Skip to main content

Privacy Policy

Last updated: June 12, 2026

Language notice: This legal text is currently available in German (DE) and English (EN) only. The authoritative version is German; the English text is a courtesy translation. Full translations in other languages are planned for a future update.

Scanara ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our EU AI Act compliance platform, website, and related services (collectively, the "Service").

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable national data protection laws.

1. Data Controller

The data controller responsible for your personal data is:

Scanara UG (haftungsbeschränkt) Managing Director: Thilo Barth Silnerstraße 37, 85221 Dachau, Germany Commercial Register: Munich Local Court (Amtsgericht München), HRB 312777 Contact: support@scanara.io

1a. Roles: Controller and Processor

For account, billing, website, newsletter, and marketing data, Scanara is the controller within the meaning of Art. 4(7) GDPR. For content that customers submit for analysis — in particular repository contents, scan results, and audit trail records — Scanara acts as a processor on behalf of the Customer (Art. 28 GDPR); the Data Processing Agreement (DPA) governs that processing. Data subject requests concerning such content should be directed to the respective Customer as controller; we forward requests received by us to the Customer pursuant to Art. 28(3)(e) GDPR.

2. Data We Collect

2.1 Account Data

When you register for Scanara, we collect your email address, name, and organization name. If you sign in via a third-party identity provider (e.g., corporate SSO via OIDC/SAML), we receive your email and identity claims from that provider. Providing this data is required to enter into the contract; without it, we cannot provide an account.

2.2 Usage Data

We collect information about how you interact with the Service, including pages visited, features used, scan history, and timestamps. This data is collected to improve the Service and is processed on the basis of our legitimate interest.

Right to object (Art. 21 GDPR): You have the right to object at any time to processing of your data based on our legitimate interest. To exercise this right, contact support@scanara.io.

2.3 Repository and Scan Data

When you connect a GitHub repository and initiate a scan, we temporarily access your repository contents (source code and documentation) to perform compliance analysis. Scan results, findings, and compliance scores are stored as part of the Service. We do not retain a full copy of your repository after the scan is complete; however, scan findings include short source code excerpts (the flagged lines plus their immediate context), which are stored as part of the scan results and are subject to the retention periods in Section 7.

To the extent scanned source code incidentally contains personal data of third parties (e.g., author names in commit histories or comments), we process such data solely as a processor on behalf of the Customer. Direct notification of these third parties pursuant to Art. 14 GDPR is not provided, as this would require disproportionate effort (Art. 14(5)(b) GDPR) — such data is generally processed only transiently during the scan and is not stored separately; where source code excerpts in scan findings incidentally contain such data, they are subject to the retention periods in Section 7 and to the Customer's responsibility as controller. This data is not collected directly from the data subjects (Art. 14(1) GDPR applies, not Art. 13 GDPR); general information about our processing is publicly accessible via this Privacy Policy and serves as substitute information pursuant to Art. 14(5)(b) second alternative GDPR.

2.4 Payment Data

Payment transactions are processed by Stripe Payments Europe, Ltd. (Ireland) ("Stripe"). We do not store your full credit card number. Stripe acts as an independent data controller for payment data. See Stripe's Privacy Policy for details.

2.5 Cookies and Analytics

We use essential cookies required for site functionality and, with your consent, Google Analytics 4 (GA4) and Microsoft Clarity for usage analytics. You can manage your cookie preferences at any time via the cookie settings in the footer of this website. See Section 8 below for details.

2.6 Demo and Contact Requests

When you submit a demo request or contact form on the marketing website, we collect the data you enter (typically name, email address, and message). We use this data solely to respond to your enquiry and, where applicable, to initiate a contractual relationship (Art. 6(1)(b) GDPR). Data is deleted six months after the last contact unless a contract is concluded. AWS Simple Email Service (SES) is used as the technical recipient (processing within the EU, eu-west-1).

2.7 Server Logs

When you access our website and the Service, our servers automatically process technical access data: IP address, date and time of access, requested URL, HTTP status code, volume of data transferred, user agent (browser type and version, operating system), and referrer URL. This processing is necessary to operate, secure, and troubleshoot the Service and is based on our legitimate interest (Art. 6(1)(f) GDPR). Logs are retained on a 90-day rolling basis (Section 7) and are not combined with other data sources.

2.8 Newsletter

When you subscribe to our newsletter, we collect your email address. Subscription uses a double opt-in procedure: you receive a confirmation email and are only added to the mailing list after confirming. We record the time and source of your consent (Art. 6(1)(a) GDPR in conjunction with § 7(2) No. 3 UWG). You can unsubscribe at any time via the unsubscribe link in every email or by contacting support@scanara.io. See Section 7 for retention of consent records.

