Privacy policy
Last updated:
This policy explains how Cloud & Code Consulting handles personal data when you visit moduleaudit.com, run a guest audit, create an account, buy a plan or contact us. It also explains your rights under the General Data Protection Regulation (GDPR).
Who is responsible for your data
Cloud & Code Consulting is the data controller for the account, billing, security and service-administration activities described here. Our place of business is The Netherlands.
Cloud & Code Consulting · sole proprietorship
Pelikaanstraat 12, 2312 DW Leiden, The Netherlands
Chamber of Commerce (KvK): 77466950 · VAT/BTW: NL003196845B26
General enquiries: [email protected]
Privacy enquiries: [email protected]
The information we process
- Account and sign-in information. Your name and email address, profile image URL where provided, sign-in provider and account identifier, and authentication data such as provider-issued tokens and session information. Google, Microsoft or GitHub supplies this information when you choose an available sign-in option. We do not receive your password for that provider.
- Sites and audit results. Site names and URLs you submit, scan settings and schedules, report-recipient email addresses, detected packages and versions, advisory matches, technical evidence, audit timestamps, errors, generated summaries and report history. URLs, public assets, headers, source maps and evidence snippets can incidentally contain personal information.
- Guest access and abuse prevention. A hash of your random guest access token, guest expiry time, audited hostname and timestamps, and a salted one-way hash derived from your network address. The guest-limiting record stores the hash rather than the raw IP address; hosting and access logs may separately contain an IP address. A hash is pseudonymous information, not necessarily anonymous data.
- Payment and usage records. Stripe collects payment-card details, billing addresses and other financial information directly. Module Audit does not store full card details or billing addresses. We store Stripe customer, subscription and transaction references, subscription status and dates, token balances and token-use history to apply your purchases.
- Support and technical information. Messages and contact details you send us, and operational, access, error and security logs that may include IP addresses, request URLs, browser information and timestamps.
Data comes from you, your chosen sign-in provider, Stripe, the public websites you ask us to scan and the operation of the service. A report recipient’s email address may be supplied by the account holder who configured the report.
We do not ask for sensitive personal data or private website credentials. Please do not place secrets, access tokens or personal information in submitted URLs or names, and do not use the service to collect information about individuals. If a report contains personal data that should not be there, contact us for help removing it.
Why we use data and our legal bases
- Providing the service — contract, Article 6(1)(b) GDPR. We use account details, submitted sites, settings, audit results and payment references to authenticate you, run requested and scheduled audits, generate summaries, deliver reports and manage your purchases and support requests.
- Operating and protecting the service — legitimate interests, Article 6(1)(f). We use technical information, usage records and guest limits to prevent misuse, investigate faults, secure the service and understand its operation. Our interests are running a reliable service and protecting users and our business. We also rely on these interests to administer business-customer accounts, communicate with their representatives and deliver reports to recipients they nominate, where those individuals are not themselves party to our contract.
- Meeting legal duties — legal obligation, Article 6(1)(c). We retain required accounting records and respond to valid legal requests.
- Optional processing — consent, Article 6(1)(a), where required. If we introduce optional marketing or tracking that requires consent, we will ask first. You can withdraw that consent without affecting earlier lawful processing.
We need an email address and sign-in information to provide an account, a URL to run an audit, and payment confirmation to provide purchased services. You can choose whether to add report recipients or contact support. Without the necessary data we may be unable to provide the corresponding feature.
Report emails and account or billing notifications are service communications. You can manage audit emails and recipients in your site settings. We do not currently send marketing newsletters or sell personal data.
Providers and other recipients
- Contabo — hosting. Our production app and database run on servers in Europe. Our backups are also stored in Europe. Hosting involves processing the application data and technical logs described above.
- Hetzner — AI processing in Germany. To generate an audit summary, we send the site name and URL, detected packages and versions, vulnerability findings, scan coverage, selected technical evidence and changes from previous audits. The summary is saved with your report. Account profile data and payment details are not included as dedicated fields in the summary request, but submitted names, URLs and technical evidence can themselves contain personal information.
- Stripe — payments and billing. Stripe receives your name, email and account reference from us and collects financial and billing information directly at checkout. It returns the references and status information needed to manage your purchases. Stripe also processes information for its own payment, fraud-prevention and legal purposes; see Stripe’s privacy policy.
- Plunk — service email delivery. Plunk receives recipient addresses and email content, including report summaries and links, to deliver the messages configured for your account.
- Google, Microsoft and GitHub — sign-in. The provider you select exchanges the identity and authentication information needed to sign you in. That provider’s own privacy policy governs its separate processing.
- Software registries, advisory databases and CDNs. Services such as the npm registry, GitHub Advisory Database and jsDelivr receive technical lookups such as package names, versions, file hashes or public asset references used to identify dependencies and retrieve advisories.
