Skip to content

executionist.app

Privacy Policy

Version 1.0 · In force from 2 August 2026

In plain terms. This summary helps you read the rest; where the two differ, the rest of this document governs.

  • We run a planning and record-keeping tool for ISO/IEC 27001 and ISO 9001 certification projects. We sell to organisations, not to consumers.
  • We collect three things that matter: your account details, your answers to the intake questionnaire, and the records you create in the product — evidence entries and an event log.
  • Your intake answers describe your organisation's security and quality posture. We treat them as confidential, and we say below exactly who can read them.
  • The database and the servers that run the application are in Frankfurt, Germany. Your intake answers, evidence and records do not leave the EU.
  • Two suppliers do process some personal data in the United States: Clerk, which handles sign-in, and Resend, which delivers email. We name exactly what each one sees.
  • We do not run analytics, advertising, session replay or A/B tooling. We do not process your data with an AI or language model, and we do not use it to train anything. We make no automated decisions about people. We take no payments, because we do not yet charge.
  • We are not ourselves ISO 27001 certified or SOC 2 attested. We say so plainly, because you will ask.

Who we are

The controller of the personal data described in this policy is Superstellar GmbH, a Swiss Gesellschaft mit beschränkter Haftung (GmbH), registered at Baarerstrasse 52, 6300 Zug, Switzerland, CHE-433.879.620, entered in the Commercial Register of the Canton of Zug. We operate the service at executionist.app.

For anything in this policy — questions, requests, or complaints — write to hello@executionist.app. A person reads it. We have not appointed a data protection officer; we are not required to, and we would rather say so than imply a function that does not exist.

What we collect, why, and for how long

Each category below is collected for the stated purpose and nothing else. Where we name a lawful basis, it is the basis under the EU and UK GDPR; under the Swiss FADP the equivalent processing is justified by the performance of the contract or by our legitimate interest in running the service.

WhatWhyLawful basisKept for
Account detailsYour name, email address, profile picture and organisation name, so you can sign in and so the record can say who did what.Performance of a contractWhile the account exists, then deleted within 90 days of closure.
Intake answersYour responses to the questionnaire, which describe your organisation, its sites, its systems and its current security or quality practices. They are what the certification file is drawn up from.Performance of a contractWhile the file is live, then deleted within 90 days of account closure.
Named colleaguesThe name, email address and role of the sponsor, project lead and area owners you nominate. We hold them so the plan can name an owner for each part of the work.Legitimate interest, and your instruction as our customerAs above. Any named person may ask us to remove their details at any time.
Evidence and the recordThe links and attestations you enter as evidence, hashed and timestamped, and an append-only log of who did what and when. Immutability is the point: an audit record that can be quietly edited is not a record.Performance of a contractWhile the file is live. Deleted with the account; individual entries cannot be edited, only superseded.
Email we send youIntake links, invitations, and — only if you ask for it — a PDF copy of your intake record.Performance of a contractDelivery logs held by our email supplier for a short period; see below.
Server logsOrdinary request logs kept by our hosting provider, used to keep the service running and to investigate faults and abuse.Legitimate interestRetained by the provider on its own schedule, typically no more than 30 days.

We do not yet run an automated deletion job. Until we do, deletion on request and on account closure is carried out by hand, against the periods above. We would rather tell you that than imply a mechanism we have not built.

Whose data it is, and who is responsible

Two different relationships sit inside one product, and the distinction decides who you should approach.

Your account, and this website

We are the controller. We decide what to collect and why, and this policy is our notice to you.

What you put into your file

For the intake answers, the evidence and the record — including the colleagues you name — we act as a processoron your organisation's instructions. Your organisation decides what goes in. We process it to provide the service and for nothing else. If you are an employee of a customer and want your details corrected or removed, you may write to us directly and we will act, but the quickest route is usually your own organisation.

If you were named by someone else

If you are reading this because a colleague entered your name, email address and role into an intake, then: we hold those three things, we obtained them from your organisation, we use them to attribute work in a certification plan, and we keep them as set out above. You have the rights described below, including the right to object. Write to hello@executionist.app and we will remove you from the plan on request. We do not currently email people to tell them they have been named; the organisation that entered the details is responsible for telling its own people, and we are working on giving them a direct notice instead.

Signing in with Google

If you choose to sign in with Google, Google passes us — through Clerk, our sign-in provider — four things: your name, your email address, your profile picture, and the Google account identifier that lets us recognise you on your next visit.

We request only the basic sign-in permissions (openid, email, profile). We ask for no access to Gmail, Drive, Calendar, Contacts or any other Google service, and we cannot read them.

