ReviewPilot
  • Terms
  • Privacy
  • DPA

Draft — pending legal review

LEGAL

Privacy Policy

Last updated: [date]

Contents

  1. 1. Who we are
  2. 2. Controller and processor roles
  3. 3. Data we collect
  4. 4. Purposes and legal bases
  5. 5. Recipients and sub-processors
  6. 6. International transfers
  7. 7. Retention
  8. 8. Security
  9. 9. Your rights
  10. 10. Complaints
  11. 11. Cookies
  12. 12. Children
  13. 13. Changes to this policy
  14. 14. Contact

This Privacy Policy explains how ReviewPilot collects and uses personal data when you visit our website, join our design partner programme, create an account or use the service, and which rights you have under the General Data Protection Regulation (GDPR) and Portuguese data protection law.

1. Who we are

The controller responsible for the processing described in this policy is [Company legal name, Unipessoal Lda], NIPC [NIPC], with registered office at [Registered address, Portugal]. You can reach us about privacy matters at [privacy email].

2. Controller and processor roles

We act as a controller for the personal data we need to run our business: website and waitlist data, accounts and teams, usage, billing records and technical logs. This policy covers that processing.

When customers connect their repositories, ReviewPilot processes the content of their pull requests, including code diffs, commit and pull-request metadata and the usernames of developers, on behalf of and under the instructions of the customer. For that data, the customer is the controller and we act as its processor under our Data Processing Agreement (DPA). If you are a developer whose code or username appears in a customer's repository, please contact that customer to exercise your rights.

  • Data Processing Agreement
  • Terms of Service

3. Data we collect

  • Account data: name, email address, hashed password, team name, role (owner or engineer), invitation and confirmation records.
  • Team and configuration data: team settings, connected repositories and their names, source control connection details, chosen AI provider and model, retention and review-guidance settings. API keys and access tokens are stored encrypted and are never shown back.
  • Service and usage data: reviews run, review findings, scores and triage decisions, pull-request titles, branch names and author usernames, token counts and monthly quota usage, and notifications.
  • Billing data: plan, subscription status and the records we receive from our Merchant of Record, [Merchant of Record, e.g. Paddle], such as the customer name, country and transaction references. The Merchant of Record collects and processes payment details as an independent controller; we never see card numbers.
  • Waitlist and contact data: name, work email, company, role, team size and any message you send us through the design partner form or by email.
  • Technical data: IP address, browser and device information, request identifiers, timestamps and error logs generated when you use the website and the service.

We do not intentionally collect special categories of personal data. Please do not include such data in pull requests or messages to us.

4. Purposes and legal bases

  • To create and manage accounts and teams, provide the service, run reviews and send service emails such as confirmations, invitations and notifications: performance of a contract (Art. 6(1)(b) GDPR).
  • To manage subscriptions, plans and quotas with our Merchant of Record: performance of a contract, and compliance with legal obligations such as accounting and tax rules (Art. 6(1)(b) and (c) GDPR).
  • To keep the service secure, prevent abuse and fraud, debug problems and understand how the service is used so we can improve it: our legitimate interests in operating a secure and reliable service (Art. 6(1)(f) GDPR).
  • To answer your questions and requests and to exercise or defend legal claims: our legitimate interests, or the performance of a contract where you are a customer.
  • To manage the design partner waitlist and send you information about the programme or marketing communications: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time without affecting prior processing.
  • To comply with legal obligations and requests from competent authorities: compliance with a legal obligation (Art. 6(1)(c) GDPR).

We do not sell personal data and we do not use personal data for automated decision-making that produces legal or similarly significant effects on you.

5. Recipients and sub-processors

We share personal data only with service providers who need it to help us run ReviewPilot and who are bound by appropriate contractual obligations:

  • [hosting provider], which hosts our application and database;
  • [email provider], which delivers transactional emails such as confirmations, invitations and notifications;
  • [Merchant of Record, e.g. Paddle], our reseller and Merchant of Record, which sells subscriptions, processes payments and handles taxes;
  • GitHub and Bitbucket, when you connect them, to retrieve pull requests and, if you enable publishing, post reviews.

