Legal

Privacy Policy

This policy describes how OpsDeck collects, uses and retains personal data across the product, including the free, unauthenticated security scan described below.

Free security scan

What we collect

  • The email address you provide to request a scan.
  • A hashed representation of your IP address (for abuse prevention only).
  • The scan results themselves: configuration, package versions, running services and similar system state read from the target server.
  • A limited amount of third-party personal data that may be present on the scanned server and is relevant to a check — for example local account names, numeric user IDs (UIDs), or the subject line of a TLS certificate.

What we never collect

  • Password hashes.
  • Private keys.
  • Full GECOS names (the free-text "real name" field of a user account).
  • Private or internal IP addresses.

Purpose and legal basis

We process this data to run the scan you requested and deliver its report (performance of a contract you initiate by requesting the scan), to prevent abuse of the free tier (legitimate interest), and — only with your separate marketing consent checkbox — to send occasional product updates (consent).

Retention

  • Verified scans and their reports: 30 days from the scan date.
  • Unverified scans (email never confirmed): 7 days.
  • Marketing leads you've consented to: up to 24 months.

Your rights

  • Access the report at any time via the link we email you.
  • Self-service delete a scan and its report from the report page.
  • Unsubscribe from marketing email at any time via the link in every email.
  • Request full erasure ("forget me") of your email address and every scan tied to it, from the same unsubscribe link.

India compliance

We continue to build out CERT-In / DPDP technical checks as part of our compliance programme. See Trust & security for the current state of these controls.

Signed-in organisation data

Data you or your team enter into the signed-in dashboard (servers, credentials, findings, activity) is governed by your organisation's plan-configured retention and is never shared across organisations — see Trust & security.