Privacy
Privacy Policy
This notice explains how Alveos processes personal data when you use the public website and the login host (GDPR Art. 13).
Alveos is a metrics product for software distribution. It is not a shop, not VetterPlaces, and not Ready-4-IT.
Scope
This notice primarily targets users with habitual residence in the EU/EEA. For access from other jurisdictions, mandatory privacy rules of those jurisdictions prevail. Where you use GitHub to sign in, GitHub’s own policy also applies.
Controller
Site operator: Serap Kusu-Eryigit — Alveos
Serviceable address: 21, rue Basse, L-3813 Schifflange, Luxembourg
No walk-in customers.
Email:
contact [at] alveos [dot] eu
Technical responsibility: Serap Kusu-Eryigit — www.alveos.eu
Phone: +352 691 868 822
Support mailbox: support [at] alveos [dot] eu
Surfaces
- www (
www.alveos.eu/ DEVdev.alveos.loc): public pages, legal texts, consent banner. - login (
login.alveos.eu/ DEVlogin.dev.alveos.loc): identity, admin, superadmin. Separate host-only session.
The metrics dashboard currently runs on the login host. Public-source snapshots, optional Beacon telemetry, processors, retention, and deletion are described in the Sources and methodology.
Purposes and legal bases
- Provide the website, stability, security (Art. 6(1)(f) GDPR)
- Account and sign-in, including GitHub OAuth and email one-time codes (Art. 6(1)(b) GDPR; where sign-in is voluntary before a contract, Art. 6(1)(a))
- Communication (Art. 6(1)(a)/(b) GDPR)
- Optional analytics or marketing cookies only with consent (Art. 6(1)(a) GDPR)
See also Cookies.
Access data / server logs
When you access the site, technically necessary data are processed (IP address, date/time, URL, referrer, user agent). These serve secure operation and are deleted after a short time.
Cookies
Details: Cookies. Necessary cookies rely on legitimate interests. Additional cookies only with consent via the consent banner.
Contact / email
If you write to us, we process your details to handle the request. Legal basis is consent or pre-contractual steps. Data are deleted once the purpose is fulfilled and no retention duties apply.
Login (GitHub OAuth and 2FA)
When you sign in with GitHub, GitHub may transmit your public profile (user ID, username, display name, avatar URL, and a public email if configured). We store the GitHub username as the stable identity. Superadmin membership is that username only. We do not request write access to your repositories.
For superadmin elevation we send a one-time code to an allowlisted mailbox. Codes are single-use and expire after a short time. Failed attempts may lock the developer and IP.
The cookie-less track API (/api/v1/track) stores the calling IP only briefly to temporarily block repeated false requests (legitimate interest, Art. 6(1)(f) GDPR). A valid ping clears that counter.
Registration of new accounts can be closed by the operator. Existing accounts can still sign in.
Legal basis: contract performance (Art. 6(1)(b) GDPR); legitimate interest in abuse prevention for lockouts and audit (Art. 6(1)(f) GDPR).
Recipients
IT / hosting providers under data processing agreements (Art. 28 GDPR) where applicable. GitHub, Inc. when you use OAuth.
We do not use Payhip or another merchant-of-record on this site. The current named processor and external-service list is published in the Sources.
Third-country transfers
GitHub is based in the United States. Transfers occur only where an adequate level of protection exists (e.g. EU Standard Contractual Clauses) and where necessary for sign-in.
Storage period
We process personal data only as long as needed for the stated purposes or where statutory retention periods apply. Login sessions end when you sign out or the host session expires. Superadmin elevation is short-lived and is not “remember this device”.
Your rights
You have rights of access, rectification, erasure, restriction, portability, and objection. You can withdraw given consent. You may lodge a complaint with a supervisory authority (in Luxembourg: CNPD).
Security
We take technical and organizational measures (TLS, hardening, logging, fail-closed access lists).
Updates
This notice is updated as needed. Status: 2026-09-20.
External links
External links are indicated. We do not assume liability for third-party content.
Third-party services
- GitHub (OAuth): GitHub Privacy Statement
- YouTube (embeds / product videos / Data API): Google Privacy Policy
- X (Twitter) (widgets / public metrics ingest): X Privacy Policy
- Streaming Zebra (optional delivery ingest, no www visitor cookie): Sources
- Consent / optional embeds: see the consent banner and Cookies