3. Purposes of Processing

  • Service delivery: To provide, maintain, and improve the Scanara compliance platform.
  • Account management: To manage your account, organization membership, and authentication.
  • Compliance scanning: To perform AI Act compliance analysis on your repositories and documents.
  • Communication: To send you transactional emails (e.g., scan results, account notifications) and, with your consent, marketing communications.
  • Billing: To process payments and manage your subscription.
  • Security and fraud prevention: To protect the Service and our users from unauthorized access and abuse.
  • Analytics: To understand usage patterns and improve the Service (with your consent for non-essential analytics).
  • Legal compliance: To comply with applicable legal obligations, including the EU AI Act audit trail requirements.

4. Legal Basis for Processing

  • Contract performance (Art. 6(1)(b) GDPR): Processing necessary to provide the Service under our Terms of Service.
  • Consent (Art. 6(1)(a) GDPR): For analytics cookies and marketing communications. You can withdraw consent at any time.
  • Legitimate interest (Art. 6(1)(f) GDPR): For security, fraud prevention, and service improvement, where our interests do not override your rights.
  • Legal obligation (Art. 6(1)(c) GDPR): Where required by law (e.g., tax records, audit trail retention).

5. Sub-processors and Third Parties

Sub-processorPurposeLocation
Amazon Web Services (AWS) (Amazon Web Services EMEA SARL)Cloud infrastructure, compute, storage, database, authentication, email delivery (SES), content delivery (CloudFront)EU (Dublin, eu-west-1); CloudFront edge locations in the EU and North America — DPA with EU entity; SCCs in the AWS DPA as fallback safeguard
GitHub, Inc.Source code repository access (via OAuth, at your direction), merge-gate integration (Checks API)USA — DPF + SCC Module 3
Google Ireland Ltd. / Google LLC (GA4)Website analytics (only with your consent)Ireland / USA — DPF + SCC Module 2
Microsoft Corporation (Clarity)Session replay and heatmap analytics on marketing website (only with your consent)USA — DPF + SCC Module 2

Note on Stripe: Stripe (Stripe Payments Europe, Ltd.) acts as an independent data controller for payment data (§ 2.4 of this Policy) and is therefore not listed as a sub-processor above.

6. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15): Obtain confirmation of whether we process your data and request a copy.
  • Right to rectification (Art. 16): Request correction of inaccurate personal data.
  • Right to erasure (Art. 17): Request deletion of your personal data ("right to be forgotten").
  • Right to restriction (Art. 18): Request restriction of processing in certain circumstances.
  • Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
  • Right to object (Art. 21): Object to processing based on legitimate interest or for direct marketing.
  • Right to withdraw consent (Art. 7(3)): Withdraw consent at any time for consent-based processing.

To exercise any of these rights, contact us at support@scanara.io. We will respond within one month; for particularly complex or numerous requests, this period may be extended by up to two further months pursuant to Art. 12(3) GDPR — we will inform you of any extension within the first month. You also have the right to lodge a complaint with a supervisory authority. The competent authority for our registered location in Bavaria is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18, 91522 Ansbach, Germany Website: www.lda.bayern.de

6a. Automated Decision-Making (Art. 22 GDPR)

Scanara does not make legally binding decisions based solely on automated processing of personal data within the meaning of Art. 22 GDPR. Risk classifications, compliance assessments, and compliance scores generated by the platform are technical analysis results and not legally binding determinations. All regulatory decisions — in particular the risk classification under Regulation (EU) 2024/1689 (EU AI Act) and decisions regarding conformity documentation — remain solely with the Customer.

Since no decision within the meaning of Art. 22(1) GDPR is made, there is no entitlement to human review under Art. 22(3) GDPR. The Customer can override automated risk classifications at any time in the dashboard and provide their own justification.

7. Data Retention

  • Account data: Retained for the duration of your account. Deleted within 30 days of account closure, unless retention is required by law.
  • Scan results and compliance findings: Retained for the duration of your active subscription plus 30 days after subscription termination (export window). Within your active subscription, tier-based retention limits apply: free: 90 days / team: 365 days / business: 730 days / enterprise: 1,825 days (implementation reference: functions/layers/layer_scanara_shared/python/lib/scanara/data_retention.py). You may request earlier deletion.
  • Audit trail records: Retained for at least 10 years on a contractual basis on behalf of the Customer (GDPR Art. 28(3)(a)), supporting the Customer's statutory documentation obligations (in particular where the AI Act applies). Upon contract termination, the records are anonymized so that they can no longer be attributed to the Customer. See the Service Description for details.
  • Payment records: Retained for 8 years pursuant to § 147(1) No. 4 AO and § 14b(1) UStG as amended by the Fourth Bureaucracy Relief Act (BEG IV, BGBl. 2024 Nr. 323; effective 1 January 2025).
  • Analytics data (GA4): Raw event data is deleted within Google Analytics 4 after 14 months (configured retention limit). Aggregated, anonymized reports are retained beyond this period.
  • Server and usage logs: 90 days rolling; automatically deleted thereafter unless retention is required by law.
  • Newsletter consent records: Proof of marketing consent granted (§ 7(3) UWG in conjunction with Art. 6(1)(a) GDPR) is retained for the period of use plus 3 years after withdrawal (§ 195 BGB); deleted upon expiry of the limitation period.
  • Demo and contact form data: 6 months after last contact, unless a contract is concluded (Section 2.6 of this Policy).

