Legal
Last updated: January 2026
FwChange is an enterprise firewall change management solution. This privacy policy explains how we handle data when you use our software and visit our website, in accordance with the General Data Protection Regulation (GDPR).
The data controller responsible for data processing on this website is FwChange, a personal project of Nick Falshaw, operating within the European Union. For data protection inquiries, contact us via the contact form.
When you visit fwchange.com, we collect: server log data (IP address, browser type, pages visited, timestamps) for security and analytics purposes. We use Google Analytics (with IP anonymization enabled) to understand site usage. The legal basis for this processing is our legitimate interest (Art. 6(1)(f) GDPR).
FwChange is designed for on-premise deployment. When self-hosted, your data remains entirely within your infrastructure. We do not have access to your firewall configurations, rules, or any other data processed by the application.
All application data is stored in your own PostgreSQL database. Firewall credentials are encrypted using AES-256-GCM encryption. You control all encryption keys. FwChange is self-hosted only, there is no managed or hosted instance, and the author never receives or stores your data.
If you configure integrations (JIRA, Taiga, Slack, Teams), data may be shared with those services according to their respective privacy policies. These integrations are optional and user-configured.
Under GDPR, you have the right to: access your personal data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing (Art. 21). To exercise these rights, reach us via the contact form. You also have the right to lodge a complaint with the EU Commission for Personal Data Protection (CPDP).
Website analytics data is retained for 14 months. Contact form submissions and email correspondence are retained for the duration of the business relationship plus 3 years. On-premise product data retention is controlled entirely by you.
For privacy inquiries, reach us via the contact form.
Copyright (c) 2026 Nicholas Falshaw