Privacy Policy

How we handle your data.

Effective date: March 1, 2026. This privacy policy describes how cramio (“we”, “us”, “our”) collects, uses, and protects information when you use our platform and services.

Who is responsible for your data

Controller: ALB Dienstliestungen, Mainzer Strasse 235, 53179 Bonn, Germany. Contact: privacy@cramio.eu.

We act as controller for account administration, billing, service security, support, and our own website operations. For personal data contained in customer-controlled compliance data, we generally act as processor on the customer's documented instructions. Those activities are governed by our Data Processing Addendum.

1. Information we collect

Account information

When you create an account, we collect your name, email address, organization name, and password (stored as a bcrypt hash). If you sign up through an OAuth provider, we receive your name, email, and provider identifier.

Product and compliance data

We process SBOM metadata (component names, versions, package URLs, and CPE identifiers), vulnerability scan results, incident records, compliance reports, and evidence records that you submit through the platform. Database storage is encrypted at rest by our infrastructure provider.

Usage data

We process basic request and security information such as IP address, browser type, and service events. Optional Sentry error and performance diagnostics are enabled only after consent and are not used for advertising.

What we do not collect

We never collect or transmit your source code, build artifacts, proprietary algorithms, or trade secrets. Our architecture ensures that only SBOM metadata and vulnerability findings leave your infrastructure.

2. How we use your information

Providing and operating the cramio compliance platform.
Matching your product components against CVE databases (NVD, CISA KEV, OSV) for vulnerability detection.
Preparing human-reviewed CRA reporting payloads and, only where an operational integration is expressly enabled, transmitting approved payloads to the relevant authority.
Maintaining tamper-evident, hash-chained evidence records for regulatory review.
Sending transactional notifications about incidents, deadlines, and account activity.
Improving platform reliability, performance, and security through consent-based diagnostics and proportionate security logs.
Providing customer support and responding to your inquiries.

3. Data sharing and subprocessors

We do not sell, rent, or trade your personal data or compliance information. We share data only in the following circumstances:

Regulatory filing evidence

Cramio prepares filing packages for your authorised staff to submit through the official SRP web portal. We retain the confirmation details you choose to record; Cramio does not transmit reports to ENISA.

Infrastructure providers

We use contracted providers for application hosting and our Neon database. Provider locations, subprocessors, and applicable transfer safeguards are documented in our subprocessor information and DPA.

Email delivery

Transactional emails (alerts, notifications, supplier notifications) are sent through our email service provider. Only the minimum necessary recipient information is shared.

Error monitoring

Application errors are reported to our monitoring service for reliability improvement. Error reports may include request metadata but never SBOM content or vulnerability details.

4. Data retention

Legal bases and transfers

We process account, subscription, support, and service-delivery data to perform our contract; billing and tax records to comply with legal obligations; proportionate security logs and diagnostics based on our legitimate interests in securing the service; and optional cookies only with consent.

Where a provider processes data outside the EU/EEA, we use an adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses. Required account and billing data is necessary to provide a subscription. We do not use personal data for solely automated decisions that produce legal or similarly significant effects.

See our current subprocessor list for provider names, purposes, and data categories.

Account data is retained for the duration of your active subscription and deleted within 90 days of account termination, unless retention is required by law.

Customer compliance records are retained according to the customer's contract, configured retention requirements, and applicable legal obligations. CRA technical documentation periods can depend on the product and its support period; Cramio does not impose a universal statutory ten-year retention period on every record.

Security and audit logs are retained only for documented operational, contractual, and legal purposes. Specific retention periods are stated in the applicable DPA or service schedule.

5. Your rights under GDPR

If you are located in the EU/EEA, you have the following rights regarding your personal data:

Access

Request a copy of the personal data we hold about you.

Rectification

Request correction of inaccurate or incomplete data.

Erasure

Request deletion of your personal data, subject to legal retention obligations.

Portability

Receive your data in a structured, machine-readable format.

Restriction

Request limited processing of your data in certain circumstances.

Objection

Object to processing based on legitimate interests.

To exercise any of these rights, contact us at privacy@cramio.eu. We will respond within 30 days.

You may withdraw consent at any time where consent is the legal basis, without affecting processing that took place before withdrawal. You may lodge a complaint with the competent supervisory authority, including the authority responsible for North Rhine-Westphalia or the authority where you live or work.

6. Security measures

We implement technical and organizational measures to protect your data, including TLS encryption in transit, provider-managed encryption at rest, tenant isolation, role-based access control, and continuous vulnerability monitoring of our own infrastructure. For full details, see our Security page.

7. Cookies

We use essential cookies for authentication and session management. We do not use third-party advertising cookies or tracking pixels. Optional cookies (e.g. for error monitoring) are used only with your consent. You can choose “Essential only” or “Accept all” in our cookie banner.

Cookie / purposeTypeExpiry
Session (e.g. __Secure-next-auth.session-token) — sign-in and sessionEssential30 days
CSRF token — securityEssentialSession
Error monitoring (e.g. Sentry) — reliabilityOptional (consent required)See current cookie details in the consent interface

Your choice is stored locally in your browser. You can withdraw optional consent at any time through the Cookie preferences control in the site footer. For more on your rights, see section 5.

8. Privacy contact

For privacy-related inquiries, data subject requests, or to request our Data Processing Addendum (DPA), contact:

ALB Dienstliestungen — Privacy

Email: privacy@cramio.eu

Mainzer Strasse 235, 53179 Bonn, Germany

You also have the right to lodge a complaint with your local data protection supervisory authority.