8. Cookies

Pursuant to § 25 TDDDG (German Telecommunications and Digital Services Data Protection Act), your prior consent is required for cookies that are not technically necessary. We use the following cookie categories:

Essential Cookies

Required for core site functionality, including authentication and security. These cannot be disabled. Legal basis: § 25(2) No. 2 TDDDG (no consent required) and Art. 6(1)(b) GDPR.

CookiePurposeDuration
scanara_sessionMaintains your authenticated session in the dashboard. Contains an opaque session identifier only.30 days
auth_hintIndicates whether you are currently signed in, used for navigation optimisation. Does not contain credentials.1 day
oauth_state, oauth_pkce, oauth_nonceTemporary cookies used during the sign-in process to prevent cross-site request forgery and replay attacks.5 minutes
scanara_cookie_consentStores your cookie consent decision (proof of consent pursuant to Art. 7(1) GDPR).1 year
scanara_consent_sidPseudonymous identifier used to log your consent decision server-side (accountability purposes).2 years

Functional Cookies

These cookies store your preferences so the platform can remember your choices across sessions. They do not track you or collect personal data for advertising or profiling. Device storage (§ 25 TDDDG): strictly necessary under § 25(2) No. 2 TDDDG (user-requested preference, e.g. language or theme). GDPR processing: Art. 6(1)(b) GDPR for authenticated users (contractual necessity) or Art. 6(1)(f) GDPR for anonymous visitors (legitimate interest in a consistent UX).

CookiePurposeDuration
localeStores your preferred language so it is preserved when navigating between the website and the dashboard.1 year
themeStores your preferred colour scheme (light or dark mode).1 year
scanara_recent_ai_systemsRemembers recently viewed AI systems in the dashboard for quick navigation.90 days

Analytics Cookies

Google Analytics 4 (GA4) and Microsoft Clarity cookies are used to collect pseudonymized usage data. Microsoft Clarity additionally enables session replays and heatmaps to analyze user behavior. Both services are only loaded after you provide explicit consent pursuant to § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. Google Consent Mode v2 is implemented with a default of "denied" — no analytics cookies are set and no analytics scripts are loaded before you consent. You can change your preference at any time using the "Cookie Settings" link in the website footer.

Your cookie preferences are stored in the scanara_cookie_consent cookie (see table above). For accountability purposes (Art. 7(1) GDPR), we additionally log your consent decision server-side under a pseudonymous identifier together with a hashed IP address and hashed user agent; this record is not linked to your user account.

9. International Data Transfers

All primary data processing and storage occurs within the European Union, specifically in AWS eu-west-1 (Dublin, Ireland). Your source code, scan results, and compliance data never leave the EU.

Amazon Web Services is provided through Amazon Web Services EMEA SARL (Luxembourg); primary data processing takes place exclusively within the EU (eu-west-1, Dublin). The website is delivered via the Amazon CloudFront content delivery network with edge locations in the EU and North America; for any incidental edge or support access from third countries, the Standard Contractual Clauses incorporated in the AWS DPA serve as a fallback safeguard. Where sub-processors are based outside the EU (GitHub, Google, Microsoft), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) adopted by the European Commission Decision (EU) 2021/914 pursuant to Art. 46(2)(c) GDPR. GitHub, Inc., Google LLC, and Microsoft Corporation are additionally certified under the EU-US Data Privacy Framework (DPF). Transfer Impact Assessments (TIAs) are available on request.

10. Security Measures

We implement appropriate technical and organizational measures pursuant to Art. 32 GDPR to protect your personal data, including:

  • Encryption at rest and in transit (TLS 1.2+)
  • Authentication via AWS Cognito; Cognito supports MFA (optional for users, software-token TOTP) and enterprise SSO (OIDC/SAML)
  • Multi-tenant data isolation at the application and database level
  • Immutable audit trail stored in WORM-compliant S3 storage
  • Regular security assessments and dependency vulnerability scanning
  • Secrets managed exclusively via AWS Secrets Manager; no plaintext credentials in application code

11. Minors

The Service is not directed at persons under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that personal data of a person under 16 has been collected without parental or guardian consent, we will delete such data without undue delay.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date above. For significant changes, we will also notify you by email.

13. Data Protection Officer and Contact

No Data Protection Officer is required or has been appointed (§ 38 BDSG; the threshold of regularly 20 individuals processing personal data in an automated manner has not been reached).

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact:

Data Protection Contact: support@scanara.io