Contents
- Scope of this Privacy Notice
- Who we are (data controller)
- What personal data we process
- Why we process it (purposes & lawful basis)
- Third parties & international transfers
- Cookies & local storage
- Retention periods
- Your rights as a data subject
- How to exercise your rights / contact us
- Right to lodge a complaint
- Children
- Security
- Changes to this notice
01 Scope of this Privacy Notice
This Privacy Notice applies to the public PegaProx websites operated by us:
- pegaprox.com — the project's marketing and information site
- docs.pegaprox.com — public documentation
- updates.pegaprox.com — the update mirror used by deployed PegaProx instances
- plugins.pegaprox.com — the community plugin marketplace (account system, plugin submissions, reviews); see § 3.7 for the marketplace-specific data we process
It does not apply to PegaProx the software when you install and run it on your own infrastructure. In that case you are the data controller for any data your PegaProx instance processes — including audit logs, alerts, and cluster credentials — and we are not involved in or able to access that data.
It also does not cover third-party services we link to (Open Collective, GitHub, etc.); those operate under their own privacy notices.
02 Who we are (data controller)
The data controller for personal data processed on the websites listed above is:
Nico Schmidt, in the capacity of natural-person operator of the PegaProx open-source project.
Correspondence address:
PegaProx · 4th Floor, Silverstream House, 45 Fitzroy Street
Fitzrovia, London W1T 6EB · United Kingdom
For privacy-related enquiries, contact support@pegaprox.com. Full contact details are on the Legal Notice.
PegaProx is fiscally hosted by Open Source Collective (a U.S. 501(c)(6) non-profit) for donation handling. Donation-related personal data (your name, billing address, payment information when you contribute) is processed by Open Collective Inc. and Open Source Collective directly — see their privacy notice: opencollective.com/privacypolicy.
03 What personal data we process
3.1 Server access logs (every visit to our websites)
Our web server records each request for security and operational purposes. The log entry contains:
- Your IP address (truncated to /24 for IPv4 and /48 for IPv6 within 7 days)
- Date and time of the request
- HTTP request line (URL accessed, method, status code, response size)
- Your user-agent string (browser / OS info as sent)
- Referrer URL if your browser sent one
We do not use these logs for analytics, advertising, profiling or any commercial purpose. They exist solely for security incident response, diagnosing outages and abuse mitigation.
3.2 Email correspondence
When you write to support@pegaprox.com or sponsor@pegaprox.com, we receive:
- Your email address (and any name / signature you include)
- The content of your message and any attachments
- Standard email metadata (subject, timestamp, message-ID, your mail-server hops via Received headers)
Our mailboxes are hosted by Proton Mail (Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland), acting as our processor. Your message and its metadata are stored on Proton’s infrastructure in Switzerland — a country the EU and the UK recognise as providing an adequate level of data protection (adequacy decisions under Art. 45 GDPR / UK GDPR), so no additional transfer mechanism is required. Proton’s own privacy notice is at proton.me/legal/privacy.
3.3 Live chat & support tickets
To offer live help and organise enquiries, we make available Charla (charla.com), an EU-based live-chat and helpdesk platform, as a chat widget on our public websites; Charla acts as our processor. The chat launcher loads on demand: Charla’s service is contacted only when you actively click to open the chat, and the widget then shows its own GDPR consent notice which you must accept before it proceeds. Only after you open the chat and consent does Charla receive your IP address and user-agent (see § 5), set a functional cookie for the chat session (see § 6), and process the messages you send, your contact details and basic ticket metadata (timestamps, status) on our behalf — under a data-processing agreement and within the EU. If you never open the chat, no data is sent to Charla. We use Charla only for support you initiate — it does not build an advertising profile of you. Its privacy notice is at charla.com/privacy-policy; its DPA is published at charla.com/…/dpa.pdf.
3.4 Phone calls to the receptionist line
If you call +44 204 620 4550, our receptionist takes a message containing whatever you choose to share — typically your name, the matter you're calling about, and a callback contact. The reception service also records the call duration and your caller-ID number where transmitted by your network.
All calls to this number are recorded in full — both the incoming caller's audio and the receptionist's responses — for quality, training and accuracy purposes, and to provide an evidential record of business enquiries. You will hear an announcement to this effect at the start of every call. If you do not wish your call to be recorded, please end the call before the announcement completes and contact us instead by email at support@pegaprox.com; we will not penalise that choice and will respond just as we would to a phone enquiry.
3.5 Voluntary input
The websites currently have no contact forms, comment systems, account creation or newsletter signup. Should that change in the future, this notice will be updated accordingly before any such feature goes live.
