GDPR Data Processing Policy

Effective Date: August 21, 2026 (version 1.0)

1. Introduction

This GDPR Data Processing Policy describes how Edgely processes personal data in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR.

This Policy complements our Privacy Policy and prevails in the event of conflict to the extent strictly required by the GDPR.

2. Data Controller

Edgely acts as the Data Controller for personal data collected through our Service. To exercise your rights or to ask any question covered by this Policy:

  • Email: contact@edgely.io
  • Postal address: as published on our website

3. Legal Basis for Processing

We process personal data on one or more of the following legal bases, depending on the activity:

  • Performance of a contract (Art. 6(1)(b)), to provide the Service you signed up for
  • Legitimate interests (Art. 6(1)(f)), to secure the Service, prevent fraud and abuse of our public forms, protect your account and its linked devices, and compile the distribution statistics described in section 5.2, balanced against your rights and freedoms
  • Legal obligation (Art. 6(1)(c)), to comply with applicable laws (in particular tax and accounting law) and to be able to demonstrate which version of a legal document you accepted and when
  • Consent (Art. 6(1)(a)), for marketing communications and any other processing requiring it

You can withdraw consent at any time without affecting the lawfulness of prior processing.

4. Data Subject Rights

Under the GDPR you have the following rights:

4.1 Right of Access (Article 15)

You can ask whether we process your personal data and obtain a copy of it.

4.2 Right to Rectification (Article 16)

You can ask us to correct inaccurate or incomplete data.

4.3 Right to Erasure (Article 17)

You can ask us to delete your personal data ("right to be forgotten") in the cases listed in Article 17.

4.4 Right to Restrict Processing (Article 18)

You can ask us to restrict the processing of your personal data in certain cases (for example, while we verify a rectification request).

4.5 Right to Data Portability (Article 20)

You can receive the personal data you provided to us in a structured, commonly-used and machine-readable format, and have it transmitted to another controller where technically feasible.

4.6 Right to Object (Article 21)

You can object at any time to processing based on legitimate interests, including profiling. You can object at any time, without justification, to processing for direct marketing.

4.7 Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to a decision based solely on automated processing that produces legal effects on you or similarly significantly affects you. We do not currently make such decisions.

4.8 How to exercise your rights

To exercise any of these rights, write to contact@edgely.io. We may need to verify your identity before answering. We respond within one month of receipt; that period may be extended by two further months for complex or numerous requests, and we will inform you of any such extension within the first month.

If we do not act on your request, we will tell you why and inform you of your right to lodge a complaint with a supervisory authority and to seek a judicial remedy.

5. Data Processing Activities

PurposeCategories of DataLegal BasisRetention
Account managementIdentity, contact, account credentials, device identifiers used for licence activation and device linking, and the IP address a device was linked fromContractAccount lifetime + reasonable wind-down; the linking address is deleted with the device
Service provisionSession and authentication data, requests you make to the ServiceContractUp to 2 years after the event
BillingIdentity, contact, payment dataLegal obligation7–10 years after invoice (tax/accounting)
MarketingContact, preferencesConsentUntil withdrawal
Distribution statisticsDownload, version-check and plugin-install events. For a download: the country and the city resolved from the connection, the user agent, utm_source, utm_medium, utm_campaign and the referrer. For a version check: the country and the user agent. For a plugin install or update: the count alone. The IP address is used in memory only, to resolve that location, and is never stored with these records (see 5.2).Legitimate interestKept as statistical records; they contain no IP address
Cross-device syncNon-credential application data only (such as connection metadata, organization of entries, preferences). Excludes the contents of the credential vault, which never leave the user's device.ContractAccount lifetime
Security & auditLogs of authentication and security-relevant actions, including a partially masked IP address written on rate-limit hits, failed anti-abuse checks and public-form submissionsLegitimate interest / legal obligationUp to 24 months
Consent recordsThe legal document accepted, its version, the date, and the IP address the acceptance came fromLegal obligation / legitimate interestKept as the evidentiary record, including after the account is deleted, where the consent is marked withdrawn
Anti-abuse on public formsContact-form and feedback submissions, and the IP address they were sent fromLegitimate interestKept with the submission; a contact-form address is cleared when the associated account is deleted or anonymized, while a feedback address stays with the feedback submission

5.1 Out of scope for portability and erasure

Because the contents of the credential vault, passwords, private keys, and access tokens, are stored exclusively on the user's device and are not accessible to Edgely, that material is out of scope for Article 15 (access), Article 17 (erasure) and Article 20 (portability) requests directed at Edgely: there is nothing for us to export, correct, or delete. Users export and delete this data through the application's own export and vault-management features.

5.2 Statistics recorded by the portal

The portal records a small number of events that it carries out itself. These are not reports sent by the applications about how they are used; they are records of the requests the portal served:

  • a download of the software from our website
  • a version check made by the software
  • an installation or update of a plugin

What we record is not the same for each:

  • a download, the event itself (a count), the country and the city resolved from the connection, the browser or client user agent, and the attribution carried by the request: utm_source, utm_medium, utm_campaign and the referrer
  • a version check, the event itself (a count), the country resolved from the connection, and the browser or client user agent
  • a plugin install or update, the event itself (a count), and nothing else

The IP address is used only, in memory, to resolve that location at the moment of the request, and is then discarded. It is never stored with these records, and it appears in no log and no backup of them. Section 5.3 sets out, separately and in full, the cases in which the portal does retain an IP address.

