You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<pclass="lead text-left"><ahref="/">Dekart Cloud</a> is designed to make your cybersecurity and legal teams happy. We achieve it by never storing tokens, and query results in Dekart Cloud backend.</p>
14
+
15
+
<!-- * **Passthrough Authentication**: Short-lived Google OAuth token is passed from your browser to Google APIs and never stored on Dekart Cloud backend.
16
+
17
+
* **No User Data Storage**: Query results are stored on Google Cloud Storage bucket provided by you.
18
+
19
+
* **Compliance Friendly**: We comply with [Google API Services User Data Policy](https://cloud.google.com/terms/services) and verified by Google's Trust & Safety team. -->
20
+
21
+
### What permissions am I granting to Dekart, and why are they necessary?
22
+
23
+
You are granting Dekart the following scopes:
24
+
*`https://www.googleapis.com/auth/bigquery` this scope grants Dekart the ability to manage user data in Google BigQuery, encompassing actions like running queries, managing datasets, and configuring settings.
25
+
*`https://www.googleapis.com/auth/devstorage.read_write` this scope allows Dekart to read and write user data in Google Cloud Storage, enabling it to manage files and potentially other data storage elements.
26
+
27
+
These permissions are necessary for Dekart to run queries and store results in your Google Cloud Storage bucket.
28
+
29
+
### How will my data be used and protected?
30
+
31
+
SQL queries and their results are stored in Google Cloud Storage bucket *provided by you!* We never store tokens, and query results in Dekart Cloud backend. Nobody at Dekart can access your BigQuery data or Google Cloud Storage bucket.
32
+
33
+
### Can I revoke Dekart's access if I change my mind?
34
+
35
+
Yes, you can revoke Dekart's access to your Google Cloud resources by signing out of Dekart Cloud. This will remove Dekart's access to your Google Cloud resources and prevent Dekart from running queries or storing results in your Google Cloud Storage bucket.
36
+
37
+
### Does Dekart comply with data protection regulations?
38
+
39
+
We are committed to upholding the principles of GDPR and ensuring that your data rights are respected. We also comply with [Google API Services User Data Policy](https://cloud.google.com/terms/services) and verified by Google's Trust & Safety team.
40
+
41
+
### What support is available if I have issues or questions about data access?
42
+
43
+
If you have any questions or issues about data access, please contact us via email at [[email protected]](mailto:[email protected]) or via [Slack](https://slack.dekart.xyz/).
Copy file name to clipboardExpand all lines: content/legal/privacy.md
+30-32
Original file line number
Diff line number
Diff line change
@@ -9,27 +9,42 @@ images: []
9
9
10
10
# Dekart Cloud Privacy Policy
11
11
12
-
Effective Date: 2024-02-21
12
+
Effective Date: 2024-03-10
13
13
14
-
Welcome to Dekart Cloud. This Privacy Policy describes how Dekart XYZ UG (haftungsbeschränkt) ("Dekart Cloud," "we," "us," or "our") collects, uses, and shares information about you through our digital platforms and services. By accessing or using our services, you agree to the collection and use of information in accordance with this policy.
14
+
This Privacy Policy outlines how Dekart XYZ UG (haftungsbeschränkt) (“Dekart Cloud,” “we,” “us,” or “our”) manages your data in compliance with the General Data Protection Regulation (GDPR) and other relevant laws. By accessing or using our services, you acknowledge that you have read this policy and understand your rights.
15
15
16
16
17
-
## Compliance with Google API Services User Data Policy
17
+
## Information We Collect and Process
18
18
19
-
Our application's use and transfer to any other application of information received from Google APIs comply with the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy#additional_requirements_for_specific_api_scopes), including the Limited Use requirements. We ensure that the handling of data received through Google APIs is done with the utmost care and respect for your privacy and data security.
19
+
Personal Information: We collect your email address solely for authorization, communication, and service delivery purposes. The lawful basis for processing this data is to fulfill our contractual obligations to you.
20
+
Metadata: We gather metadata such as report names, data warehouse usage, and map configurations to enhance our services. This data is processed on the basis of legitimate interests in improving and personalizing our offerings.
21
+
22
+
Nobody at Dekart Cloud has access to your data and results of your queries.
