Legal

Data processing agreement

This applies to the account area and the licence service we operate. It does not apply to the software you install on your own servers — there, no data reaches us at all.

1. What this covers, and what it does not

Portiger is two different things for data protection purposes, and mixing them up is the usual mistake.

  • The software you install. It runs on your servers. Your workloads, your containers, your logs and your users' data never reach us. For that part we are not a processor at all, because we process nothing.
  • The account area and the licence service. Here we hold your account details and the record of which installation activated which licence. This agreement is about that.

2. Roles

For the account you open, you are the data subject and we are the controller — see the privacy notice. Where you open accounts for colleagues, you are the controller for those people and we act as processor on your instructions.

3. Scope of processing

  • Subject matter: operating accounts and licences for the Portiger software.
  • Duration: for as long as the account exists, plus the retention periods in the privacy notice.
  • Categories of data: e-mail address, password hash, billing details held by Polar Software, Inc. as merchant of record, licence activation records, and server-side access logs.
  • Categories of data subject: the people you give account access to.

4. Our obligations

  • We process personal data only on your documented instructions, and to meet legal obligations.
  • Everyone with access is bound by confidentiality. Today that is one person.
  • We apply the security measures in section 6 and keep them current.
  • We assist you, as far as we reasonably can, with data subject requests and with breach notification.
  • On termination we delete or return the data, as described in section 7.

5. Subprocessors

We engage the companies listed on the subprocessor page, and no others. That page is the notice: it names each one, what they do and where they are. We will update it before adding a subprocessor, not after.

6. Security measures

  • Traffic to our systems is encrypted in transit; certificates are issued automatically and renewed.
  • Passwords are stored as bcrypt hashes; sensitive fields in the database are encrypted at rest with a key held outside the database.
  • Administrative access requires an account with a role that permits it; access is logged.
  • Licences are signed with a private key that never leaves the server that holds it.

7. Deletion

When an account is closed, account data is deleted. Records we are legally required to keep — invoices, in particular — are retained for the statutory period and nothing longer. Licence activation records are kept while the licence is valid, because that is what the software checks against.

8. Audits

On request we will answer a security questionnaire and provide what we have. We do not offer on-site audits; a one-person business cannot honestly promise them.

9. Signing

If your procurement process needs this signed rather than published, write to sales@portiger.com.