How Turbo EA handles personal data across its website, blog, and online store, and the rights you have over that data.
Last updated: 11 July 2026
This policy explains how personal data is handled by Turbo EA, an open-source enterprise architecture platform. The data controller responsible for the data described here is Vincent Verdet, the individual who operates Turbo EA and its websites. This policy is written to meet the requirements of the EU General Data Protection Regulation (GDPR) and equivalent data-protection law, and it reflects a firm commitment to handling personal data lawfully, fairly, and transparently.
This policy applies to the personal data collected through the properties operated directly by Turbo EA:
The Turbo EA application itself does not collect your data. Turbo EA is self-hosted software: you run it on your own infrastructure, and it holds your enterprise architecture data on systems you control. The application and any installed extensions do not send your usage data or your architecture data back to us. Extension bundles distributed through the store are inert static files that do nothing until you choose to install them.
When you send a message through a contact form on the website, the information you enter is collected. This typically includes your name, your email address, an optional company or organization name, and the content of your message. This data is used to respond to you and to keep a record of the conversation for follow-up. Notification of your enquiry is delivered by email to the operator, and your details are stored in a customer-relationship and lead-management system so that the conversation can be managed over time.
When you buy a commercial extension, the checkout is handled by a third-party payment processor. Payment card details are entered directly with that processor and are never stored by Turbo EA. Turbo EA receives the information needed to fulfil the purchase and to issue your license, such as your email address, the extension purchased, and the status of your subscription. The license itself is delivered to you by email.
The websites use an analytics service to understand how pages are used, so the content and structure can be improved. This service sets cookies and collects information such as the pages you view, approximate location derived from your network address, the type of device and browser you use, and how you arrived at the site. This information is used in aggregate and is not used to identify you personally.
The websites are served through a hosting and content-delivery provider. To deliver pages and to protect the sites against abuse, that provider processes technical request data such as your network (IP) address and browser information. Contact forms are additionally protected by a bot-detection challenge, which may set a cookie in order to tell automated traffic from genuine visitors.
Under the GDPR, every use of personal data rests on a lawful basis. The bases relied on here are:
A cookie is a small file stored by your browser. The websites use a limited set of cookies:
You can control or delete cookies through your browser settings. Blocking analytics cookies does not affect your ability to use the sites.
Your personal data is never sold, rented, or traded to anyone. Data is shared only with the service providers that make the websites and store function, and only to the extent each provider needs to perform its role. These providers act as processors on documented instructions and are not permitted to use your data for their own purposes. They fall into the following categories:
Data may also be disclosed where required by law, for example in response to a valid legal request from a competent authority.
Some of the service providers listed above operate outside the European Economic Area. Where personal data is transferred internationally, it is protected by appropriate safeguards, such as the European Commission’s standard contractual clauses or an adequacy decision recognising an equivalent level of protection.
Personal data is retained only for as long as it is needed for the purposes described in this policy. Enquiry and lead information is kept for as long as there is a genuine prospect of a business relationship, and is removed when it is no longer relevant. Records tied to purchases are kept for the period required by tax and accounting law. Analytics data is retained according to the analytics service’s standard retention settings.
Under the GDPR you have the following rights over your personal data:
To exercise any of the rights above, or to ask a question about this policy, please get in touch through the contact form on the website. Requests are handled promptly and, in any case, within the time limits set by the GDPR.
The websites and the store are intended for professional and business use and are not directed at children. Personal data relating to children is not knowingly collected.
This policy may be updated from time to time to reflect changes in how data is handled or in legal requirements. When it changes, the date shown at the top of this page will be revised. Significant changes will be made clearly visible on this page.