Privacy notice
In effect from 2026-09-05.
Who is responsible
Conformity Guru is operated by Markle srls, VAT 03983380241, Via Lago di Lugano 20, 36015 Schio (VI), Italy. For questions about this notice, or to exercise any of the rights below, write to privacy@conformity.guru or call +39 0445 1620029.
Most of the data in this platform belongs to an organisation that uses it to document its own regulatory compliance. For that data the organisation decides what is processed and why: it is the controller, and we act on its instructions. We are the controller in our own right for your account, and for the measures that keep the service available and free of abuse.
What we collect
If you hold an account:
- Your email address, display name, and the organisations you belong to.
- Authentication data, including the secret behind your two-factor codes and your recovery codes.
- A record of what you changed and when, so an organisation can show who made a compliance decision.
If you report a vulnerability from a public product page:
- Your email address, so the manufacturer can reply to you.
- Your name, only if you choose to give it. The form works without it.
- The description you write and any files you attach.
- The time your report arrived, recorded by our servers and never editable.
Please do not include other people's personal data beyond what the report actually needs.
If you simply visit a public page:
- Your network address is used to limit how many requests can be made from one place, and to make an automated verification work. It is stored only as a one-way hash: we keep no log of visitor addresses.
Why, and on what legal basis
- To provide the service you or your organisation asked for — performance of a contract.
- To handle vulnerability reports. Manufacturers have a legal duty under Regulation (EU) 2024/2847 (the Cyber Resilience Act) to receive, assess and report vulnerabilities, and to keep a record of doing so — a legal obligation, supported by the legitimate interest of everyone using a product in it being secure. We do not rely on consent for this: a report cannot be withdrawn from a record the manufacturer is required to keep, and a permission that could not be honoured would not be a real one.
- To keep the platform available — rate limits, an automated human check, and abuse prevention, on our legitimate interest in a service that works.
- To meet our own accounting and tax duties — a legal obligation.
Who else processes it
We use the following providers. Each acts on our instructions under a data processing agreement, and none of them may use your data for their own ends.
- Supabase — database and server functions. Data is held in Frankfurt, Germany.
- Hetzner — file storage, in Nuremberg, Germany.
- Vercel — serves the web application, from its Frankfurt region.
- Resend — sends our email.
- Stripe and Fatture in Cloud — payments and invoicing, for paying customers only.
- GitHub or GitLab — only where an organisation chooses to connect a source repository.
Your data is stored in Germany. Some of these companies are established outside the EU, so their staff may access it for support; where that happens it is governed by the European Commission's standard contractual clauses.
Vulnerability reports are never sent to an AI model. The platform uses AI to help draft compliance documents from an organisation's own material; reports submitted by the public are not part of that and never leave the organisation that received them.
How long we keep it
- Account data — while the account exists, then deleted.
- Vulnerability reports — a report that became part of a manufacturer's compliance record is kept as long as that record, because the manufacturer must be able to show what was reported and when it was handled. A report closed without action is deleted on a shorter schedule.
- Invoices and accounting records — for the period tax law requires.
Cookies
We set cookies only to keep you signed in and to keep that session secure. We use no analytics, no advertising and no third-party tracking, which is why you are not asked to accept anything.
Your rights
You may ask for a copy of your data, ask us to correct it, ask us to delete it, object to processing based on legitimate interest, or ask for a portable copy. If you hold an account you can export your data yourself from your account page.
One limit is worth stating plainly. If you reported a vulnerability and ask us to erase your data, we can remove your name and email address from the report while keeping the report itself, because the manufacturer is legally required to retain the record. After that the report no longer identifies you.
Where an organisation is the controller, we will pass your request to it. You may also complain to a supervisory authority in the country where you live or work.
Conformity Guru is powered by AI and is currently in beta. Always review AI-generated responses before relying on them.
Markle srls — P. IVA 03983380241 · Privacy · Conformity Guru security