Skip to content

Privacy

What we store, and for how long

This notice describes the product as it is written today. Where a provider or a retention rule is still planned, it says so. Last updated 2026-09-17.

Still to name

Registered company name, address and VAT number of the GDPR controller. Until it is registered, data-protection requests go to privacy@audixa.com and are handled by the people building the product.

Who we are

Controller

Audixa is the product. The legal entity that will act as controller under the GDPR is not incorporated yet, so it is not named here. Inventing one would be worse than leaving the gap: a name we cannot stand behind is not a name.

The product is aimed at people in the European Union. Application data will live on a single Hetzner server in European Union, with PostgreSQL on that same machine — not on a separate database host, and not on a second cloud for workers. Hostinger holds DNS and marketing hosting (European Union). Those names come from the same list as the processors below, so a hosting change is one edit. None of them is processing paying customers’ data yet. We have not provisioned that server.

Lawyer's review of both pages before we take paying customers or process a data-subject request in anger.

What we collect

The data, and why

An account

Your name, email address and password hash, so you can sign in. We do not need a phone number, a company number or a date of birth to run a scan, so we do not ask for them.

An organization

The name you give a workspace, who is in it, and what each of them is allowed to do. Membership is the unit of access: we do not infer it from an email domain.

A scan

A connected repository is cloned into a throwaway sandbox for the length of the job. The workspace is destroyed when the scan ends. What we keep is the findings, up to three lines of redacted evidence around each match, and the metadata needed to compare one scan with the next. Source code is not retained. Detected secrets are redacted before anything is stored.

A professional-services enquiry

The fields on the form: name, email, phone number, optional company and URL, the description you typed, website briefing answers when you asked for a site, optional timeline, and the exact consent sentence you agreed to, with a timestamp. We store that so we can answer the enquiry and so we can show a regulator what was agreed, not so we can market to you afterwards.

Technical logs

Request metadata (IP address, user agent, URL) for a short window, used to diagnose incidents and to rate-limit abuse. Credential-shaped values are stripped before they reach a log.

We do not sell personal data. We do not buy lists. We do not run advertising pixels, and we do not use cookies for anything other than keeping you signed in.

How long

Retention

A rule per category, because a single number would either keep an enquiry forever or delete a findings history that is the point of the product.
Your repository's source code
Not retainedThe sandbox workspace is destroyed when a scan ends, whether it succeeded or failed. What survives is the findings and up to three lines of redacted evidence around each one.
Findings and scan history
While your account is openComparing a scan to the one before it is the point of the product, so history has to persist. Deleting a project deletes its findings.
Service enquiries sent through this site
24 months from the last contactLong enough to run a sales conversation and honour a quote; short enough that a form filled in once does not follow somebody around. Ask us and we will delete it sooner.
Audit log
24 monthsIt records who changed access and settings. An audit trail that can be shortened on request would not be one.
Account and organization records
Until you delete themDeleting your organization removes its projects, findings and reports.

Who else can see it

Processors

Named, with a region, with a status. A provider that is contracted but not yet integrated is listed as planned, not as a fact.

No third-party processor is handling paying customers’ data today. Local development uses a database on the machine that runs the app. The providers below are the ones we will use in production, named now so a later change is a visible one rather than a surprise.

Chosen, not yet integrated

  • HetznerEuropean Union

    A single server in the European Union running the application and PostgreSQL on that same box. When scanning ships, workers and sandboxes run there too — not on a second cloud. Your name and email address, your organization, your projects, findings, and service enquiries. Repository content only for the length of a scan, in a throwaway workspace.

  • HostingerEuropean Union

    DNS for the product domains, and hosting for marketing pages that are not the application. DNS queries and request metadata for marketing pages. Not your account, repositories or findings.

  • ResendEuropean UnionVendor unsigned

    Transactional email: invitations, scan notifications and enquiry acknowledgements. Your email address and the content of the message we send you.

  • StripeEuropean Union and United States

    Subscription payments and VAT calculation (Stripe Tax) for the paid plans. Billing details, which you give to Stripe directly. We store a customer reference, never a card number.

  • OSV.devUnited States

    Looking up published advisories for the packages your project depends on. A list of package names and versions. Never your source code, and nothing that identifies you.

  • OpenAIEuropean Union processing, zero data retentionVendor unsigned

    Rewriting scanner evidence into plain language, when AI assistance is enabled. The few lines of code a finding points at, with detected secrets removed first. Never the whole repository.

Final AI provider. The working default in SUBPROCESSORS is OpenAI; it is not signed off. Unsigned vendors are marked in the list so they cannot hide as if they were contracted.

Your rights

What you can ask us to do

You can ask for a copy of what we hold, a correction, deletion, restriction, or to object to processing that is not required to run the service you asked for. You can also ask us to send a structured copy of your account and findings to another controller. Write to privacy@audixa.com.

Deleting an organization deletes its projects, findings and reports. Deleting a service enquiry deletes the thread, including internal notes. Audit-log rows that record a change of access are kept for the period above even after the account is gone, because an audit trail that can be shortened on request would not be one; they no longer contain a live email address.

You can complain to your national data-protection authority. Which one depends on where you live, and on the country the company is incorporated in — which is not named yet.

Cookies: the only cookies we set are the ones that keep a signed-in session. There is no marketing cookie, so there is no cookie banner and no separate cookies page.