Legal
Privacy Policy
What we collect about the people who sign in, and why.
- Version
- draft-2026-09-09
- Bundle
- draft-2026-09-09
- Permanent
- this page
- Status
- Draft - not in force
This is a permanent, dated copy of Privacy Policy version draft-2026-09-09. It is never edited. The version currently in effect is at /legal/privacy.
1. Who this is about
This notice describes what FortressFlag LLC (“FortressFlag”, “we”) does with personal data for which we are the controller: the data we collect to run our business and to let people sign in to our dashboard.
It is a notice under Articles 13 and 14 GDPR. It is not a contract. You are not asked to agree to it, only to confirm that you have read it. What we do with the personal data our customers put into the platform — where they are the controller and we are their processor — is governed by the Data Processing Agreement instead.
Contact: [[PRIVACY_CONTACT]], or by post to FortressFlag LLC, [[ENTITY_ADDRESS]].
2. This website
The marketing site you are reading collects nothing. No forms, no cookies, no analytics, no
tracking pixels, no third-party scripts. The one thing it stores on your device is your light/dark
preference, in localStorage under the key ff.theme, written only if you click the switch. It
holds no identifier, is readable only by this site, and is never sent anywhere.
That is why there is no cookie banner. A preference you set through the interface, for the sole purpose of customising that interface, does not require consent under ePrivacy Article 5(3).
Our documentation site, docs.fortressflag.com, behaves the same way: search runs entirely in
your browser, and the one thing it stores on your device is your theme preference.
3. What we collect, and why
| What | Why | Lawful basis |
|---|---|---|
| Your name and email address, when you create an organisation or accept an invitation | To create your account, identify you, and attribute changes you make | Performance of a contract (Art. 6(1)(b)) |
| Your password, stored only as an Argon2id hash | To authenticate you | Performance of a contract |
| Your TOTP secret and recovery codes, if you enrol a second factor | To authenticate you | Performance of a contract |
| The IP address of a sign-in, and of each audited action | Security: to investigate suspicious access and to make an audit record complete | Legitimate interests (Art. 6(1)(f)) — securing a system that holds the switches controlling our customers’ production software |
| The name and role of each member of an organisation | To operate role-based access control | Performance of a contract |
| Your organisation’s name, its URL slug, and the billing contact | To run the account and to bill it | Performance of a contract |
| A record that you accepted a specific version of our legal documents, including your email address as it stood at that moment, the document versions and hashes, the time, and the originating IP address | To prove that a contract was formed, and on what terms | Legitimate interests, and Art. 17(3)(e) for its retention |
| A support ticket you open — its subject, description, replies, and any files you choose to attach | To provide support and resolve the issue you raised | Performance of a contract (Art. 6(1)(b)) |
We do not collect user-agent strings, we do not use advertising or analytics cookies in the dashboard, and we do not profile you or make automated decisions with legal or similarly significant effects.
4. Who else sees it
Our sub-processors, listed at fortressflag.com/legal/subprocessors. The list covers both the customer data we process and the account data described here.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
We disclose personal data to a public authority only where we are legally compelled, and we will tell you unless the law forbids it.
5. Where it is processed
Outside the European Economic Area and the United Kingdom. Where a transfer requires a safeguard under Chapter V GDPR we rely on the Standard Contractual Clauses and, where the UK GDPR applies, the UK International Data Transfer Addendum.
6. How long we keep it
| What | How long |
|---|---|
| Account records (name, email, membership, role) | For the life of the account |
| Password hash, second-factor secret, recovery codes | For the life of the credential |
| Session records, including the sign-in IP address | Retained indefinitely today. Expiry is enforced when a session is read, and revocation marks a session rather than deleting it. No sweep job is built. We would rather say that plainly than describe a deletion routine that does not run. |
| Pending invitations, including the invited email address | Expire after seven days; the row is retained |
| Support tickets, replies and attachments | For the life of the organisation’s account |
| Audit records, including the pseudonymous actor reference and the source IP | For the life of the customer relationship. Deleted only by a deliberate, separately authorised purge |
| Contract-acceptance records | For the life of the relationship, and for as long as a claim may be brought |
7. Your rights
You have the right to access your personal data, to have it corrected or erased, to restrict or object to processing, and to data portability. You can withdraw consent where we rely on it (today we do not rely on consent for anything described here).
The honest state of these paths. There is no self-service export or deletion in the product today, and there is no screen on which you can edit your own name or email address. A request to [[PRIVACY_CONTACT]] is answered by hand. We respond within one month, as Article 12(3) requires, and we will tell you if we need the permitted extension.
Erasing an account removes the account record, its memberships, its sessions and its access grants. Three things deliberately survive, and you should know before you ask:
- Audit records. They keep a pseudonymous reference to the actor rather than your name. After erasure the log still shows that one actor performed a sequence of actions; it no longer shows who. Our customers are entitled to a complete change history of their own production configuration.
- Contract-acceptance records, if you accepted our terms on behalf of an organisation. These keep your email address as it stood at acceptance, under Article 17(3)(e) — establishment, exercise or defence of legal claims.
- Support messages. Messages and attachments in an organisation’s support threads remain, because they are part of that organisation’s record. Erasure removes the link to your name, so the thread no longer identifies who wrote them.
If you are unhappy with how we have handled your data you may complain to the supervisory authority where you live or work. FortressFlag LLC is established in the United States and does not have a lead supervisory authority in the EEA.
[[EU_REPRESENTATIVE]] — the details of our representative in the Union under Article 27 GDPR, once appointed, will appear here.
8. Security
Described in Annex A of the Data Processing Agreement, including the measures that are not yet in place.
9. Children
The Service is a business tool. It is not directed at children, and we do not knowingly collect personal data from anyone under 16.
10. Changes
We publish each version of this notice at a permanent, dated URL and never edit a published version in place. Where a change is material we tell you in the product.
All five documents, and their versions, are listed at /legal.