Effective Date: July 11th, 2023
Version 3
Welcome to Layer5. We are Layer5, Inc., the company behind the cloud native management platform Meshery, the Layer5 Cloud service, Kanvas, and a vibrant global open-source community. We are committed to protecting your privacy and being transparent about how we handle your personal data.
This Privacy Notice explains what personal data we collect when you visit our websites, use our services, or participate in our community. It also describes why we collect it, how we use and protect it, and what rights you have regarding your personal data.
For detailed information about the third-party service providers we work with to deliver our services, please see our Sub-Processors and Service Providers, which includes our Data Protection Addendum.
Welcome to Layer5. We are Layer5, Inc., the company behind the cloud native management platform Meshery, the Layer5 Cloud service, Kanvas, and a vibrant global open-source community. We are committed to protecting your privacy and being transparent about how we handle your personal data.
The data controller responsible for your personal data is:
Layer5, Inc.
If you have any questions about this Privacy Notice or wish to exercise your data protection rights, please see the How to Contact Us section below.
Important Clarification: This Privacy Notice applies solely to the services, websites, and communities operated by Layer5, Inc., incorporated in the United States, accessible via the layer5.io domain and its subdomains. It does not apply to any other company or organization that may have a similar name, such as "Layer 5 Solutions Ltd". We are not affiliated with any other entity named "Layer5" or "Layer 5."
We process your personal data for a variety of purposes depending on how you interact with us. The table below details what we collect, why we collect it, and the legal justification (lawful basis) under the GDPR for doing so.
| Purpose for Processing Your Data | Categories of Personal Data We Process | Lawful Basis for Processing (under GDPR) | Data Retention Duration |
|---|---|---|---|
| When you browse our websites (layer5.io, getnighthawk.dev, meshery.dev, ) and applications (cloud.layer5.io, kanvas.new) | |||
| To operate, secure, and maintain our website. | IP Address, device type, browser information, server logs. | Legitimate Interest (Article 6(1)(f)) - to ensure the security, availability, and performance of our digital properties. | Up to 26 months for server logs, depending on the specific data and its purpose. |
| To analyze website usage and improve user experience. | Anonymized IP address, cookie identifiers, pages visited, duration of visit, clickstream data. | Consent (Article 6(1)(a)) - for non-essential analytics and tracking cookies. You can manage your consent through our cookie banner. | Up to 26 months for analytics data, depending on the specific service used. |
| When you join our community (e.g., Slack, Forum, GitHub) | |||
| To manage your participation and facilitate collaboration in our open-source projects. | Name, email address, GitHub username, public profile information, content of your contributions (code, comments, issues), and communications. | Legitimate Interest (Article 6(1)(f)) - to operate, manage, and grow our collaborative open source community. | Your contributions are retained indefinitely as part of the public project record. Other personal data is retained for the duration of your participation and up to 12 months thereafter. |
| When you sign up for and use Layer5 Cloud | |||
| To create and manage your account and provide our services to you. | Name, email address, company name, securely hashed password, GitHub user ID (if used for single sign-on). | Performance of a Contract (Article 6(1)(b)) - this data is necessary to fulfill our contractual obligation to provide the service you have signed up for. | For the duration of your account activity and up to 12 months thereafter for account reactivation and support purposes. |
| To process payments for our paid subscription plans. | Billing address, payment card information (we do not store full card details; they are securely processed by our payment provider, who provides us with a transaction token and confirmation). | Performance of a Contract (Article 6(1)(b)). | Financial data is retained for 7 years to comply with legal and tax obligations. |
| To communicate with you about the service (e.g., important updates, security alerts, billing information). | Email address. | Performance of a Contract (Article 6(1)(b)) and Legitimate Interest (Article 6(1)(f)) - to provide you with essential information about the service you are using. | For the duration of your account activity and up to 12 months thereafter for account reactivation and support purposes. |
| To monitor service performance and improve our products. | Service usage data, API logs, user activity logs, device and browser information. | Legitimate Interest (Article 6(1)(f)) - to maintain and improve the quality and functionality of our services. | For the duration of your account activity and up to 12 months thereafter for account reactivation and support purposes. |
| When you contact us for support or information | |||
| To respond to your inquiries and provide customer support. | Name, email address, and any other information you provide in the content of your message. | Legitimate Interest (Article 6(1)(f)) - to effectively respond to user inquiries and provide assistance. | For the duration of the support interaction and up to 12 months thereafter for quality assurance purposes. |
| When you subscribe to our marketing communications | |||
| To send you newsletters, product updates, and other marketing materials. | Name, email address. | Consent (Article 6(1)(a)) - you provide your consent when you opt-in to receive these communications, and you can unsubscribe at any time. | Until you unsubscribe. |
| INTERNAL DOC# | #gdpr-10c | #gdpr-2 | #gdpr-9b |
We use cookies and similar technologies on our website to help it function, to analyze performance, and to personalize your experience. A cookie is a small text file stored on your device.
