Privacy Policy

Privacy Policy

Last updated 2026-07-16.

Who is responsible

The controller for the personal data described here is the entity named in our Impressum. For any data-protection matter — access, correction, deletion, or questions about this policy — contact admin@protet.io.

What we collect

To create an account: your email address, an optional name, and a password (stored as a salted Argon2 hash — we never store or can recover your plaintext password). To operate the service: your IP address is used transiently for rate-limiting abuse (signups, login attempts), and is not retained beyond that purpose.

Build session data (cloud tier)

If you use the cloud-hosted detection tier, execve telemetry from your build sessions is processed in real time to produce findings, which are streamed live to your account's dashboard. This data is not persisted on our side: if no one is connected to view a finding when it fires, it is not queued, stored, or retained — it is simply not seen. We do not use your build session content for any purpose other than producing your own findings.

On-prem deployments don't send build session data to us at all — detection runs entirely within your own infrastructure.

What we don't do

  • We do not sell your data.
  • We do not share build session content with third parties.
  • We do not use your data to train models without a separate, explicit agreement.

Where data is processed, and who processes it

Our infrastructure — compute, storage, and email — is hosted in Switzerland (Infomaniak). Your build-session telemetry is processed on that Swiss infrastructure and, as described above, is not persisted.

We rely on a small number of service providers (sub-processors) to run the service:

  • Infomaniak (Switzerland) — hosting and transactional email.
  • Stripe (Ireland / USA) — payment and subscription processing for paid plans. Stripe receives your billing name and email and handles card data directly; we never store card numbers. Transfers outside Switzerland/the EEA are covered by standard contractual clauses and applicable data-transfer frameworks.

Retention

Account records (email, hashed password, license and billing history) are retained for as long as your account is active, plus a reasonable period afterward for legal and accounting purposes. Audit log entries recording account and license actions (signup, license issuance, suspension, etc.) are retained indefinitely for security and support purposes. Cloud-tier build session findings are not retained at all, per above.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or restrict processing of your personal data, to object to certain processing, and to receive a copy in a portable form. To exercise any of these, email admin@protet.io.

Supervisory authority

If you are in Switzerland, you may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC / EDÖB). If you are in the EU/EEA, you may contact your local data-protection authority.

Contact

Questions about this policy: admin@protet.io. Provider identity and address: see our Impressum.