Interim version. Coruls is in a testing phase and is not publicly available yet. Before the public launch we will add the controller's details and publish the final version of this policy. Registered users will be notified of changes by email.
Data controller
The controller of your personal data is [name, address and tax ID of the controller: to be added before the public launch]. For any matter concerning personal data, write to contact@coruls.com.
What we process
- Coruls account: email address, optionally your full name, a hash of your password (we never store the password itself), preferred language, the dates the account was created and the address confirmed.
- Google sign-in (if you use it): your Google account identifier and email address. We do not receive your Google password or any other profile data.
- Two-step verification (if you turn it on): the encrypted authenticator secret and hashes of the recovery codes.
- Sessions and security: IP address, browser and device information (User-Agent), sign-in and last activity times, and counters of sign-in attempts and other operations we use to limit abuse.
- Contact form: your name, email address, the subject and text of the message, and the IP address and browser information sent with it.
We use no analytics or advertising tools and do not profile users.
Purposes and legal bases
- Creating and running your account, signing in to Coruls products and account messages (address confirmation, password reset, security notifications): performance of a contract (Art. 6(1)(b) GDPR).
- Security of the services, that is protection against account takeover, attempt limits and the list of active sessions: legitimate interest (Art. 6(1)(f) GDPR).
- Replying to a message from the contact form: legitimate interest (Art. 6(1)(f) GDPR).
Providing an email address is voluntary, but you cannot create an account without it.
Recipients
The services run on the controller's server in Poland. Data may be passed to:
- OVH: email (sending account messages and hosting the mailboxes) and encrypted backups of the account database, stored in Warsaw;
- Google: when you sign in with Google;
- Cloudflare: bot protection of the contact form (Turnstile).
Google and Cloudflare may process data outside the European Economic Area, in particular in the USA, under the European Commission's EU-US Data Privacy Framework decision or standard contractual clauses.
How long we keep data
- We keep account data for as long as the account exists. When you ask us to delete your account, we block it immediately; for 30 days you can cancel the deletion with the link in the email, after which the account data is permanently erased. It disappears from backups within a further 30 days.
- A session ends when you sign out, after 7 days without activity or at the latest 30 days after sign-in. We delete an ended session, together with its IP address and browser information, after a further 30 days.
- We delete an account whose email address was never confirmed 30 days after its last session ended.
- We delete links and codes sent by email once they are used or expire, and attempt counters expire on their own within a day.
- We keep contact form messages for as long as needed to handle the matter.
Your rights
You have the right to access, rectify and erase your data, to restrict its processing, to data portability, and to object to processing based on legitimate interest. You can exercise most of them yourself in the account panel at auth.coruls.com: edit your data, download a data export (a JSON file) and delete your account. For anything else, write to contact@coruls.com.
You may also lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland).
Cookies
We use only cookies that are necessary for the services to work. Details are in the cookie policy.
Changes to this policy
We will notify registered users of significant changes by email before they take effect.