Edgely

Privacy Policy

Version 1.0, effective August 21, 2026

Edgely is published and operated by SIGEAD SRL. This policy applies to the edgely.io website and to every Edgely application without a privacy policy of its own, including Edgely Console Mobile and Edgely Transfer Mobile.

1. Introduction

Edgely ("we", "us", "our") respects your privacy. This Privacy Policy explains what personal information we collect when you use our Service, how we use it, with whom we share it, how long we keep it, and the rights you have over it. By using the Service you confirm that you have read and understood this Policy.

If you do not agree with this Policy, please do not use the Service.

2. Information We Collect

We collect only the information we need to operate the Service. We group it in the categories below.

2.1 Information you provide

  • Identity and contact details (name, email address)
  • Account credentials
  • Billing information when you purchase a paid plan
  • Optional profile information (locale, time zone, organization)
  • Content you submit through support requests, feedback forms, and similar channels

2.2 Information generated by your use of the Service

  • Session information needed to authenticate you and keep you signed in
  • Account activity required to operate your subscription: licence activations, the devices you link to your account, and the history of your support requests

Our applications do not report on the way you use them. They send us no usage statistics and no diagnostic, error, or crash reports. Diagnostic logs and crash dumps are written to a folder on your own device and are never uploaded. See section 2.5.

2.3 Information the portal records when it serves a request

Our website and our distribution servers keep a record of the requests they serve. This applies in three situations: you download the software, an installed application checks whether a newer version is available, or you install or update a plugin. What is recorded is not the same for each:

  • a download, the event as a count, the country and the city resolved from the connection, the browser or client user agent, and the attribution carried by the link you followed: utm_source, utm_medium, utm_campaign, and the referring page
  • a version check, the event as a count, the country resolved from the connection, and the browser or client user agent
  • a plugin install or update, the event as a count, and nothing else

These records contain no IP address. Your IP address is used only in memory, at the moment of the request, to resolve the country, and, for a download, the city, and it is discarded immediately afterwards. It is never written to the download, version-check or plugin-install record, nor to any log or backup of those records, and it is never used to build a profile of you.

That promise is about these statistics. It is not a claim that the portal never handles an address at all: for a small number of security, consent, and account purposes it does keep one, and section 2.4 sets out exactly which, why, and for how long.

These records tell us how often our software is downloaded and updated, and roughly from where. They exist because our servers handled the request, not because an application reported on your activity, and they say nothing about the way you use the software.

We also process the device identifiers supplied when a licence is activated or when you link a device to your account. This is an account function. It lets you see and manage your own devices and lets us apply the limits of your licence, and it is not used to track you.

2.4 When we do keep an IP address

The promise above is about the distribution statistics, and we can make it because those records genuinely contain no address. Elsewhere, the portal does retain an IP address, in a small number of places, each for one specific security, consent, or account purpose, and never for statistics or marketing:

  • Proof of consent. When you accept a version of one of our legal documents, we store, alongside the document, its version and the date, the address the acceptance came from. It is the evidence that a given person accepted a given text on a given day. Legal basis: our legal obligation to be able to demonstrate consent, and our legitimate interest in holding evidence of the agreement (GDPR Art. 6(1)(c) and 6(1)(f)).
  • Anti-abuse on our public forms. The contact form and the feedback form are open to anyone, so we store the address a submission came from in order to apply rate limits and to investigate spam and abuse. Legal basis: our legitimate interest in protecting the Service and its users (Art. 6(1)(f)).
  • Device linking. When you link a device to your account, we store the address the linking request came from, so that you can recognize your own devices and so that we can react if one of them is linked from somewhere you did not expect. Legal basis: performance of the contract and our legitimate interest in the security of your account (Art. 6(1)(b) and 6(1)(f)).
  • Security logs. Our application log records a partially masked address, the final part is replaced, for example 203.0.113.xxx, when a request trips one of our rate limits, when an anti-abuse check on a sign-in, registration, contact or feedback request fails, and when a message is sent through our public contact or feedback forms, together with what happened. Legal basis: our legitimate interest in the security of the Service (Art. 6(1)(f)).

None of these addresses is used to build a profile of you, to measure how you use our software, or for marketing. Section 9 states how long each one is kept, and section 7 explains how to ask us what we hold.

2.5 Information we do NOT collect

No usage analytics. Our applications send us no feature-usage counters, no session tracking, no plugin-usage beacons, and no event stream keyed to a device or a session. There is no analytics ingestion endpoint, and no analytics database or dashboard on our side. Because there is nothing to collect, there is no analytics option to turn on or off.

No crash or error reports. None of our applications embeds a crash-reporting library, and our infrastructure exposes no crash-reporting endpoint. Diagnostic logs and crash dumps are written to a folder on your own device and are never transmitted. If you choose to attach one to a support request, that is your own deliberate act and you decide what to send.

No advertising and no third-party tracking. We use no advertising SDK, no advertising identifier, and no third-party tracker. Our website loads no analytics script and no tag manager; apart from the anti-abuse widget that protects our forms, described in section 5, the only external host it contacts is Google Fonts, which serves typefaces and is not used to measure your behaviour.

No credential-vault contents. We do not collect, store, or transmit the contents of your credential vault, the passwords, private keys, and access tokens you save inside the desktop application. They remain on your device under your sole control.

