The Short Version: CertifyClouds stores application data in your Azure environment. Our services do not receive your secrets, credentials, scan results, or audit logs; they receive license validation and bounded aggregate fleet-health counters. Optional integrations transmit selected data only to destinations your administrator configures.
Data controller: CertifyClouds is operated by CertifyClouds Ltd, registered in Scotland (company number SC892952), registered office 120 Kings Park Road, Glasgow G44 4SX, which is the data controller for the information described in this policy. To contact us about this policy or your data, email privacy@certifyclouds.com.
Enterprise agreements: If you have entered into a separate written agreement with us, such as an enterprise Master Services Agreement or Data Processing Agreement, the data controller and terms identified in that agreement govern that engagement and take precedence over this policy to the extent of any conflict.
1. Information We DO NOT Collect
CertifyClouds is designed with privacy in mind. We do NOT receive or have access to:
- Your Azure Key Vault secret values
- Your Azure credentials or tokens
- Individual secret, certificate, or key names
- Per-asset compliance scan results or violation detail
- Your audit log entries
- Any Azure resource metadata (tags, identifiers, etc.)
CertifyClouds application data is stored inside your environment in your managed database. We have no administrative access to it. Optional customer-configured integrations can transmit selected data directly to destinations your administrator approves.
Section 2 below describes the limited information our license server does receive (license key + version + optional aggregate operational counts) and how to disable each.
2. Information We DO Collect
License Validation
When CertifyClouds validates your license, we receive:
| Data | Purpose | Retention |
|---|---|---|
| Licence key | Verify valid licence | Duration of licence + 1 year (see §8) |
| Timestamp | Record first activation and the hourly heartbeat | Activation record kept for the life of the licence; heartbeat data expires after 30 days of inactivity |
| Client IP address, stored only as a SHA-256 hash | Detect licence-key sharing and abuse. The hash cannot be read back as an IP address | Same as the activation and heartbeat records above |
These records are held in a Cloudflare D1 database created with EU jurisdiction, which keeps the stored data inside the EU. See §4 and §9.
Optional: Update Checks
If update checking is enabled, we receive:
| Data | Purpose | Retention |
|---|---|---|
| Current version | Determine if update available | Not stored |
Update checks can be disabled by removing network access to license.certifyclouds.com.
Scanner CLI Registration
The standalone CertifyClouds scanner CLI asks for an email address and company name on first run, so we can issue it a scanner key. We receive:
| Data | Purpose | Retention |
|---|---|---|
| Email address and company name | Issue and support your scanner key | For as long as the scanner key is active |
| Client IP address, stored only as a SHA-256 hash | Detect scanner-key sharing and abuse | Heartbeat data expires after 30 days of inactivity |
Microsoft Marketplace Enquiries
If you request CertifyClouds through the Microsoft Azure Marketplace, Microsoft passes us the contact details you gave them so we can follow up:
| Data | Purpose | Retention |
|---|---|---|
| Name, email address, phone number, job title, company and country supplied to Microsoft | Respond to your enquiry | 12 months |
Optional: Fleet Visibility (Aggregate Operational Counts)
When the ENABLE_FLEET_VISIBILITY setting is enabled (default on), the hourly license-validate heartbeat also carries aggregate operational counts alongside the license key + version. This helps us understand fleet health and identify customers who may need onboarding support.
What we receive: aggregate integer counts only. No asset names, no PII, no per-asset detail. Examples:
- Total vault / secret / certificate / key counts in your tenant
- Scans run in the last 30 days
- Rotation success rate (e.g. 47 succeeded / 50 attempted)
- Feature adoption counts (number of sync targets configured, alert rules count, SSO state on/off, etc.)
What we do NOT receive: Any individual secret / certificate / key names. Any vault names. Any compliance findings. Any audit log content. Any customer data.
Defensive limits: The license-server worker rejects payloads that are not a plain object or whose serialised JSON exceeds 4 KB. A malicious or outdated client cannot poison our licence-server database with surprise shapes or unbounded payloads.
Opt out: Advanced Settings → App Behaviour → Enable Fleet Visibility → off. Toggle takes effect on the next heartbeat. License validation continues to work normally without the stats payload.
| Data | Purpose | Retention |
|---|---|---|
| Aggregate operational counts | Customer-success outreach, fleet-health monitoring | Last-known value per license (overwritten each heartbeat) |
Optional: Hosted AI Clients Through MCP
The ENTERPRISE MCP Connector is disabled by default. If your administrator enables it and an authorized user invokes a read-only tool, CertifyClouds sends that result over TLS directly to the selected hosted AI provider.
