Privacy Policy

Effective date: June 2026 · Last updated: June 2026

1. Data Controller

The data controller for InfraBase is:

Brightline Software

Zur Bütenheide 21, 14621 Schönwalde-Glien, Germany

CEO: Melanie Marcelus · datenschutz@infrabase.tech

2. What Data We Collect

We collect only what is necessary to provide the InfraBase service:

  • Account data: email address and password (via Supabase Auth) when you sign up.
  • Organisation data: company name and office locations you enter during setup.
  • Device inventory data: hardware records, serial numbers, MAC addresses, IP addresses, and any other asset information you input into InfraBase.
  • Audit log data: which user made which change and when, retained to support your compliance obligations.

We do not collect analytics, use tracking pixels, or embed third-party advertising scripts.

3. Legal Basis for Processing

We process your data on the following legal bases (GDPR Art. 6):

  • Contract (Art. 6(1)(b)): processing your account and inventory data is necessary to provide the InfraBase service you have signed up for.
  • Legitimate interest (Art. 6(1)(f)): maintaining audit logs to support the integrity and security of the service.

4. Data Processors

We use the following sub-processors. All data is processed within the European Economic Area or under appropriate safeguards:

  • Supabase, Inc.: database, authentication, and storage infrastructure. Data is hosted in Frankfurt, Germany (EU).
  • Vercel, Inc.: hosting of the InfraBase web application and this marketing site. Vercel processes request metadata (IP addresses, headers) as part of serving the application.

We have Data Processing Agreements (DPAs) in place with both processors.

5. Data Retention

We retain your personal data for as long as your account is active. When you delete your account, all personal data and device inventory records are permanently deleted within 30 days.

Audit log entries may be retained for up to 90 days after account deletion to support security and fraud prevention, after which they are purged.

6. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of access (Art. 15): request a copy of the data we hold about you.
  • Right to rectification (Art. 16): correct inaccurate data.
  • Right to erasure (Art. 17): request deletion of your data ("right to be forgotten").
  • Right to data portability (Art. 20): receive your data in a structured, machine-readable format.
  • Right to object (Art. 21): object to processing based on legitimate interests.
  • Right to restriction (Art. 18): request that we restrict processing of your data.

To exercise any of these rights, email datenschutz@infrabase.tech. We will respond within 30 days.

7. Right to Lodge a Complaint

If you believe we have not handled your data in accordance with the GDPR, you have the right to lodge a complaint with the competent supervisory authority:

Berliner Beauftragte für Datenschutz und Informationsfreiheit

Friedrichstr. 219, 10969 Berlin, Germany

Website: www.datenschutz-berlin.de

8. Cookies

InfraBase uses a single session cookie set by Supabase Auth to maintain your login session. No advertising cookies, analytics cookies, or third-party tracking cookies are used.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email to the account holder at least 14 days before they take effect.

10. Contact

For all privacy-related enquiries: datenschutz@infrabase.tech

Last updated: June 2026