Legal

Privacy

Privacy Policy

This notice explains how Alveos processes personal data when you use the public website and the login host (GDPR Art. 13).

Alveos is a metrics product for software distribution. It is not a shop, not VetterPlaces, and not Ready-4-IT.

Scope

This notice primarily targets users with habitual residence in the EU/EEA. For access from other jurisdictions, mandatory privacy rules of those jurisdictions prevail. Where you use GitHub to sign in, GitHub’s own policy also applies.

Controller

Site operator: Serap Kusu-Eryigit — Alveos
Serviceable address: 21, rue Basse, L-3813 Schifflange, Luxembourg
No walk-in customers.
Email: contact [at] alveos [dot] eu

Technical responsibility: Serap Kusu-Eryigit — www.alveos.eu

Phone: +352 691 868 822

Support mailbox: support [at] alveos [dot] eu

Surfaces

  • www (www.alveos.eu / DEV dev.alveos.loc): public pages, legal texts, consent banner.
  • login (login.alveos.eu / DEV login.dev.alveos.loc): identity, admin, superadmin. Separate host-only session.

The metrics dashboard currently runs on the login host. Public-source snapshots, optional Beacon telemetry, processors, retention, and deletion are described in the Sources and methodology.

Purposes and legal bases

  • Provide the website, stability, security (Art. 6(1)(f) GDPR)
  • Account and sign-in, including GitHub OAuth and email one-time codes (Art. 6(1)(b) GDPR; where sign-in is voluntary before a contract, Art. 6(1)(a))
  • Communication (Art. 6(1)(a)/(b) GDPR)
  • Optional analytics or marketing cookies only with consent (Art. 6(1)(a) GDPR)

See also Cookies.

Access data / server logs

When you access the site, technically necessary data are processed (IP address, date/time, URL, referrer, user agent). These serve secure operation and are deleted after a short time.

Cookies

Details: Cookies. Necessary cookies rely on legitimate interests. Additional cookies only with consent via the consent banner.

Contact / email

If you write to us, we process your details to handle the request. Legal basis is consent or pre-contractual steps. Data are deleted once the purpose is fulfilled and no retention duties apply.

Login (GitHub OAuth and 2FA)

When you sign in with GitHub, GitHub may transmit your public profile (user ID, username, display name, avatar URL, and a public email if configured). We store the GitHub username as the stable identity. Superadmin membership is that username only. We do not request write access to your repositories.

For superadmin elevation we send a one-time code to an allowlisted mailbox. Codes are single-use and expire after a short time. Failed attempts may lock the developer and IP.

The cookie-less track API (/api/v1/track) stores the calling IP only briefly to temporarily block repeated false requests (legitimate interest, Art. 6(1)(f) GDPR). A valid ping clears that counter.

Registration of new accounts can be closed by the operator. Existing accounts can still sign in.

Legal basis: contract performance (Art. 6(1)(b) GDPR); legitimate interest in abuse prevention for lockouts and audit (Art. 6(1)(f) GDPR).

Recipients

IT / hosting providers under data processing agreements (Art. 28 GDPR) where applicable. GitHub, Inc. when you use OAuth.

We do not use Payhip or another merchant-of-record on this site. The current named processor and external-service list is published in the Sources.

Third-country transfers

GitHub is based in the United States. Transfers occur only where an adequate level of protection exists (e.g. EU Standard Contractual Clauses) and where necessary for sign-in.

Storage period

We process personal data only as long as needed for the stated purposes or where statutory retention periods apply. Login sessions end when you sign out or the host session expires. Superadmin elevation is short-lived and is not “remember this device”.

Your rights

You have rights of access, rectification, erasure, restriction, portability, and objection. You can withdraw given consent. You may lodge a complaint with a supervisory authority (in Luxembourg: CNPD).

Security

We take technical and organizational measures (TLS, hardening, logging, fail-closed access lists).

Updates

This notice is updated as needed. Status: 2026-09-20.

External links

External links are indicated. We do not assume liability for third-party content.

Third-party services