Privacy Policy

Effective 25 June 2026

This policy explains how Nomad Crow s.r.o., the controller of Normproof, processes personal data under the EU General Data Protection Regulation (GDPR). It covers our website, the free CRA readiness checker, and the authenticated application.

1. Who we are

The data controller is Nomad Crow s.r.o., Astrová 43, 900 41 Rovinka, Slovakia. For any privacy question or to exercise your rights, contact privacy@normproof.com.

2. What we collect

  • Account data: your name, work email, organisation name, role, and hashed credentials when you sign up.
  • Customer Data: the product, source/build metadata, SBOMs, vulnerability findings, and dossiers you create in the app. This is business data and usually contains no personal data beyond the names/emails of the people in your workspace.
  • Billing data: for paid plans, payment is handled by Stripe. We receive subscription and invoice metadata; we do not receive or store full card numbers.
  • Readiness-checker input: the answers you give the public checker. You may optionally provide an email to receive your result. The checker is designed not to leak personal data into shareable result URLs.
  • Technical data: IP address and basic request logs, used for security, rate-limiting, and abuse prevention.

3. Why we use it (legal bases)

  • To provide the Service (Art. 6(1)(b) — contract): create your account, generate and store dossiers, run assessments.
  • To take payment (Art. 6(1)(b)): manage subscriptions via Stripe.
  • Security and abuse prevention (Art. 6(1)(f) — legitimate interests): rate-limiting, logging, and protecting tenant isolation.
  • Service communications (Art. 6(1)(b)/(f)): account, security, and transactional emails. Any marketing email is sent only with your consent and you can opt out.

4. Cookies

We use only the cookies needed to run the Service — principally a secure, httpOnly session cookie to keep you signed in. We do not use advertising or analytics cookies. Because these are strictly necessary, no consent banner is required for them.

5. Sub-processors and where data is stored

We host the Service in the European Union. We share personal data only with processors acting on our instructions:

  • Google Cloud (EU region) — hosting, database, and object storage.
  • Stripe — payment processing for paid plans.
  • Our email provider — sending transactional email.

We draw vulnerability information from public data sources (such as NVD, OSV, GHSA, and the EUVD); these involve no personal data of yours. Some of our sub-processors (for example Stripe) may transfer personal data to the United States or other countries outside the EEA as part of their own operations; where that happens, the transfer is covered by an adequacy decision or Standard Contractual Clauses.

6. Processing on behalf of customers (processor/controller)

We wear two different hats depending on the data. For account data (Section 2) — the details of you and your team that we collect to run the Service and your subscription — we are the controller, as Section 1 describes. For personal data that happens to be inside the Customer Data you upload or connect (for example, names or email addresses of your own team or end users referenced in your source, build, or support-contact metadata), you are the controller and we are the processor, handling it only on your documented instructions.

You are responsible for having an appropriate legal basis and any required consents before including personal data in the Customer Data you submit. Our processor role is governed by our Data Processing Addendum, which sets out our obligations, the sub-processors we use, and how we assist you with data-subject requests and security incidents.

7. How long we keep it

We keep account and Customer Data for as long as your account is active and as needed to provide the Service. Retention after that depends on the category of data:

  • Account and Customer Data: when you delete your organisation through the Service, the deletion is immediate — your organisation, products, SBOMs, findings, dossiers, and audit-trail records are removed at that point, other than any records we must keep for the reasons below.
  • Invoices and billing records: retained separately for as long as required by applicable accounting and tax law (currently up to ten years under Slovak law).
  • Backups: kept for a limited rolling window sufficient for disaster recovery (on the order of a week), then overwritten or deleted.
  • Technical/request logs: kept only for as long as needed for security, rate-limiting, and abuse prevention, then deleted.
  • Dossier reproducibility metadata (the rules-library, SBOM, and engine versions recorded on a generated dossier) is retained with that dossier for audit purposes for as long as the dossier itself is retained.

8. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to withdraw consent where processing relies on it. Contact privacy@normproof.com to exercise any of these. To protect your data we may need to verify your identity (for example, by confirming the request comes from the email address on your account) before acting on a request, and we aim to respond within one month, as the GDPR requires. You also have the right to lodge a complaint with your local data-protection supervisory authority.

9. Security

We apply technical and organisational measures appropriate to the risk, including strict per-organisation tenant isolation, encryption in transit, hashed credentials and API tokens, role-based access control, and audit logging. No system is perfectly secure, but protecting your data is core to how the Service is built. We maintain procedures for detecting and responding to security incidents and will notify affected customers and, where required by law, supervisory authorities, without undue delay after becoming aware of a personal-data breach.

10. Children

The Service is a business tool and is not directed to children under 16.

11. Changes

We may update this policy. We will post the new version here and update the effective date; material changes will be notified to account holders.

12. Contact

Nomad Crow s.r.o., Astrová 43, 900 41 Rovinka, Slovakia (company no. 51320304, VAT SK2120677383). Privacy enquiries: privacy@normproof.com. See also our Terms of Service and Data Processing Addendum.

Questions? See the Privacy Policy and Terms of Service, or contact support@normproof.com.