← Back to Cardean
Legal

Privacy notice

This notice explains what personal data Cardean collects through cardean.io and the Cardean software, and the basis on which we process it under the EU General Data Protection Regulation (Regulation (EU) 2016/679).

Last updated · 2026-06-09

1. Who is the controller

Cardean is operated by Cardean B.V., Amsterdam, the Netherlands. For privacy questions, contact [email protected].

2. What we collect on cardean.io

This marketing site is intentionally low-trust. We do not run third-party analytics, ad trackers, or fingerprinting on cardean.io. Server access logs (IP address, user-agent, request path, timestamp) are kept up to 30 days for security and abuse defence on the basis of legitimate interests (Art. 6(1)(f) GDPR).

  • No cookies are set by default. The only browser storage we use is a localStorage key recording your chosen UI language.
  • External calls from the page are limited to font files and icon assets we host ourselves and a CDN-served icon library; see Cookies & storage.
  • No personal data is sold or shared with brokers, ever.

3. What the Cardean gateway processes

The Cardean gateway is self-hosted software you run on your infrastructure. Cardean B.V. has no access to traffic that passes through your deployment. The software is engineered to minimise what touches disk and what leaves the process:

  • PII and secrets are redacted before any request leaves your perimeter — see the Cardean Gateway page and the docs.
  • Audit events carry request IDs and policy outcomes — never prompts, completions, or bearer tokens.
  • The binary makes no telemetry or "phone-home" calls. Outbound traffic is limited to the model providers you configure.
  • When you classify a route as residency: eu-only, the gateway rejects the request rather than fall through to a non-EU endpoint.

4. Contact & commercial enquiries

If you contact us by e-mail or via a contact form on cardean.io, we process the data you submit (name, organisation, e-mail, message) to reply and to keep a record of the exchange. The basis is performance of pre-contractual steps at your request (Art. 6(1)(b) GDPR) or legitimate interests (Art. 6(1)(f)). Contact records are kept for up to 24 months after the last interaction.

5. International transfers

Where cardean.io is served from a CDN with edge nodes outside the EU/EEA, transfers rely on the European Commission's adequacy decisions or on Standard Contractual Clauses. The Cardean software itself does not transfer data — your deployment decides which providers and regions to route to.

6. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing carried out on the basis of legitimate interests. You also have the right to lodge a complaint with a supervisory authority — for the Netherlands, the Autoriteit Persoonsgegevens.

7. Security

We follow the principles set out in our security & disclosure policy. The gateway is shipped with reproducible builds, a CycloneDX SBOM, and SLSA provenance with every release.

This document is provided for transparency. It does not replace tailored legal advice for your jurisdiction.