20
23
21
-
## Information We Collect
24
+
Payment Information: Payments are processed by our third-party provider, Stripe. We do not store payment details.
25
+
Your Data Protection Rights
22
26
23
-
Personal Information: We collect your email address for authorization purposes and to communicate with you. We also collect metadata about the reports, data warehouse jobs (like id, bites processed), and map configurations and report names you create, including the names of the data warehouses used and bucket names. We do not store SQL queries, data caches, or access tokens.
27
+
You have the right to access, rectify, erase, and port your data, and to restrict or object to its processing. You can withdraw consent at any time, where applicable. To exercise these rights, please contact us at [email protected].
24
28
25
-
Nobody at Dekart Cloud has access to your data or warehouse credentials.
29
+
### Compliance with Google API Services User Data Policy
26
30
27
-
Payment Information: Payment processing is handled by our third-party service provider, Stripe. We do not store your payment data.
31
+
Our application's use and transfer to any other application of information received from Google APIs comply with the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy#additional_requirements_for_specific_api_scopes), including the Limited Use requirements. We ensure that the handling of data received through Google APIs is done with the utmost care and respect for your privacy and data security.
28
32
29
-
## How We Collect Information
33
+
###How We Collect Information
30
34
31
35
We collect information directly from you when you sign up via Google OAuth and when you use our services. Metadata is automatically generated by our backend systems hosted on Google Cloud and stored in a Cloud SQL database.
32
36
37
+
38
+
## Security Measures
39
+
40
+
We employ robust security practices to protect your data, including encryption and restricted access. We commit to notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
41
+
42
+
Our infrastructure implements state-of-the-art security practices, including network security, credential storage, and two-factor authentication for data access.
43
+
44
+
## Data Sharing and Transfers
45
+
46
+
Your data is hosted within the EU and is not transferred internationally without adequate protections. We use third-party services that comply with GDPR and provide necessary safeguards.
47
+
33
48
## Use of Your Information
34
49
35
50
Your information is used to provide our services, communicate with you, and for marketing purposes. We strive to improve our offerings based on the data we collect.
@@ -38,40 +53,23 @@ Your information is used to provide our services, communicate with you, and for
38
53
39
54
Access to your information is limited to Dekart XYZ shareholders. We may share your information with third parties in compliance with legal obligations or to provide you with our services.
40
55
41
-
## Protection of Your Information
56
+
## Retention of Data
42
57
43
-
We prioritize the security of your data. Our infrastructure on Google Cloud implements state-of-the-art security practices, including network security, credential storage, and two-factor authentication for data access.
44
-
45
-
## Your Rights
46
-
47
-
You have the right to access, correct, or request the deletion of your personal data. To exercise these rights, please contact us at [email protected]. We adhere to standard GDPR rights regarding personal data.
58
+
Data is kept for as long as necessary to provide our services, and is securely deleted after one year of inactivity or upon your request, whichever comes first.
48
59
49
60
## Cookies and Tracking Technologies
50
61
51
62
Dekart Cloud does not use cookies or similar tracking technologies.
52
63
53
-
## Data Retention
54
-
55
-
Your information is retained for as long as necessary to provide our services. After the termination of services, data is deleted after one year or upon your request.
56
-
57
64
## Changes to This Privacy Policy
58
65
59
66
We reserve the right to update our Privacy Policy. Updates will be published on our website at this URL.
Dekart Cloud complies with international data protection laws, including GDPR and CCPA, as applicable to our operations as a Germany-based company.
68
-
69
-
## International Data Transfer
68
+
## Commitment to Compliance
70
69
71
-
Data is hosted in the EU/Frankfurt. We use third-party services like Mailchimp, Gmail, and Slack for communication, ensuring compliance with international data protection standards.
70
+
We are committed to upholding the principles of GDPR and ensuring that your data rights are respected.
72
71
73
-
## Third-Party Services
72
+
## Contact Us
74
73
75
-
We integrate services such as Plausible Analytics and Google OAuth, which adhere to privacy standards affecting user data.
74
+
For any questions about this policy or our privacy practices, contact our Data Protection Officer at [email protected].
76
75
77
-
This Privacy Policy provides a comprehensive overview of our data practices. For more detailed information or if you have questions, please contact us directly.
0 commit comments