Privacy policy
How Permenta handles personal data, as the controller for your account and as a processor for what you keep in your workspace.
Last updated .
1. Scope and who is responsible
This policy explains how personal data is processed when you visit permenta.com, use the Permenta application at app.permenta.com, or correspond with us. It is written under the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”). The controller for the processing described in section 3 is:
- Legal name
- Patchgate, LLC
- Address
- 651 N Broad St, Suite 201Middletown, DE 19709United States
- Privacy contact
- privacy@permenta.com
- Data protection officer
- No data protection officer appointed
2. Our two roles: controller and processor
For your account, your workspace’s billing, our website and our security logs we decide why and how personal data is processed, so we are the controller.
For the content you and your colleagues put into a workspace, such as product records, software bills of materials, vulnerability reports, Article 14 case files, documents and the names of people mentioned in them, you decide why and how it is processed. For that content we are your processor and act on your instructions under the Data processing agreement. If you are a person whose data appears in a customer’s workspace, please contact that customer; we will pass on any request we receive.
3. What we process, why, and on which legal basis
- Account data: name, email address, password hash, passkey and one-time-code credentials, sign-in method (including an optional GitHub account link), language and time zone. Purpose: to create, secure and operate your account. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Workspace and membership data: workspace name, your role, the invitations you send and receive, API keys you create (stored as hashes). Purpose: to operate the workspace and its access control. Legal basis: contract (Art. 6(1)(b)).
- Billing data: billing contact, company name and address, VAT identification number, plan, invoices and payment status. Card details are entered with our payment processor and never reach us. Purpose: to charge for paid plans and keep accounts. Legal basis: contract (Art. 6(1)(b)) and legal obligations under tax and commercial law (Art. 6(1)(c)).
- Emails we send: verification links, invitations, reporting-deadline reminders and account notices, with delivery records. Purpose: to operate the Service. Legal basis: contract (Art. 6(1)(b)). We do not send marketing email without your consent.
- Security and access logs: IP address, user agent, timestamps, rate-limit counters, sign-in events and an audit trail of actions in the workspace. Purpose: to keep the Service secure, prevent abuse, investigate incidents and attribute changes to the evidence record. Legal basis: our legitimate interest in the security and integrity of the Service (Art. 6(1)(f)); the audit trail is also part of the record you keep under the contract.
- Support and correspondence: what you send us by email, including vulnerability reports. Purpose: to answer you and to handle the report. Legal basis: contract or pre-contractual steps (Art. 6(1)(b)) and our legitimate interest in handling security reports (Art. 6(1)(f)).
- Website visits: server logs with IP address, requested page and user agent, kept briefly for security and troubleshooting. Legal basis: legitimate interest (Art. 6(1)(f)). We do not use third-party analytics or advertising trackers.
We do not knowingly process special categories of personal data and we do not use personal data for automated decision-making with legal or similarly significant effects.
5. Who receives personal data
We use a small number of service providers who process data on our behalf under contracts that meet Article 28 GDPR: our hosting provider, our payment processor and our email provider. They are listed, with their purpose and location, on the Subprocessors page. We also disclose personal data where a law, a court or an authority requires it, and to professional advisers bound by confidentiality. We never sell personal data.
6. Where data is processed and international transfers
The Service runs in the European Union, in the Azure region Sweden Central, where the application, the database, file storage and backups are located. Two providers, our payment processor and our email provider, are established in the United States; where a transfer outside the European Economic Area takes place, it is covered by the European Commission’s standard contractual clauses or by an adequacy decision such as the EU-US Data Privacy Framework, as set out in each provider’s data processing terms. You can ask us at privacy@permenta.com for details of the safeguard that applies.
7. How long we keep data
- Account and workspace data: while the account or workspace exists, then 30 days so records can be exported, after which they are deleted from the live systems. Backups containing them expire within a further 35 days.
- Workspace content and the evidence ledger: as long as the workspace exists, because the ledger is the ten-year record the Cyber Resilience Act expects manufacturers to keep; you control when it ends.
- Billing records: for the period that tax and commercial law require, typically between six and ten years from the end of the financial year.
- Security and access logs: up to 12 months, longer only while needed for an investigation or a legal claim.
- Correspondence: as long as needed to handle the matter and, for vulnerability reports, as long as the advisory it led to remains relevant.
8. Security
We protect personal data with technical and organisational measures appropriate to the risk: EU hosting, encryption in transit and at rest, per-tenant row-level security in the database, least-privilege roles, hash-chained audit logs, a separate staff realm with passkeys, dependency scanning and a reviewed deployment pipeline. They are described on our Security page, together with our coordinated vulnerability disclosure policy.
9. Your rights
Under the GDPR you may, subject to its conditions:
- ask for access to the personal data we hold about you and for a copy of it;
- have inaccurate data corrected and incomplete data completed;
- have data erased, or its processing restricted;
- receive data you provided in a portable format, or have it sent to another controller;
- object to processing based on our legitimate interests, for reasons arising from your particular situation;
- withdraw a consent you have given, without affecting processing before withdrawal;
- lodge a complaint with a supervisory authority, in particular in the EU Member State of your residence, your place of work or the place of the alleged infringement.
To exercise a right, write to privacy@permenta.com. We may ask you to confirm your identity. Where we act as a processor for one of our customers, we forward your request to that customer and help them answer it.
10. Children, changes and contact
The Service is intended for use by businesses and their staff and is not directed at children. We may update this policy when the Service or the law changes; the date at the top shows the current version and material changes are announced to workspace owners by email.
Privacy questions and requests: privacy@permenta.com. Company details: Imprint.