3.6 Update mirror requests
Deployed PegaProx instances poll updates.pegaprox.com to check for new releases. Each poll produces a server access log entry per § 3.1. We do not receive or store any cluster identifier, customer name, or other software-state data from the poll — the request contains only the version manifest URL and the originating IP.
3.7 Community plugin marketplace (plugins.pegaprox.com)
Unlike our other sites, the marketplace is an authenticated service. If you register an account there, we process the following:
- Account profile — your chosen username (public), email address (private), an optional avatar URL and short bio you decide to publish, and a bcrypt hash of your password (we never see the plaintext).
- Email verification token — a 40-character random token tied to your account during sign-up, valid for 24 hours, deleted once you click the verification link.
- Two-factor authentication — if you enable TOTP, we store your authenticator-app secret (160-bit, base32-encoded) so we can verify your 6-digit codes, plus eight backup recovery codes stored as bcrypt hashes (the plaintext is shown to you once at generation). 2FA is mandatory for accounts holding the administrator role.
- Session — a single
PEGAPROX_MPcookie holding an opaque session identifier (HTTP-only, Secure, SameSite=Lax). Required for login; absolute lifetime 14 days. We do not set any other cookies on this site. - Plugin submissions — the public GitHub owner / repo URL you submitted, your provided tagline, description and category. Plugin metadata (stars, latest release, README) is fetched on demand from the GitHub public API and cached server-side.
- Reviews — your star rating (1–5) and optional text comment, attached to your username on the plugin page.
- Audit log — for brute-force protection, abuse mitigation and operational debugging we log security-relevant events (sign-up, login successes & failures, 2FA verifications, plugin submit/approve/reject/delete, review create/delete, throttle blocks). Each entry records the action, the actor's user id (where applicable), the source IP address and a timestamp. IP addresses in marketplace audit-log rows are retained for 30 days, after which the entire row is deleted by a scheduled cleanup job.
The marketplace performs only two outbound calls on your behalf: (1) the GitHub public API at api.github.com when a plugin row needs refreshing — see § 5; and (2) outbound SMTP to send transactional email (verification, plugin approval / rejection, admin notification) to the address you registered with.
The marketplace does not run analytics, advertising or third-party trackers. It does not share, sell or trade your data with anyone.
04 Why we process it (purposes & lawful basis)
| Processing | Purpose | Lawful basis (UK / EU GDPR Art. 6) |
|---|---|---|
| Server access logs | Security monitoring, abuse mitigation, debugging | Legitimate interest — Art. 6(1)(f). Necessary to protect the service against attacks; outweighs the minimal privacy intrusion of truncated logs. |
| Email correspondence | Replying to your enquiry, providing support, handling sponsorship matters | Legitimate interest — Art. 6(1)(f), or the precursor to a contract — Art. 6(1)(b), where applicable. |
| Phone calls (receptionist) | Routing your enquiry to the appropriate team member; recording the call in full for quality, training and an accurate evidential record of business enquiries | Legitimate interest — Art. 6(1)(f). Up-front announcement at the start of every call; email alternative offered. |
| Update-mirror logs | Capacity planning, abuse mitigation, troubleshooting failed updates | Legitimate interest — Art. 6(1)(f). |
| Marketplace account & submissions | Operating an authenticated account on plugins.pegaprox.com — sign-up, login, email verification, password reset, publishing your plugin submissions and reviews | Performance of a contract — Art. 6(1)(b) (the account agreement you enter into when you register). |
| Marketplace 2FA secrets & security log | Verifying your second factor at login, generating + checking backup codes, brute-force protection, abuse mitigation, audit trail | Performance of a contract — Art. 6(1)(b) — combined with legitimate interest in account security and the integrity of the service — Art. 6(1)(f). |
| Marketplace transactional email | Sending verification links, plugin-approval / rejection notifications and admin alerts to the email address you registered with | Performance of a contract — Art. 6(1)(b). |
| Cookies / local storage | See § 6 below — currently only strictly-necessary state | Strictly necessary — UK PECR Reg. 6(4) / ePrivacy equivalent. No consent prompt required for the categories we use. |
We have not designated a Data Protection Officer (DPO) because our processing falls outside the UK GDPR Art. 37 thresholds (no large-scale special-category processing, no systematic monitoring on a commercial scale).
