политика конфиденциальности
Текст документа доступен только на английском языке.
Privacy Policy
Last updated: [EFFECTIVE DATE]
This Privacy Policy explains how personal data is processed when you use tempus.build (the “Service”), in accordance with Regulation (EU) 2016/679 (GDPR), Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights (LOPDGDD), and the transparency duties of Articles 13 and 14 GDPR.
1. Data controller
The controller of your personal data is:
- Controller:
[FULL NAME](individual entrepreneur — autónomo) - NIF/DNI:
[NIF/DNI] - Address:
[REGISTERED ADDRESS] - Contact for privacy matters:
[CONTACT EMAIL]
Data Protection Officer (DPO)
No DPO has been appointed. Under Article 37(1) GDPR, designation of a DPO is mandatory only for (a) public authorities, (b) controllers whose core activities consist of large-scale, regular and systematic monitoring of data subjects, or (c) controllers whose core activities consist of large-scale processing of special categories of data (Article 9) or criminal-offence data (Article 10). The operator is a small self-employed provider; its core activity is providing CI/CD compute, it does not carry out large-scale, regular and systematic monitoring of individuals as a core activity, and it does not process special categories of data. On that basis a DPO is not legally required.
For any privacy question or to exercise your rights, contact [CONTACT EMAIL].
2. Categories of personal data processed
| Category | Data | Source |
|---|---|---|
| Identity / account (via GitHub OAuth) | GitHub user ID, login/username, and — where available and released by your GitHub settings — email address; organization membership relevant to your tenant | You, via GitHub OAuth (Art. 13); some fields obtained from GitHub rather than directly from you (Art. 14) |
| Technical / connection | IP address, essential session cookie identifier, server and application logs, timestamps | You / your device |
| Service usage & metadata | Job and runner metadata (labels, timing, status, resource usage), and an actor-hash — a pseudonymized identifier derived by HMAC-SHA256, not reversible without the secret key | Generated by the Service |
| Billing | Prepaid-credit balance and ledger, transaction/settlement records | Generated by the Service; payment/settlement data received from the payment provider (see §4) |
| Analytics | Online/cookie identifiers, pages viewed, referrer, approximate location derived from IP, device/browser data and interaction events — including session-replay data via Yandex Webvisor. Cookie-based analytics are collected only if you accept; before consent, Google Analytics processes your IP to return cookieless, aggregated signals (see §3) | You / your device, via Google Analytics and Yandex Metrica |
Payment-card data is NOT processed or stored by the operator. Card data and tax handling are managed by the payment provider acting as Merchant of Record (see §4 and the Terms of Service).
The actor-hash is a pseudonymization measure (Art. 4(5), Art. 32 GDPR): it lets the Service correlate activity for abuse-prevention and metering without exposing a direct identifier. It remains personal data while the operator holds the secret key.
3. Purposes and legal bases
Each purpose is matched to a legal basis under Article 6(1) GDPR:
| Purpose | Legal basis |
|---|---|
| Create and authenticate your account; provide the Service (run and meter jobs, manage runners) | Contract — Art. 6(1)(b): necessary to perform the contract you enter into / take pre-contractual steps |
| Prepaid-credit accounting, per-second billing, ledger and invoicing records | Contract — Art. 6(1)(b); and legal obligation — Art. 6(1)(c) for statutory accounting/tax retention |
| Security, abuse/fraud prevention, quota enforcement, service integrity (incl. the actor-hash, IP logging, rate limiting) | Legitimate interests — Art. 6(1)(f): the operator’s interest in a secure, non-abused platform, balanced against your rights |
| LLM-based cost-advisor feature (sending aggregated cost metrics and structural labels such as repository/workflow names — no source code, no secrets, acting user pseudonymized — to an external model provider) | Legitimate interests — Art. 6(1)(f): providing an optional cost-optimization insight |
| Service-related communications (e.g. security or billing notices) | Contract — Art. 6(1)(b); or legitimate interests — Art. 6(1)(f) |
Cookie-based website analytics — Google Analytics (_ga) and Yandex Metrica — set after you accept, to understand how visitors use the site | Consent — Art. 6(1)(a): given via the cookie banner and withdrawable at any time (Art. 7(3) GDPR; Art. 22.2 LSSI-CE) |
| Cookieless, aggregated measurement by Google Analytics before any choice (consent mode — no cookies and no identifiers are stored on your device; your IP is processed by Google to return an aggregated, non-identifying signal) | Legitimate interests — Art. 6(1)(f): low-impact, non-identifying audience measurement, balanced against your rights, with the right to object (§7) |
| Complying with legal requests, exercising or defending legal claims | Legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f) |
Where processing relies on legitimate interests (Art. 6(1)(f)), you have the right to object (see §7), and a balancing test has been carried out to ensure your interests and fundamental rights do not override those interests.
Essential cookies are not used for tracking and do not require consent (Art. 22.2 LSSI-CE). Analytics cookies (Google Analytics, Yandex Metrica) are set only with your consent, which you can withdraw at any time. Before you choose, Google Analytics runs in consent mode and collects only cookieless, aggregated signals (no cookies, no cross-site identifiers) under legitimate interest; Yandex Metrica is not loaded until you accept. All of this is described in the Cookies Policy.