We will not set non-essential cookies on your device without your explicit consent. You can manage your cookie preferences at any time through our cookie consent tool, which is accessible via a link in the footer of our website. Withdrawing your consent is as easy as giving it.
We do not sell your personal data. However, we share it with trusted third-party service providers who act as our data processors to help us operate our business and services. We only share the minimum amount of data necessary and have contracts in place that require them to keep your information secure and only use it for the purposes we specify.
Categories of these recipients include:
We may also disclose your personal data if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).
We may provide access or links to third-party websites, Apps, and services that are outside Layer5's control and governed by the respective third party’s privacy policy, not by this Privacy Statement. We encourage you to review the privacy statements posted on the websites you visit and in the applications you use.
If you participate in a discussion forum, local communities, or chat room on a Layer5 website, you should be aware that the information you provide there (such as your public profile and comments) will be made broadly available to others and could be used to contact you, to send you unsolicited messages, or for purposes neither Layer5 nor you have control over. Also, please recognize that individual forums and chat rooms may have additional rules and conditions. Layer5 is not responsible for the Personal Data or any other information you choose to submit in these forums. To request removal of your Personal Data from our blog or community forum, please submit a Privacy Request. In some cases, we may not be able to remove all Personal Data and comments. In such cases, we will provide you with a response and explanation.
Layer5, Inc. is based in the United States. Your personal data will be processed in the United States and other countries where our third-party service providers are located. When we transfer personal data from the European Economic Area (EEA), the UK, or Switzerland to other countries, we do so in compliance with applicable data protection laws.
For transfers of data to countries not deemed to provide an adequate level of data protection by the European Commission, we rely on legal safeguards, primarily the European Commission's Standard Contractual Clauses (SCCs), to ensure your data is protected.
We retain your personal data only for as long as is necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it, and whether we can achieve those purposes through other means.
Under the GDPR, you have several important rights regarding your personal data. These include:
To exercise any of the rights described above, please send your request to our dedicated privacy email address: privacy@layer5.io.
We will respond to your request within one month of receipt. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
Our services and community are not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that a child under 16 has provided us with personal data, we will take steps to delete such information. If you believe that a child has provided us with personal data, please contact us at privacy@layer5.io.
We may update this Privacy Notice from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any significant changes by posting the new notice on our website and, where appropriate, by notifying you directly via email. We encourage you to review this notice periodically.
We are committed to resolving any concerns you may have about our use of your information. If you have a complaint, we hope you will contact us first at privacy@layer5.io so that we can try to resolve it.
However, if you are not satisfied with our response, you have the right to lodge a complaint with a data protection supervisory authority. This will typically be the authority in the EU country where you live or work, or where the alleged infringement of data protection law occurred.
A privacy notice that promises data subject rights without the internal capacity to fulfill them creates a significant liability. Layer5 must establish a formal, documented process for managing received at the designated privacy@layer5.io email address.
Operational readiness is a core component of the accountability principle under GDPR. Having this process in place ensures that Layer5 meets legal obligations efficiently and demonstrably.
To lawfully use non-essential cookies for analytics and marketing, we obtain valid, explicit consent from users in the EU/EEA. This requires more than a simple "we use cookies" banner.
We uphold our commitment to lawfully conducting website analytics and honoring users' right to withdraw consent at any time.
In accordance with Article 30 of the GDPR, as a data controller, we maintain an internal Record of Processing Activities (ROPA). This document details all categories of personal data we process, the purposes of processing, data subjects, data recipients, international transfers, retention periods, and security measures.
We are committed to proactively ensuring clarity in all corporate communications to reinforce professionalism and transparency. We welcome your comments or questions about this privacy policy. You may also contact us as follows:
Layer5, Inc
1000 Congress Avenue
Austin, Texas 78735
Email Address: legal@layer5.io
Telephone number: 512-810-8200
Last Updated: March 8th, 2024