Privacy Policy

How we handle your data, what we collect, and what we don't. Transparency matters.

Version 2025-12-04 (this version)
Version 2025-11-01

Effective Date: December 6, 2025

Privacy Policy v1.1 | Last Updated: December 6, 2025

This Privacy Policy explains how Mikael Vesavuori ("we," "us," or "Phaset") collects, uses, and protects your personal data when you visit our website or use our software.

The short version: We collect as little as possible. For self-hosted Phaset, your operational data stays on your infrastructure. For Managed Phaset, data is hosted and securely processed in the EU. We don't sell or share your data with third parties.

Core Principle: Phaset is available in two forms: Self-Hosted Phaset (you run it on your infrastructure) and Managed Phaset (hosted and operated for you). Data handling differs between these offerings, and this policy explains both clearly.

1. Who We Are

Data Controller: Mikael Vesavuori
Email: [email protected]
Location: Göteborg, Sweden

As a Sweden-based business, we comply with the General Data Protection Regulation (GDPR) and Swedish data protection laws.

Service Offerings

Phaset is available in two forms:

  1. Self-Hosted Phaset: You download and run on your infrastructure
  2. Managed Phaset: Hosted and operated for you on EU infrastructure

This Privacy Policy covers both offerings. Where handling differs, we explain clearly.

2. What Data We Collect

Website Analytics (Umami)

We use Umami, a privacy-focused analytics service, to understand how visitors use our website. Umami is GDPR-compliant and does not use cookies.

What we collect through Umami:

What we DON'T collect:

Umami data is hosted on Umami Cloud and aggregated anonymously. We cannot identify individual visitors from this data.

License and Payment Information

When you purchase a plan, we collect:

Payment processing is handled by Polar. We do not store your credit card information—Polar handles all payment data securely.

License Validation

When you run Phaset, the software performs a boot-time license check to validate your license key and guard against abuse. This check is made to our first-party back office system and includes:

This check happens only at startup and does not involve any operational data from your Phaset deployment.

Support Communications

If you contact us for support, we collect:

Managed Phaset (Hosted Service)

If you subscribe to Managed Phaset, our hosted service offering, data handling differs from self-hosted deployments:

What This Means

For Managed Phaset subscribers:

Data We Process for Managed Phaset

Operational data in your instance:

Infrastructure/system data:

How We Access This Data

Access to your Managed Phaset data is strictly limited:

Routine access (no notification):

Support access (with your request):

Emergency access (with notification):

Never accessed for:

Your Data Protection Rights (Managed Phaset)

As a Managed Phaset customer, you have these additional rights:

Subprocessors for Managed Phaset

For a complete list of all subprocessors that process your operational data for Managed Phaset, including their locations, purposes, and GDPR compliance details, see:

phaset.dev/subprocessors.html

All subprocessors comply with GDPR. We'll notify you 30 days before changing subprocessors.

Data Processing Agreement (DPA)

A separate Data Processing Agreement is available upon request for Managed Phaset customers. To request a DPA, contact: [email protected]

Security Incident Notification

If a security incident affects your Managed Phaset data:

See the Managed Service Agreement for complete details.

3. What We DON'T Collect

This is equally important. We do NOT collect:

Note: For Managed Phaset, we process your operational data as described in Section 2, but only for service operation purposes—never for marketing, analytics about usage patterns, or other purposes.

4. How We Use Your Data

We use the data we collect for these specific purposes:

Website Analytics

License Management

Customer Support

Legal Compliance

5. Legal Basis for Processing (GDPR)

Under GDPR, we process your data based on:

6. Data Sharing and Third Parties

We share data only with essential service providers. The specific services depend on which Phaset offering you use:

For the Marketing Website (phaset.dev)

These services are only used on our marketing website, not within your Phaset instance:

Polar (Payment Processing)

Umami (Website Analytics)

For Managed Phaset Subscribers Only

If you subscribe to Managed Phaset, your operational data is processed by these additional subprocessors (see Section 2 for full details):

Scaleway (Infrastructure)

Cloudflare Pages (Frontend Hosting)

For Self-Hosted Phaset

If you self-host Phaset, none of your operational data is shared with third parties. Only the license validation check reaches our servers (see Section 2).

We do NOT:

7. Data Retention

We retain your data for as long as necessary:

After these periods, data is securely deleted or anonymized.

8. Your Rights Under GDPR

As an individual in the EU/EEA, you have these rights:

Right to Access

Request a copy of all personal data we hold about you.

Right to Rectification

Request corrections to inaccurate or incomplete data.

Right to Erasure ("Right to be Forgotten")

Request deletion of your personal data, subject to legal retention requirements.

Right to Restriction

Request that we limit how we use your data.

Right to Data Portability

Request your data in a machine-readable format to transfer elsewhere.

Right to Object

Object to processing based on legitimate interests (e.g., analytics).

Right to Withdraw Consent

Withdraw consent for data processing that relies on it (doesn't affect lawfulness of prior processing).

Right to Lodge a Complaint

File a complaint with your local data protection authority if you believe we've violated your rights.

To exercise your rights: Email [email protected] with your request. We'll respond within 30 days.

9. Data Security

We protect your data with:

For your self-hosted Phaset instance, you are responsible for securing your deployment, including:

10. International Data Transfers

Our service providers (Polar, Umami) operate within the EU and comply with GDPR. If data must be transferred outside the EU, it's done under appropriate safeguards:

11. Children's Privacy

Phaset is not intended for individuals under 16. We do not knowingly collect data from children. If we discover we've collected data from a child, we'll delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we do:

Continued use of our website or software after changes means you accept the updated policy.

13. Contact Us

Questions, concerns, or requests about your privacy?

Email: [email protected]
Response time: We aim to respond within 5 business days

For GDPR-related requests, include "GDPR Request" in your subject line for faster processing.

Our commitment: We built Phaset with privacy as a core principle. Self-hosting means you control your data. We collect only what's necessary to run the business and improve the product. Your trust matters to us.

Privacy Questions?

We're here to help. Reach out if you have any concerns about your data.

Email Support

Contact us about privacy matters

[email protected]

GDPR Requests

Exercise your data protection rights

Submit GDPR Request

Documentation

Learn about data handling in Phaset

View Docs