4. Recipients and processors
Personal data is shared only with the following recipients, each for the stated role. Data-processing agreements under Article 28 GDPR are (or must be) in place with those acting as processors.
| Recipient | Role | Purpose | Location |
|---|---|---|---|
| GitHub, Inc. | Independent controller (for GitHub’s own platform) / source of identity data | Authentication (OAuth), account identity, org membership; the Service integrates with your GitHub account | USA |
| DodoPayments | Merchant of Record / independent controller for payments; PSP | Processing of payments and taxes, card handling, settlement to the operator | US |
| OpenRouter | Processor / recipient | Receives aggregated cost metrics and structural labels (e.g. repository and workflow names) for the optional LLM cost-advisor; no source code and no secrets are sent, and the acting user is pseudonymized (hashed) | USA |
| Mailgun | Processor | Delivery of transactional email and service notifications | EU |
| Hetzner | Processor (hosting/infrastructure) | EU hosting of the platform and databases | EU (Germany/Finland) |
| Google (Google Ireland Ltd / Google LLC) | Processor / independent controller | Google Analytics — website audience measurement. Runs in consent mode: cookieless, aggregated signals before your choice; cookie-based analytics only after you accept. No advertising or remarketing signals are enabled. | USA |
| Yandex | Processor | Yandex Metrica — website audience measurement and session replay (Webvisor); loaded only with your consent | Russian Federation |
Platform and account data is stored in the EU (Hetzner). Analytics providers process data outside the EU: Yandex only if you consent, and Google in cookieless, aggregated form before your choice and cookie-based after it (see §5). Personal data is not sold and is not shared for third-party advertising.
DodoPayments acts as Merchant of Record, i.e. it is the seller of record for the payment transaction and independently determines and is responsible for card processing, tax collection/remittance, chargebacks and refunds; the operator receives settlement and does not store card data. For DodoPayments’ own processing of your data as controller, see DodoPayments’ privacy policy.
5. International data transfers
Some recipients are located outside the EEA — in the United States (GitHub, DodoPayments, Google) and, for the analytics you consent to, the Russian Federation (Yandex). Transfers rely on an Article 46 / adequacy mechanism, on legitimate interest (Google’s pre-consent cookieless measurement), or on your explicit consent (Yandex):
- GitHub, Inc. (USA): transfers are covered by the EU-U.S. Data Privacy Framework (DPF) adequacy decision (European Commission, 10 July 2023) where and to the extent GitHub is DPF-certified.
- OpenRouter (USA): where the provider is not DPF-certified, transfers rely on the European Commission’s Standard Contractual Clauses (SCCs), supported by a Transfer Impact Assessment, and by the safeguard that only aggregated, non-identifying cost metrics are transmitted.
- DodoPayments: transfers, if any, outside the EEA rely on the mechanism set out in the provider’s terms (adequacy, DPF or SCCs as applicable).
- Google (USA): Google Analytics transfers data to the US — cookieless, aggregated signals before your choice and cookie-based analytics after you accept — covered by the EU-U.S. Data Privacy Framework (DPF) adequacy decision where and to the extent Google LLC is DPF-certified, otherwise by Standard Contractual Clauses.
- Yandex (Russian Federation): the Russian Federation has no EU adequacy decision, so this transfer takes place only with your explicit, informed consent (Art. 49(1)(a) GDPR) and is further safeguarded by Standard Contractual Clauses and a Transfer Impact Assessment where relied upon. If you do not consent, no data is sent to Yandex.
You may request a copy of the relevant safeguards by contacting [CONTACT EMAIL].
6. Retention periods
- Account and identity data: for as long as your account is active; deleted or anonymized within a reasonable period after account closure, subject to the retention below.
- Billing, ledger and invoicing records: retained for the periods required by Spanish commercial and tax law (generally up to 6 years under the Código de Comercio, and per applicable tax rules).
- Security and access logs: retained for a limited period necessary for security and abuse prevention, then deleted or aggregated.
- Actor-hash and job metadata: retained while needed for metering, dispute resolution and abuse prevention, then deleted or anonymized.
- Analytics data: retained by the analytics providers (Google Analytics, Yandex Metrica) under their own retention settings and policies; the operator keeps only aggregated, non-identifying reports for as long as useful for audience measurement. Processing stops if you withdraw consent.
When no longer needed, data is securely deleted or irreversibly anonymized.
7. Your rights
Under Articles 15–22 GDPR you have the right to:
- Access the personal data being processed (Art. 15);
- Rectification of inaccurate data (Art. 16);
- Erasure (“right to be forgotten”) (Art. 17), subject to legal-retention exceptions;
- Restriction of processing (Art. 18);
- Data portability — receive your data in a structured, commonly used, machine-readable format (Art. 20);
- Object to processing based on legitimate interests (Art. 21);
- Withdraw consent at any time where processing is based on consent (without affecting prior processing).
How to exercise them: send a request to [CONTACT EMAIL], indicating the right you wish to exercise. The operator may need to verify your identity (e.g. via your authenticated GitHub account). Requests are answered within one month (extendable by two further months for complex requests, with notice), free of charge unless manifestly unfounded or excessive.
Right to complain: if you consider your rights have been infringed, you may lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD) — C/ Jorge Juan 6, 28001 Madrid — www.aepd.es (открывается в новой вкладке), or with the supervisory authority of your EU place of residence.
8. Automated decision-making and profiling
The Service does not carry out automated decision-making producing legal or similarly significant effects, nor profiling within the meaning of Article 22 GDPR. The optional LLM cost-advisor produces informational suggestions only and does not make decisions about you.
9. Security
The operator applies appropriate technical and organizational measures (Art. 32 GDPR), including EU storage of platform and account data (analytics providers process data outside the EU as described in §§4–5), encryption in transit, pseudonymization (actor-hash), least-privilege access, httpOnly session cookies, and rate limiting.
10. Changes to this policy
This Privacy Policy may be updated; the “Last updated” date reflects the current version. Material changes will be notified through the Service or by email where appropriate.
11. Contact
Privacy queries and rights requests: [CONTACT EMAIL].