Legal · Version 1.0 · Effective 27 July 2026
Privacy policy
What personal data CRA Kit holds, why, for how long, who else touches it, and how to get it back or get it deleted.
We set one cookie and it is the one that keeps you signed in. There is no analytics, no tracking pixel, no advertising network, and we do not record IP addresses anywhere. That is why this site has no cookie banner: there is nothing here that needs your consent.
Who is responsible
DNS Ventures LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States of America, is the controller for the personal data described here. Email hello@synthworx.com. We are not required to appoint a data protection officer and we have not appointed one, so that address reaches the people who actually run the service.
Where you upload personal data belonging to other people as part of your own compliance work, you are the controller of it and we are your processor. The data processing addendum covers that relationship.
What we collect
When you sign up
- Your email address. It is the only thing needed to create an account.
- Your name, if you give it.
- Your organisation: display name, legal name, registered address, country and VAT identifier. These are needed because they are printed on the EU declaration of conformity we generate for you.
When you use the product
- Product records, SBOMs, components, findings, VEX statements, documents, reporting cases and their audit events.
- Contact details you enter for your own single point of contact and coordinated vulnerability disclosure policy. These are usually work contact details of your staff.
- Firmware images you upload, which are analysed in a temporary directory that is destroyed when the job finishes. We keep the component list and the evidence, not your image.
- Events that measure how long it takes an account to produce its first artifact. These carry an account identifier and a kind, and nothing else.
When you pay
- Dodo Payments, our merchant of record, collects your billing name, address, tax identifier and payment method. We never receive card details.
- We store their customer identifier and subscription identifier, your plan, your billing interval, your currency and the dates your subscription starts, changes and ends.
When you use the free wizard
The scope and class wizard needs no account and asks for no email address. We store the answers you gave, the determination it produced, and the product and company name you typed onto the PDF, against a random token. Nothing links that record to you unless you later sign up and claim it. Send us the link and we will delete it.
What we do not collect
- IP addresses. Nothing in the application reads or stores one.
- Analytics of any kind. There is no Google Analytics, no Plausible, no PostHog, no session recorder and no heatmap.
- Third-party cookies, advertising identifiers or tracking pixels. There are none on any page.
- Special category data. Do not put health, biometric or similar data into free-text fields; the product has no reason to hold any.
Cookies
One cookie, named cra_session. It holds a random session identifier, it is httpOnly and secure, and it lasts 30 days or until you sign out. It is strictly necessary: without it you cannot stay signed in. We do not set any other cookie, so there is no consent to collect and no banner to click.
Why we are allowed to process it
| What | Lawful basis |
|---|---|
| Creating your account, signing you in, running the service | Performance of a contract, Article 6(1)(b) GDPR |
| Taking payment and issuing invoices | Performance of a contract, and legal obligation for tax records |
| Emailing you an alert about a vulnerability in your own product | Performance of a contract. It is the service you bought |
| Keeping the suppression list that stops us emailing you again | Legal obligation, and our legitimate interest in not contacting people who asked us not to |
| Security, fraud prevention and keeping the audit trail intact | Legitimate interests, Article 6(1)(f) GDPR |
| Keeping your evidence for ten years | Performance of a contract. The retention exists because your own CRA obligation needs it |
We do not process personal data for marketing, and we never send email to somebody who did not ask for it.
Stopping the email
We send three kinds of email and only one of them repeats, so only one of them has an unsubscribe. Alerts about vulnerabilities in your own products stop the moment you say so. Sign-in links do not, because they only go when you type your address into the login box and ask for one, and stopping them would take your account rather than your email. An invitation to join somebody’s account does not either: a person typed your address to send it, it happens once, and it says in the message that ignoring it does nothing.
Every alert carries an unsubscribe link at the bottom. The link is signed for one address, so nobody can turn somebody else’s alerts off, and nobody can turn them back on either. Signed in, the same switch is on the account page and works in both directions. Either way it takes effect immediately and you can still sign in afterwards.
