Privacy Policy
1. Who we are
ShiftLeft AS ("ShiftLeft", "we", "us") is a Norwegian limited company and the data controller for personal data collected through shiftleft.no and the ShiftLeft MCP Gateway service.
Contact: privacy@shiftleft.no
2. What data we collect and why
Account data
When you sign up we collect your email address and an organisation slug derived from it. We use this to identify your account, send transactional emails (welcome, billing receipts, policy alerts), and to contact you about the service.
Legal basis: Art. 6(1)(b) GDPR — performance of the contract with you.
Gateway audit logs
The MCP Gateway records every tool-call evaluation: timestamp, MCP server name, tool name, policy decision (ALLOW / DENY / REDACT), and the tenant identifier. These logs are the core product — they let you audit what your AI agents did.
Audit logs do not include the content of tool arguments or responses unless you explicitly configure argument capture.
Legal basis: Art. 6(1)(b) GDPR — the logs are the service you signed up for.
Technical and billing data
We log server-side request metadata (IP address, user-agent, HTTP status) for security monitoring and debugging. Logs are rotated after 30 days.
Payment is handled by Stripe. We never see or store card numbers or full payment details — Stripe provides us only with a subscription status and the last four digits of your card. Stripe's privacy policy applies to data they collect: stripe.com/privacy.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating a secure, reliable service.
3. Where your data is stored
All ShiftLeft infrastructure runs in Norway. Your account data, audit logs, and gateway configuration are stored exclusively on servers located in Norway and are not replicated outside the country by default.
Stripe may process billing data in the United States and other countries. Stripe participates in the EU–U.S. Data Privacy Framework and uses Standard Contractual Clauses for transfers from the European Economic Area.
4. How long we keep your data
| Data type | Retention |
|---|---|
| Account (email, org slug) | Until account deletion + 30-day grace period |
| Gateway audit logs | 90 days (configurable per tenant on Pro plan) |
| Server access logs | 30 days |
| Billing records | 5 years (Norwegian accounting law) |
5. Who we share data with
We do not sell your data. We share it only with the following processors:
- Stripe — payment processing. Stripe processes card data on our behalf under a Data Processing Agreement.
- GitHub — source code hosting and CI/CD. Deployment pipelines may process environment configuration. No user data is sent to GitHub.
We may disclose data if required by Norwegian law or a valid court order.
6. Your rights under GDPR
As a resident of the EEA (which includes Norway through the EEA Agreement) you have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — ask us to delete your account and associated data ("right to be forgotten").
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive your audit logs in a machine-readable format (JSON).
- Objection — object to processing based on legitimate interest.
To exercise any of these rights, email privacy@shiftleft.no. We will respond within 30 days. Account deletion can also be initiated directly from your dashboard.
7. Supervisory authority
If you believe we have processed your data unlawfully, you have the right to lodge a complaint with the Norwegian Data Protection Authority:
Datatilsynet
Postboks 458 Sentrum, 0105 Oslo
www.datatilsynet.no · postkasse@datatilsynet.no
8. Cookies
ShiftLeft does not use tracking cookies or third-party analytics. We set a session cookie strictly necessary for authentication when you are signed in. No cookie banner is shown because we do not use cookies that require consent under ePrivacy rules.
9. Changes to this policy
We will notify registered users by email if we make material changes to this policy. The "Last updated" date at the top of this page reflects the most recent revision.