Skip to content

Legal

Privacy Policy

This Privacy Policy describes how RuleCerta processes personal and customer data when you use our website and product.

Version
1.2.0
Last updated

Controller

Mohammad Abu Khshait operates the RuleCerta service at rulecerta.com.

Postal address: Altendorfer Straße 98, 09113 Chemnitz, Germany.

Privacy and data-rights requests: privacy@rulecerta.com. Other inquiries can be submitted through the Contact page.

Categories of data

Account and authentication data: email address, display name or identity-provider metadata, authentication factors (including password hashes managed by our auth provider and passkeys when enrolled), and session state.

Workspace and product data: workspace names, memberships, invitations, environments, connection metadata (without returning connector secrets to the browser), audit runs, findings, evidence references, relationships, history, comparisons, and report artifacts.

Connector data: when you connect a provider, we store encrypted credentials server-side and read the workflow configuration needed for audits. RuleCerta does not write to your provider.

Audit and report data: completed audits freeze input and findings for inspectable history. Reports and PDFs are stored as private artifacts with integrity controls.

Security-related signals: authentication events handled by our auth provider, and application error logging used to operate the service.

Communications: messages you send for privacy, support, security, or other service inquiries.

Purposes

To provide the RuleCerta service you request: accounts, workspaces, connections, audits, findings, history, comparison, and reports.

To secure the service: authentication, access control, abuse resistance, and incident response.

To communicate with you about access, support, privacy requests, and security reports.

Artificial intelligence

RuleCerta does not use customer data to train machine-learning models.

Vendors and subprocessors

We use infrastructure and communications vendors listed on the Subprocessors page. That list is limited to vendors with a current processing role.

Retention

We retain account, workspace, audit, and report data while your account remains active and as needed to provide the service and meet legal obligations.

Connector credentials are removed when a connection is disconnected.

After a verified deletion request, we delete or de-identify in-scope data as described on the Data Deletion page.

Infrastructure backups operated by vendors may retain residual copies for a limited period after deletion from the primary store.

Data rights

Depending on applicable law, you may have rights to access, correct, export, or delete personal data. Submit requests to privacy@rulecerta.com. We may need to verify your identity and workspace ownership before acting.

Account and workspace deletion is completed after identity and ownership verification.

See the Data Deletion & Data Requests page for the request path.

Cookies and local storage

We use strictly necessary authentication and session technology, plus first-party preferences such as language. Details are on the Cookies & Storage page. Advertising and marketing cookies are not used. A consent banner is not shown while only essential technologies are in use.

Security

Security controls for the product are described on the Security page. Report vulnerabilities through the disclosure path published there.

Privacy contact

Privacy and data-rights requests: privacy@rulecerta.com.

We may update this policy. The version and last-updated date appear at the top of this page. Material changes will be reflected here.