Privacy Policy
Summary
RatelKey holds your account, your sessions, and a record of the Burrows you may enter. RatelKey does not hold the contents of a Burrow, including its secrets, which remain on the infrastructure you operate.
This summary is provided for convenience under Article 12(1) GDPR. Sections 00 to 13 govern.
Section 00
Scope
This policy applies to ratelkey.com and to the services operated by RatelKey: the account and sign-in service, the relay, and the update service. It states the personal data RatelKey processes, the purposes and legal bases for that processing, the retention periods applied, and the rights available to data subjects.
It does not apply to the contents of a Burrow operated by a customer, which are addressed in section 03. This policy is to be read together with the Terms of Service.
Section 01
Data Controller
RatelKey is the controller of the personal data listed in section 02. Contact details are given in section 13.
A Burrow is installed and operated by the customer on their own infrastructure. Where the contents of a Burrow include personal data, the operator of that Burrow is the controller of it. RatelKey is neither controller nor processor of that data and does not receive it. Section 03 applies.
Section 02
Personal Data We Collect
RatelKey collects and processes the following:
- Account data. Email address, username, password hash (Argon2id), profile image selection, and email confirmation status.
- Passkey data. Where a passkey is registered, its public key, credential identifier and device label. The private key remains on your device and is not transmitted to RatelKey.
- Session data. For each session, the originating IP address and user agent, the time of creation and the time of expiry.
- Sign-in history. For each sign-in attempt, the source IP address, the outcome, and the reason for failure.
- Burrow registration data. For each Burrow claimed by an Account, its identifier, the callback address it supplied, and the Accounts holding membership of it.
- Service records. Actions performed against RatelKey services, including claiming a Burrow, entering a Burrow, signing out and membership changes, recorded with the Account and source IP address responsible.
- Relay connection metadata. Where the relay is used, the Burrow a connection was destined for, its time, and the volume of data transferred.
- Email records. Recipient address, message type and delivery outcome.
RatelKey does not operate analytics, advertising or third-party tracking on ratelkey.com. RatelKey does not carry out profiling or automated decision-making producing legal or similarly significant effects.
Section 03
Data Held in a Burrow
Secrets, projects, environments, machine registrations and the audit trail of a Burrow are stored in that Burrow’s database, on infrastructure operated by the customer. They are not transmitted to RatelKey and RatelKey holds no copy of them.
Values are encrypted under a key-encryption key supplied to the Burrow through its environment. RatelKey does not receive that key and cannot decrypt, produce or restore the data protected by it.
Where a Burrow is reached through the relay, connections are encrypted to the Burrow and terminated there. RatelKey does not have access to the contents of relayed connections.
RatelKey cannot respond to a request from a data subject, a supervisory authority or a court for the contents of a Burrow, and will direct such a request to the operator of that Burrow.
Section 04
Legal Basis for Processing
- Performance of a contract (Article 6(1)(b) GDPR) for Account data, session data and Burrow registration data.
- Legitimate interests (Article 6(1)(f) GDPR) for sign-in history, service records, relay connection metadata and rate limiting. The interest pursued is the security and continued operation of the Service. A balancing assessment has been carried out and is available on request.
- Legal obligation (Article 6(1)(c) GDPR) where retention or disclosure is required by law.
RatelKey does not rely on consent for any processing described in this policy. You may object to processing based on legitimate interests in accordance with section 10.
Section 05
How We Use Personal Data
RatelKey processes the data listed in section 02 in order to:
- Authenticate you and respond to a Burrow’s validation of your session.
- Present your active sessions and allow you to revoke them.
- Send service email, including address confirmation and password reset.
- Detect, investigate and prevent abuse, and apply rate limits.
- Route connections through the relay where it is used.
- Comply with legal obligations and respond to lawful requests.
RatelKey does not sell personal data, does not disclose it for advertising purposes, and does not use it to train machine learning models.
Section 06
Disclosure and Processors
RatelKey engages third parties in providing the Service. Each is identified in the sub-processor register, together with its role, the purpose of the processing, the categories of personal data concerned, the location of processing and the applicable transfer mechanism.
A party listed in that register as a processor acts under a written agreement satisfying Article 28 GDPR and processes personal data only on RatelKey’s documented instructions. A party listed as an independent controller determines its own purposes and means under its own terms.
