Privacy Policy
Hashfort, Simon Kramarič s.p.
1. Data controller
The data controller is Simon Kramarič s.p., Partizanska pot, Črnomelj, Slovenia. For any privacy question, and to exercise the rights described below, contact us at contact@hashfort.org.
2. What data we collect
When using our services we may collect: first and last name, company name, email address, telephone number and IP address. For billing we collect the details required to issue an invoice. Data is collected only to the extent necessary for service delivery or communication with the client.
3. What the assessment agent collects
The agent you install on your machine inspects its state and reports what it concludes. It collects technical data about the machine: hostname and operating system, installed packages and their versions, services that are listening, encryption and remote access settings, and system hardening settings. The agent does NOT read your files, documents, email or database contents, and does not record keystrokes or screen contents. Only the findings of the assessment leave the machine.
4. Purpose of processing
We process personal data for the following purposes: delivering the subscription service and producing reports, managing your user account and authenticating you, communicating with clients, preparing offers and invoices, technical support, keeping the service secure and detecting abuse, and improving the service.
5. Legal basis
Processing is based on the contractual relationship (Art. 6(1)(b) GDPR) for delivering the subscription, legal obligation (Art. 6(1)(c) GDPR) for accounting records, legitimate interest (Art. 6(1)(f) GDPR) for keeping the service secure and preventing abuse, and consent (Art. 6(1)(a) GDPR) where consent is required.
6. Data retention
Account data is retained for as long as the account exists and is deleted within 30 days of the account being closed. Assessment findings and reports are not kept indefinitely: they exist for as long as your account exists, and are deleted when the account is deleted, or earlier if you ask us to. Security and audit logs are retained for 30 days. Contact form messages are retained for 30 days. Accounting documents are retained for 10 years, as required by Slovenian law.
7. Separation of identity from findings
Your identity and the findings about your systems are stored separately. The system that runs assessments and produces reports works with non-identifying references and does not hold your contact details alongside your findings. The purpose of this design is to limit the consequences of any single incident.
8. Processing with artificial intelligence
To produce risk summaries, remediation guidance and report translations we use an artificial intelligence service provided by OpenAI, acting as our processor. We send the technical findings of an assessment (for example the names and versions of vulnerable components), and not your contact details or the contents of your files. This processing may involve a transfer of data outside the European Economic Area, made on the basis of the European Commission Standard Contractual Clauses. The data we send is not used to train public models.
9. Data sharing
We do not sell personal data. We share data only with the processors required to run the service: our cloud infrastructure provider in the European Union, our email provider for delivering reports and notifications, our payment and accounting providers, and the artificial intelligence provider described in section 8. We have data processing agreements in place with all of them. We may also disclose data where the law requires it.
10. Where data is held
Your account, your assessment findings and your reports are stored and processed on infrastructure we operate within the European Union. The only exception is the processing described in section 8.
11. Cookies
We use strictly necessary cookies only, to keep you signed in, maintain your session and protect forms. These cookies are required for the service to work, so they do not require consent. We do not use cookies for tracking or advertising.
12. Individual rights
You have the right to access your data, and to rectification, erasure, restriction of processing, data portability and objection. Send your request to contact@hashfort.org and we will respond within one month at the latest. If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the Information Commissioner of the Republic of Slovenia.
13. Data security
We use appropriate technical and organisational measures to protect data against unauthorised access, loss, misuse, alteration or destruction. Data is protected in transit and at rest, access is limited to what a given task requires, and sensitive operations leave an audit trail. We do not publish the details of these measures, because a precise description would mainly be of use to an attacker.
14. Policy changes
We may update this privacy policy from time to time. The current version is always published on this page. We will notify you by email of any material change that affects your rights.