
OpenAI is the only AI provider. The workspace master setting and every product setting are off by default, both must be enabled, and only a workspace Owner or Admin can change them. Turning the workspace setting off resets all product choices and blocks new OpenAI requests. ConformOps does not use a model to make final legal or approval decisions. Optional AI output is a proposal only; the deterministic engine and recorded human approvals control requirement state, risk approval, conformity-route decisions, and generated declarations. Turning AI off does not rewrite completed run history or recall a request already in flight.
12. Breach notification
When ConformOps acts as a processor and becomes aware of a personal-data breach affecting customer personal data, the operator will notify the affected customer without undue delay and provide available information and material updates. The scope, contact route, and contents of the notice are published in the Breach notification commitment.
13. Changes to this notice
This notice is updated when the operator, material data flows, providers, purposes, or legal bases change. The date at the top identifies the current published version.