Legal

Privacy Policy

This privacy policy explains how personal data is processed when using CertCockpit and which rights data subjects have.

Controller

Responsible organization / person
Guarded Data Solutions / Theresa Meiksner
Address
Rechte Wienzeile 229, 1120 Vienna, Austria
Email
office@guarded-data.at

Data We Process

  • Account data, e.g. display name, email address, role, language, timezone, and theme preferences.
  • Authentication and security data, e.g. password hash, session data, login attempts, IP addresses, user agent, MFA data, and trusted-device status.
  • Certificate and operational data, e.g. domains, subject alternative names, issuer, validity periods, fingerprints, renewal status, remote scan targets, findings, and assignments.
  • Uploaded files and attachments, which may contain personal data depending on user content.
  • Administration and security logs, e.g. audit events, IP blocks, login events, and changes to system settings.

Purposes and Legal Bases

Purpose Typical data Possible legal basis
Providing and operating CertCockpit Account data, roles, settings, certificate data, notifications Contract performance or legitimate interest, Art. 6(1)(b) or Art. 6(1)(f) GDPR
Authentication, access protection, and abuse prevention Password hash, MFA data, sessions, IP addresses, user agent, login attempts Legitimate interest in secure operation, Art. 6(1)(f) GDPR
Auditing, compliance, and traceability Audit logs, system events, role changes, security-relevant actions Legitimate interest or legal obligation, Art. 6(1)(f) or Art. 6(1)(c) GDPR
Communication and notification Email address, notification settings, event content Contract performance or legitimate interest, Art. 6(1)(b) or Art. 6(1)(f) GDPR
Backup, maintenance, and troubleshooting Backups, technical logs, error logs, configuration data Legitimate interest in stability and security, Art. 6(1)(f) GDPR

Recipients / Processors

Personal data is only shared with processors that are required to operate CertCockpit, such as hosting, infrastructure, email, and backup providers. All processors are selected with appropriate privacy and security safeguards and, where legally required, bound by contract.

Retention Period

  • Active account and certificate data is generally stored for the duration of use and deleted or anonymized according to the applicable retention policy.
  • Security logs and audit entries may be retained longer to investigate abuse and meet accountability obligations.
  • Backups may contain personal data until they are overwritten according to the backup cycle.

Data is deleted or anonymized once it is no longer required for service delivery, security, or legal obligations.

Your Rights

  • Right of access, rectification, and erasure.
  • Right to restriction of processing.
  • Right to data portability.
  • Right to object where processing is based on legitimate interests.
  • Right to lodge a complaint with a supervisory authority.

Security Measures

CertCockpit includes technical and organizational measures such as authenticated access controls, role-based permissions, session security checks, audit logging, and optional multi-factor authentication.

Changes to this Privacy Policy

This privacy policy should be reviewed and updated whenever processing activities, service providers, or legal requirements change.

Last reviewed: July 26, 2026