How we handle your data.
Effective date: March 1, 2026. This privacy policy describes how cramio (“we”, “us”, “our”) collects, uses, and protects information when you use our platform and services.
Who is responsible for your data
Controller: ALB Dienstliestungen, Mainzer Strasse 235, 53179 Bonn, Germany. Contact: privacy@cramio.eu.
We act as controller for account administration, billing, service security, support, and our own website operations. For personal data contained in customer-controlled compliance data, we generally act as processor on the customer's documented instructions. Those activities are governed by our Data Processing Addendum.
1. Information we collect
Account information
When you create an account, we collect your name, email address, organization name, and password (stored as a bcrypt hash). If you sign up through an OAuth provider, we receive your name, email, and provider identifier.
Product and compliance data
We process SBOM metadata (component names, versions, package URLs, and CPE identifiers), vulnerability scan results, incident records, compliance reports, and evidence records that you submit through the platform. Database storage is encrypted at rest by our infrastructure provider.
Usage data
We process basic request and security information such as IP address, browser type, and service events. Optional Sentry error and performance diagnostics are enabled only after consent and are not used for advertising.
What we do not collect
We never collect or transmit your source code, build artifacts, proprietary algorithms, or trade secrets. Our architecture ensures that only SBOM metadata and vulnerability findings leave your infrastructure.
2. How we use your information
3. Data sharing and subprocessors
We do not sell, rent, or trade your personal data or compliance information. We share data only in the following circumstances:
Regulatory filing evidence
Cramio prepares filing packages for your authorised staff to submit through the official SRP web portal. We retain the confirmation details you choose to record; Cramio does not transmit reports to ENISA.
Infrastructure providers
We use contracted providers for application hosting and our Neon database. Provider locations, subprocessors, and applicable transfer safeguards are documented in our subprocessor information and DPA.
Email delivery
Transactional emails (alerts, notifications, supplier notifications) are sent through our email service provider. Only the minimum necessary recipient information is shared.
Error monitoring
Application errors are reported to our monitoring service for reliability improvement. Error reports may include request metadata but never SBOM content or vulnerability details.
4. Data retention
Legal bases and transfers
We process account, subscription, support, and service-delivery data to perform our contract; billing and tax records to comply with legal obligations; proportionate security logs and diagnostics based on our legitimate interests in securing the service; and optional cookies only with consent.
Where a provider processes data outside the EU/EEA, we use an adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses. Required account and billing data is necessary to provide a subscription. We do not use personal data for solely automated decisions that produce legal or similarly significant effects.
See our current subprocessor list for provider names, purposes, and data categories.
Account data is retained for the duration of your active subscription and deleted within 90 days of account termination, unless retention is required by law.
Customer compliance records are retained according to the customer's contract, configured retention requirements, and applicable legal obligations. CRA technical documentation periods can depend on the product and its support period; Cramio does not impose a universal statutory ten-year retention period on every record.
Security and audit logs are retained only for documented operational, contractual, and legal purposes. Specific retention periods are stated in the applicable DPA or service schedule.
5. Your rights under GDPR
If you are located in the EU/EEA, you have the following rights regarding your personal data:
Access
Request a copy of the personal data we hold about you.
Rectification
Request correction of inaccurate or incomplete data.
Erasure
Request deletion of your personal data, subject to legal retention obligations.
Portability
Receive your data in a structured, machine-readable format.
Restriction
Request limited processing of your data in certain circumstances.
Objection
Object to processing based on legitimate interests.
To exercise any of these rights, contact us at privacy@cramio.eu. We will respond within 30 days.
You may withdraw consent at any time where consent is the legal basis, without affecting processing that took place before withdrawal. You may lodge a complaint with the competent supervisory authority, including the authority responsible for North Rhine-Westphalia or the authority where you live or work.
6. Security measures
We implement technical and organizational measures to protect your data, including TLS encryption in transit, provider-managed encryption at rest, tenant isolation, role-based access control, and continuous vulnerability monitoring of our own infrastructure. For full details, see our Security page.
8. Privacy contact
For privacy-related inquiries, data subject requests, or to request our Data Processing Addendum (DPA), contact:
ALB Dienstliestungen — Privacy
Email: privacy@cramio.eu
Mainzer Strasse 235, 53179 Bonn, Germany
You also have the right to lodge a complaint with your local data protection supervisory authority.