Privacy Policy
What we process, why, where it lives, and the rights you and your team have over it - in plain language.
Effective 2026-07-30
1. Who we are
Busfactor (busfactor.tech) provides an engineering-organization assessment platform: it connects read-only to the tools your engineering org already uses and computes an evidence-linked diagnosis. For the data your org connects, your company is the controller and Busfactor acts as a processor. For your account data (email, login), Busfactor is the controller.
Controller identity
- VojGin s.r.o. (operating Busfactor)
- Registered seat: Argentinská 1140/30, Holešovice, 170 00 Praha 7, Czech Republic
- IČO (company number): 19630727 · VAT ID: CZ19630727
- Registered with the Městský soud v Praze (Prague Municipal Court), file C 389056
- Contact for anything in this policy, including data-subject requests: support@busfactor.tech
2. What we process
Data you connect (org data)
- Code-host metadata - commits, pull requests, reviews, review comments, repository names, contributor names and handles.
- Ticketing metadata - issues/tickets, states, types, assignees, timestamps.
- Collaboration signals - messages from the specific channels you point us at (e.g. a deploy channel). Nothing is processed under this heading today: the chat connector is waiting on marketplace app review, and this policy covers it in advance rather than changing under you the week it clears.
- CI & incident metadata - workflow/deploy runs, error/incident events from connected providers.
Data you give us directly
- Account data - email address, password (stored hashed), org membership and role.
- Configuration - org settings, connector tokens (encrypted; read-only scopes), intake answers (headcount, cost figures you choose to enter).
- Free scan report - if you ask for the dependency scan report by email: your address, the verdict you saw, the terms version you accepted and whether you asked for our updates. We are the controller. We use it to send you the report and to answer questions about it later, and we keep it until you ask us to delete it: delete it here. The file you scanned is parsed in memory and never stored.
- Support correspondence - what you send to support@busfactor.tech.
3. Why we process it
- To compute your org’s assessment - the entire point of the product. Numbers are computed deterministically from the connected data and quoted with receipts; they are never invented.
- To operate accounts: authentication, authorization, notifications you configure.
- To provide support when you contact us.
- To bill for the service.
We do not sell personal data, use your private org data to train models, or use it for advertising.
4. Legal bases (GDPR)
- Contract - providing the service you signed up for (account data, org data processing on your instructions).
- Legitimate interest - service security, abuse prevention, minimal product analytics.
- Legal obligation - accounting and tax records.
- Consent - our product updates, if you ticked the box. Withdraw it from any message.
5. Where your data lives
You choose your org’s data region - EU (default) or US - during onboarding. The two regions are separate deployments, so your choice is where the data physically sits. Moving an existing org between regions is a manual migration our team runs for you - ask support and we will schedule it. See the Security & Compliance page for encryption and access details.
6. Who else touches it (subprocessors)
Only the parties needed to run the service - our hosting provider, plus the tools you connect (which already hold your data; we only read from them). The current list, with purposes, is maintained on the Security & Compliance page.
7. How long we keep it
- Org data - for the life of your subscription (it powers your history and trends), plus 90 days past a lapse or termination, then deleted. Enterprise retention is what your agreement says.
- Free scan report - your address and the verdict, until you ask us to delete them (here).
- Review-comment bodies - retained only for a short, configurable classification window, then nulled.
- Account data - until you delete your account.
- Invoices/records - as long as law requires.
8. Your rights
Access, export, rectification, erasure, restriction, objection, and portability - for both account holders and the team members whose work metadata is processed on an org’s behalf. Write to support@busfactor.tech; we verify the request and respond within the statutory timelines. You can also complain to your local supervisory authority.
Stopping the mail and erasing the record are separate: every message carries one-click unsubscribe, and erasure is the request above (or, for a scan report, this link).
9. Cookies
We use a session cookie to keep you signed in and a CSRF token to protect writes. No third-party advertising or cross-site tracking cookies.
10. Changes
We’ll post updates here with a new “last updated” date, and notify org admins of material changes before they take effect.
11. Contact
support@busfactor.tech - privacy requests, questions, complaints.