Legal
Privacy statement
What this site records, why it is allowed to and how to have it removed.
Version 2026-09-09.
Who is responsible
DossierForge is built and sold by Skoft Software, a sole proprietorship established in the Netherlands and registered with the Kamer van Koophandel under 42097143. Skoft Software decides what happens to the data described below, which makes it the controller in the sense of the GDPR. The full business identification is on the imprint. Write to hello@dossierforge.com about anything on this page.
Writing to that address means we hold your address and your message for as long as answering them takes. The basis is our legitimate interest in answering the people who write to us, under article 6(1)(f) of the GDPR. A settled exchange is deleted with ordinary mailbox housekeeping rather than archived forever.
How this site works
Fonts, styles and images load from this domain. The site uses no analytics or tracking pixels. When you first interact with a signup form, your browser loads the Cloudflare Turnstile challenge. That challenge uses browser state, including cookies, to check the submission.
The free scope check sends one request to this site when it produces a result. The host counts these requests as completed checks. The request contains no answers, product details, cookies, identifiers or referrer.
Cloudflare sees your network address when you visit and keeps short-lived operational logs to run and protect the site. Skoft Software reads completed-check totals, not those logs. The basis for this handling is our legitimate interest in running and defending the site, under article 6(1)(f) of the GDPR. Those logs live only as long as that operational purpose needs.
Choosing a light or dark theme saves that preference in your browser. It is not sent to a server.
The waitlist
Giving an address is entirely voluntary. No law and no contract requires it. The only thing that happens if you do not is that no build log arrives.
Submitting the form subscribes you immediately and records:
- the email address you typed
- the moment you gave consent, to the second
- the version of the consent sentence that stood next to the checkbox
Your IP address is not stored. No name, no company, no referrer and no record of which page you were on when you did it.
The basis is your consent, under article 6(1)(a) of the GDPR and article 11.7 of the Telecommunicatiewet. The timestamp and consent version provide a record of what you agreed to and when.
One welcome email goes out the moment you join. After that the purpose is the weekly DossierForge build log and one message when the beta opens. Nothing else is sent to this list. It is never sold, rented, lent or shared for anyone else to mail.
Someone else can enter your address. To remove it, open the unsubscribe link in the welcome email and press Unsubscribe. If you would rather not press anything in an email you did not ask for, one line to hello@dossierforge.com does the same thing by hand within five working days.
You can withdraw at any moment. Withdrawing is as easy as giving. Every email carries an unsubscribe link. One button on the page it opens removes the address. Your mail client's own unsubscribe button does the same thing in one press. If you no longer have one of our emails, one line to hello@dossierforge.com removes you by hand within five working days. Withdrawing stops everything that has not been sent yet. What was done on your consent before that moment stays lawful.
Your address is deleted when you withdraw. If DossierForge is not on sale by 31 December 2027, the whole list is deleted without anyone having to ask.
Who else touches it
The following companies process the website and feedback data described here. Neither may use it for its own purposes.
- Cloudflare, Inc. serves this site, holds the waitlist in its key value store and sends the mail. It also runs the challenge that stands in front of the forms here, its own Turnstile: fetched when you first touch a form rather than when you open the page, reading the browser that is submitting rather than anything you typed. What it hands back to us is a yes or a no. Cloudflare replicates the waitlist store across its data centres, so your address is held outside the European Economic Area as well as inside it, in the United States among other places. Cloudflare, Inc. is certified under the EU-US Data Privacy Framework, which the European Commission recognises as adequate protection, so the transfer rests on that adequacy first, with the standard contractual clauses in Cloudflare's data processing addendum standing behind it should the certification ever fall. Write to hello@dossierforge.com for a copy of those clauses; Cloudflare also publishes the addendum on its own site.
- Google LLC receives what you send to hello@dossierforge.com, because that mailbox is forwarded to a Google hosted inbox. It touches nothing unless you choose to write to us. Google is certified under the same EU-US Data Privacy Framework.
The licence check in the application
The installed application sends its licence key to license.skoft.app for validation. The service does not store the submitted key or link it to an email address. Cloudflare keeps sampled operational request metadata, including request times, URLs and response status codes.
As with any request to any website, Cloudflare's edge sees the network address the request came from and handles it as the processor described above. The basis is our legitimate interest in answering the request and keeping the endpoint defended, under article 6(1)(f) of the GDPR, for as long as the edge's own operational logs live and no longer.
Licence validation, app update checks at updates.skoft.app and scanner database downloads from its publisher run automatically. Scanning and document generation run on your machine.
Optional connections in the application
When you run or schedule a vulnerability check, component names and versions go to the public OSV database at api.osv.dev. CVE identifiers go to the public NVD database at services.nvd.nist.gov. If you set an NVD API key, it is sent to NVD with those requests. Checks also download the public list of known exploited vulnerabilities from cisa.gov when needed. No product information is sent to CISA.
If you connect GitHub or GitLab, your access token goes to the service you configured. The app reads release information and downloads SBOM files from that service. These services also receive the network address the requests come from.
Sending feedback from the application
Pressing Send in the Feedback panel sends your message, attached screenshots, app version, operating system and processor architecture. You choose whether to include diagnostics and a reply address. Dossier documents are not attached automatically; anything you include in your message or screenshots is sent.
feedback.dossierforge.com receives the report and relays it to hello@dossierforge.com. The relay does not store report content. Cloudflare keeps sampled operational request metadata, including request times, URLs and response status codes. The mailbox forwards to a Google hosted inbox, so Google LLC receives the report. Include a reply address if you want a response.
Your rights
You can ask for a copy of what we hold about you, have it corrected, have it deleted, have what we do with it restricted, receive it in a portable form, or object to it. You can withdraw consent at any moment. One email to hello@dossierforge.com is enough. We answer within one month and in practice within the same week.
No decision about you is taken automatically here. No profile of you is built from any of this.
If you think we have this wrong, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl.
Changes
This statement carries the date it took effect. If it ever changes in a way that affects data already given, everyone on the waitlist is told by email before the change takes effect, not after it.
Join the waitlist
Get the weekly DossierForge build log and an email when the beta opens.