Privacy
What we hold, and why
Declara is a compliance tool for companies, not a consumer product, so the personal data involved is small and deliberately kept that way.
The controller of the data described here will be [entity to be named]. The company is not registered yet, so this document states the position that will apply rather than one that binds anybody today, and it takes effect with the terms when the entity does. You will find that said here rather than find a name invented for it.
Personal data
An email address and an optional name for each person who signs in, plus the addresses a workspace nominates for reminders. There is no tracking pixel, no advertising identifier, and analytics are cookie-free.
If you give us an address without signing up
Two forms on this site take an email address from somebody who has no account. Both store the address and nothing else — no name, no company, no page history — and neither is shared with anyone or used for anything but the one thing it is for.
- The waitlist
- One message, on the day accounts open. The removal link appears the moment you join and in that message; using it deletes the address rather than marking it, so nothing is retained. An address still on the waitlist twelve months after it was added is deleted then, because a year-old waiting list is not a waiting list.
- The monthly digest
- Confirmed twice: nothing is sent until you click the link in the first email. An address that is never confirmed is deleted after seven days. Every issue carries an unsubscribe link, and unsubscribing is honoured immediately and permanently. These are two separate consents — joining one never joins you to the other, and a test asserts it.
Product data
The substance of what we store is not personal: software bills of materials, component inventories, advisories, and the record of what a company decided and filed. It is commercially sensitive, which is why isolation between workspaces is enforced in one database client and tested on every build.
Cookies
Two, and both do a job you asked for. A session cookie once you sign in, which is what keeps you signed in, and which goes when you sign out. And, if you arrived through a partner’s referral link, one holding that partner’s code for ninety days, so they are credited when you sign up on a later visit. It holds a code, not anything about you, and no script on the page can read it.
There is no analytics cookie, no advertising cookie and nothing from a third party. We count how many people started a scope check and how many uploads came back with a match, because that decides what we write next, and none of it is tied to a person or carried between visits.
The free tools store nothing
An SBOM dropped into the public check is parsed in memory and discarded. It is never written to storage and no account is created. A scope-check result is stored only if you ask for a shareable link, and it holds answers and a verdict, never a name.
Where it lives
Database, file storage and compute all run in Frankfurt. Stated precisely: the infrastructure is in the EU and our providers are US companies, so this is EU hosting rather than EU legal control. If your procurement needs the latter, ask and we will tell you honestly whether we can meet it.
How long
Case data and audit events are kept for seven years, because they are the evidence an authority may ask for long after the incident. Everything else belonging to a closed workspace is purged within thirty days. Notification logs are kept a year.
Your rights
Access, correction, export and deletion, on request. Deletion of a person is immediate; deletion of case records is bounded by the retention above, because those records exist to protect the customer who created them.
There is no address to write to yet, because the company is not registered — and a right you cannot exercise is not a right, so it is worth saying plainly rather than leaving you to find out. What does work today is self-serve and needs nobody’s cooperation: the removal link on the waitlist confirmation, and the unsubscribe link in every digest. Both delete rather than flag. An address appears here the moment the entity does.
In effect from . Earlier versions are available on request.