Skip to content

privacy/

Privacy notice

This page says in plain words which personal data we touch, why we touch it and what you can ask us. It covers both the website and the product.

Last updated: 31 August 2026

Who processes the data

The data controller is CloseYourIt. For any question about this notice, or to exercise the rights described below, write to:

[email protected]

What we collect

  • Access request: if you fill in the access request form, we store your name, work email and the text you write.
  • Account: name, email address and password (never in clear text: we only keep an encrypted fingerprint).
  • What you write in the product: tickets, comments, notes, attachments and messages. That content is yours, and it may contain personal data you decide to put there.
  • Product usage: which pages and features you open, with your role and organisation. It tells us what works and what does not.
  • Diagnostics: errors, response times and log lines from the applications you connect. Sensitive values are filtered out before we store them.
  • Website statistics: page views, referrer, device type and country. The IP address is only used to derive the country and is never stored.

Why we process it

  • To let you use the service: without an account and the content you write, the product does nothing.
  • To keep it running and safe: notice failures, understand what happened, stop abuse.
  • To improve it: know which features are actually used, in aggregate.
  • To answer you: if you write to us or request access, we use your contact details for that.

On what basis

Processing account data and content is based on the contract: without it we cannot provide the service. Diagnostics, security and aggregate statistics rest on our legitimate interest in keeping the service working and improving it. Where consent is required, we ask you first.

For how long

  • Account data and content: as long as the account exists. On closure we delete or anonymise it.
  • Access requests that are not accepted: up to 12 months.
  • Errors, metrics and logs: kept for limited windows and then deleted automatically.
  • Website statistics: in aggregate form, with nothing that identifies a person.

Who we share it with

We do not sell personal data and we do not pass it to third parties for marketing. We rely on providers that process data on our behalf and only on our instructions: the infrastructure hosting the service, the storage for attachments and the service that sends system email. Data stays within the European Economic Area, except for transfers covered by the safeguards the law provides.

Cookies

We use a single technical cookie, the one that keeps your session open after sign-in. There are no profiling cookies and no advertising tracking. Website statistics are collected without cookies and without following the same person across different sites.

Your rights

You can ask us to see your data, correct it, delete it, restrict its use, receive it in a format another application can read, or object to processing based on legitimate interest. We answer within one month. If you think something is wrong, you can contact your data protection authority.

How we protect it

Data travels encrypted, credentials and secrets are stored encrypted, access is limited by role and every sensitive action leaves a trace. No measure is perfect: should a breach affecting you occur, we will tell you.

If this page changes

When we change this notice we update the date at the top. If the change is significant, we flag it inside the product.