SimpleSCEP SimpleSCEP Back to simplescep.com

Privacy Policy

What SimpleSCEP collects, why, and what you can ask us to do with it.

Effective 27 August 2026.

1. Who we are

Growing Technologies LLC, a Michigan limited liability company, is the controller of the personal data described here, and can be reached at [email protected]. For data you place into the service about your own users and devices, you are the controller and we are your processor.

2. What we collect

Account data

Service data

Billing data

Payment details are collected and processed by our payment processor. We store the customer and subscription identifiers associated with your account, your plan, and transaction status; we do not store full card numbers.

3. Why we use it, and on what basis

4. Who we share it with

We disclose personal data only as needed to operate the service, complete transactions, comply with law, and protect our rights and users. The categories of recipients are:

These recipients may process personal data only for the purposes described above and subject to applicable contractual or legal duties. We do not sell personal data or share it for cross-context behavioural advertising. When legally permitted, we will notify you before disclosing your data in response to compulsory legal process.

5. Where data is processed

Data is processed in the United States. The service is offered to customers in the United States; if you are subject to the GDPR or the UK GDPR and need a transfer mechanism or a data processing agreement in place, contact us at [email protected] before placing personal data into the service.

6. How long we keep it

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, or port your personal data, to object to or restrict processing, and to withdraw consent. California residents have the rights to know, delete, correct, and to opt out of sale or sharing — we do neither.

Exercise any of these by writing to [email protected]. We respond within 30 days. You may also complain to your supervisory authority.

Two limits are worth stating plainly, because they are the ones most likely to matter to you.

We do not delete records of certificates we issued, or the audit trail of administrative actions, on request or on account closure. Relying parties depend on being able to check the status of a certificate after it has expired, and an audit log that could be erased would not be an audit log. If a certificate should no longer be trusted, ask us to revoke it — that is the remedy, and it takes effect immediately in the CRL and the OCSP responder.

Everything else — your account data, your name and email address, your session records — is deleted on request, and in any case 30 days after the account is closed.

8. Security

Tenant data is separated by row-level security enforced in the database. Certificate authority keys are held in a key management service and cannot be exported. Two-factor authentication is mandatory for every account, and destructive actions require re-authentication. Data is encrypted in transit and at rest.

9. Data processing agreement

If you need a DPA covering the personal data you place into the service, request one at [email protected].

10. Changes

We will post any change here and update the effective date. Material changes are notified by email at least 30 days in advance.


Questions about this document: [email protected].