Toevan ("we", "us") builds deterministic code-governance software. This policy explains what personal data we collect when you visit this website, submit an enquiry, or hold a Toevan account, and how we handle it. For this data, Toevan is the data controller.
Personal data that flows through the product on behalf of our customers (source code and its contents) is a separate matter: there Toevan acts as a data processor, and that processing is governed by our Data Processing Agreement, not by this policy.
Who we are
Toevan OÜ, an Estonian private limited company (osaühing), is the data controller for the personal data described in this policy.
- Registry code: 17583678.
- Contact: info@toevan.com for privacy and general enquiries.
- Registered address: Tartu mnt 67/1-13b, Kesklinna linnaosa, 10115 Tallinn, Harju maakond, Estonia.
What we collect and why
We collect the minimum personal data needed to run this website, respond to enquiries, and provide accounts. Each category has its own lawful basis under Article 6 of the GDPR.
- Website visitors. When we enable cookieless analytics we will measure only aggregate traffic; no such tool is enabled yet. We do not build profiles of visitors and we set no tracking cookies (see Cookies and analytics). Lawful basis: our legitimate interest (Article 6(1)(f)) in understanding and securing our own website.
- Leads. When you submit the enterprise contact form we collect your name, work email, company, engineer-count band, an optional field describing what is driving your interest, and your message. Lawful basis: our legitimate interest in responding to business enquiries and, where you ask us to, taking steps prior to entering a contract.
- Account users. When you or your organisation creates a Toevan account we process your name, work email, and authentication identifiers. You sign in with your own GitHub account, so those identifiers come from your GitHub identity. Lawful basis: performance of a contract (Article 6(1)(b)) to provision and secure your account.
- Security. Our servers process your IP address transiently to rate-limit and protect our endpoints against abuse. Lawful basis: our legitimate interest in the security of the service. We do not store your IP address against your enquiry.
We rely on consent (Article 6(1)(a)) only where we actually ask for it. Today no feature of this website relies on consent.
Data location and transfers
We host this website and our controller data in the European Union: compute in Helsinki (Hetzner) and CDN, DNS, and edge services on Cloudflare's EU configuration.
Controller personal data is processed in the European Union. You authenticate with your own GitHub account (GitHub is US-based), and, once billing is live, our payments processor (Stripe) will process billing data; those flows can involve a transfer outside the European Economic Area (EEA), which relies on the provider's adequacy decision or the European Commission's Standard Contractual Clauses.
How long we keep it
- Leads. We keep contact-form submissions for up to 24 months from your last contact, then delete them, unless an ongoing relationship or a legal obligation requires longer.
- Account data. [OWNER: account-data retention period].
- Billing and invoice records. Kept for the statutory retention period (approximately seven years) as required by law. Lawful basis: compliance with a legal obligation (Article 6(1)(c)).
Product and customer data (the source code and its contents processed inside the product) is not covered by this policy. Its retention is governed by our Data Processing Agreement.
Sub-processors
A small set of providers processes the personal data described above on our behalf, under data processing agreements. These are distinct from the product sub-processors that handle customer source code, which are listed on our Sub-processors page and governed by the Data Processing Agreement. We do not sell your personal data.
- meetergo (Germany, EU). Scheduling for the enterprise Book a pilot call. It processes a prospect's name, email, and meeting metadata. meetergo hosts booking data in the EU, primarily Germany, with limited non-EU sub-processor transfers under Standard Contractual Clauses and the EU-US Data Privacy Framework. Booking data is automatically deleted after 24 months, matching the leads-retention window below. The call-to-action is a cookieless link-out (see Cookies and analytics), under meetergo's standard Article 28 data processing agreement.
- Mailgun (EU). Outbound transactional and alert email, for example new-lead alerts. It handles account and lead email addresses and message content, in the EU. A legacy SendGrid integration remains in the codebase but is disabled by default and is being removed.
- mailbox.org (Berlin, Germany, EU). Hosts our human mailboxes (info@toevan.com and security@toevan.com) and receives inbound email: contact enquiries, security and vulnerability disclosures, and sub-processor-change subscribe messages. It handles the email address and message content of anyone who emails us.
- Stripe. Payments and billing. Intended processor, not yet live: billing is currently simulated, so no live payment data flows to Stripe today. When billing goes live it will handle billing-contact and payment metadata under an EU contracting entity, with onward transfer to the United States under Standard Contractual Clauses and the EU-US Data Privacy Framework.
Changes
This policy is versioned. The current semantic version and the date it last changed appear at the top of this page, and the full history is in the changelog below. When we make a material change we update the version and the Last updated date.
Changelog
- v1.0.0
Initial draft: controller identity, data collected and lawful bases, cookieless analytics, EU data residency, retention, GDPR rights, the Estonian supervisory authority, and the controller-data processors (meetergo for scheduling, Mailgun and mailbox.org for email, Stripe for billing) moved here from the product sub-processors page.