05 Third parties & international transfers
Our public websites load resources from the following third-party origins. When your browser fetches one of these, the third party automatically receives your IP address, user-agent, and the URL of the page that triggered the request. We do not control what those third parties do with that information — they operate under their own privacy notices.
| Third party | Purpose | Region | Privacy notice |
|---|---|---|---|
| Google Fonts | Webfonts (Inter, JetBrains Mono) — visual presentation | US / global | policies.google.com/privacy |
| Cloudflare CDN (cdnjs) | Icon font (Font Awesome) | US / global | cloudflare.com/privacypolicy |
| YouTube (Google LLC) | Embedded walkthrough video — only loaded when you visit the page that contains it; uses the youtube-nocookie variant where the embed format permits | US / global | policies.google.com/privacy |
| GitHub (Microsoft Corp.) | Avatar images of community contributors loaded from avatars.githubusercontent.com; outbound links to repositories & issues; the marketplace also makes server-to-server calls to the public GitHub API at api.github.com to refresh plugin metadata (stars, latest release, README) — your IP is not sent to GitHub for this; only the marketplace server's IP is |
US / global | github.com privacy |
| Proton Mail (Proton AG) | Hosting our @pegaprox.com mailboxes and sending transactional email (marketplace verification, plugin-approval / rejection, admin alerts) — the destination is the email address you registered with. Acts as our processor; see § 3.2 |
Switzerland (EU/UK adequacy) | proton.me/legal/privacy |
| Charla (live chat / helpdesk) | Chat widget loaded on demand — Charla is contacted only after you click to open the chat and accept its GDPR consent notice; then your IP address and user-agent are sent and any conversation you start (messages, contact details) is processed on our behalf. Acts as our processor; see § 3.3. No data is sent if you never open the chat | EU | charla.com/privacy-policy |
| Open Collective (Open Collective Inc.) | Outbound links to our public collective ledger | US | opencollective.com/privacypolicy |
5.1 International transfers
The third parties above are predominantly U.S.-based. Where personal data is transferred outside the UK or EEA, we rely on the recipients' own transfer safeguards under UK GDPR Art. 46 and Chapter V — typically the EU Standard Contractual Clauses (SCCs) with the UK Addendum, or the UK International Data Transfer Agreement, depending on the recipient. For Google services, we additionally rely on the EU-U.S. Data Privacy Framework (DPF) and its UK extension (the "UK Extension to the EU-U.S. Data Privacy Framework").
06 Cookies & local storage
The public PegaProx websites do not currently set any cookies of their own and do not use analytics. We do not set advertising or tracking cookies.
The single exception is the marketplace at plugins.pegaprox.com, which is an authenticated service. When you log in there, the marketplace sets one cookie:
PEGAPROX_MP— opaque session identifier. HTTP-only, Secure (HTTPS), SameSite=Lax. Strictly necessary for the login session. Absolute lifetime: 14 days; rotated every 30 minutes against session-fixation; deleted on logout. No analytics, advertising or tracking purpose. Lawful basis: strictly necessary — UK PECR Reg. 6(4) / ePrivacy equivalent.
Note that third-party cookies may still be set by the providers in § 5 when you load a page that triggers their resources — for example, YouTube may set cookies when its video player initialises, and the Charla chat widget (§ 3.3) may set a functional cookie once you open the chat and accept its consent notice. These are set by the respective provider, not by us; the Charla cookie is functional (it maintains the live-chat conversation you choose to start, and is only set after you open the chat and consent) rather than for advertising or cross-site tracking. Your browser settings control whether you accept these.
The PegaProx software, when you install it on your own infrastructure, uses its own session cookies and a small number of localStorage entries (e.g. UI-language preference, sidebar collapse state). Those run on your own server, are scoped to the cluster you log into, and are covered by your own organisation's privacy policy as data controller.
If we add functionality to the public websites that requires cookies in the future (e.g., a contact form with CSRF protection, an opt-in newsletter), we will add a cookie banner with consent management for any non-essential cookies and update this notice accordingly.
07 Retention periods
- Server access logs — IP addresses retained in full for up to 7 days (security-incident window), then truncated as described in § 3.1. Truncated logs retained for up to 90 days for capacity-planning purposes, then deleted.
- Update-mirror logs — same as access logs above.
- Email correspondence — retained as long as the matter is active, plus a reasonable buffer for follow-up. Routine support threads are typically deleted within 2 years of last activity. Sponsorship-related emails may be retained longer where required for accounting traceability.
- Phone-call notes (taken by the receptionist) — passed to us by email and retained per the email policy above.
- Phone-call audio recordings — retained by the reception service for up to 30 days for quality and dispute purposes, then automatically deleted. Where a specific recording is needed as evidence in an active matter (e.g. a sponsorship dispute or security incident), it may be exported to a separate case file and kept for the duration of that matter plus a reasonable buffer, but never longer than necessary for the purpose. You may request access to or deletion of a recording of your own call at any time — see § 8 and § 9.