Device identifiers are processed for licence activation and to link your own devices to your account. That is an account function performed under the contract, not tracking.

5.3 IP addresses the portal does retain

The statement in 5.2 is confined to the distribution statistics. Outside them the portal does retain an IP address, for a small number of security, consent and account purposes. None of them is statistical and none feeds a profile:

PurposeWhat is storedLegal basisRetention
Proof of consentThe address from which you accepted a given version of a legal document, together with the document, its version and the dateArt. 6(1)(c) legal obligation (being able to demonstrate consent) and Art. 6(1)(f) legitimate interest (evidence of the agreement)For as long as the acceptance may need to be proved; it survives account deletion, where the consent is marked as withdrawn rather than erased
Anti-abuse on the public contact and feedback formsThe address a submission was sent fromArt. 6(1)(f) legitimate interest in protecting the Service and its users from spam and abuseKept with the submission; a contact-form address is cleared when the associated account is deleted or anonymized, while a feedback address stays with the feedback submission
Device linkingThe address a device-linking request came fromArt. 6(1)(b) performance of the contract and Art. 6(1)(f) legitimate interest in account securityKept with the device record; unlinking marks the device revoked, and the record and its address are deleted when the account is deleted
Security logsA partially masked address, the final part replaced, for example 203.0.113.xxx, written to the application log when a rate limit is hit, when an anti-abuse check fails, or when a message is sent through our public contact or feedback formsArt. 6(1)(f) legitimate interest in the security of the ServiceSecurity-log retention, up to 24 months

Because the consent record is the evidence of your own acceptance, erasing it would destroy the very proof that protects both sides; we therefore rely on Article 17(3)(b) and (e) and keep it after an erasure request, marked as withdrawn. The other three follow the retention stated in the table above. You can object to any processing based on legitimate interests under section 4.6.

5.4 Processing we do not carry out

  • No usage analytics. No usage analytics of any kind leave your device. There are no feature-usage counters, no session tracking, no plugin-usage beacons and no device-keyed or session-keyed event stream. The ingestion endpoint, the tables behind it and the associated administration dashboards have been removed.
  • No crash or error reports. None are transmitted. There is no crash-reporting SDK and no crash-reporting endpoint anywhere in the product. Diagnostic logs and crash dumps are written to a folder on your own device and are never uploaded. If you choose to attach them to a support request, that is your own deliberate act.
  • No analytics setting. There is no analytics opt-in, opt-out or toggle, because there is nothing to switch on or off.
  • No advertising or third-party tracking. We use no advertising, no advertising SDK and no advertising identifier, and we embed no third-party tracker. Our web front end loads no analytics script and no tag manager; apart from the anti-abuse widget that protects our forms, described in section 4 of our Cookie Policy, the only external host it contacts is Google Fonts.
  • No credentials. The contents of the credential vault, passwords, private keys and access tokens, never leave your device (see 5.1). Cross-device sync carries only non-sensitive application data and is guarded server-side against credential material.

6. International Data Transfers

When we transfer personal data outside the European Economic Area or the United Kingdom, we rely on a recognized transfer mechanism, including:

  • Standard Contractual Clauses adopted by the European Commission (and the UK International Data Transfer Addendum where applicable)
  • Adequacy decisions
  • Other appropriate safeguards permitted under Articles 46–49 of the GDPR

Where the legal landscape requires it, we apply supplementary measures (such as encryption and contractual commitments) and document our assessment.

7. Data Protection Measures

We implement technical and organizational measures appropriate to the risk, including:

  • Encryption of data in transit and at rest
  • Strict access controls based on the principle of least privilege
  • Regular security assessments and patch management
  • Confidentiality obligations and security training for staff
  • An incident-response and breach-notification process

8. Data Breach Notification

Where a personal-data breach is likely to result in a risk to your rights and freedoms, we will:

  • Notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it
  • Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms
  • Document the facts of the breach, its effects, and the remedial action taken

9. Supervisory Authority

You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. A list of supervisory authorities is published on the European Data Protection Board's website.

10. Self-Service Account Deletion

You can exercise your right to erasure (Article 17) directly from the application or by writing to contact@edgely.io. Two flows are offered:

  • Delete in 30 days (default), your account is suspended immediately and finalized after 30 days. A one-click cancel link is emailed to you and remains valid for the full 30-day window.
  • Delete immediately, same as above, but finalized in the same request, with no undo.

When deletion is finalized, we delete personal data that is no longer necessary and anonymize records that we are required by law (tax, accounting, audit) to keep for a longer period. This satisfies Article 17 in the cases listed in that Article. You can still email contact@edgely.io for a manual review or for any case not covered here.

11. Changes to This Policy

We may update this Policy from time to time. We will notify you of material changes by email or through the Service before they take effect.