Effective Date: August 21, 2026 (version 1.0)
This GDPR Data Processing Policy describes how Edgely processes personal data in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR.
This Policy complements our Privacy Policy and prevails in the event of conflict to the extent strictly required by the GDPR.
Edgely acts as the Data Controller for personal data collected through our Service. To exercise your rights or to ask any question covered by this Policy:
We process personal data on one or more of the following legal bases, depending on the activity:
You can withdraw consent at any time without affecting the lawfulness of prior processing.
Under the GDPR you have the following rights:
You can ask whether we process your personal data and obtain a copy of it.
You can ask us to correct inaccurate or incomplete data.
You can ask us to delete your personal data ("right to be forgotten") in the cases listed in Article 17.
You can ask us to restrict the processing of your personal data in certain cases (for example, while we verify a rectification request).
You can receive the personal data you provided to us in a structured, commonly-used and machine-readable format, and have it transmitted to another controller where technically feasible.
You can object at any time to processing based on legitimate interests, including profiling. You can object at any time, without justification, to processing for direct marketing.
You have the right not to be subject to a decision based solely on automated processing that produces legal effects on you or similarly significantly affects you. We do not currently make such decisions.
To exercise any of these rights, write to contact@edgely.io. We may need to verify your identity before answering. We respond within one month of receipt; that period may be extended by two further months for complex or numerous requests, and we will inform you of any such extension within the first month.
If we do not act on your request, we will tell you why and inform you of your right to lodge a complaint with a supervisory authority and to seek a judicial remedy.
| Purpose | Categories of Data | Legal Basis | Retention |
|---|---|---|---|
| Account management | Identity, contact, account credentials, device identifiers used for licence activation and device linking, and the IP address a device was linked from | Contract | Account lifetime + reasonable wind-down; the linking address is deleted with the device |
| Service provision | Session and authentication data, requests you make to the Service | Contract | Up to 2 years after the event |
| Billing | Identity, contact, payment data | Legal obligation | 7–10 years after invoice (tax/accounting) |
| Marketing | Contact, preferences | Consent | Until withdrawal |
| Distribution statistics | Download, version-check and plugin-install events. For a download: the country and the city resolved from the connection, the user agent, utm_source, utm_medium, utm_campaign and the referrer. For a version check: the country and the user agent. For a plugin install or update: the count alone. The IP address is used in memory only, to resolve that location, and is never stored with these records (see 5.2). | Legitimate interest | Kept as statistical records; they contain no IP address |
| Cross-device sync | Non-credential application data only (such as connection metadata, organization of entries, preferences). Excludes the contents of the credential vault, which never leave the user's device. | Contract | Account lifetime |
| Security & audit | Logs of authentication and security-relevant actions, including a partially masked IP address written on rate-limit hits, failed anti-abuse checks and public-form submissions | Legitimate interest / legal obligation | Up to 24 months |
| Consent records | The legal document accepted, its version, the date, and the IP address the acceptance came from | Legal obligation / legitimate interest | Kept as the evidentiary record, including after the account is deleted, where the consent is marked withdrawn |
| Anti-abuse on public forms | Contact-form and feedback submissions, and the IP address they were sent from | Legitimate interest | Kept with the submission; a contact-form address is cleared when the associated account is deleted or anonymized, while a feedback address stays with the feedback submission |
Because the contents of the credential vault, passwords, private keys, and access tokens, are stored exclusively on the user's device and are not accessible to Edgely, that material is out of scope for Article 15 (access), Article 17 (erasure) and Article 20 (portability) requests directed at Edgely: there is nothing for us to export, correct, or delete. Users export and delete this data through the application's own export and vault-management features.
The portal records a small number of events that it carries out itself. These are not reports sent by the applications about how they are used; they are records of the requests the portal served:
What we record is not the same for each:
utm_source, utm_medium, utm_campaign and the referrerThe IP address is used only, in memory, to resolve that location at the moment of the request, and is then discarded. It is never stored with these records, and it appears in no log and no backup of them. Section 5.3 sets out, separately and in full, the cases in which the portal does retain an IP address.
Device identifiers are processed for licence activation and to link your own devices to your account. That is an account function performed under the contract, not tracking.
The statement in 5.2 is confined to the distribution statistics. Outside them the portal does retain an IP address, for a small number of security, consent and account purposes. None of them is statistical and none feeds a profile:
| Purpose | What is stored | Legal basis | Retention |
|---|---|---|---|
| Proof of consent | The address from which you accepted a given version of a legal document, together with the document, its version and the date | Art. 6(1)(c) legal obligation (being able to demonstrate consent) and Art. 6(1)(f) legitimate interest (evidence of the agreement) | For as long as the acceptance may need to be proved; it survives account deletion, where the consent is marked as withdrawn rather than erased |
| Anti-abuse on the public contact and feedback forms | The address a submission was sent from | Art. 6(1)(f) legitimate interest in protecting the Service and its users from spam and abuse | Kept with the submission; a contact-form address is cleared when the associated account is deleted or anonymized, while a feedback address stays with the feedback submission |
| Device linking | The address a device-linking request came from | Art. 6(1)(b) performance of the contract and Art. 6(1)(f) legitimate interest in account security | Kept with the device record; unlinking marks the device revoked, and the record and its address are deleted when the account is deleted |
| Security logs | A partially masked address, the final part replaced, for example 203.0.113.xxx, written to the application log when a rate limit is hit, when an anti-abuse check fails, or when a message is sent through our public contact or feedback forms | Art. 6(1)(f) legitimate interest in the security of the Service | Security-log retention, up to 24 months |
Because the consent record is the evidence of your own acceptance, erasing it would destroy the very proof that protects both sides; we therefore rely on Article 17(3)(b) and (e) and keep it after an erasure request, marked as withdrawn. The other three follow the retention stated in the table above. You can object to any processing based on legitimate interests under section 4.6.
When we transfer personal data outside the European Economic Area or the United Kingdom, we rely on a recognized transfer mechanism, including:
Where the legal landscape requires it, we apply supplementary measures (such as encryption and contractual commitments) and document our assessment.
We implement technical and organizational measures appropriate to the risk, including:
Where a personal-data breach is likely to result in a risk to your rights and freedoms, we will:
You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. A list of supervisory authorities is published on the European Data Protection Board's website.
You can exercise your right to erasure (Article 17) directly from the application or by writing to contact@edgely.io. Two flows are offered:
When deletion is finalized, we delete personal data that is no longer necessary and anonymize records that we are required by law (tax, accounting, audit) to keep for a longer period. This satisfies Article 17 in the cases listed in that Article. You can still email contact@edgely.io for a manual review or for any case not covered here.
We may update this Policy from time to time. We will notify you of material changes by email or through the Service before they take effect.