# Runtrace Privacy Notice

## Scope
This notice explains how Runtrace processes account, device, security, support, and billing metadata when organizations evaluate or use the service. For customer device data, the customer determines which devices are enrolled and acts as controller. Runtrace acts as processor under the Data Processing Addendum.

## Data we process
- Account data, including organization name, administrator name, work email, role, session information, and authentication identifiers.
- Device data, including device identifier, device name, operating system context, agent version, owner or team labels, criticality, and check-in timestamps.
- Software inventory, including package, tool, binary, ecosystem, installed version, safe source location, signing state, and package-manager origin where available.
- Vulnerability and workflow data, including advisory identifiers, severity, CVSS, affected version, fixed version, evidence summary, status, owner, notes, and allowlist decisions.
- Operational data, including remote scan profile and status, package-bound pilot and lifecycle acceptance records, audit events, reports, support requests, service diagnostics, and billing identifiers.
- Public website analytics, limited to pages viewed, referrer, coarse browser and device context, and interactions with public links. Runtrace does not send account, device inventory, vulnerability, scan, or form-field data to website analytics.

## Data we do not collect
Runtrace does not upload source code, document contents, secret values, private-key contents, shell history, terminal output, screenshots, clipboard contents, or arbitrary command output. Dependency files are parsed on the device and only the metadata needed for inventory and vulnerability matching is sent.

## Why we process data
We process data to provide software inventory and vulnerability management, authenticate users and devices, prioritize and track remediation, produce reports, provide support, secure and monitor the service, process billing, and meet legal obligations.

For account and prospect data, processing is based on steps requested before a contract, performance of a contract, legitimate interests in operating and securing a business service, consent where required, and legal obligations. Customer device data is processed on the customer's documented instructions.

## Sharing and subprocessors
Runtrace shares data only with service providers needed to host, authenticate, support, and bill for the service, or when required by law. Public-site analytics is processed in a self-hosted OpenPanel instance operated with Runtrace infrastructure and is not configured to record visitor sessions. The current provider list and processing purposes are published on the Subprocessors page. Runtrace does not sell customer data.

## Retention and deletion
Operational customer data is retained while the account is active and for the periods described in the Retention Policy. Authorized administrators can export organization data. Following termination, Runtrace deletes or returns customer data according to the applicable order form, legal obligations, and backup lifecycle.

## Your choices and rights
Administrators can manage devices, policies, finding status, allowlists, reports, exports, and account deletion through the product. Individuals may request access, correction, deletion, restriction, or portability where applicable by contacting Runtrace. Requests concerning an employer-managed device may be referred to the customer organization as controller.

## Contact
Privacy and data-protection questions may be sent to sales@runtrace.co.
