1. Who we are

CRA Alert ("we", "us") provides software that helps companies monitor their products for actively exploited vulnerabilities and draft regulatory reports, for the customer's own review and submission, under the EU Cyber Resilience Act. This policy explains what data we collect, why, on what legal basis, and how it's handled. CRA Alert is pre-launch; our registered legal entity details will be published here once incorporation is complete, and this policy will be updated to name it directly.

2. What we collect

Call requests: your name, company name, email address, and the timestamp you submitted the request.

Customer accounts (once launched): your company and contact details, the repository metadata needed to generate a component inventory (not your proprietary source code itself, retained beyond the scan), scan results, alert history, and any report drafts generated on your behalf.

Site usage: we use a single, strictly necessary cookie (stored via your browser's local storage) to remember that you've dismissed the cookie notice. We don't run analytics or advertising trackers on this site.

3. Why we collect it, and our legal basis

  • Call requests — to get in touch and schedule an introductory call. Legal basis: your consent, given when you submit the form.
  • Customer accounts — to provide the monitoring and reporting service itself. Legal basis: performance of the contract between us.
  • Aggregated product improvement — to improve detection accuracy over time, using de-identified, aggregated patterns; your raw code is never shared with third parties. Legal basis: our legitimate interest in improving the service, balanced against your right to privacy.

4. How long we keep it

Call request details are kept until the call has taken place and any resulting relationship ends, or until you ask us to delete them, whichever comes first. If we haven't managed to connect within 12 months of your request, we delete the details rather than hold them indefinitely. Customer scan and report history is kept for the duration of your subscription plus a reasonable retention period, so you have a record for audits. Full details will be specified in your customer agreement.

5. Who we share it with

We do not sell personal data. Call requests submitted through this site are currently processed via Formspree, our form-handling provider, strictly to deliver the request to us. Once the product launches, customer data may also be shared with hosting and email delivery providers strictly to operate the service. All such providers act under standard data processing agreements, and none are permitted to use your data for their own purposes.

6. Security

Data is encrypted in transit and, once we're storing customer product data, at rest. Access is limited to the people who need it to operate the service or support you directly. Full technical detail is on our Security page.

7. Your rights

If you're in the EU (or covered by equivalent data protection law elsewhere), you have the right to access, correct, delete, or export your personal data, and to withdraw consent at any time — withdrawing consent doesn't affect anything we did with your data before that point. You also have the right to lodge a complaint with your local data protection supervisory authority if you believe we've mishandled your data. To exercise any of these rights with us directly, contact us at the address below.

8. Changes to this policy

We may update this policy as the product develops, particularly once our legal entity and infrastructure providers are finalized ahead of launch. Material changes will be posted here with an updated date, and communicated directly to anyone with an active call request or customer account.

9. Contact

privacy@craalert.com