The AI provider that reviews your code (for example OpenAI, Anthropic or Google) is chosen and contracted by the customer, which supplies its own API key. That provider processes the submitted content under the customer's agreement and instructions, not as our sub-processor.

We may also disclose personal data to professional advisers, to authorities where required by law, or to a successor in the event of a merger, acquisition or sale of assets, subject to this policy.

6. International transfers

Some of our providers may process personal data outside the European Economic Area. Where a transfer is not covered by an adequacy decision of the European Commission, we rely on the Standard Contractual Clauses adopted by the Commission, together with supplementary measures where needed. You can request a copy of the relevant safeguards at [privacy email].

7. Retention

  • Account and team data: for as long as the account or team exists; after deletion we erase or anonymise it within [deletion period], unless we must keep it longer.
  • Pull-request diffs: discarded right after analysis by default (0 days). Team owners may choose to keep them for 7 or 30 days, after which an automatic job that runs every hour purges them.
  • Review findings, scores, metadata and triage history: until the customer deletes them or closes the team.
  • Billing and accounting records: for the periods required by Portuguese tax and accounting law.
  • Waitlist entries: until the design partner programme ends, or earlier if you ask us to delete them or withdraw your consent.
  • Technical logs: for a limited period of up to [log retention period], unless needed longer to investigate a security incident.

8. Security

We protect personal data with technical and organisational measures appropriate to the risk, including encryption of API keys and access tokens at rest with AES-256-GCM, encryption in transit with TLS, HMAC verification of incoming webhooks, strict isolation between teams, role-based access for owners and engineers, hashed passwords, single-use and time-limited invitation links, configurable source retention with automatic purging, and least-privilege access to source control. No system is completely secure, but we work to protect your data and will notify you and the authorities of personal data breaches where required by law.

9. Your rights

Subject to the conditions set out in the GDPR, you have the right to:

  • access your personal data and obtain a copy of it;
  • have inaccurate data rectified and incomplete data completed;
  • have your data erased;
  • restrict the processing of your data;
  • receive your data in a portable format and have it transmitted to another controller;
  • object to processing based on our legitimate interests, and at any time to direct marketing;
  • withdraw your consent at any time, where processing is based on consent.

To exercise these rights, email [privacy email]. We may need to verify your identity, and we will answer within one month, which may be extended by two further months for complex requests. Many account details can also be updated directly in your account settings.

10. Complaints

If you believe we have not handled your personal data lawfully, please contact us first so we can try to resolve the issue. You also have the right to lodge a complaint with a supervisory authority, in particular the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt, or the authority of your habitual residence or place of work.

11. Cookies

ReviewPilot uses only cookies that are necessary for the website and the service to work, or that remember a choice you made. We do not use analytics, advertising or other tracking cookies.

  • _review_pilot_key: the session cookie that keeps you signed in and carries the token protecting forms against cross-site request forgery (CSRF); it expires when the session ends.
  • _review_pilot_user_remember_me: set only if you choose to stay signed in; it expires after 14 days.
  • reviewpilot_sidebar: remembers whether you collapsed the workspace sidebar; it expires after one year.

Because these cookies are strictly necessary or store a preference you set, they do not require consent. You can delete them in your browser settings, but parts of the service may stop working.

12. Children

ReviewPilot is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

13. Changes to this policy

We may update this policy to reflect changes to the service or to the law. We will publish the new version on this page with a new date and, for material changes, notify customers by email or in the service before they take effect.

14. Contact

[Company legal name, Unipessoal Lda], [Registered address, Portugal]. Privacy requests: [privacy email]. General contact: [contact email]. Website: [domain].

ReviewPilot [Company legal name, Unipessoal Lda] · NIPC [NIPC] Back to ReviewPilot