Privacy notice
What we hold, why, and for how long.
Who is responsible
The controller of the personal data described here, and the address for privacy questions and for exercising the rights below: PENDING-CONTROLLER-IDENTITY — the legal entity and its contact address are being registered and will be named here before any account can be created.
Stating that this is unfinished is deliberate. A notice that invented a name would be worse than one that admits which line is still blank, and no data is being collected while it is.
Requests about your data — access, correction, erasure — go to privacy@ugix.io. It is separate from the security contact because a vulnerability report and a request to erase your data are different work, read by different people.
That mailbox was confirmed to accept mail before this address was published here, on both of the domain’s mail servers and with a control that proves the answer was not a catch-all. An address that silently drops mail is worse than none, because whoever writes to it believes they have been heard.
What is collected, and why
The list is short because the database is. Every field had to justify itself before it was created, and nothing is collected “in case it is useful later”.
| What | Why | Legal basis | Kept |
|---|---|---|---|
| Your email address | To identify your account and sign you in | Contract, Art. 6(1)(b) | While the account exists |
| Your password, as a hash | To verify it is you, without storing what you typed | Contract, Art. 6(1)(b) | While the account exists |
| Your company name | To attach the account to its subscription | Contract, Art. 6(1)(b) | While the customer relationship exists |
| Sessions, as a hash of an opaque token | To keep you signed in, and to let you sign out everywhere | Contract, Art. 6(1)(b) | Until it expires; deleted nightly |
| Sign-in attempts, as a hash of the address and the outcome | To notice an account under attack, and stop guessing | Legitimate interests, Art. 6(1)(f) | 90 days, then deleted on a schedule |
| The network address an attempt came from, as a hash | To slow down a source guessing at many accounts. It is never used to block anyone, and never stored as an address | Legitimate interests, Art. 6(1)(f) | 90 days, with the attempt it belongs to |
| Confirmation links, as a hash of a one-time token | To prove the address receives mail, so nobody can sign an address up but its owner | Contract, Art. 6(1)(b) | 24 hours unused, 7 days once used; deleted nightly |
| Billing records, once there is a subscription | To invoice, and because tax law requires it | Legal obligation, Art. 6(1)(c) | The statutory period |
In full: the contract basis is Article 6(1)(b), performance of the contract you enter into by subscribing; the security basis is Article 6(1)(f), our legitimate interest in keeping accounts from being taken over; the billing basis is Article 6(1)(c), a legal obligation.
The password is never stored. What is stored is a hash, which cannot be turned back into what you typed. Sign-in attempts store a hash of the address rather than the address, so that table is not a list of who tried to sign in.
What is not collected
- No analytics and no cookies on this site. Nothing here observes you, which is why you were not asked to consent to anything.
- No operational data from your system. Your instance runs on your own infrastructure. What it sends out is whether it is healthy and which version it runs — not your orders, suppliers, stock or staff.
- No profiling and no automated decisions. Nothing here makes a decision about you by algorithm.
- No selling, and no sharing for advertising. Ever.
Deleting your account
Erasure destroys the row that identifies you: the address, the password hash and the sessions. It is not a rename — nothing is left behind that can be turned back into you.
Records the law requires us to keep survive, and billing is the standard case: Article 17(3)(b) allows that, and after your identity is destroyed those records keep only an opaque identifier that no longer resolves to a person. If we ever refuse an erasure request in part, we will say which part, on what legal basis, and for how long it will be kept.
Your rights
- Access — a copy of what is held about you (Art. 15).
- Rectification — correcting what is wrong (Art. 16).
- Erasure — as described above (Art. 17).
- Restriction and objection — Art. 18 and 21, including objecting to the security processing done under legitimate interests.
- Portability — the data you gave us, in a machine-readable form (Art. 20).
- Complaint — to your national supervisory authority, at any time (Art. 77). You do not have to come to us first.
Requests go to the contact address named above, which is why that line has to be filled in before the first account exists.
Where the data is, and who else sees it
Account data is held on infrastructure operated by us in the EEA. It is not sold, and it is not shared for advertising.
One processor exists today, and it is the mail provider. A message confirming your address is handed to Hostinger, which operates the mailbox for this domain and delivers it — so your address passes through them, in the EEA, for that purpose and no other. There is no marketing list, and no message from us that you did not cause by using the service.
When subscriptions open there will be a payment processor, and that choice is not made yet. If a processor outside the EEA is chosen, that becomes an international transfer with its own safeguards, and this notice will name the processor and the safeguard before any payment is taken.
Changes to this notice
When what is collected changes, this page changes with it, and the change is made before the collection starts rather than after. This version is published while the service collects nothing, so there is nothing yet that an earlier version could have described differently.