Privacy Policy
Last updated 5 October 2026
This policy explains how Rasmus Wejlgaard, trading as Updawg("Updawg", "we") handles personal data. We are the controller of the data about people who use Updawg — your account, sign-ins and billing. For data your hosts report, we act on your organization's behalf as its processor.
What we collect, and why
| Data | Why | Legal basis |
|---|---|---|
| Your name and email address | To create your account, sign you in with emailed links, and contact you about the service | Contract |
| If you sign in with GitHub, Google or Microsoft: that account's ID, name and verified email | To sign you in | Contract |
| If your organization uses single sign-on or SCIM: the ID, name and email its identity provider sends us for you | To sign you in and keep your membership in step with your employer's directory | Contract (with your organization); legitimate interests |
| Organization memberships, roles, invitations you send or receive | To decide what you may see and do | Contract |
| An audit log of actions you take, with the time and IP address | Security, and so your organization can see who did what | Legitimate interests (security); contract |
| Sign-in sessions: a cookie, IP address and browser user agent | To keep you signed in and detect misuse | Contract; legitimate interests (security) |
| Billing: your organization's name, billing address, VAT number if given, and invoices | To charge for paid plans and keep accounting records | Contract; legal obligation |
| Emails you send us | To answer them | Legitimate interests |
Card details are entered on Stripe's pages and never reach us; we see only the card's brand, last four digits and expiry.
Host data. Hostnames, package inventories and the other host details listed at docs.updawg.netare processed for your organization. The agent does not collect file contents, environment variables, users, credentials or network configuration.
Cookies
The portal sets one cookie, which keeps you signed in, and a short-lived one while you sign in with GitHub, Google, Microsoft or single sign-on. Both are strictly necessary. The website updawg.net sets no cookies and runs no analytics.
Who we share it with
Only the service providers we need to run Updawg, under contracts that require them to protect it: Google Cloud (hosting and database, Frankfurt), Hetzner (email, Germany) and Stripe (payments). If you choose to sign in with GitHub, Google or Microsoft, that provider confirms who you are. We do not sell personal data or use it for advertising.
Some providers, such as Stripe, may process data outside the UK and EEA. Where they do, the transfer is covered by the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.
How long we keep it
- Account data: while your account exists. If you ask us to delete it, we do so within 30 days.
- Audit log: as long as your organization's plan keeps it (7 days on Free, 6 months on Team and Business, 13 months on Enterprise), or less if an owner chooses.
- Sign-in links: 15 minutes. Sessions: until they expire or you sign out.
- Invoices and billing records: six years, as UK law requires.
Your rights
You can ask for a copy of your personal data, have it corrected or deleted, object to or restrict how we use it, or ask for it in a portable form. Emailprivacy@updawg.net; we answer within one month. If your data is in an organization's host data, ask that organization first — we process it for them.
You can complain to the UK Information Commissioner's Office atico.org.uk, though we would like the chance to put things right first.
Security
Data is encrypted in transit, every organization's data is isolated in the database by row-level security, and jobs sent to your hosts are signed with your organization's own key.
Changes
If we change this policy materially, we will email account owners before the change takes effect.
Contact
Rasmus Wejlgaard, trading as Updawg.privacy@updawg.net