Trust & support

Privacy & GDPR Notice

This notice explains the information Threadcairn handles when you use the public scan, connect a repository, create an account, or use a paid plan. It is factual launch copy, not legal advice.

Owner inputs required before publication

The service owner must add the controller legal name and address, effective date, retention periods, approved legal bases, subprocessors and recipient categories, international-transfer details, and the final rights-request process.

Those details are intentionally not guessed here. This draft should be reviewed and completed for the jurisdictions in which Threadcairn is offered.

1. Who controls the information

Owner completion required: identify the Threadcairn legal entity or individual responsible for the service and provide the controller address before publication. General privacy questions can be sent to admin@threadcairn.com.

2. Information Threadcairn may process

  • Account data: name, email address, login information, and workspace details needed to provide the account.
  • GitHub and repository data: connected repository information and the dependency or repository data needed for scans, SBOMs, findings, incidents, and evidence.
  • Security workflow data: vulnerability findings, incident records, supporting evidence, and alert-recipient email addresses that a customer chooses to configure.
  • Public scan data: public repository metadata and bounded dependency information used to produce the free scan result.
  • Billing data: information needed to provision and manage a paid plan. Payment details are handled through the configured payment flow rather than entered into the scan itself.
  • Support messages: the name, email address, and message submitted through the contact form.

3. Why the information is used

  • To create and secure accounts and provide requested workspace features.
  • To connect authorized GitHub repositories and run the public or connected-repository workflows.
  • To organize SBOMs, vulnerability findings, incidents, and supporting evidence.
  • To send alert emails and respond to support requests.
  • To verify and manage paid access and billing-related workflows.

Owner completion required: document the approved GDPR legal basis for each purpose and any additional purposes used in production.

4. Retention, recipients, and transfers

Threadcairn retains repository, scan, findings, incident, evidence, account, billing, alert, and support information only according to the service owner's approved operational policy.

Owner completion required: list the retention period or deletion rule for each category, the subprocessors or recipient categories used by the deployed service, and any international-transfer safeguards that apply.

5. Rights and questions

Depending on the applicable law and the customer's role, a person may have rights relating to access, correction, deletion, restriction, objection, or portability. The final process and response time must be confirmed by the service owner before publication.

To ask a product or privacy question, use the Contact & Support page. General privacy and administrative requests can also be sent to admin@threadcairn.com. Security or vulnerability reports should be sent to security@threadcairn.com. The owner must confirm the final rights-request method and response time before publication.

Threadcairn does not provide legal advice. Customers should obtain independent legal advice about their own obligations, notices, and processing decisions.