Privacy notes for the CRA Readiness Check
1. Controller
Innomatica GmbH, Ostfildern, Germany · [email protected]. Our general privacy policy applies in addition.
2. Registration (form)
We collect company, name, business e-mail address, optionally a phone number, and a partner code. Purpose: delivery of your one-time code and the report, attribution to a sales partner, and the subsequent contact about our offer (pre-contractual measures, Art. 6(1)(b) GDPR; B2B direct contact based on legitimate interest, Art. 6(1)(f) GDPR).
3. What the collector transmits — and what it does not
The default run transmits nothing. The
jochwacht-sbom program reads your build and writes your SBOM, the software bill of materials, to a file in
your project folder. Only once you explicitly confirm sending does anything leave your machine.
When sending, you provide your e-mail address. We use it solely to deliver your report and to answer questions about it (pre-contractual measures, Art. 6(1)(b) GDPR).
What is then transmitted:
- for every component found: name, version, package ecosystem and its classification (where the finding came from and how certain it is),
- for components you declared yourself in Ihrer Deklarationsdatei, additionally the
supplier, licence and identifiers (PURL, CPE) you entered there — switch this off with
--no-declared-metadata, - the project name (hashed on request:
--anonymize) and your partner code, if you have one, - the number of scanned build files, the ecosystems detected and the names of build manifests found,
- time of collection, program version and language setting.
Not transmitted: source code, file paths, file contents,
configuration, credentials and host names. What would be sent is written to a file in your project
folder beforehand; in addition, --dry-run shows the exact transmission.
On personal names in the bill of materials. The supplier entries come
from your own declaration. In open-source ecosystems they frequently hold names and e-mail addresses
of maintainers. Where that is the case with you, those entries travel along. For components we
discovered rather than ones you declared, no supplier is transmitted. If you would rather hold your
declaration back, --no-declared-metadata suppresses these fields entirely.
4. Processing and storage location
Analysis and storage take place in Germany, on a server the Innomatica GmbH operates at netcup GmbH in Nuremberg. E-mail delivery also runs through netcup.
For transport and attack protection we use Cloudflare (Cloudflare, Inc., USA) as a processor: DNS, TLS encryption and mitigation of attacks. In doing so, Cloudflare processes connection data including your IP address. Processing outside the EU cannot be ruled out here. The basis is the European Commission's standard contractual clauses, which Cloudflare incorporates through its data processing addendum.
For vulnerability analysis, component names and versions are checked against public vulnerability databases (e.g. OSV.dev). No data is passed to third parties for their own purposes. We do not sell data.
5. Retention and your rights
We keep registration and analysis data as long as required for the purposes above and delete it on request at any time. You have the rights of access, rectification, erasure, restriction and objection — an e-mail to [email protected] is enough.