1. Controller and Data Protection Officer
The controller is cdnCore, Lda., CIEC — Centro de Inovação Empresarial da Covilhã, R. António Augusto de Aguiar 60, 6200-053 Covilhã, Portugal.
We have appointed a Data Protection Officer. Contact: [email protected].
2. An important distinction
Operational data processed inside an AtlasEye installation — syslog, device inventory, topology, alerts, incidents and any personal data they contain — belongs to the customer, and the customer is its controller.
Self-hosted: that data stays on the customer's infrastructure and cdnCore does not receive it. Managed by cdnCore: cdnCore processes it on the customer's behalf, as processor, on a dedicated instance in Portugal under a Data Processing Agreement.
cdnCore is the controller only for its own processing: website visitors, enquiries, trial requests, commercial relationships, account administration and support.
3. Personal data we process
- Identification and contact data — name, business e-mail, telephone, company and role.
- Trial request data — company, country, intended use and the number of devices you plan to monitor.
- Enquiry content — what you write to us and the correspondence that follows.
- Account administration data — named operators, roles and licence records.
- Support data — tickets, logs and diagnostic material you choose to send us.
- Technical data from the website — IP address, device and browser information, pages viewed, kept in server logs.
4. Why we process it, and on what basis
- Answering enquiries, reviewing trial requests and preparing proposals — steps taken at your request before entering a contract.
- Supplying the platform, the managed service, licences and support — performance of a contract.
- Security, abuse prevention and service improvement — our legitimate interests.
- Invoicing, accounting and statutory records — legal obligation.
- Marketing communications, where applicable — consent, withdrawable at any time.
7. International transfers
Our own processing takes place inside the European Economic Area, and managed instances are hosted in Portugal. Where a provider processes data outside the EEA, we rely on an adequacy decision or on the European Commission's standard contractual clauses together with any additional measures the transfer requires.
If you connect an AI model provider to your installation, data you allow the AI to see is sent to that provider under your own agreement with it.
8. How long we keep it
- Enquiries and trial requests that do not lead to a contract: 24 months from the last contact.
- Contracts and the correspondence that documents them: 10 years after the contract ends.
- Invoices and accounting records: 10 years, as required by Portuguese tax law.
- Support tickets and operational correspondence: 3 years from closure.
- Website and mail server logs: 6 months, then deleted.
- Where a longer period is needed to establish, exercise or defend a legal claim, we keep the specific records concerned until that need ends.
9. Your rights
You may request access, rectification, erasure, restriction and portability, and object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time.
Write to [email protected]. We respond within one month; complex requests may take up to two further months, and we will tell you if that applies.
10. Complaints
If you believe we have handled your data unlawfully you may complain to the Comissão Nacional de Proteção de Dados (CNPD), the Portuguese supervisory authority, or to the authority where you live or work.
11. Security
We apply technical and organisational measures appropriate to the risk. The GDPR page and the Security page describe them in more detail.
12. Changes
We update this policy when our processing changes. The date at the top of the page always reflects the current version.