Privacy Policy
Version 1.0 · effective from 27 September 2026 · Czech original
This is an English translation for information. The Czech version prevails in case of any discrepancy.
This policy describes how Enver processes personal data under Regulation (EU) 2016/679 (GDPR) and the Czech Personal Data Processing Act No. 110/2019 Coll. Capitalised terms have the meaning given in the Terms of Service.
1. Controller
The controller is Tomáš Cupák, company ID 09449957, registered office Podhradí 701/5, 680 01 Boskovice, Czech Republic. Contact us about personal data at tomcupak@gmail.com. We have not appointed a data protection officer, as the law does not require us to.
2. What we process, why and for how long
| Data | Purpose and legal basis | Retention |
|---|---|---|
| Sign-in: name, e-mail and Google or GitHub account identifier | Signing in and providing the Service – performance of a contract (Art. 6(1)(b) GDPR) | While you use the Service, then deleted within 30 days |
| Account membership: membership, permissions, ownership | Access control – performance of a contract | While you are a member |
| Consent to the terms of service: the version of the terms the User accepted and when | Proof that the contract was concluded and on which terms – legitimate interest (Art. 6(1)(f)) | For the duration of the contract and 3 years after it ends |
| Invitations: the invitee’s e-mail and the invitation link | Delivering an invitation requested by an Account member – the Account’s legitimate interest in inviting a colleague (Art. 6(1)(f)) | Until the invitation is accepted or rejected, 30 days at most |
| Audit log: who changed environments, services, permissions or Subscriptions in an Account and when, or revealed a secret (User identifier and e-mail, name of the changed item; never secret values) | Account security and traceability of changes – legitimate interest (Art. 6(1)(f)) | 3 years from the entry |
| Payments: Stripe customer and subscription identifiers, content and price of the Subscription, periods, payment status, invoices | Billing – performance of a contract; accounting and tax records – legal obligation (Art. 6(1)(c)) | For the Subscription’s duration; tax documents 10 years |
| Verification: payment card fingerprint (an identifier from which the card number cannot be derived) and Stripe customer identifier | Preventing one card from verifying several Users – legitimate interest in protecting the free plan from abuse (Art. 6(1)(f)) | While you use the Service |
| Push notifications: the browser’s push subscription address, encryption keys, device label (e.g. “Chrome · macOS”), chosen time window and time zone | Delivering notifications the User turned on – performance of a contract | Until notifications are turned off on the device or the browser invalidates the subscription |
| Feedback: message text, name, e-mail, selected Account and the page it was sent from | Handling the request and improving the Service – legitimate interest (Art. 6(1)(f)) | As long as needed to handle it, at most 3 years |
| E-mails: recipient address and content of service e-mails (invitations, Subscription information) | Service messages – performance of a contract, legitimate interest for invitations | Delivery records at the e-mail provider 45 days |
| Operational logs: technical application records that may contain a User’s e-mail or identifier and item names | Operation, troubleshooting and security of the Service – legitimate interest (Art. 6(1)(f)) | 90 days |
| Customer data: service configuration, variables (secrets encrypted), registry and Kubernetes credentials, status and metrics of Edge servers | Providing the Service. Where it contains personal data, we process it as a processor for the Customer (article 10.3 of the Terms). | For the term of the contract; Edge server metrics 7 days |
We do not make automated decisions or profile anyone, and we do not sell personal data or use it for advertising. Sign-in and payment data are required to conclude the contract; without them the Service cannot be provided.
3. What stays on your servers
Enver is a control plane – your applications run on your Edge servers. Container content, volumes and database backups are not transferred to us; for backups we only receive the file name, size and date. Container logs are shown live on request (the last 250 lines) and are not stored. Secret variables and registry credentials are decrypted only to be sent to your Edge server over an encrypted connection.
4. Recipients and processors
- Hosting of the Service: INTERNET CZ, a.s. (FORPSI), Czech Republic – processor, runs the servers the Service runs on.
- Postmark (ActiveCampaign, LLC, USA) – processor, sends service e-mails.
- Stripe (Stripe Payments Europe, Ltd., Ireland) – processes payments and card details as an independent controller under its own policy. You enter card details directly with Stripe; we never see them.
- Google and GitHub – pass us your name and e-mail when you sign in; they act as independent controllers under their own policies.
- Browser push services (e.g. Google, Mozilla, Apple, Microsoft) – deliver push notifications. The content is encrypted and the push service cannot read it.
- Container registries you connect (e.g. Docker Hub) – the Service signs in with your credentials to look up images and tags, on your instruction.
We also disclose data to public authorities where the law requires it.
5. Transfers outside the EU
Postmark, Stripe, Google and GitHub may process data in the United States. Transfers rely on the European Commission’s adequacy decision for the EU–US Data Privacy Framework, under which these companies are certified, and additionally on standard contractual clauses.
6. Cookies and browser storage
Enver uses no cookies, no analytics and no advertising tools, and does not track your behaviour. The application keeps only what it strictly needs to work in the browser’s storage (localStorage):
enver:access_token,enver:refresh_token– keeping you signed in,enver:account– the last selected Account,enver:lang– the chosen language (also used by this website),enver:maintenance– the last known planned maintenance, so it can be shown when the server is unreachable,- in sessionStorage
enver:chunk-reload-at– prevents repeated reloads after a new version is deployed.
If you turn on push notifications, the browser also stores the push subscription and a service worker. This is strictly necessary storage under Section 89(3) of the Czech Electronic Communications Act No. 127/2005 Coll. and needs no consent. The fonts of this website and the application are served by us; your browser does not fetch them from third parties.
7. Security
All communication is encrypted (HTTPS, WSS). Secret variables, registry credentials and Kubernetes tokens are stored encrypted and never returned in regular API responses; only a User with the permission can reveal them, and every reveal is written to the audit log. The Account Owner controls access with permissions, including per-environment permissions.
8. Your rights
You have the right to access your data, to have it corrected or erased, to restrict its processing and to data portability, and the right to object to processing based on legitimate interest. The Owner downloads the Account’s data in the application (Account → Data and deletion) and deletes the Account there, and every User deletes their profile under Profile → Delete profile. Otherwise just write to tomcupak@gmail.com; we reply within one month. If you are a member of another Customer’s Account, we pass requests concerning the data in that Account to its Owner.
You also have the right to lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz, or with the supervisory authority of your EU country.
9. Changes
We update this policy when the Service or its processors change. We announce substantial changes, including a new processor, by e-mail or in the application at least 14 days in advance.