Privacy Policy
What SimpleSCEP collects, why, and what you can ask us to do with it.
Effective 27 August 2026.
1. Who we are
Growing Technologies LLC, a Michigan limited liability company, is the controller of the personal data described here, and can be reached at [email protected]. For data you place into the service about your own users and devices, you are the controller and we are your processor.
2. What we collect
Account data
- Name, email address, and organization name, provided at signup or invitation.
- Role within your organization.
- Authentication material: a time-based one-time password secret, held encrypted; passkey public keys and their metadata; and hashed recovery codes. We never hold a password, because the service does not use one.
- Session records, including IP address and the time of sign-in.
Service data
- Certificate metadata: subject names, subject alternative names, serial numbers, validity periods, issuing CA, and revocation status. Subject names may contain personal data where you issue certificates to named people or personal devices — that is your choice as controller.
- Certificate signing requests and issued certificates. We do not receive subscriber private keys.
- Enrollment records: which credential enrolled, when, from what address, and whether it succeeded.
- An audit log of administrative actions, including the actor, action, and time.
Billing data
Payment details are collected and processed by our payment processor. We store the customer and subscription identifiers associated with your account, your plan, and transaction status; we do not store full card numbers.
3. Why we use it, and on what basis
- To provide the service and issue certificates you request — performance of our contract with you.
- To authenticate you and protect accounts — legitimate interest in the security of the service, and legal obligation where applicable.
- To maintain an audit trail — legitimate interest, and in many cases your own compliance requirement. Audit records are append-only by design and cannot be edited or deleted through the application.
- To take payment — performance of our contract.
- To send service and security notices — legitimate interest. These are not marketing and cannot be unsubscribed from while you hold an account.
4. Who we share it with
We disclose personal data only as needed to operate the service, complete transactions, comply with law, and protect our rights and users. The categories of recipients are:
- Hosting, database, security, and key-management service providers that process data to operate and secure the service.
- Payment and invoicing service providers that process transactions and maintain billing records.
- Communications service providers that deliver transactional, account, and security messages.
- Third-party integrations that you choose to connect, which receive only the data needed to provide the requested integration.
- Professional advisers, auditors, insurers, regulators, courts, and law-enforcement authorities where disclosure is reasonably necessary or legally required.
These recipients may process personal data only for the purposes described above and subject to applicable contractual or legal duties. We do not sell personal data or share it for cross-context behavioural advertising. When legally permitted, we will notify you before disclosing your data in response to compulsory legal process.
5. Where data is processed
Data is processed in the United States. The service is offered to customers in the United States; if you are subject to the GDPR or the UK GDPR and need a transfer mechanism or a data processing agreement in place, contact us at [email protected] before placing personal data into the service.
6. How long we keep it
- Account data: for the life of the account, then deleted 30 days after the account is closed or the subscription is cancelled. We will delete it sooner on request.
- Certificate and revocation records: retained indefinitely. A relying party may need to check the status of a certificate long after it has expired, and a certificate authority that cannot answer that question has failed at its purpose. These records are not deleted on account closure or on request.
- Audit records: retained indefinitely. The audit trail is append-only by design — it cannot be edited or deleted through the application — because an audit log that can be altered is not evidence of anything.
- Billing records: as required by tax law, typically seven years.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal data, to object to or restrict processing, and to withdraw consent. California residents have the rights to know, delete, correct, and to opt out of sale or sharing — we do neither.
Exercise any of these by writing to [email protected]. We respond within 30 days. You may also complain to your supervisory authority.
Two limits are worth stating plainly, because they are the ones most likely to matter to you.
We do not delete records of certificates we issued, or the audit trail of administrative actions, on request or on account closure. Relying parties depend on being able to check the status of a certificate after it has expired, and an audit log that could be erased would not be an audit log. If a certificate should no longer be trusted, ask us to revoke it — that is the remedy, and it takes effect immediately in the CRL and the OCSP responder.
Everything else — your account data, your name and email address, your session records — is deleted on request, and in any case 30 days after the account is closed.
8. Security
Tenant data is separated by row-level security enforced in the database. Certificate authority keys are held in a key management service and cannot be exported. Two-factor authentication is mandatory for every account, and destructive actions require re-authentication. Data is encrypted in transit and at rest.
9. Data processing agreement
If you need a DPA covering the personal data you place into the service, request one at [email protected].
10. Changes
We will post any change here and update the effective date. Material changes are notified by email at least 30 days in advance.
Questions about this document: [email protected].