Controller
Mohammad Abu Khshait operates the RuleCerta service at rulecerta.com.
Postal address: Altendorfer Straße 98, 09113 Chemnitz, Germany.
Privacy and data-rights requests: privacy@rulecerta.com. Other inquiries can be submitted through the Contact page.
Categories of data
Account and authentication data: email address, display name or identity-provider metadata, authentication factors (including password hashes managed by our auth provider and passkeys when enrolled), and session state.
Workspace and product data: workspace names, memberships, invitations, environments, connection metadata (without returning connector secrets to the browser), audit runs, findings, evidence references, relationships, history, comparisons, and report artifacts.
Connector data: when you connect a provider, we store encrypted credentials server-side and read the workflow configuration needed for audits. RuleCerta does not write to your provider.
Audit and report data: completed audits freeze input and findings for inspectable history. Reports and PDFs are stored as private artifacts with integrity controls.
Security-related signals: authentication events handled by our auth provider, and application error logging used to operate the service.
Communications: messages you send for privacy, support, security, or other service inquiries.
Purposes
To provide the RuleCerta service you request: accounts, workspaces, connections, audits, findings, history, comparison, and reports.
To secure the service: authentication, access control, abuse resistance, and incident response.
To communicate with you about access, support, privacy requests, and security reports.
Artificial intelligence
RuleCerta does not use customer data to train machine-learning models.
Vendors and subprocessors
We use infrastructure and communications vendors listed on the Subprocessors page. That list is limited to vendors with a current processing role.
Retention
We retain account, workspace, audit, and report data while your account remains active and as needed to provide the service and meet legal obligations.
Connector credentials are removed when a connection is disconnected.
After a verified deletion request, we delete or de-identify in-scope data as described on the Data Deletion page.
Infrastructure backups operated by vendors may retain residual copies for a limited period after deletion from the primary store.
Data rights
Depending on applicable law, you may have rights to access, correct, export, or delete personal data. Submit requests to privacy@rulecerta.com. We may need to verify your identity and workspace ownership before acting.
Account and workspace deletion is completed after identity and ownership verification.
See the Data Deletion & Data Requests page for the request path.
Security
Security controls for the product are described on the Security page. Report vulnerabilities through the disclosure path published there.
Privacy contact
Privacy and data-rights requests: privacy@rulecerta.com.
We may update this policy. The version and last-updated date appear at the top of this page. Material changes will be reflected here.