The Short Version: CertifyClouds stores application data in your Azure environment. Our services do not receive your secrets, credentials, scan results, or audit logs; they receive license validation and bounded aggregate fleet-health counters. Optional integrations transmit selected data only to destinations your administrator configures.

Data controller: CertifyClouds is operated by CertifyClouds Ltd (company number SC892952), United Kingdom, which is the data controller for the information described in this policy. To contact us about this policy or your data, email [email protected].

Enterprise agreements: If you have entered into a separate written agreement with us, such as an enterprise Master Services Agreement or Data Processing Agreement, the data controller and terms identified in that agreement govern that engagement and take precedence over this policy to the extent of any conflict.

1. Information We DO NOT Collect

CertifyClouds is designed with privacy in mind. We do NOT receive or have access to:

CertifyClouds application data is stored inside your environment in your managed database. We have no administrative access to it. Optional customer-configured integrations can transmit selected data directly to destinations your administrator approves.

Section 2 below describes the limited information our license server does receive (license key + version + optional aggregate operational counts) and how to disable each.

2. Information We DO Collect

License Validation

When CertifyClouds validates your license, we receive:

DataPurposeRetention
License keyVerify valid licensePermanent (in our database)
TimestampTrack validation requests90 days

Optional: Update Checks

If update checking is enabled, we receive:

DataPurposeRetention
Current versionDetermine if update availableNot stored

Update checks can be disabled by removing network access to license.certifyclouds.com.

Optional: Fleet Visibility (Aggregate Operational Counts)

When the ENABLE_FLEET_VISIBILITY setting is enabled (default on), the hourly license-validate heartbeat also carries aggregate operational counts alongside the license key + version. This helps us understand fleet health and identify customers who may need onboarding support.

What we receive: aggregate integer counts only. No asset names, no PII, no per-asset detail. Examples:

What we do NOT receive: Any individual secret / certificate / key names. Any vault names. Any compliance findings. Any audit log content. Any customer data.

Defensive limits: The license-server worker rejects payloads that are not a plain object or whose serialised JSON exceeds 4 KB. A malicious or outdated client cannot poison our license-server KV with surprise shapes or unbounded payloads.

Opt out: Advanced Settings → App Behaviour → Enable Fleet Visibility → off. Toggle takes effect on the next heartbeat. License validation continues to work normally without the stats payload.

DataPurposeRetention
Aggregate operational countsCustomer-success outreach, fleet-health monitoringLast-known value per license (overwritten each heartbeat)

Optional: Hosted AI Clients Through MCP

The ENTERPRISE MCP Connector is disabled by default. If your administrator enables it and an authorized user invokes a read-only tool, CertifyClouds sends that result over TLS directly to the selected hosted AI provider.

CertifyClouds-operated services do not receive MCP results. The selected provider processes them under your agreement and settings with that provider. The MCP connector does not return bearer tokens, secret values, private keys, certificate material, or value-shaped hints. Disable the connector in Settings → MCP Connector to close this data path.

Optional: Transactional Email

When you contact us through the website contact form, or when CertifyClouds (deployed in your environment) sends operational emails such as licence-expiry warnings to the address you registered, those emails are delivered via SMTP2GO as a sub-processor. SMTP2GO is GDPR-compliant; their privacy policy is at smtp2go.com/privacy-policy.

3. How We Use Information

We use the limited information we collect to:

We do NOT use your information to:

4. Data Storage and Security

License Server

Our license validation server (license.certifyclouds.com) is:

Your Environment

All CertifyClouds application data is stored in your environment:

We have no administrative access to your environment or stored application data.

5. Data Sharing

We do not sell or rent your information. We share data only with the sub-processors below, and only as needed for the service to function:

Sub-processorPurposePrivacy policy
CloudflareEdge / DDoS protection for the marketing site and the license servercloudflare.com/privacypolicy
SMTP2GOTransactional email delivery (contact-form replies, licence-expiry notices)smtp2go.com/privacy-policy
Reddit, Inc.Advertising-pixel attribution for paid social campaigns (when active; see §6)reddit.com/policies/privacy-policy

We may additionally disclose data:

6. Website Cookies, Analytics, and Visitor Identification

Important: This section applies only to our marketing website (certifyclouds.com). The CertifyClouds application deployed in your Azure environment contains no third-party tracking scripts.

Cookies set by the marketing site

CookieSet byPurposeCategory
__cf_bmCloudflareBot management; distinguishes humans from botsStrictly necessary
cf_chl_*Cloudflare TurnstileCAPTCHA challenge on form submissions (contact / trial signup)Strictly necessary
cc_consentcertifyclouds.comRecords your cookie preference choiceStrictly necessary
_rdt_uuid + Reddit advertising pixelReddit, Inc.Attribution for paid social campaigns; loaded only when an active campaign is running (see below)Marketing; opt-in

The strictly-necessary cookies above are required for site security and consent persistence. The Reddit advertising pixel is only loaded after you accept marketing cookies via the consent banner, and only during periods when a paid social campaign is active.

Reddit advertising pixel

When a paid Reddit campaign is active, we load the Reddit advertising pixel on the marketing site to measure ad-attribution and reach (for example, how many of our Reddit ad clicks land on the scanner or trial signup pages). The pixel sends Reddit:

Lawful basis: consent. The pixel does not load until you accept marketing cookies via the consent banner, and is not loaded at all outside an active paid campaign.

Reddit's privacy policy is at reddit.com/policies/privacy-policy.

Opting out

You can opt out of marketing-pixel tracking by:

Note: Analytics and advertising-pixel tracking apply only to our marketing website, not to the CertifyClouds application deployed in your environment.

7. Your Rights (GDPR/UK GDPR)

Depending on your jurisdiction, you may have rights to:

To exercise these rights, contact: [email protected]

8. Data Retention

Data TypeRetention Period
License recordsDuration of license + 1 year
Validation logs90 days
Support communications2 years
Legal/compliance recordsAs required by law

9. International Transfers

Our license server is hosted on Cloudflare's global network. Your license validation request may be processed in various countries. Cloudflare maintains appropriate safeguards for international data transfers.

10. Children's Privacy

CertifyClouds is a business software product. We do not knowingly collect information from children under 16. If you believe a child has provided information to us, contact [email protected].

11. Changes to This Policy

We may update this Privacy Policy periodically. The current version is always published at certifyclouds.com/privacy. The "Last Updated" date at the top of this page reflects the most recent revision; continued use of the site or service after a revision constitutes acceptance.

12. Contact Us

For privacy questions or concerns:

Summary

QuestionAnswer
Do you see my secrets?No
Do you store my Azure data?No
What do you collect?License key and validation timestamp only
Can I use this offline?Yes, with cached license for a configurable grace period
Who has access to my scans?Only you

By using CertifyClouds, you acknowledge that you have read and understood this Privacy Policy.