CertifyClouds-operated services do not receive MCP results. The selected provider processes them under your agreement and settings with that provider. The MCP connector does not return bearer tokens, secret values, private keys, certificate material, or value-shaped hints. Disable the connector in Settings → MCP Connector to close this data path.
Optional: Transactional Email
When you contact us through the website contact form, or when CertifyClouds (deployed in your environment) sends operational emails such as licence-expiry warnings to the address you registered, those emails are delivered via SMTP2GO as a sub-processor. SMTP2GO is GDPR-compliant; their privacy policy is at smtp2go.com/privacy-policy.
3. How We Use Information
We use the limited information we collect to:
- Validate your license is active and not expired
- Prevent license key sharing or abuse
- Provide version update notifications
- Improve our service (aggregate, anonymized usage)
We do NOT use your information to:
- Sell to third parties
- Send marketing communications (unless you opt in)
- Profile your Azure environment
- Track your secret management practices
4. Data Storage and Security
License Server
Our license validation server (license.certifyclouds.com) is:
- Hosted on Cloudflare's global edge network
- Protected by DDoS mitigation
- Encrypted in transit (TLS 1.3)
- Backed by a Cloudflare D1 database created with EU jurisdiction, so the customer records it holds — licence records, activation and heartbeat telemetry, scanner registrations and Marketplace enquiries — are stored in the EU
- Minimal log retention: Cloudflare keeps request logs for 3 days on the plan we use, and those log lines contain no email addresses and no full licence keys
Client IP addresses are never stored in readable form. They are turned into a SHA-256 hash before anything is written down, and only the hash is kept.
Cloudflare Workers KV, a separate store with no EU residency guarantee, holds only software version pointers and two internal digest flags. It holds no personal data.
Your Environment
All CertifyClouds application data is stored in your environment:
- Your managed database (you control)
- Log files (you control)
We have no administrative access to your environment or stored application data.
5. Data Sharing
We do not sell or rent your information. We share data only with the sub-processors below, and only as needed for the service to function:
| Sub-processor | Purpose | Processing location | Privacy policy |
|---|---|---|---|
| Cloudflare | Hosting and DDoS protection for the licence server; D1 database storage for licence-server records; Workers Logs (request logs); Turnstile anti-spam checks on website forms; Pages hosting for the marketing site and the documentation site | D1 storage in the EU. Worker execution at the data centre nearest the caller. Workers Logs in the United States | cloudflare.com/privacypolicy |
| SMTP2GO | Transactional email delivery (contact-form replies, licence-expiry notices, and our own internal activation, lead and status alerts) | Global | smtp2go.com/privacy-policy |
| Microsoft | Delivers the contact details of Azure Marketplace enquiries to us | Global (Microsoft Azure) | privacy.microsoft.com/privacystatement |
| Reddit, Inc. | Advertising-pixel attribution for paid social campaigns (when active; see §6) | Global (United States) | reddit.com/policies/privacy-policy |
| Google (YouTube) | Hosts the product demo video on the home page. The player only loads after you press play (privacy-enhanced youtube-nocookie.com embed); nothing is requested from Google until then | Global | policies.google.com/privacy |
We may additionally disclose data:
- Legal requirements: if required by law, subpoena, or legal process
- Business transfer: in connection with a merger or acquisition, with prior notice
6. Website Cookies, Analytics, and Visitor Identification
Important: This section applies only to our marketing website (certifyclouds.com). The CertifyClouds application deployed in your Azure environment contains no third-party tracking scripts.
Cookies set by the marketing site
| Cookie | Set by | Purpose | Category |
|---|---|---|---|
__cf_bm | Cloudflare | Bot management; distinguishes humans from bots | Strictly necessary |
cf_chl_* | Cloudflare Turnstile | CAPTCHA challenge on form submissions (contact / trial signup) | Strictly necessary |
zaraz-consent | certifyclouds.com | Records your cookie preference choice | Strictly necessary |
_rdt_uuid + Reddit advertising pixel | Reddit, Inc. | Attribution for paid social campaigns; set only during periods when a paid campaign is active (see below) | Marketing |
_gcl_* + Google Ads tag | Google Ireland Ltd | Attribution for paid search campaigns; set only after you press OK on the cookie banner (see below) | Marketing |
The strictly-necessary cookies above are required for site security and consent persistence. The Reddit advertising pixel loads by default during periods when a paid social campaign is active; see the lawful basis and opt-out options below.
