Privacy Policy
Last updated: July 19, 2026
1. Data Controller
The data controller is DevPrism SAS (registered with the Paris Trade & Companies Register under No. 107 187 734). Contact: privacy@devprism.io.
2. Data Collected
The Service collects: (a) Identification data: email, name, organization (when you sign up); (b) Engineering metadata: PR titles, commit statistics (count, frequency, size), CI/CD metrics (success rates, durations), issues/tickets (titles, statuses, story points), quality metrics (coverage, technical debt); (c) AI assistant usage metrics: number of suggestions accepted/rejected per tool (Copilot, Cursor, etc.); (d) Technical data: connection logs, IP address, user-agent. The Service NEVER collects source code, file contents, full commit messages, or sensitive personal data as defined by Art. 9 GDPR.
3. Processing Purposes
Data is processed to: (a) Provide engineering dashboards and metrics (contract performance); (b) Power AI investigation and suggestion agents (legitimate interest — improving engineering intelligence); (c) Calculate AI Impact / DORA / Quality correlations (contract performance); (d) Detect anomalies and generate alerts (contract performance); (e) Improve the Service (legitimate interest, aggregated and anonymized data).
4. Legal Basis
Art. 6.1.b GDPR (contract performance) for processing necessary to provide the Service. Art. 6.1.f GDPR (legitimate interest) for Service improvement and security. Art. 6.1.a GDPR (consent) for optional marketing communications and participation in anonymized benchmarks.
5. Retention Period
Account data: duration of subscription + 30 days. Synchronized metrics: duration of subscription (configurable, maximum 24 months retention). AI audit logs: 12 months. Technical logs: 90 days. After account deletion: permanent erasure within 30 days, unless legal retention obligation.
6. Hosting and Location
All account data and metrics are hosted in the European Union (Microsoft Azure, France Central region — France). No data transfer outside the EU is performed for storage. AI API calls (Azure OpenAI, Google Gemini) transmit only technical prompts (no personal data) and are covered by respective Microsoft/Google DPAs with Standard Contractual Clauses. Card payment processing (Stripe) may involve a framework-governed transfer to the United States (see §7).
7. Sub-processors
Microsoft Azure (hosting, Azure OpenAI) — EU. Google Cloud (Gemini API, embeddings) — EU. SendGrid/Resend (transactional emails) — covered by DPA. Stripe Payments Europe Ltd (billing and payment) — sub-processor established in the EU (Ireland); some processing may involve a transfer to the United States, governed by Standard Contractual Clauses and the EU–U.S. Data Privacy Framework. The up-to-date sub-processor list is available upon request at privacy@devprism.io.
8. Your Rights
Under GDPR, you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21). To exercise your rights: privacy@devprism.io. Response time: maximum 30 days. Complaint to supervisory authority: CNIL (France) at www.cnil.fr.
9. Security Measures
Encryption at rest (AES-256-GCM) and in transit (TLS 1.3). Multi-tenant isolation at application and database level. Secret management via Azure Key Vault with automatic rotation. SSO authentication via Microsoft Entra ID (MFA supported). Access logging and audit trail. Automatic backups with 35-day retention and geo-replication.
10. Cookies
The Service uses exclusively strictly necessary technical cookies: authentication token (HttpOnly, Secure, SameSite=Strict), language preference, theme preference (light/dark). No advertising or third-party tracking cookies are used. The public website uses a privacy-friendly, cookieless audience measurement solution (Plausible Analytics), hosted in the European Union, which collects no personally identifiable data. No consent is required for strictly necessary cookies or for this exempt audience measurement (ePrivacy Directive).
11. Changes
DevPrism reserves the right to modify this policy. In case of substantial modification, users will be notified by email. The current version is always accessible from this page.
12. Contact
For any questions regarding your data protection: privacy@devprism.io. No Data Protection Officer is designated at this time within the meaning of Art. 37 GDPR; your requests are handled directly by our data protection team.