Legal · Version 1.0 · Effective 27 July 2026

Privacy policy

What personal data CRA Kit holds, why, for how long, who else touches it, and how to get it back or get it deleted.

We set one cookie and it is the one that keeps you signed in. There is no analytics, no tracking pixel, no advertising network, and we do not record IP addresses anywhere. That is why this site has no cookie banner: there is nothing here that needs your consent.

Who is responsible

DNS Ventures LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States of America, is the controller for the personal data described here. Email hello@synthworx.com. We are not required to appoint a data protection officer and we have not appointed one, so that address reaches the people who actually run the service.

Where you upload personal data belonging to other people as part of your own compliance work, you are the controller of it and we are your processor. The data processing addendum covers that relationship.

What we collect

When you sign up

  • Your email address. It is the only thing needed to create an account.
  • Your name, if you give it.
  • Your organisation: display name, legal name, registered address, country and VAT identifier. These are needed because they are printed on the EU declaration of conformity we generate for you.

When you use the product

  • Product records, SBOMs, components, findings, VEX statements, documents, reporting cases and their audit events.
  • Contact details you enter for your own single point of contact and coordinated vulnerability disclosure policy. These are usually work contact details of your staff.
  • Firmware images you upload, which are analysed in a temporary directory that is destroyed when the job finishes. We keep the component list and the evidence, not your image.
  • Events that measure how long it takes an account to produce its first artifact. These carry an account identifier and a kind, and nothing else.

When you pay

  • Dodo Payments, our merchant of record, collects your billing name, address, tax identifier and payment method. We never receive card details.
  • We store their customer identifier and subscription identifier, your plan, your billing interval, your currency and the dates your subscription starts, changes and ends.

When you use the free wizard

The scope and class wizard needs no account and asks for no email address. We store the answers you gave, the determination it produced, and the product and company name you typed onto the PDF, against a random token. Nothing links that record to you unless you later sign up and claim it. Send us the link and we will delete it.

What we do not collect

  • IP addresses. Nothing in the application reads or stores one.
  • Analytics of any kind. There is no Google Analytics, no Plausible, no PostHog, no session recorder and no heatmap.
  • Third-party cookies, advertising identifiers or tracking pixels. There are none on any page.
  • Special category data. Do not put health, biometric or similar data into free-text fields; the product has no reason to hold any.

Cookies

One cookie, named cra_session. It holds a random session identifier, it is httpOnly and secure, and it lasts 30 days or until you sign out. It is strictly necessary: without it you cannot stay signed in. We do not set any other cookie, so there is no consent to collect and no banner to click.

Why we are allowed to process it

WhatLawful basis
Creating your account, signing you in, running the servicePerformance of a contract, Article 6(1)(b) GDPR
Taking payment and issuing invoicesPerformance of a contract, and legal obligation for tax records
Emailing you an alert about a vulnerability in your own productPerformance of a contract. It is the service you bought
Keeping the suppression list that stops us emailing you againLegal obligation, and our legitimate interest in not contacting people who asked us not to
Security, fraud prevention and keeping the audit trail intactLegitimate interests, Article 6(1)(f) GDPR
Keeping your evidence for ten yearsPerformance of a contract. The retention exists because your own CRA obligation needs it

We do not process personal data for marketing, and we never send email to somebody who did not ask for it.

Stopping the email

We send three kinds of email and only one of them repeats, so only one of them has an unsubscribe. Alerts about vulnerabilities in your own products stop the moment you say so. Sign-in links do not, because they only go when you type your address into the login box and ask for one, and stopping them would take your account rather than your email. An invitation to join somebody’s account does not either: a person typed your address to send it, it happens once, and it says in the message that ignoring it does nothing.

Every alert carries an unsubscribe link at the bottom. The link is signed for one address, so nobody can turn somebody else’s alerts off, and nobody can turn them back on either. Signed in, the same switch is on the account page and works in both directions. Either way it takes effect immediately and you can still sign in afterwards.

To turn alerts back on: the switch on your account page, or the unsubscribe link from any older alert, which keeps working because it is signed for the address and does not expire.

A separate do-not-contact list stops everything including sign-in links. It is set by a bounce, a spam complaint or an erasure request, never by clicking unsubscribe, and a link cannot undo it. If you are on it the login page says so rather than pretending a link is on its way. Email hello@synthworx.com to come off it.

There is no newsletter, no product announcement list and no marketing email, so there is nothing else to unsubscribe from.

How long we keep it

DataKept for
Sign-in links30 minutes, then they expire and cannot be reused
Sessions30 days, or until you sign out
Account and organisation recordsWhile the account exists, then until you ask us to erase them
Compliance evidence: SBOMs, documents, findings, cases, audit eventsTen years per product, stored as a date on every row. Your CRA obligations outlive your subscription
Firmware imagesDeleted when the scan finishes. Only the component list and the evidence survive
Free wizard determinationsUntil you ask us to delete one
Billing recordsAs long as tax law requires. Dodo Payments holds the payment records themselves
The email suppression listIndefinitely, on purpose. It exists so we cannot email somebody who opted out

Who else touches it

A short list, published in full with what each one does and where it runs, on the sub-processors page. In summary: Vercel hosts the web application, Railway runs the firmware analysis engine and the database, Dodo Payments handles payment as merchant of record, and Zoho sends transactional email.

We do not sell personal data, we do not share it with advertisers, and we have no data-sharing arrangement with any other company.

One thing worth knowing that most vendors do not mention: to find vulnerabilities in your components we send component names and versions to public vulnerability APIs, principally NVD. Those requests carry the component identifier and nothing about you.

Where it is processed

The application and the database run in the United States, in the US West region. This is stated plainly rather than buried, because for a product sold to EU manufacturers it is a real consideration. Transfers out of the European Economic Area rely on the European Commission’s standard contractual clauses with each sub-processor.

If EU data residency is a contractual requirement for you, tell us before you buy rather than after.

Your rights

If you are in the European Economic Area or the United Kingdom you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to processing we base on legitimate interests. You can also ask for it in a portable format, though the product already exports everything in CycloneDX, SPDX, OpenVEX and CSAF whenever you want it.

Email hello@synthworx.com. We answer within 30 days and usually much sooner. We do not charge for it and we will not make you prove your identity twice.

Erasure runs through a dedicated authorised path in the database, which is the only route allowed to remove rows the append-only audit triggers otherwise protect. No other code path can delete them.

If you think we have got this wrong you can complain to your national supervisory authority. We would rather you told us first, but that is your right and not our permission to give.

Security

Encryption in transit and at rest, firmware analysed in an isolated per-scan directory, upload authorisation by short-lived signed token bound to one scan, and an audit chain the database itself refuses to let anyone rewrite. The detail is on the security page.

Children

CRA Kit is a business tool. It is not for anyone under 16 and we do not knowingly collect their data.

Changes

Every version of this policy carries a number and a date and the history is at the bottom of this page. For a change that materially affects you we email account owners at least 30 days before it takes effect.

Version history

VersionDateWhat changed
1.027 July 2026First published.

DNS Ventures LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States of America. Questions about this document go to hello@synthworx.com and a person answers.