STALE MEASUREMENTPast this project's own 2-release window: the published result was measured with v0.32.0, 9 releases ago. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart
LEGAL

Privacy policy.

This policy covers the provael.com website. It is written to meet the EU GDPR and India’s Digital Personal Data Protection (DPDP) Act. Effective 26 July 2026.

Who we are

Provael, maintained by Sattyam Jain (India). Contact:hello@provael.com.

What we collect

  • Analytics. When analytics is enabled on a deployment we use cookieless, privacy-first analytics (Plausible, and optionally PostHog in memory-only mode). These do not use cookies or cross-site identifiers and do not build a profile of you. Because they are cookieless, we do not show a consent banner. This deployment ships no analytics script at all.
  • Repository lookup. When you hover over or focus the GitHub star control, the site reads the project’s star count from GitHub’s public API. That request sends your IP address and browser user-agent to GitHub; no cookie is set and we store nothing from it. It does not run on page load.
  • The contact form. If you submit the request form on the homepage or the readiness snapshot, we receive the fields you enter (name, work email, company, stack, milestone, what you want to prove, role and a message) together with your country as derived by Cloudflare from your IP address, your browser user-agent and the time of submission. The submission is written to a Cloudflare KV store, forwarded to our lead backend on Amazon Web Services (a DynamoDB table in the us-east-1 region), and, when that path is configured, emailed to us through Resend. To limit abuse, a per-IP counter of submissions is kept in Cloudflare KV for two hours. If none of these capture paths succeeds, the page offers a pre-filled email instead and nothing is stored.
  • Email you send us. If you email us, we process the contact details and message you provide to respond.
  • Booking. Scoping calls are arranged by email today. If a scheduling embed (Cal.com) is switched on in future, it will process the details you enter to arrange the meeting and this section will say so.

We do not collect special-category data, and we do not sell personal data.

Legal basis (GDPR)

  • Legitimate interest for aggregate, cookieless analytics that cannot identify you.
  • Steps to enter into / perform a contract for assessment enquiries and bookings.

Subprocessors

This is the same list published in the diligence packet at /trust; the two pages render one source.

  • Cloudflare (Global edge; form data lands in the stores below) - Hosts and serves this website; runs the server-side function behind the contact form. Touches: Website traffic metadata, and the fields you type into a contact form in transit.
  • Amazon Web Services (US (us-east-1)) - Durable store for contact-form submissions (the operated lead backend). Touches: Name, email, organisation and the message you submit. No assessment data, ever.
  • Resend (US) - Email delivery for contact-form notifications, used as a fallback capture path. Touches: The same contact-form fields, in an email.
  • GitHub (US) - Source hosting, CI, issue tracking and release publishing. Touches: Public source and public issues. Nothing customer-confidential is placed here.
  • PyPI (US) - Distributes the open-source package. Touches: Nothing of yours. Your installs are visible to PyPI as anonymous download counts.
  • Cal.com (EU/US) - Scheduling embed for a scoping call - not switched on in production today (calls are arranged by email); listed so the list is complete if it is enabled. Touches: Nothing today. If enabled: the name, email and time you enter to book a call.
  • Plausible / PostHog (EU (Plausible) / US (PostHog)) - Cookieless website analytics, environment-gated and off unless configured. Touches: Aggregate page-view data. No cookies, no cross-site identifiers.
  • GitHub (Microsoft, United States) also receives the star lookup described above.
  • Analytics (Plausible / PostHog) - not enabled on this deployment. If either is switched on, it is listed here with the endpoint it sends to.
  • Cal.com - assessment-call scheduling (loaded only when you choose to book).

Retention

Analytics are aggregate and not tied to you. Contact-form submissions expire automatically730 days after they are received, in both the Cloudflare KV store and the AWS lead backend; the per-IP rate-limit counter expires after two hours. Emails you send us are kept only as long as needed to respond and to meet legal obligations, then deleted. You can ask for earlier deletion at any time (see your rights below).

Your rights

Under the GDPR and the DPDP Act you may request access, correction, erasure, restriction, portability, or object to processing, and you may withdraw consent. Email hello@provael.com and we will respond within the statutory timeframe. EU/EEA users may also complain to their supervisory authority.

International transfers

We are based in India and use processors in multiple regions. India is not currently the subject of an EU adequacy decision, so where personal data of EU or UK data subjects is transferred to India we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum), supported by a transfer-impact assessment of the destination’s laws and safeguards. Such data is processed in line with both the GDPR and India’s Digital Personal Data Protection Act, 2023 (DPDP Act). Where a processor stores data within the EEA or UK, no such transfer arises.

Some processors are outside the EEA or UK. Contact-form submissions are stored on Amazon Web Services in the United States (us-east-1) and, when that path is configured, emailed through Resend (United States). GitHub (Microsoft) is United States based, so the repository lookup described above involves a transfer to the US. Each of these transfers is made under the transfer mechanism that processor publishes for EU/UK data (standard contractual clauses). Analytics endpoints are set per deployment, so the processing region is whichever the host named in the subprocessor list above implies - it is not guaranteed to be the EEA.

EU/UK representative

Provael is a small, non-EU open-source project. We will appoint a GDPR Article 27 representative in the EU (and a corresponding representative under the UK GDPR) if and when our processing of EU or UK personal data reaches a level that requires one. Until then, EU and UK data subjects may exercise their rights and raise any concern directly with us at hello@provael.com, and may also complain to their local supervisory authority.

Changes

We will update this page as our processing changes and revise the effective date.