Privacy & Data Protection
How we handle personal data across the website and Upwarden Cloud, and your rights under the GDPR.
Draft — not yet legally reviewed. The technical descriptions below reflect how the site and service are built, but the legal specifics (controller identity, legal bases, processor list, retention, transfers) are placeholders to be confirmed by counsel and your DPO before launch. Not legal advice.
Last updated: 9 July 2026
1. Controller
The data controller is Agentic Discovery Solutions Ltd (trading as Upwarden), a company registered in England & Wales, company no. 16609866 — see the Impressum for our registered office and operating address. Data-protection contact: privacy@upwarden.io.
2. The website
The marketing site is static. We use Google Analytics 4 to understand site usage, and it is consent-gated: no analytics script loads and no analytics cookies are set unless you explicitly allow it. If you decline, nothing loads. Your choice is stored locally in your browser and can be changed at any time via Manage cookies in the footer. We also honour the Global Privacy Control signal — if your browser sends it and you have not made an explicit choice here, we treat that as a decline and do not show the banner. On blog posts, consented analytics additionally record which article was viewed and how far it was read. Our hosting provider may process technical connection data (e.g. IP address, user agent) in server logs to deliver and secure the site.
3. Forms (demo & Upwarden Cloud early access)
If you submit the demo/contact or early-access form, we process the details you provide (e.g. name, work email, company, message) to respond and, where relevant, to onboard you. Form submissions are handled via our forms processor [Netlify Forms]. We use this data to contact you about Upwarden and do not sell or share it.
4. Upwarden Cloud (managed service)
When you use the managed service we process account and tenant data, project metadata, and audit logs. Upwarden is a registry proxy: it sees package coordinates (names and versions) and the artifacts it serves — not your source code. Every tenant is isolated. Sub-processors may include [hosting], [authentication: Stytch], and [email]. Retention varies by plan. Self-hosting keeps all of this inside your own infrastructure with no telemetry to us.
5. Audit-log retention
Upwarden records an audit event for security- and policy-relevant actions (dependency decisions, configuration changes, authentication, and administrative actions). Under the storage-limitation principle (GDPR Art. 5(1)(e)) we retain these audit events only as long as needed, for a period that depends on your plan:
| Plan | Audit-log retention |
|---|---|
| Free | 7 days |
| Team | 30 days |
| Org | 365 days (1 year) |
| Enterprise | Retained for the life of the account (no automatic deletion) |
When your plan's retention period elapses, the corresponding audit events are permanently deleted from our systems, and deletion is irreversible. A minimum floor of 7 days applies to all plans: audit events are never deleted sooner than 7 days after they are recorded.
Two narrow exceptions to the schedule above follow. Both are limited to specific record types, and neither extends the retention of your ordinary activity.
Exception — records of erasure. Where you exercise your right to erasure or close your account (see Your rights), the specific audit records documenting that the erasure took place are retained as our lawful record that we honoured the request, even though the underlying activity data is deleted. These records contain no package, project, or user activity content. [Retention periods and the erasure-record basis to be confirmed by counsel.]
Exception — security and abuse records. The retention periods above cover activity we serve. Authentication attempts we refuse at the network edge — because the credential presented is forged, unknown, expired or revoked — are recorded separately as a security record and retained for 400 days, on all plans.
These records exist to detect and investigate abuse directed at our system. A refused request never reaches the service, so it leaves no trace anywhere else; these records are the only durable evidence that the attempt occurred. Deleting them on the schedule above would remove the evidence of an attack at the same rate we remove the record of ordinary use.
A security record includes what was requested (the package coordinate, the upstream registry host and the HTTP method), non-secret details of the credential presented (its public identifier, a hash prefix, its type and length — never the credential itself), the account and key it resolved to where one could be resolved, and the IP address the request came from. It contains no credential secret and no package content. Note that, unlike our records of erasure, a security record does carry the package coordinate that was requested. [Retention period, the 400-day window and its legitimate-interests basis to be confirmed by counsel.]
6. Legal bases (GDPR Art. 6)
We rely on: performance of a contract (providing the service you request); legitimate interests (securing and improving the service, responding to enquiries); and consent where required (e.g. optional communications). [Confirm mapping per processing activity.]
7. International transfers
Where data is processed outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses. [Confirm transfer mechanisms per processor.]
8. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your personal data, and to object to certain processing. You may withdraw consent at any time, and you have the right to lodge a complaint with a supervisory authority. To exercise your rights, contact [privacy@upwarden.io].
9. Changes
We may update this policy; the "last updated" date reflects the latest revision.
See also Impressum and Terms of Service.