- Marketplace account profile, plugins, reviews — retained until you delete your account. On account deletion, your reviews are anonymised (username replaced with "[deleted user]") and approved plugin submissions remain listed with the same anonymisation; pending submissions are removed entirely.
- Marketplace audit-log entries (with IP) — retained for 30 days, then automatically pruned by a scheduled job. IPs are not separately retained beyond that window.
- Marketplace session cookie — 14 days maximum, or until logout / inactivity timeout.
- Marketplace email-verification tokens — 24 hours, then expired and deleted; a new token can be requested.
- Marketplace used backup codes — flagged as used and kept for up to 1 year for fraud-investigation traceability, then deleted.
- Backups — system backups containing log and email data are kept for up to 30 days in encrypted form before being overwritten. Personal data may persist in backup snapshots for that period after deletion from the live system.
08 Your rights as a data subject
Under the UK GDPR (and the EU GDPR where applicable to you), you have the following rights regarding personal data we hold about you:
- Right of access (Art. 15) — request a copy of the personal data we hold about you
- Right to rectification (Art. 16) — ask us to correct inaccurate or incomplete data
- Right to erasure / "right to be forgotten" (Art. 17) — ask us to delete your data, subject to legal exceptions
- Right to restriction of processing (Art. 18) — ask us to limit how we use your data while a dispute is resolved
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format where the processing is based on consent or contract and carried out by automated means
- Right to object (Art. 21) — object to processing based on our legitimate interest, and we will stop unless we can show compelling overriding grounds
- Right not to be subject to automated decision-making (Art. 22) — we do not carry out solely-automated decisions producing legal effects on you
- Right to withdraw consent — where we ever rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal
Exercising these rights is free of charge except where requests are manifestly unfounded or excessive (UK GDPR Art. 12(5)). We aim to respond within one calendar month of receiving your request, in line with Art. 12(3); complex cases may extend this by up to two further months, in which case we will notify you of the extension and the reasons.
09 How to exercise your rights / contact us
plugins.pegaprox.com account, you can exercise the access and erasure rights yourself, without writing in:
- Art. 15 access — log in and visit Dashboard → Privacy & data → Download my data. You will receive a JSON file containing every personal-data field we hold about your marketplace account.
- Art. 17 erasure — log in and visit Dashboard → Privacy & data → Delete my account. After confirming with your password (and 2FA if enabled), your account is anonymised immediately. Approved plugin submissions and reviews you authored remain visible but the author label switches to
[deleted user].
10 Right to lodge a complaint
If you believe our processing of your personal data infringes the UK GDPR or the EU GDPR, you have the right to lodge a complaint with a supervisory authority — without prejudice to any other administrative or judicial remedy.
- UK: Information Commissioner's Office (ICO) — ico.org.uk/make-a-complaint
- EU member state: the supervisory authority of the member state of your habitual residence, place of work, or place of the alleged infringement. The European Data Protection Board maintains a directory: edpb.europa.eu/about-edpb/members
We would, however, appreciate the chance to address your concern first — please reach out to us before contacting the regulator if practical.
11 Children
Our websites are aimed at IT professionals and developers and are not directed at children. We do not knowingly collect personal data from children under 16 (UK / EU minimum age for information-society-service consent under GDPR Art. 8). If you believe a child has provided us with personal data, please contact us at support@pegaprox.com and we will delete it.
12 Security
We protect personal data with the following technical and organisational measures, in line with UK GDPR Art. 32:
- Transport encryption — all public websites are served exclusively over HTTPS with HSTS
- At-rest encryption — backup volumes are encrypted with AES-256
- Access control — administrative access to web infrastructure is restricted to a small number of named individuals using SSH-key authentication and 2FA where supported
- Patching — systems are kept on supported, security-patched versions of their underlying OS and runtime
- Minimisation — we deliberately collect as little personal data as the operational purpose allows; truncating IPs in access logs after the security-incident window is part of this
- Incident response — in the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware (UK GDPR Art. 33) and inform affected data subjects without undue delay where required by Art. 34
13 Changes to this notice
We may update this Privacy Notice from time to time — for example, when we add new functionality to the websites, change service providers, or in response to changes in applicable law. The version number and "last updated" date at the top of this page will reflect the current revision. Material changes will be announced with reasonable prominence (a notice on the homepage or a banner on the affected page) before they take effect.
An archive of previous revisions is available on request via support@pegaprox.com.