Our cross-device synchronization feature is limited to non-credential application data (such as connection metadata, the way you organize your entries, and your personal preferences). Credentials cannot be transferred between devices through the Service: our servers inspect every synchronized item and reject anything that looks like a credential. To move them yourself, the application offers an encrypted, password-protected export that you generate and import on your own.

3. How We Use Your Information

We use your information to:

  • Operate, secure, and maintain the Service
  • Authenticate users and prevent unauthorized access
  • Process payments and issue invoices
  • Communicate with you about your account, security, and material changes to the Service
  • Provide customer support
  • Detect, prevent, and respond to fraud, abuse, and security incidents
  • Comply with legal obligations
  • Measure how often our software is downloaded and updated, from the request records described in section 2.3
  • Send marketing communications, only with your prior consent and only until you withdraw it

We do not use your personal information to make automated decisions that produce legal or similarly significant effects on you.

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • Performance of a contract: to provide the Service you signed up for
  • Legitimate interests: to secure the Service, prevent fraud and abuse of our public forms, protect your account and the devices linked to it, and measure the distribution of our software as described in section 2.3
  • Legal obligation: to comply with tax, accounting, and other applicable laws, and to be able to demonstrate which version of a legal document you accepted and when
  • Consent: for marketing communications and any other processing that requires it

You can withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

5. Data Sharing

We share personal information only with the categories of recipients listed below, and only to the extent necessary:

  • Service providers acting on our instructions (hosting, payment processing, transactional email, customer support tooling, and the security provider whose anti-abuse widget checks that a request to our forms is not automated), bound by written confidentiality and data-processing terms
  • Professional advisers (lawyers, accountants, auditors), where required to obtain advice or comply with legal obligations
  • Authorities and other third parties, where required by law, court order, or to protect the rights, property, or safety of Edgely, our users, or the public
  • Successors in the event of a merger, acquisition, or sale of assets, subject to a confidentiality undertaking that is at least as protective as this Policy

We do not sell or rent personal information.

6. Data Security

We apply technical and organizational measures appropriate to the sensitivity of the data, including:

  • Encryption in transit and at rest
  • Access controls and the principle of least privilege
  • Regular security reviews and dependency monitoring
  • Confidentiality obligations on personnel and processors
  • An incident-response process that we test periodically

No system is perfectly secure. We will inform you and the competent authorities of a personal-data breach if and as required by applicable law.

7. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you
  • Rectify information that is inaccurate or incomplete
  • Erase your information ("right to be forgotten")
  • Restrict or object to certain processing
  • Receive your information in a portable format and have it transmitted to another controller
  • Withdraw consent at any time
  • Lodge a complaint with your data protection authority

To exercise any of these rights, write to contact@edgely.io. We respond within the timeframe required by applicable law (one month under the GDPR, extendable by two months for complex requests, with notice).

8. Cookies and Similar Technologies

We use a small number of cookies and similar technologies, strictly to keep you signed in and to remember your preferences. We set no analytics cookies and no advertising cookies, and our website loads no analytics script and no tag manager. See our Cookie Policy for the full list and your options.

9. Data Retention

We retain personal information for as long as your account is active and for the period needed to fulfil the purposes set out in this Policy. After that, we either delete it, anonymize it, or keep it in a restricted form when the law requires us to (typically tax and accounting records). Encrypted backups follow our standard retention cycle and are not selectively edited; personal data within a backup is removed when the backup itself ages out. The request records described in section 2.3 contain no IP address. The addresses we do retain, listed in section 2.4, each follow their own period: a consent record is kept for as long as we may need to prove the acceptance and survives the deletion of your account, where the consent is marked as withdrawn rather than erased; an address stored with a contact-form message is cleared when the associated account is deleted or anonymized, while an address stored with a feedback submission stays with that submission for as long as the submission is kept; the address recorded when a device is linked stays with that device record, unlinking marks the device revoked rather than erasing the record, and is deleted with it when your account is deleted; and the partially masked addresses in our security logs follow our security-log retention of up to 24 months.

10. International Transfers

Personal information may be processed in, or transferred to, countries other than the one where you live. When we transfer personal information outside the European Economic Area or the United Kingdom, we rely on a recognized transfer mechanism, such as Standard Contractual Clauses or an adequacy decision, and we apply additional safeguards where appropriate.

11. Children's Privacy

The Service is not directed to, and we do not knowingly collect personal information from, individuals under the age of 16. If you believe a minor has provided us with personal information, please contact contact@edgely.io and we will take appropriate steps to delete it.

12. Account Deletion

You may delete your Edgely account at any time, either from within the application or by writing to contact@edgely.io. Two options are offered:

  • Delete in 30 days (default), your account is suspended immediately and finalized after 30 days. You can cancel within that window with a single click using the link we email you.
  • Delete immediately, your account is suspended and finalized in the same request. There is no undo.

When deletion is finalized, we delete personal information that is no longer needed and anonymize the records we are required to keep for legal, accounting, or audit reasons. Your email address becomes available again for new registrations.

13. Changes to This Policy

We may update this Policy from time to time. We will notify you of material changes by email or through the Service before they take effect. The current version, with its effective date, is always available on our website.

14. Contact Us

For privacy questions or to exercise your rights: