Privacy notes for the CRA Readiness Check

1. Controller

Innomatica GmbH, Ostfildern, Germany · [email protected]. Our general privacy policy applies in addition.

2. Registration (form)

We collect company, name, business e-mail address, optionally a phone number, and a partner code. Purpose: delivery of your one-time code and the report, attribution to a sales partner, and the subsequent contact about our offer (pre-contractual measures, Art. 6(1)(b) GDPR; B2B direct contact based on legitimate interest, Art. 6(1)(f) GDPR).

3. What the collector transmits — and what it does not

The default run transmits nothing. The jochwacht-sbom program reads your build and writes your SBOM, the software bill of materials, to a file in your project folder. Only once you explicitly confirm sending does anything leave your machine.

When sending, you provide your e-mail address. We use it solely to deliver your report and to answer questions about it (pre-contractual measures, Art. 6(1)(b) GDPR).

What is then transmitted:

  • for every component found: name, version, package ecosystem and its classification (where the finding came from and how certain it is),
  • for components you declared yourself in Ihrer Deklarationsdatei, additionally the supplier, licence and identifiers (PURL, CPE) you entered there — switch this off with --no-declared-metadata,
  • the project name (hashed on request: --anonymize) and your partner code, if you have one,
  • the number of scanned build files, the ecosystems detected and the names of build manifests found,
  • time of collection, program version and language setting.

Not transmitted: source code, file paths, file contents, configuration, credentials and host names. What would be sent is written to a file in your project folder beforehand; in addition, --dry-run shows the exact transmission.

On personal names in the bill of materials. The supplier entries come from your own declaration. In open-source ecosystems they frequently hold names and e-mail addresses of maintainers. Where that is the case with you, those entries travel along. For components we discovered rather than ones you declared, no supplier is transmitted. If you would rather hold your declaration back, --no-declared-metadata suppresses these fields entirely.

4. Processing and storage location

Analysis and storage take place in Germany, on a server the Innomatica GmbH operates at netcup GmbH in Nuremberg. E-mail delivery also runs through netcup.

For transport and attack protection we use Cloudflare (Cloudflare, Inc., USA) as a processor: DNS, TLS encryption and mitigation of attacks. In doing so, Cloudflare processes connection data including your IP address. Processing outside the EU cannot be ruled out here. The basis is the European Commission's standard contractual clauses, which Cloudflare incorporates through its data processing addendum.

For vulnerability analysis, component names and versions are checked against public vulnerability databases (e.g. OSV.dev). No data is passed to third parties for their own purposes. We do not sell data.

5. Retention and your rights

We keep registration and analysis data as long as required for the purposes above and delete it on request at any time. You have the rights of access, rectification, erasure, restriction and objection — an e-mail to [email protected] is enough.