What we collect, and why it is so little
This policy describes the data SEGARK handles when you create an account, buy a plan and use the portal. It was written from the code that runs, not from a template.
The most important thing
Your security events never reach us. SEGARK Pipeline is self-hosted in every edition: it runs on your infrastructure, and the licence is verified locally with no phone-home. We do not receive, do not store and cannot see the logs, alerts or telemetry moving through your pipeline.
What this policy covers is only what happens on the website and the buyer portal at segark.com: creating an account, subscribing to a plan, issuing and downloading a licence, and contacting support.
The open-source engine (CentralOps, AGPLv3) needs no account, needs no licence and never talks to us. If you only run the Community edition, we handle no data of yours at all.
Who handles the data
The controller of your data is Segark Consulting LTDA, registered under CNPJ 64.471.727/0001-30, which operates SEGARK Pipeline. For anything about privacy, including to exercise the rights below, write to support@segark.com. We answer by email, at the same address.
What we collect, moment by moment
When you create an account we store:
- Required. It is your identity in the portal and where the licence and billing notices are sent.
- Name
- Optional. Only so we can address you.
- Organisation
- Optional. Shown in the portal, and it helps support find your deployment.
- Password
- Stored irreversibly. We cannot recover or read it, and a database leak does not expose your password.
If you sign in with Google we request the openid, email and profile scopes. We store the stable identifier of your Google account, the email and the name. We do not request and do not receive your calendar, your contacts or your files.
When you subscribe to a plan:
- Stripe customer identifier
- An opaque reference that links your account to the subscription.
- Subscription data
- Plan, status, seat count, billing interval and the next renewal date.
No card data passes through our servers. Payment happens entirely on Stripe-hosted pages, and changing a card, cancelling and downloading invoices all live in Stripe's own billing portal. We never see, transmit or store a card number, a CVV or a cardholder name.
When a licence is issued we store its details (plan, enabled features, seats, organisation cap, and issue and expiry dates), along with an audit record of every issue, renewal and revocation.
If your plan grants access to the Enterprise images, we record that access was granted and when it expires. We never store the credential itself.
Who we share with
We do not sell personal data and we do not share it for advertising. We use a small number of processors, each for a functional reason:
- Stripe
- Processes payment and hosts the checkout and billing portal. It receives your email and the payment details you type directly into its pages.
- Only if you choose to sign in with Google. In that case Google confirms your identity to us.
- GitHub
- Hosts the open-source code, the documentation and the Enterprise image registry.
- Railway
- Hosts the website and the billing API.
These processors are outside Brazil. The international transfer happens in order to perform our contract with you: to bill the subscription, authenticate access and deliver the software.
How long we keep it
We keep account data for as long as the account exists. Sessions expire on their own after 30 days. Licence and billing records are kept for as long as they are needed to evidence what was sold and to meet tax and accounting obligations.
When an account is closed we erase your email, name, organisation, password and Google link, and end every session. The billing record is removed when the paid period ends. Until then it has to exist for the subscription you are still using. The record of the sale stays for the statutory period, with nothing in it that identifies you.
Your rights
Under Brazil's LGPD (and, if you are in the European Union, under the GDPR) you may request confirmation of processing, access, correction, portability, anonymisation, blocking or erasure, and you may withdraw consent.
You can close the account yourself, from Settings in the portal. Your personal data is erased straight away and the subscription stops renewing. You do not lose what you already paid for: the licence keeps working until the end of the period. We ask for your password first, so a stolen session cannot do it for you. If you prefer, write to support@segark.com and we will do the same.
We answer by email, at the same address. If you are unhappy with the answer, you may complain to Brazil's data protection authority (ANPD).
How we protect it
- Your password is stored irreversibly. Not even we can read it.
- Sessions are stored so that reading the database does not let anyone impersonate you.
- Access to billing systems is restricted and kept separate from the rest of the environment.
- Sensitive pages limit repeated attempts.
- Licences are digitally signed, and the signing key never leaves the service that issues them.
Changes to this policy
If we change what we collect or who we share it with, we update this page and the date above. Material changes are announced by email to account holders.