Legal
Privacy Policy
Last updated: [DATE]. Effective for accounts created on or after that date.
Draft — pending legal review
This is a first draft prepared for internal review, not a finalized or legally reviewed document. It should not be relied upon, linked publicly, or treated as accurate until reviewed by qualified counsel, the sub-processor list is confirmed against actual production infrastructure, and the bracketed placeholders below are filled in with real values.
This Privacy Policy explains how Sæle Digital ("Decretum", "we") handles personal data in connection with the Decretum Cloud Service at decretum.app. It does not cover Self-Hosted Deployments — see Self-Hosted Deployments below for why.
Self-Hosted Deployments
Where an organization deploys Decretum on its own infrastructure (for example, via the provided Docker image), that organization — not Decretum — controls the database, storage, and email delivery, and is the data controller for any personal data processed there. This Privacy Policy does not apply to that data; the deploying organization's own privacy policy governs it. Decretum, as the software provider, does not receive, store, or process personal data from a Self-Hosted Deployment in the ordinary course of its operation.
1. Who We Are
Sæle Digital (org. no. 838 358 152), Breimyra 74, 5134 Flaktveit, Norway, is the data controller for personal data processed through the Decretum Cloud Service. Contact: support@decretum.app.
2. What We Collect
We collect the following categories of personal data through the Cloud Service:
- Account data — name and email address, whether provided directly (email/password sign-up) or via a third-party identity provider (Google, Microsoft Entra ID) you choose to sign in with. We do not receive your password from those providers, only confirmation of your identity and the profile fields they share.
- Organization data — your role within an Organization, and, for invited members, the email address an Admin used to invite you.
- Content you submit — decisions, posts, comments, tags, and file attachments your Organization creates in the Service. This may include personal data your Organization chooses to include in that content; Decretum does not control what an Organization's Users write.
- Usage and preference data — settings such as language, date/time format, dashboard layout, and notification preferences, plus technical logs (e.g. request logs, error logs) generated by operating the Service.
We do not use third-party advertising or analytics trackers on the Cloud Service. The application sets two cookies: a session cookie required to keep you signed in, and a locale-preference cookie that remembers your chosen display language. Neither is used for tracking or advertising.
3. Why We Process It (Legal Basis)
- Performance of a contract — to create your account, operate your Organization's workspace, and provide the Service you or your Organization signed up for.
- Legitimate interests — to secure the Service, diagnose and fix problems, and improve reliability, balanced against your rights.
- Consent — where required for a specific optional feature (for example, connecting an optional third-party identity provider).
- Legal obligation — where we must retain or disclose data to comply with law.
4. Who We Share It With
We do not sell personal data. We share it only with the sub-processors necessary to operate the Cloud Service, under contractual terms requiring them to protect it, and with an Organization's own Users to the extent your Organization's visibility and access-control settings permit:
- Application hosting — Vercel Inc.
- Database hosting — Neon, Inc., a managed PostgreSQL provider running on Amazon Web Services infrastructure in the Frankfurt, Germany (eu-central-1) region
- File attachment storage — Amazon S3 (Amazon Web Services, Inc.), in the Frankfurt, Germany (eu-central-1) region
- Email delivery — Zoho Mail (Zoho Corporation B.V.), used to send notification and digest emails, processed in Zoho's EU data centers
- Identity providers — Google and/or Microsoft, only if and when you choose to sign in through them
We may also disclose personal data where required by law, to enforce our Terms of Service, or to protect the rights, safety, or property of Decretum, our Customers, or others.
5. International Data Transfers
Our database, file storage, and email delivery are located in the EU/EEA (Frankfurt, Germany for the database and file storage; Zoho's EU data centers for email). Two of our infrastructure providers — Vercel Inc. and Neon, Inc. — are United States companies that may access personal data from the United States in the ordinary course of providing their services (for example, for customer support or account administration), even though the data itself is stored in Frankfurt. Where this occurs, we rely on those providers' certification under the EU-U.S. Data Privacy Framework, with the Standard Contractual Clauses approved by the European Commission applying as a fallback safeguard. [PLACEHOLDER — confirm our application hosting provider's compute region is explicitly configured for the EU/EEA before this is published as settled fact.]
6. Data Retention
We retain Organization and Content data for as long as the Organization's account remains active. If an Organization's account is closed, we retain data for [PLACEHOLDER — e.g. 30 days] to allow export or reactivation, then delete it, except where retention is required by law or for legitimate business records (for example, billing history).
7. Your Rights
Depending on your location, you may have the right to access, correct, export, or delete your personal data, object to or restrict certain processing, and withdraw consent where processing is based on consent.
Export and deletion are self-service. You can export your own account data, and delete your own account, directly from Settings within the Service. Deleting your account signs you out immediately. For 14 days afterward, you can cancel the deletion using the link sent to your email. After that window, we permanently remove your name, email address, and other personal identifiers from your account. Decisions, posts, and other Content you authored remain part of your Organization's record — that Content belongs to your Organization, not to you individually (see Terms of Service §5) — and is not deleted; your name on it is replaced with a generic label (for example, "Former member") once your account is purged.
For other rights — correcting inaccurate data, objecting to or restricting certain processing, or withdrawing consent — contact support@decretum.app. Where an Organization's Admin manages your account (for example, a work account created by your employer), some requests may need to go through your Organization's Admin, since they control your account within the Service. EU/EEA residents also have the right to lodge a complaint with their local data protection authority.
8. Security
All traffic between your browser and the Service is encrypted in transit (TLS). Access within an Organization is governed by role-based permissions and, for restricted decisions, explicit collaborator lists. See the Security & Deployment page for more detail. No system is perfectly secure; we cannot guarantee absolute security of information transmitted to the Service.
9. Children's Privacy
The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal data from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide reasonable notice (for example, by email to an Organization's Admins or a notice within the Service) before the change takes effect.
11. Contact
Questions about this Privacy Policy, or requests relating to your personal data, can be sent to support@decretum.app.