← BAXY SSL

Privacy Policy

Last updated: 24 July 2026

1. Data controller

BAXY IT Sp. z o.o. (BAXY IT Spółka z ograniczoną odpowiedzialnością)
Registered office: Plac Kaszubski 8/107, 81-350 Gdynia, Poland
KRS 0001108913 (District Court Gdańsk-Północ in Gdańsk), NIP 5862406501, REGON 528800690
Contact: contact@baxy.it

2. BAXY SSL has no server

The app runs entirely in your browser. We operate no backend that stores anything about you, and we set no cookies and run no analytics. The code is open source and can be verified.

3. What we process and why

4. Recipients and transfers outside the EEA

Recipients are ISRG/Let's Encrypt, Cloudflare, Google, and the operator of allorigins.win, all located in or transferring data to the USA — a transfer outside the EEA under Chapter V GDPR. These transfers rely on Art. 49(1)(b) GDPR (necessary to perform the certificate issuance you requested) and, where applicable, the providers' EU-US Data Privacy Framework certification and/or Standard Contractual Clauses. allorigins.win is a free public relay we have no processing agreement with, used only for a best-effort HTTP file check that you may skip.

5. What is stored in your browser

To let you resume a started verification, we store on your device (not on our server) for up to 7 days: in localStorage the domains, optional email and order; in IndexedDB the ACME account key as a non-extractable key that cannot be read back out. UI preferences (language, theme) are stored separately. No cookies. Clearing your site data removes all of it. This storage is strictly necessary/functional (ePrivacy), so it needs no consent and no cookie banner.

6. Your rights

We hold no data server-side, so you exercise access and erasure by clearing your browser data. For the email passed to Let's Encrypt, contact ISRG as a separate controller. You have the right to lodge a complaint with the Polish supervisory authority (Prezes UODO).