Reddit advertising pixel
When a paid Reddit campaign is active, we load the Reddit advertising pixel on the marketing site to measure ad-attribution and reach (for example, how many of our Reddit ad clicks land on the scanner or trial signup pages). The pixel sends Reddit:
- Pages visited on certifyclouds.com
- Standard events such as page-view and form-submit
- The browser-set first-party identifier (
_rdt_uuidcookie) so Reddit can de-duplicate views by browser
Lawful basis: legitimate interests — measuring the performance of our own advertising campaigns. The pixel loads by default while a paid campaign is active, and is not loaded at all outside an active paid campaign.
Reddit's privacy policy is at reddit.com/policies/privacy-policy.
Google Ads conversion tag
When a paid Google Ads campaign is active, we load Google's conversion tag (gtag.js) on the marketing site to measure whether a trial request followed a click on one of our search ads. It uses Google Consent Mode:
- Until you press OK on the cookie banner, no advertising cookies are set and Google receives only cookieless, aggregate signals that cannot be tied to you
- After you press OK, Google may set the
_gcl_*cookies so a trial request can be attributed to the ad click that led to it
Lawful basis: consent — given by pressing OK on the cookie banner. Your choice is stored for one year in the zaraz-consent cookie.
Google's privacy policy is at policies.google.com/privacy.
Opting out
You can opt out of marketing-pixel tracking by:
- Enabling Global Privacy Control or equivalent tracking-protection settings in your browser
- Using a browser privacy extension that blocks third-party scripts
- Adjusting your Reddit ad personalisation settings at reddit.com/settings/privacy
- Not pressing OK on the cookie banner (Google Ads cookies are never set without it), or adjusting your Google ad settings at adssettings.google.com
- Contacting privacy@certifyclouds.com to request removal from our marketing lists
Note: Analytics and advertising-pixel tracking apply only to our marketing website, not to the CertifyClouds application deployed in your environment.
7. Your Rights (GDPR/UK GDPR)
Depending on your jurisdiction, you may have rights to:
- Access: Know what data we have about you
- Correction: Fix inaccurate data
- Deletion: Request deletion of your data
- Portability: Receive your data in portable format
- Objection: Object to certain processing
To exercise these rights, contact: privacy@certifyclouds.com
8. Data Retention
| Data Type | Retention Period |
|---|---|
| Licence records | Duration of licence + 1 year |
| Activation and heartbeat telemetry (with hashed IP addresses) | Activation record for the life of the licence; heartbeat data expires after 30 days of inactivity |
| Scanner CLI registrations (email, company) | As long as the scanner key is active |
| Microsoft Marketplace enquiries | 12 months |
| Request logs (Cloudflare Workers Logs) | 3 days |
| Support communications | 2 years |
| Legal/compliance records | As required by law |
9. International Transfers
Stored customer data stays in the EU. The licence server's D1 database is created with EU jurisdiction, so licence records, activation and heartbeat telemetry, scanner registrations and Marketplace enquiries are held there.
Two parts of the service do process request metadata outside the UK and EU:
- Worker execution: the licence server runs at whichever Cloudflare data centre is nearest the caller. For our customers that is normally in the UK or EU, but it is not guaranteed.
- Request logs: Cloudflare Workers Logs are stored in Cloudflare's core data centres in the United States, and kept for 3 days. Those log lines carry no email addresses and no full licence keys.
Both are covered by Cloudflare's standard contractual clauses and UK addendum, which are the safeguards we rely on for these transfers.
10. Children's Privacy
CertifyClouds is a business software product. We do not knowingly collect information from children under 16. If you believe a child has provided information to us, contact privacy@certifyclouds.com.
11. Changes to This Policy
We may update this Privacy Policy periodically. The current version is always published at certifyclouds.com/privacy. The "Last Updated" date at the top of this page reflects the most recent revision; continued use of the site or service after a revision constitutes acceptance.
12. Contact Us
For privacy questions or concerns:
- Email: privacy@certifyclouds.com
- Website: https://certifyclouds.com
Summary
| Question | Answer |
|---|---|
| Do you see my secrets? | No |
| Do you store my Azure data? | No |
| What do you collect? | Licence key and validation timestamp, plus a hashed IP address. Also your email and company if you register the scanner CLI or enquire through the Microsoft Marketplace |
| Can I use this offline? | Yes, with cached license for a configurable grace period |
| Who has access to my scans? | Only you |
By using CertifyClouds, you acknowledge that you have read and understood this Privacy Policy.