1. Scope and controller
This notice applies to Gapis account holders, website visitors, and use of the public-edge monitoring service at gapis.it. During the current free launch, Gapis is operated by the administrator of gapis.it, who acts as controller for account, security, and service-operation data. The verified operational contact is webmaster@boscolo.io. Paid billing will remain disabled until the contracting operator’s full legal identity and address are published here and at checkout. The public DNS, TLS, and HTTP metadata observed during a scan is collected at the account holder’s instruction from publicly reachable systems.
2. Data we collect
Account and authentication
We store your email address, password hash, account and tenant identifiers, session metadata, plan, preferences, and timestamps needed to operate and secure the account. Gapis does not store plaintext passwords.
Endpoint observations
We store submitted public hostnames; normalized DNS records; certificate and TLS metadata; redirect URLs without query strings; HTTP status and security-header values; derived findings, scores, changes, incidents, acknowledgements, and scan timing. We do not intentionally store response bodies, cookies, authorization headers, certificate private keys, or monitored-service credentials.
Billing
If you purchase a plan, the payment provider processes card and payment details. Gapis stores limited subscription identifiers, plan, status, renewal timing, and billing-event references needed to provide the service. Full card numbers are not stored by Gapis.
Operations and analytics
We record security and audit events, request timing, coarse product events, error details, IP address where needed for security and rate limiting, user agent, and service logs. Analytics are limited to operating and improving the product and avoid monitored response content.
3. Why we use the data
- Provide scans, comparisons, incidents, notifications, account tools, exports, and subscriptions.
- Authenticate users, isolate customer data, enforce plan limits, rate-limit abuse, and investigate security events.
- Maintain service reliability, diagnose errors, measure core workflow use, and improve scan accuracy.
- Meet billing, accounting, fraud-prevention, and legal obligations.
Depending on your location and the processing involved, the legal basis may be performance of a contract, legitimate interests in security and service improvement, compliance with law, or consent where specifically requested.
4. Service providers and disclosure
We may use infrastructure, email-delivery, payment, backup, and error-monitoring providers strictly to operate Gapis. They receive only the data needed for their function and are subject to applicable contractual and security obligations. We may disclose information when required by law, to protect the service and its users, or as part of a business transaction with appropriate safeguards. We do not sell personal data.
5. Retention
Scan history follows the active plan: 7 days on Free, 90 days on Operator, and 365 days on Fleet. Operational logs and security events are retained only as long as reasonably needed for reliability, abuse prevention, and investigation. Billing and transaction records may be retained for applicable accounting or legal periods. Backups expire on a rolling schedule and are not used to restore an individually deleted account.
6. Security
Gapis uses encrypted transport, password hashing, secure session handling, CSRF protection, authorization and tenant filters, input validation, network target validation, rate limits, audit logging, restricted secrets, backups, and dependency review. No internet service can promise absolute security; suspected issues can be reported to webmaster@boscolo.io.
7. Your choices and rights
You can update account information, export customer-owned data, and request permanent deletion from account settings. Depending on applicable law, you may also ask to access, correct, erase, restrict, or port personal data, object to processing, or withdraw consent. You may complain to your local data-protection authority.
8. International transfers
Where a provider handles data outside your country, we use legally recognized transfer mechanisms and appropriate safeguards when required.
9. Children
Gapis is a business infrastructure service and is not directed to children.
10. Changes to this notice
Material changes will be dated here and, when appropriate, communicated through the service or by email.
11. Contact
Questions or privacy requests can be sent to webmaster@boscolo.io. Please do not send passwords, API keys, private keys, or other secrets.