1. Who is responsible for your data
The controller of personal data described here is Onetelos LLC-FZ, a free-zone company registered in Dubai, United Arab Emirates, trading as Prodable. For any privacy question or to exercise a right below, contact hello@prodable.app.
We process personal data under the UAE's Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL”). Because our customers are global, where the EU GDPR or UK GDPR applies to you, we also honour the rights and protections they provide.
2. What we collect
When you run a scan
- ›the target URL you submit and the findings we generate about it;
- ›your IP address (used for rate-limiting and abuse prevention);
- ›your email address, only if you choose to unlock the full report;
- ›technical metadata such as timestamps and the scan result.
When you have an account or subscription
- ›your GitHub identity (username and email) via sign-in, and the access token needed to run the service;
- ›billing information — handled by Stripe. We do not see or store your card number; we keep a Stripe customer reference and your subscription status;
- ›the URLs you ask us to monitor, their scan history, and any fix tickets you open.
3. How we use it
- ›to deliver the scan, audit, monitoring, and Care services you request;
- ›to send transactional email (receipts, drift alerts, ticket updates) via Cloudflare Email Service;
- ›to take payment and manage subscriptions;
- ›to keep the service secure, prevent abuse, and meet legal obligations.
Our lawful bases include performing our contract with you, your consent (for example, submitting your email to unlock a report), and our legitimate interests in running and securing the service.
4. Who we share it with
We use a small set of processors to run Prodable. They handle data on our behalf, not for their own purposes:
- ›Cloudflare — hosting, the scanner, DNS, and transactional email.
- ›Stripe — payment processing.
- ›GitHub — authentication.
- ›Fly.io — the build/audit runner infrastructure.
We may also disclose data where required by law, or to protect our rights, users, or the public.
5. Where your data is processed
Our infrastructure runs on global providers, so your data may be processed outside the UAE, including in the EU, UK, and US. Where we transfer personal data across borders, we rely on the safeguards permitted under the PDPL and, where relevant, GDPR/UK GDPR transfer mechanisms.
6. How long we keep it
- ›Scan data (URL, IP, findings) is retained to power your report and historical comparisons; anonymous scan records are kept for up to 12 months unless you ask us to delete them sooner.
- ›Account and subscription data is kept while your account is active and for a reasonable period afterwards to meet legal, accounting, and dispute-handling needs.
7. Your rights
Subject to applicable law, you can ask us to:
- ›access the personal data we hold about you;
- ›correct inaccurate data;
- ›delete your data;
- ›restrict or object to certain processing; and
- ›receive a portable copy of data you provided.
To exercise any of these, email hello@prodable.app. You also have the right to complain to your data-protection regulator.
8. Cookies and local storage
We keep cookies to a minimum. We store a sign-in token in your browser's local storage so you stay logged in; this is necessary for the service and is not used for tracking. We do not use advertising or cross-site tracking cookies.
9. Security
We take reasonable technical and organisational measures to protect personal data. No method of transmission or storage is perfectly secure, but we design the service to hold as little sensitive data as possible and to keep it protected in transit and at rest.
10. Children
Prodable is for business use and is not directed at children under 18. We do not knowingly collect their data.
11. Changes
We may update this policy. Material changes will be reflected in the “effective” date above and, where appropriate, notified to you.
12. Related
For the details of what the free scan probes, see our Scan Consent page and our security.txt.