CANARIOStart monitoring

Legal and data · v2026-09-02

Privacy notice

Canario separates account and control-plane information from raw operational events. This notice describes the intended processing boundary and the items that require final legal approval.

The responsible legal entity, privacy contact, applicable legal bases, subprocessor list, international-transfer terms and final retention periods are still required before this notice is published as a final policy.

1. Information we process

  • Account and identity: email, authentication state, provider identifiers and security events needed to sign in and recover access.
  • Organization and configuration: organization name, memberships, roles, canary names, deployment mode, enrollment metadata, alert-channel metadata and billing entitlement state.
  • Summarized operational state: node health, heartbeats, rollups, incident lifecycle, delivery status and audit events authorized for the organization.
  • Support information: version, readiness, bounded diagnostics and operational metadata voluntarily provided during troubleshooting. Support should not receive `.env` files, secrets or raw payloads.

2. Information that stays with the node

Raw signals, provider payloads, dimensions, local rules, evaluator state, local incidents, deliveries and the cloud outbox are stored in the selected node/ClickHouse profile. The browser does not connect to ClickHouse. When cloud reporting is enabled, the node sends summarized heartbeats, rollups and incident envelopes through authenticated outbound HTTPS.

Customers must configure redaction and avoid sending credentials or unnecessary personal data. The customer remains responsible for the source data and for deciding whether the signal contract contains personal or regulated information.

3. Purposes and access

Canario processes the information above to authenticate users, isolate organizations, enroll and monitor nodes, display authorized summaries, deliver configured alerts, process billing events, provide support, maintain security and measure product activation without copying operational payloads into commercial analytics.

Access is scoped by organization and role. Service-side credentials are not exposed to the browser. Administrative or support access, if needed, must be recorded and limited to the purpose agreed with the customer.

4. Providers and transfers

The deployment may use Supabase for identity and control-plane storage, Vercel for the console, Resend for enabled email alerts and Mercado Pago for enabled checkout flows. The final provider list, locations, subprocessors and international-transfer mechanism must be confirmed in the published policy and customer data-processing annex.

5. Retention and rights

Control-plane retention, account deletion, export handling and backup deletion must follow the final customer contract and legal policy. The node baseline documents 395 days for raw signal/incident state, 30 days for completed cloud-outbox rows and operator-defined backup retention; customer-specific values take precedence when recorded.

Authenticated users can submit a request from Workspace Settings for access, correction, suppression, opposition, portability or blocking of control-plane data. The request is recorded for human review; the workflow does not execute irreversible deletion automatically. The designated privacy contact, entity and address must still be published before this draft becomes final. On-premise raw data requests are primarily handled by the customer operator because that operator controls the storage.

6. Security and incident response

Canario uses tenant-scoped authorization, RLS, one-shot enrollment tokens, hashed token storage, signed webhooks, encrypted alert secrets and minimized cloud envelopes. Security incidents, notification windows, evidence preservation and customer communication must be defined in the final security/DPA annex.