- Your chosen recipients. People whose addresses you add receive the configured report emails. You control whether to share downloaded reports. Target websites and their infrastructure also receive the requests necessary for a scan.
Access is limited to what is needed for the relevant purpose. We may also disclose necessary information to professional advisers, authorities where legally required, or a successor in a business transfer, subject to applicable privacy safeguards.
Where processing takes place
The app, database and backups are hosted in Europe, and AI processing takes place in Germany. This does not mean every third-party activity stays in Europe: payment, sign-in, email and technical-lookup providers may process data in other countries.
Transfers of personal data outside the European Economic Area must be covered by a lawful transfer mechanism, such as an applicable European Commission adequacy decision or Standard Contractual Clauses with any necessary additional safeguards. Contact [email protected] for information about the safeguards applicable to your data and how to obtain a copy.
Cookies and browser storage
Our cookies are used for authentication and sign-in security. The authenticated session has a maximum age of 30 days and can be renewed when you use the service. Temporary cookies support the sign-in process.
Separately, browser local storage keeps your guest access token under moduleaudit.guest and your selected pricing currency under moduleaudit:currency. Local storage has no automatic browser expiry. The server stops accepting a guest token when the guest expires; the browser copy can remain until cleared or removed when the guest is claimed.
We do not use advertising or analytics cookies on Module Audit. Stripe and sign-in providers may use their own cookies on their payment or sign-in pages. You can remove cookies and local storage through your browser settings; this can sign you out, reset your currency choice or prevent you from returning to guest reports. Clearing browser storage does not itself delete server-side records.
How long we keep information
- Accounts and associated data: kept while your account is open. Deleting your account removes its active database records, including sign-in records, sites, audits and token history. Residual account-related data in our backups is removed within one week after deletion, subject to the separate legal and security retention described below.
- Audit history: accounts without a subscription keep 14 days of history; Inspect: 30 days; Monitor: 60 days; Oversee: 90 days. Older completed audits are removed in daily cleanup. The newest successful audit for each retained site is kept for comparison even if it falls outside that window; queued and running audits are retained until processing ends. Deleting the site or account removes its audits.
- Unclaimed guest accounts: expire after 7 days and are removed with their sites and reports by the next hourly cleanup. If you sign in and claim the guest before expiry, the claimed data follows your account’s retention rules.
- Guest anti-abuse records: hashed network identifiers, hostnames and grant timestamps are kept for 30 days, then removed in hourly cleanup. These records can outlive the guest account.
- Server and access logs: retained for a maximum of 30 days.
- Backups: retained for one week in Europe. Deleted data may remain in an existing backup until it expires within that period.
- Support messages: deleted when the issue is closed.
- Accounting and legal records: records required for Dutch tax and accounting obligations are generally kept for seven years, or longer where a specific legal duty applies. Financial records held by Stripe follow its applicable legal retention requirements. Account deletion does not erase records that must legally be retained. Information needed for a legal claim or preservation order may be retained for that specific purpose for as long as necessary.
Security and automated processing
We use measures such as authenticated access, report-ownership checks, hashed guest tokens and usage limits to protect information. No online service can guarantee absolute security. Keep your sign-in credentials and guest token private, and choose report recipients carefully.
AI summaries analyse technical audit findings; they are not used to make decisions about people with legal or similarly significant effects. Automatic guest-abuse limits may temporarily restrict access to free audits. You can contact us for a human review if you believe a limit was applied incorrectly.
Your privacy rights
Subject to the conditions in the GDPR, you may request access to your personal data, correction, deletion, restriction of processing, or a portable copy of data you provided where processing is based on consent or contract and carried out automatically. You may object to processing based on legitimate interests and withdraw consent for any processing that relies on it. Withdrawal does not affect processing that was lawful before you withdrew.
You can update your name and delete your account in Account, and manage or delete sites in the dashboard. For other requests, or if you are a report recipient or a person mentioned in scan evidence, email [email protected]. Identify the account, report or correspondence concerned without sending unnecessary sensitive information. We may ask for proportionate proof of identity.
We normally respond free of charge within one month. Where legally permitted because of complexity or the number of requests, we may extend this by up to two further months; we will explain this within the first month.
You may complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or to a supervisory authority where you live, work or believe an infringement occurred. You do not need to contact us before making a complaint.
Children
Module Audit is intended for adults and is not directed at children under 18. If you believe a child has supplied personal data, contact us so we can investigate and remove it where appropriate.
Changes and contact
We will update this page and its date when our practices change. We will bring material changes to affected users’ attention and obtain consent where required before introducing new optional processing.
For privacy questions or requests, contact [email protected] or write to Cloud & Code Consulting at the address above. For general service questions, use [email protected].