Privacy notes for the CRA Readiness Check
1. Controller
Innomatica GmbH, Ostfildern, Germany · [email protected]. Our general privacy policy applies in addition.
2. Registration (form)
We collect company, name, business e-mail address, optionally a phone number, and a partner code. Purpose: delivery of your one-time code and the report, attribution to a sales partner, and the subsequent contact about our offer (pre-contractual measures, Art. 6(1)(b) GDPR; B2B direct contact based on legitimate interest, Art. 6(1)(f) GDPR).
3. What the collector transmits — and what it does not
The embtrace-check program transmits exclusively:
- names, versions and package ecosystems of your software components,
- the project name (hashed on request:
--anonymize), - the number of scanned build files and the program version.
Not transmitted: source code, file paths, file contents, configuration,
credentials, or personal data from your project. With --dry-run you can inspect the exact
transmission before anything is sent.
4. Processing and storage location
All data is processed and stored exclusively on Innomatica GmbH's own servers in Germany. No data is shared with or sold to third parties. For vulnerability analysis, component names and versions are checked against public vulnerability databases (e.g. OSV.dev).
5. Retention and your rights
We keep registration and analysis data as long as required for the purposes above and delete it on request at any time. You have the rights of access, rectification, erasure, restriction and objection — an e-mail to [email protected] is enough.