Privacy
Who we are
The controller for your personal data is datadir s.r.o. ("we"), the company behind temnir. Contact us at hello@temnir.com for any privacy matter.
What we collect
When you request a free scan we collect the company domain and work email you enter. When you email us, we receive your email address and message. Our servers keep standard technical logs (such as IP address and request time). We also collect basic browser telemetry (the page address with any tokens removed, browser type, error reports and page-speed measurements) on our own EU servers to find and fix problems, and we honour your browser's Do-Not-Track setting; we keep it for 30 days.
Why we use it
We use your domain and email to run the passive scan you requested, to email you the results, and to reply to your inquiries. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Our servers keep technical logs to operate and secure the site, on the basis of our legitimate interest (Art. 6(1)(f) GDPR).
Where it lives
We build and host in the EU. Our processors are Hetzner Online GmbH (Germany, servers), BunnyWay d.o.o. (Slovenia, content delivery) and Scaleway SAS (France, transactional email). All three are EU companies subject to EU law, so no provider under US jurisdiction processes your data, and we do not transfer it outside the EU. We will tell you here before we add or change a processor.
Sending your findings to your tools
This policy covers temnir.com, the grimoire reference graph and the temnir dashboard. Inside the product, module ward can turn a finding into a task or alert in the tools your team already uses. When you connect an integration such as Jira, GitHub, Slack or Microsoft Teams, we send the remediation details to the provider you chose, and only to the providers you have connected. You decide which tools receive data and can disconnect any of them at any time. Some of those providers sit outside the EU; where you connect one, that transfer is your choice, and your use of it is governed by your own agreement with that provider. We send only what is needed to open and track the item.
How we measure our sites
On grimoire, our public threat-knowledge graph, we measure how the site is used, in aggregate: which pages are viewed, how many distinct visitors we have, browser and operating-system family, the country your network reports, and the search terms people enter (counted together, never tied to a person). To count distinct visitors we turn your IP address and browser into a short one-way code using a secret we generate fresh and discard every day, so the code cannot be traced back to you or linked across days, and your IP address itself is never stored. We use no cookies, place nothing on your device and read nothing stored on it, do not fingerprint your device, and do not collect your screen size. We honour your browser's Do-Not-Track and Global Privacy Control signals; if either is set, we measure nothing for your visit. The legal basis is our legitimate interest in measuring our own audience (Art. 6(1)(f) GDPR); because nothing is stored on or read from your device, no cookie banner is needed. We process this on our own EU servers with no third-party analytics provider, and we keep these aggregate measurements for 18 months before deleting them; the daily visitor code becomes meaningless within 24 hours.
How long we keep it
We keep your scan report and its findings for 90 days. We keep your domain and work email for 12 months after you last contact us, then delete them. We keep web server logs for 14 days to operate and secure the site. Where the law requires us to keep proof of your consent, we keep that record for 4 years after you withdraw it. Our backups are replaced on a 35 day cycle, so a deleted record can persist in a backup for up to 35 days after we remove it from our live systems. We use backups only to restore service, never for anything else.
Your rights
Under the GDPR you can request access to, correction, or deletion of your data, restrict or object to processing, and receive your data in a portable format. Where we rely on your consent, you can withdraw it at any time, without affecting processing already carried out. You may also lodge a complaint with a supervisory authority. To exercise any right, email hello@temnir.com.