RatelKey maintains the register and will give at least 30 days’ notice, by email to the address associated with your Account or by notice in the dashboard, before engaging a new processor.
RatelKey does not disclose personal data to any other party except where required by law. Where RatelKey receives such a request, it will notify the data subject unless prohibited from doing so.
In the event of a merger, acquisition or transfer of assets, personal data may be transferred as part of that transaction. Data subjects will be notified before any change to this policy takes effect.
Section 07
International Transfers
RatelKey services and the data listed in section 02 are hosted within the European Union. Where a processor operates outside the European Union or the European Economic Area, the transfer is made under an adequacy decision or under the European Commission’s Standard Contractual Clauses, with supplementary measures where required. The mechanism applying to each is stated in the sub-processor register.
The location of a Burrow is determined by the customer operating it. RatelKey has no involvement in that decision and effects no transfer of its contents.
Section 08
Retention
- Account data is retained for the lifetime of the Account.
- Session data is deleted on expiry or revocation.
- Burrow registration data is retained while the Burrow remains claimed.
- Sign-in history and service records are retained for 12 months.
- Relay connection metadata is retained for 90 days.
- Email records are retained for 30 days.
On deletion of an Account, the data listed above is permanently deleted within 30 days, subject to any legal obligation requiring continued retention.
Deletion of an Account does not affect a Burrow or its contents, which remain on the customer’s infrastructure.
Section 09
Cookies and Local Storage
RatelKey sets cookies that are strictly necessary to authenticate you. RatelKey does not set advertising, analytics or tracking cookies, and no consent banner is presented.
rk_bur_atcarries the access token. It is transmitted with requests to RatelKey services and to your Burrow, which uses it to identify you.rk_bur_rtis used to renew an expired session. It is scoped to the sign-in path and is not transmitted with other requests.
Both cookies are set HttpOnly, so they cannot be read by scripts, and SameSite=Lax, so they are not transmitted on cross-site requests. In production both are set Secure and are transmitted only over HTTPS. Where you do not select the option to remain signed in, both are session cookies and are discarded when the browser closes.
Signing out revokes the session on the server in addition to clearing the cookies.
Section 10
Your Rights Under the GDPR
You have the right to:
- Obtain confirmation of processing and a copy of the personal data held about you (Article 15).
- Have inaccurate personal data rectified (Article 16).
- Have personal data erased (Article 17), which you may also effect by deleting your Account.
- Obtain restriction of processing (Article 18).
- Receive your personal data in a structured, machine-readable format (Article 20).
- Object to processing based on legitimate interests (Article 21).
- Lodge a complaint with a supervisory authority (Article 77).
Requests should be sent to the address in section 13 and will be answered within one month of receipt. That period may be extended by two further months where a request is complex, in which case you will be informed within the first month.
Where a request concerns data held in a Burrow, RatelKey will inform the requester that it holds no such data and will direct the request to the operator of that Burrow.
The supervisory authority in Denmark is Datatilsynet. You may also lodge a complaint with the supervisory authority in your country of residence.
Section 11
Security Measures
Passwords are stored as Argon2id hashes and are not recoverable in plaintext. Sessions are opaque tokens with a limited lifetime, revocable by the Account holder, and are validated against the sign-in service on each request rather than accepted on the basis of the token alone.
Traffic between clients and RatelKey services is transmitted over TLS. Requests between RatelKey services are signed and subject to replay protection. Access to production systems is restricted to personnel who require it, and actions taken against Accounts are recorded.
Where a personal data breach is likely to result in a risk to the rights and freedoms of data subjects, RatelKey will notify the competent supervisory authority within 72 hours of becoming aware of it in accordance with Article 33 GDPR, and will notify affected data subjects without undue delay where the risk is high in accordance with Article 34.
Section 12
Children
The Service is intended for persons aged 18 and over and is not directed at children. RatelKey does not knowingly collect personal data from persons under 18. Where RatelKey becomes aware that such data has been collected, it will be deleted. Contact the address in section 13 to report an Account held by a child.
Section 13
Changes to This Policy
RatelKey may update this policy. Material changes will be notified by email to the address associated with your Account, or by notice in the dashboard, at least 30 days before they take effect. The effective date stated above reflects the current version.
Section 14
Contact
For privacy enquiries, to exercise a right under section 10, or to report a vulnerability affecting the Service: