As the operator of this website and as a business, we process your personal data. This means any information relating to you that can be used to identify you. This Privacy Policy explains how, for what purposes and on what legal basis we process your data.
The controller responsible for data processing on this website and within our business is:
vu7
Austria
hello@vu7.sh
What data we collect and why
When you visit our website, we process technically necessary data that your browser transmits automatically. This includes your IP address, the date and time of access, the URL requested and information about your browser. This data is processed solely to ensure the operation of the website and is deleted within 30 days at the latest. The legal basis is Article 6(1)(f) GDPR (legitimate interests).
When you register on our platform, we collect your email address and a password, which is stored only as a hash. We process this data to establish and perform our contractual relationship on the basis of Article 6(1)(b) GDPR and retain it for the duration of that relationship and any statutory retention periods.
As part of security scans, we process the targets you define, such as repository URLs or uploaded code archives. We use this data solely to carry out the audit you have commissioned. Scan results are stored in your account and deleted on request. The legal basis is Article 6(1)(b) GDPR.
To process payments, we collect the data necessary for the transaction, such as your billing address. Payments are processed by our payment service provider Stripe (see the Processors section). We do not store complete payment details. The legal basis is Article 6(1)(b) GDPR.
If you contact us by email, we process your sender address, the timestamp and the content of your message to handle your enquiry on the basis of Article 6(1)(f) GDPR. This data is deleted after your enquiry has been fully resolved, and within three years at the latest.
Cookies
We use only technically necessary cookies, for example to maintain your session after login. We do not use analytics or marketing cookies. The legal basis is Article 6(1)(f) GDPR in conjunction with Section 165 of the Austrian Telecommunications Act 2021 (TKG 2021). A cookie consent banner is therefore not required.
Processors
We use the following service providers as processors under Article 28 GDPR. Written data processing agreements (DPAs) are in place with all processors. Where data is transferred to third countries, the transfer is based on standard contractual clauses under Article 46(2)(c) GDPR.
Vercel Inc. (USA): hosting of the web application and serverless functions. DPA: vercel.com/legal/dpa. Legal basis for transfers: standard contractual clauses.
Clerk Inc. (USA): authentication and user management (email address, password hash and session token). DPA: clerk.com/legal/dpa. Legal basis for transfers: standard contractual clauses.
Amazon Web Services Inc. (USA): cloud infrastructure for the scan pipeline (ECS Fargate, Lambda, S3 and API Gateway). Scan results and code archives are temporarily processed and stored in the EU (Frankfurt) region. DPA: aws.amazon.com/de/compliance/gdpr-center. Legal basis for transfers: standard contractual clauses.
Supabase Inc. (USA): database for scan metadata and user data. DPA: supabase.com/dpa. Legal basis for transfers: standard contractual clauses.
Stripe Inc. (USA): payment processing. DPA: stripe.com/de/legal/dpa. Legal basis for transfers: standard contractual clauses.
GitHub Inc. (USA): connection of GitHub repositories through a GitHub App to perform scans and process pull request events. Processing is based on the installation permissions granted by the user. DPA: GitHub Data Protection Agreement. Legal basis for transfers: standard contractual clauses.
Data security
We implement technical and organisational measures under Article 32 GDPR to protect your data. These include encrypted transmission via HTTPS/TLS, strict access controls, short-lived access tokens for third-party services and regular security reviews. Uploaded code archives are automatically deleted once the scan is complete.
Your rights
You have the following rights in relation to our processing of your data: you may request access to the personal data we hold about you at any time (Article 15 GDPR), have inaccurate data rectified (Article 16 GDPR), request erasure of your data (Article 17 GDPR), restrict processing (Article 18 GDPR) and receive your data in a structured, machine-readable format (Article 20 GDPR). Where we process data on the basis of Article 6(1)(f) GDPR, you have the right to object to that processing (Article 21 GDPR).
To exercise your rights, please contact hello@vu7.sh. We respond within 30 days in accordance with Article 12(3) GDPR.
Right to lodge a complaint
You have the right to lodge a complaint with the Austrian Data Protection Authority (DSB) if you believe that the processing of your personal data infringes the GDPR (Article 77 GDPR).
Changes
We reserve the right to amend this Privacy Policy in response to changes in the law or our processing activities. The current version is available on this page.