Privacy Policy & Data Processing Agreement
🛡️ The Core Doctrine: Zero Code Retention (RAM-Only)
Garnet Gate was architected under an unyielding sovereign principle: Your proprietary source code is never stored, never written to disk, and never shared.
When a GitHub Pull Request webhook triggers our inspection engine, the incoming code diff is parsed and audited purely in volatile RAM within our secure Frankfurt cluster (fra). Within milliseconds of publishing the GitHub Check Run, the memory space is permanently purged.
1. Information We Process
To deliver automated Pull Request gating and process B2B subscriptions, Garnet Gate processes only the minimal metadata required:
- Installation Metadata: GitHub Organization / User Account ID, GitHub Installation ID, and repository name identifiers solely to enforce tier quotas (e.g. 5 repos on Solo Pro, 1 repo on Student).
- Ephemeral Pull Request Diffs: Code lines submitted in a Pull Request are inspected strictly in-memory and immediately destroyed. We never retain copies, clones, or full git histories.
- Commercial Billing Information: For paid subscriptions, Customer email address, company name, and Stripe Customer ID are stored to maintain subscription entitlement and transmit official VAT/tax invoices. All payment card details are handled directly by Stripe (PCI-DSS Level 1 certified).
2. What We Never Do
- We NEVER store or persist customer code, git history, or pull request diffs on persistent storage or databases.
- We NEVER train, fine-tune, or feed customer proprietary code into public or private Large Language Models (LLMs).
- We NEVER sell, monetize, broker, or disclose customer code or organization metadata to third parties or advertising brokers.
- We NEVER track your developers with tracking pixels, session replay scripts, or advertising cookies.
3. Global Regulatory Alignment
Garnet Gate's sovereign infrastructure is intentionally located in Frankfurt, Germany to satisfy the most stringent multi-jurisdiction compliance frameworks:
🇪🇺 GDPR & EU CRA
Operates as a compliant Data Processor under GDPR Article 28. Validates pre-merge code integrity aligned with direct supply-chain liabilities under the EU Cyber Resilience Act.
🇸🇦 Saudi PDPL & GCC
Zero-retention volatile processing guarantees compliance with Saudi Personal Data Protection Law and UAE Decree-Law 45/2021 by ensuring zero offshore data storage.
🇯🇵 APPI & 🇰🇷 PIPA
Respects Japan's Act on the Protection of Personal Information and South Korea's PIPA by treating developer code as confidential intellectual property with immediate erasure.
🇺🇸 SOC 2 & HIPAA Shield
Provides healthcare and FinTech engineering teams with audit-ready check runs proving no PII or PHI leaked through AI-generated pull requests.
4. Data Storage & Encryption Standards
All network communications between GitHub, our API endpoints, and Stripe are encrypted in transit using TLS 1.3. Our persistent database (garnet-gate.db) contains zero customer code and is strictly limited to subscription status records encrypted at rest on dedicated Fly.io Frankfurt encrypted volumes.
5. Customer Rights & Data Deletion
Customer maintains the unilateral right to delete all organization metadata at any moment. Uninstalling the Garnet Gate GitHub Application immediately revokes repository access. To request complete purging of your Stripe billing record, simply contact our compliance desk.
6. Privacy Inquiries & DPO Contact
For custom Data Processing Agreements (DPA), vendor security questionnaires, or direct inquiries to our Data Protection Officer, please contact:
Data Protection Officer & Sovereign Security Desk
Nivansware Studios
Email: privacy@nivansware.com / rifaiangga6@gmail.com