Privacywhat we hold, and for how long
Privacy notice
Last updated: 27 September 2026
Who this is from
Kombine is a product of UAB KONTRATEK, a company registered in Lithuania under company code 308113992. Write to us at info@kombine.work.
This notice covers both the website you are reading and the Kombine platform at app.kombine.work.
When we decide, and when you do
For this website, and for the people who buy or administer a subscription, we are the data controller. We decide what to collect and why, and this notice explains it.
For the security and compliance records inside a workspace, the customer is the controller and we are the processor. We act on their instructions and we do not use their content for our own purposes. That relationship is set out in the data processing agreement.
This website collects almost nothing
There is no analytics, no advertising and no third party tracker on kombine.work. Three first party cookies exist for preferences and none of them tracks you: lang and theme, written only when you pick a language or a colour theme in the footer, and consent, which records your answer to the banner so it stops asking. All three last a year, hold nothing but that one preference each, and never leave this site. The pages themselves are static files served from the edge.
The one exception is the form. When you send it we receive the work email, company name and message you typed, plus the IP address the request came from so that we can stop abuse. It reaches our mailbox as an email and is not stored in a database on this site. We keep the correspondence for as long as the conversation is live and for up to two years afterwards.
Signing in adds one thing, and only if you choose to. Your name and email address come from WorkOS, the identity provider that runs the sign-in screen, and this site keeps them only inside a signed cookie in your own browser, eight hours at a time. There is no user database here and nothing about you is written to disk on kombine.work. WorkOS processes in the United States. Write to privacy@kombine.work to have the account deleted.
What the platform holds
Account data: name, work email, role, whether multi factor authentication is enabled, and sign in times. If a workspace uses Microsoft Entra to sign in, we hold the identifiers that connect an account to that directory.
Workspace content: the asset inventory and its software, vulnerabilities and misconfigurations, incidents and service requests, supplier records, risks, controls and the evidence files a customer uploads. Incidents and tickets contain whatever the people writing them choose to write, which can include personal data about employees or third parties.
Collector agents installed on customer machines report inventory and posture, for example operating system, patch level, disk encryption state and installed software. They do not read the contents of documents or user files.
Logs, and how long they live
Every request to the platform is recorded with the time, the path, the outcome, the account that made it and the IP address it came from. Those records stay in the database for at least 90 days, then move to encrypted archives that are kept for two years and then deleted.
Separately, an audit log records who changed what inside a workspace. Customers can read their own audit log in the app. It exists so that a change to a control, a risk or an incident can always be attributed.
Why we are allowed to hold it
To perform the contract, which covers everything needed to run the subscription. For our legitimate interest in operating a secure service, which covers access logs, abuse prevention and error monitoring. To meet legal obligations, which covers accounting records. And on consent where we ask for it, which you can withdraw at any time.
How long we keep things
Account and billing records: for the life of the subscription, then as long as accounting law requires.
Workspace content: until the customer deletes it or the subscription ends. After termination we delete the workspace within 30 days unless the customer asks for longer in writing.
Backups: nightly database backups and per workspace exports age out on their own schedule, so deleted content can persist in a backup for a short period after deletion before expiring.
Who else touches it
We use a small number of sub-processors: Amazon Web Services for hosting and backups, Cloudflare for DNS and protection at the edge, Resend for email, Stripe for subscription payments, Sentry for error monitoring and WorkOS for signing in to this website. Each one, its role and where it processes data is listed in the data processing agreement.
We do not sell data, we do not share it for advertising, and we do not use customer content to train models. If a workspace switches on the AI assistant, the customer chooses and configures the provider themselves, and only what that feature sends is processed there.
Where it is
The platform runs in the European Economic Area, in Amazon Web Services in Stockholm. Inbound email is received through Amazon infrastructure in Ireland.
Some sub-processors operate globally and may process data outside the EEA. Where they do, transfers rely on the European Commission standard contractual clauses and the safeguards described in their own terms.
How it is protected
Data is encrypted in transit and at rest, and the most sensitive values, such as integration credentials, are encrypted individually in the database. Each workspace is isolated and every query is scoped to it.
The origin servers accept traffic only through Cloudflare. The platform administration console sits behind a separate identity gate and requires multi factor authentication. Customers can restrict their own workspace to named IP ranges.
Backups run nightly across three tracks and restores are tested. Every request is logged, so access to data can be reconstructed after the fact.
Cookies
Five at most, all first party, none of them tracking you. Three are preferences: the language and the colour theme you pick in the footer, written only if you click them, and your answer to the cookie banner, so that it stops asking. Those last a year. The other two appear only if you sign in: the session itself, which is signed, unreadable to scripts and expires after eight hours, and a flag holding the single character 1, so the page knows to offer you Account rather than Sign in. Signing out removes both. None of the five leaves this site.
There is no analytics cookie because there is no analytics. If that ever changes, it will run only for people who accepted it, and this page will say so before it does.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, object to processing, ask us to restrict it, or ask for it in a portable form. Write to privacy@kombine.work and we will answer within one month.
If your data sits inside a customer workspace, that customer is the controller and we will pass your request to them rather than act on it ourselves.
If you think we have handled your data badly, please tell us first. You also have the right to complain to the State Data Protection Inspectorate of Lithuania, or to the supervisory authority where you live or work.
Changes
This page carries the date it last changed. If we change something that matters, we will say so in the app or by email to workspace administrators rather than quietly editing the text.