TrustData legal

Privacy notice

TrustData is designed to collect the minimum information needed to operate visitor accounts and assess participating SaaS data practices.

Effective 15 July 2026

Catalogue and visitor accounts

Anyone may browse the participating-company catalogue and current public control matrix. A free visitor account is required to read detailed TrustData conclusions, history, and recommendations. We process the visitor’s name, email address, authentication records, and essential security metadata for account access; marketing consent is separate and optional.

Founder accounts

We process account identity, organization membership, billing status, scope declarations, evidence, findings, verification state, and publication state to provide the service and protect tenant boundaries. Founder declarations are stored separately and never treated as badge evidence.

Repository and provider evidence

TrustData is designed to collect configuration metadata and redacted evidence rather than customer content. Temporary repository workspaces are deleted after scanning.

  • No persistent GitHub installation tokens
  • No environment variable values
  • No complete repository retention
  • No training on submitted customer code

Retention and deletion

Evidence retention is kept short and tied to assessment needs. Visitors and organization administrators may request account export or deletion, subject to security, audit, and legal retention obligations.

Contact

Privacy questions and rights requests may be sent to privacy@trustdata.example. Production deployments must replace this example address with the configured TrustData privacy contact.