Privacy notice
What personal data the SOM Managed Bus sandbox processes, why, for how long, who helps us process it, and how to use your rights.
This notice covers the SOM Managed Bus sandbox: this website, its request-access form, the portal you sign in to, the docs and the bus API. It explains what personal data we process, why, and for how long, and how you can use your rights under the EU General Data Protection Regulation (GDPR).
The sandbox is a test environment for newsroom software vendors and news publishers. It is built to carry synthetic test data only, so we keep the personal data it needs to a minimum.
Who we are
The controller of your personal data is:
- R&D Solutions Ltd. (RND Solutions)
- UIC 203244195, VAT number BG203244195
- 1 Atanas Dukov str., floor 6, EN Building, 1407 Sofia, Bulgaria
- Data protection contact: dataprotection@rnd-solutions.net
You can write to that address without an account. Company details are also on the legal notice.
What we process, why, and on what basis
When you request access
The request-access form asks whether you are a vendor or a publisher, and for your organisation, its website, your name, your work email, what you want to test and the message families you expect to use. With the request we store the version of the sandbox terms you accepted, the time, and the IP address it came from.
- Why: so an RND engineer can review the request, reply to you, and set up your workspace if it is approved. The IP address helps us spot and stop abuse of the form.
- Legal basis: steps you ask us to take before entering into an agreement (GDPR Art. 6(1)(b)), and our legitimate interest in deciding who gets access to the sandbox and in protecting the form from abuse (Art. 6(1)(f)).
- Who sees it: the request is stored in the portal's database and a copy is emailed to RND's team mailbox (without the IP address).
You don't have to give us these details, but without them we can't review a request or open a workspace.
When you have an account
A portal account holds your email address, your password and your authenticator (TOTP) setup, which the sign-in service keeps; we never see your password. The portal also records the workspaces you belong to and your role in each, and invitations that name your email address.
- Why: to let you sign in securely, work in your workspace, and send you the emails the service needs (invitations, sign-in, and the notifications you choose).
- Legal basis: performance of our agreement with you or your organisation (Art. 6(1)(b)).
The audit log
Important actions in the portal, such as issuing credentials or inviting someone, and every page RND opens under a support grant, are recorded in an audit log: who acted, what they acted on, when, and from which IP address. Some entries include an email address, for example when someone is invited.
- Why: security, and to be able to show who did what.
- Legal basis: our legitimate interest in keeping the service secure and accountable (Art. 6(1)(f)).
Ask RND
When you send a message with Ask RND in the portal, it is emailed to RND's team mailbox with your sign-in email address and the page you asked from, so an engineer can reply. The portal does not store the message.
- Legal basis: performance of our agreement with you (Art. 6(1)(b)).
Messages you send through the bus
Message payloads must be synthetic test data only, never real personal data (see the sandbox terms). They are not intended to hold personal data, and we don't use them to learn anything about people.
If real personal data is sent anyway, tell us at the contact address above. We will remove what we can reach, and anything left expires on the schedule below. We may suspend a connection that keeps sending it.
Service logs
The service writes operational logs so we can run it and fix problems. The bus's gateway logs ids and outcomes, never payloads. The portal's logs also hold some email addresses: when a portal account is created, invited, changed or removed, the log line names that account's email address. Logs are kept for one month. The firewall in front of the API logs only the requests it blocks or flags, including their IP address, with the authorisation header removed.
- Legal basis: our legitimate interest in running a secure, working service (Art. 6(1)(f)).
How long we keep it
| Data | How long |
|---|---|
| Access request | Deleted 12 months after it was made. Its IP address is deleted as soon as the request is approved or rejected. |
| Portal account and workspace records | While the account or workspace exists. Ask us to remove them at any time. |
| Audit log entries | 365 days |
| Message archive (payloads, for replay) | 30 days in production, 7 days on staging |
| Message queues | Up to 14 days |
| Story timeline in the portal | 7 days |
| Test runs | 90 days |
| Service and firewall logs | 1 month |
| Database backups (point-in-time recovery) | Up to 35 days |
The databases that hold workspaces, the audit log and access requests have point-in-time recovery. A record deleted from them can remain in those backups for up to 35 days, and is then gone.
Emails in RND's team mailbox (access-request copies and Ask RND messages) are not deleted automatically. Ask us and we will delete them.
Who receives it
RND's engineers see what they need to run the sandbox and answer you. We don't sell personal data or share it for advertising.
Sub-processors
These providers process personal data for us, under their data processing terms:
| Provider | What for | Where |
|---|---|---|
| Amazon Web Services (AWS) | Hosting the whole service: sign-in (Amazon Cognito), databases, messaging, storage, content delivery (Amazon CloudFront), email sending, keys, firewall and logs | EU (Ireland, eu-west-1). CloudFront's certificates are held in us-east-1, and CloudFront answers requests from its edge location nearest to you. |
| Microsoft (Microsoft 365) | RND's email, which receives access-request notifications and Ask RND messages | As set for RND's Microsoft 365 tenant |
We will update this list before we add a provider that processes personal data. Where a provider processes data outside the European Economic Area, we rely on the safeguards in its data processing terms, such as the EU Standard Contractual Clauses.
Cookies and browser storage
The sandbox uses no analytics and no advertising or tracking cookies.
- Signing in: the portal keeps your sign-in tokens in your browser's session storage, which is cleared when you close the tab. If you use the sign-in service's own hosted page, it sets its own cookie to remember that sign-in.
- Preferences: the portal remembers your colour theme, the workspace you last chose and whether you have seen the first-run guide, in your browser's local storage. The docs remember your colour theme the same way.
These are strictly necessary for the features you use, so we don't ask for consent to them. None of them is used to track you.
Your rights
You have the right to:
- access the personal data we hold about you;
- have it corrected if it's wrong;
- have it erased;
- restrict how we use it;
- object to processing based on our legitimate interests;
- receive it in a portable format (portability).
If you have a portal account, you can do two of these yourself on the Your account and data page, under People: download what the portal holds about you as a JSON file, and delete your account. A workspace's owners can delete the workspace there too. Deleting removes your sign-in and your memberships at once. Audit log entries about you stay until they expire (365 days), and backups for up to 35 days, as described above. A few records a workspace leaves behind are removed by RND.
For anything else, or if you have no account, email dataprotection@rnd-solutions.net from the address the data is about, or tell us how to confirm it's you. We will reply within one month.
We don't make decisions about you by automated means that have legal or similarly significant effects. An RND engineer reviews access requests.
You also have the right to complain to a supervisory authority. In Bulgaria that is the Commission for Personal Data Protection (CPDP), cpdp.bg. You can also complain in the EU country where you live or work.
Changes to this notice
When we change this notice we publish the new version here, with a new date below. If a change matters to how we use your data, we will tell account holders by email.
Version 2026-09 · last updated