We use that data only to create and authenticate your account, and to show who took an action in the record. We do not sell it, we do not share it with advertisers, we do not use it for marketing, and we do not use it to train any model. If we ever wanted to use it for something else, we would ask you first.

You can disconnect executionist from your Google account at any time in your Google account settings. Doing so stops future sign-in; to delete the data we already hold, ask us.

Where your data is

The database and the servers that execute the application both run in Frankfurt, Germany. Your intake answers, your evidence and your record are stored and processed in the European Union.

Two suppliers process a narrower set of personal data in the United States: Clerk, which holds the account identity used to sign you in, and Resend, which delivers our email. Where we ask Resend to send you the PDF copy of your intake, that email — and therefore your answers — passes through their infrastructure. Those transfers rely on the European Commission's standard contractual clauses, together with the UK addendum and the Swiss amendments where they apply. Before relying on a supplier's participation in the EU–US Data Privacy Framework we check its current entry on the official list rather than take it on trust.

If you would rather your intake record was never emailed, simply do not tick the box that offers it. Nothing else is sent by email except the link that opens your intake and, where relevant, your invitation.

Who processes your data for us

We use four suppliers, and no others. Each one is bound by a data processing agreement and may use its own suppliers in turn — Neon runs on Amazon Web Services, for example.

SupplierWhat it doesWhere it processes
ClerkSign-in, accounts, organisations and invitations. Holds your name, email address and profile picture.United States
NeonThe database. Holds your intake answers, the certification file, evidence entries and the event log.Frankfurt, Germany (on AWS)
VercelHosting and application execution, and bot detection on the public intake form. Sees requests as they are served.Frankfurt, Germany, for application execution
ResendTransactional email: intake links, invitations, and the PDF record of intake where you ask for it.United States

We will tell you before adding a supplier that processes your data. There is no analytics provider, no advertising network, no session-replay tool and no AI service in this list, because we use none.

Who at our company can read your answers

Your intake answers describe how your organisation protects itself. We treat them as confidential. In practice a very small number of people at Superstellar GmbHcan read them: those who administer the service, through the product's own admin screens or through direct database access.

Access through the product is recorded in the event log. Direct database access is not separately logged today. We would rather state that plainly than let you assume otherwise, and it is on our list to change.

How we protect it

We describe only measures that actually exist. We are not ISO 27001 certified and hold no SOC 2 report of our own.

  • Everything travels over TLS. The database is reached over an encrypted connection and is encrypted at rest by the provider.
  • Every read and write in the workspace is scoped to your organisation and checked on the server, not merely hidden in the interface.
  • Evidence entries are hashed with SHA-256 at the moment of entry and cannot be edited afterwards; a correction is a new entry recorded beside the original.
  • The record of who did what and when is append-only.
  • The intake questionnaire accepts no file uploads, so we never hold your documents — only the links and attestations you choose to enter.
  • Intake links are single-purpose, expire, and are stored only as a hash, so we cannot reconstruct one from our own database.
  • Sign-in, password handling and multi-factor authentication are managed by Clerk. Automated abuse of the public intake form is filtered by bot detection.
  • Access to production is limited to the people who run the service.

Cookies

We set no advertising or analytics cookies. The cookies in use are the ones that make sign-in work — set by Clerk to keep you signed in and to protect against cross-site request forgery — together with any cookie our bot-detection uses to tell a person from an automated script on the public intake form. There is no consent banner because there is nothing to consent to beyond what is strictly necessary to run the service.

Your rights

Whether you are a customer, an employee of one, or someone whose details were entered by a colleague, you may ask us to: give you a copy of the personal data we hold about you; correct it; delete it; restrict how we use it; object to our use of it; or send it to another provider in a portable form. Where we rely on your consent, you may withdraw it at any time.

Write to hello@executionist.app. We will answer within one month. There is no charge. We may ask you to confirm who you are, so that we do not disclose one person's data to another.

One limit worth stating: the audit record is deliberately immutable, because a certification record that can be silently altered is worthless. We can delete a whole file or a whole account. We cannot quietly rewrite an entry inside one while leaving the rest standing — a correction is recorded as a further entry.

Complaints

Tell us first if you can. You may also complain to a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC); in the EU, the authority in the country where you live or work; in the UK, the Information Commissioner's Office.

Children

The service is for organisations and the people who work in them. It is not directed at children and we do not knowingly collect their data.

Changes to this policy

When we change it we update the version and the date at the top and record what changed below. If a change materially affects how we use data you have already given us, we will tell account holders directly rather than rely on you noticing.

VersionDateWhat changed
1.02 August 2026First published.