PRIVACY NOTICE
What Small sees—and why.
This notice covers personal data Small handles as controller for its website, accounts, commercial relationship, security, and operation of the platform. Customer application data is processed on the customer's instructions.
Who is responsible
The Small operator is the controller for account, service administration, billing, security, and business-contact data described here. For personal data inside customer applications or submitted for deployment on a customer's instructions, the customer is generally controller and Small is its processor.
The legal operator, registration number, postal address, governing law, and legal and privacy contacts have not yet been activated. Production validation will fail until every value is supplied.
Data and sources
- Account and contact data: name, email address, verified domain, workspace membership, role, and sign-in method.
- Service configuration: app manifests, domains, runtime assignments, deployment status, encrypted secrets metadata, and customer support requests.
- Usage and commercial data: measured resource usage, subscription state, provider identifiers, invoices, and payment status. Small does not store full card details.
- Security and operational data: IP address, user agent, authentication events, API-token metadata, audit events, delivery evidence, runtime health, and bounded diagnostic output.
Data comes from account holders and their organization, their coding agents and runtime nodes, configured identity and payment providers, and the systems used to operate Small.
An account email and authentication data are required to provide an account; workspace and deployment configuration are required to run the requested service; and billing details are required only for a paid plan. Without the applicable required data, Small cannot provide that part of the service. Optional profile and communication choices can be omitted.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provide accounts, deployments, support, and billing | Performance of a contract or steps requested before one |
| Secure, debug, and improve the service | Legitimate interests in a reliable, abuse-resistant platform |
| Keep tax, accounting, and compliance records | Legal obligations |
| Optional product communication | Consent where required, otherwise legitimate interests |
Small does not make decisions producing legal or similarly significant effects about account holders solely through automated profiling.
Recipients and subprocessors
Data is available only to authorized operator personnel and service providers that need it for hosting, edge delivery, transactional email, identity, billing, monitoring, support, or encrypted recovery. Small may also disclose data where law requires it, to protect rights and safety, or during a corporate transaction subject to appropriate safeguards.
The current provider list, purpose, processing locations, and provider privacy links are maintained on the Subprocessors page.
International transfers
Small is designed around European runtime infrastructure, but some service providers may process limited account or operational data outside the European Economic Area. Where required, Small uses an adequacy decision, standard contractual clauses, or another lawful transfer mechanism. Actual provider locations are disclosed rather than inferred.
Retention
Active customer resources remain available while needed to provide the service. Automated cleanup applies these maximum operational windows after records become expired or stale:
- expired sessions and short-lived authentication artifacts: 7 days;
- stale invitation and credential metadata: 90 days;
- bounded command, result, and diagnostic payloads: 30 days; and
- audit, billing, and email-delivery evidence: 365 days.
Some records may be kept longer when required by law, needed to resolve a dispute, or preserved in encrypted backups until their bounded rotation completes.
Security
Small uses role-scoped access, hashed credentials, versioned encryption for application secrets, constrained runtime identities, tenant-aware authorization, signed provider webhooks, audit records, and encrypted backup verification. No system is risk-free. Current controls and deliberately unclaimed certifications are listed on the Security page.
Your rights
Depending on applicable law, individuals may ask for access, correction, deletion, restriction, portability, or an objection to processing. Consent can be withdrawn where processing relies on it, without affecting earlier lawful processing. Identity may need to be verified before a request is fulfilled.
A privacy-request mailbox and operator identity must be activated before commercial launch. Individuals may complain to the data protection authority where they live or work, or where an alleged infringement occurred.
Cookies and local storage
Small uses strictly necessary cookies or equivalent browser storage for authentication, session security, interface preferences, and abuse prevention. The platform does not currently use third-party advertising trackers. If optional analytics or marketing technology is introduced, this notice and any required consent controls must be updated before it is enabled.
Changes and questions
Material changes will be dated and communicated through the service or account contact where appropriate. Questions about customer application data should first be directed to the customer that controls that application.