To turn alerts back on: the switch on your account page, or the unsubscribe link from any older alert, which keeps working because it is signed for the address and does not expire.
A separate do-not-contact list stops everything including sign-in links. It is set by a bounce, a spam complaint or an erasure request, never by clicking unsubscribe, and a link cannot undo it. If you are on it the login page says so rather than pretending a link is on its way. Email hello@synthworx.com to come off it.
There is no newsletter, no product announcement list and no marketing email, so there is nothing else to unsubscribe from.
How long we keep it
| Data | Kept for |
|---|---|
| Sign-in links | 30 minutes, then they expire and cannot be reused |
| Sessions | 30 days, or until you sign out |
| Account and organisation records | While the account exists, then until you ask us to erase them |
| Compliance evidence: SBOMs, documents, findings, cases, audit events | Ten years per product, stored as a date on every row. Your CRA obligations outlive your subscription |
| Firmware images | Deleted when the scan finishes. Only the component list and the evidence survive |
| Free wizard determinations | Until you ask us to delete one |
| Billing records | As long as tax law requires. Dodo Payments holds the payment records themselves |
| The email suppression list | Indefinitely, on purpose. It exists so we cannot email somebody who opted out |
Who else touches it
A short list, published in full with what each one does and where it runs, on the sub-processors page. In summary: Vercel hosts the web application, Railway runs the firmware analysis engine and the database, Dodo Payments handles payment as merchant of record, and Zoho sends transactional email.
We do not sell personal data, we do not share it with advertisers, and we have no data-sharing arrangement with any other company.
One thing worth knowing that most vendors do not mention: to find vulnerabilities in your components we send component names and versions to public vulnerability APIs, principally NVD. Those requests carry the component identifier and nothing about you.
Where it is processed
The application and the database run in the United States, in the US West region. This is stated plainly rather than buried, because for a product sold to EU manufacturers it is a real consideration. Transfers out of the European Economic Area rely on the European Commission’s standard contractual clauses with each sub-processor.
If EU data residency is a contractual requirement for you, tell us before you buy rather than after.
Your rights
If you are in the European Economic Area or the United Kingdom you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to processing we base on legitimate interests. You can also ask for it in a portable format, though the product already exports everything in CycloneDX, SPDX, OpenVEX and CSAF whenever you want it.
Email hello@synthworx.com. We answer within 30 days and usually much sooner. We do not charge for it and we will not make you prove your identity twice.
Erasure runs through a dedicated authorised path in the database, which is the only route allowed to remove rows the append-only audit triggers otherwise protect. No other code path can delete them.
If you think we have got this wrong you can complain to your national supervisory authority. We would rather you told us first, but that is your right and not our permission to give.
Security
Encryption in transit and at rest, firmware analysed in an isolated per-scan directory, upload authorisation by short-lived signed token bound to one scan, and an audit chain the database itself refuses to let anyone rewrite. The detail is on the security page.
Children
CRA Kit is a business tool. It is not for anyone under 16 and we do not knowingly collect their data.
Changes
Every version of this policy carries a number and a date and the history is at the bottom of this page. For a change that materially affects you we email account owners at least 30 days before it takes effect.
Version history
| Version | Date | What changed |
|---|---|---|
| 1.0 | 27 July 2026 | First published. |
DNS Ventures LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States of America. Questions about this document go to hello@synthworx.com and a person answers.
The rest of the policies
The contract between you and DNS Ventures LLC for CRA Kit. What we do, what we do not do, what you pay, and who is responsible for what.
Refund and cancellation policyCancel from a screen, keep what you paid for until the period ends, and the cases where we give money back.
Sub-processorsEvery third party that touches customer data, what it does, and what it sees.
Data processing addendumThe Article 28 GDPR processor terms, already in force for every customer. No signature needed, no procurement queue to join.
Acceptable use policyWhat you may point the firmware analysis engine at, and the small number of things that get an account suspended.