Privacy
Last updated 28 September 2026.
This page explains what personal data AcquiCode at acquicode.infinityore.com processes, why, for how long, and your rights. The controller is the operator of this AcquiCode deployment. For source code and dossiers, your organisation decides what is analysed and we act on its behalf.
What we collect
| Data | Source | Why | Kept for |
|---|---|---|---|
| GitHub account id, username, display name, verified primary email | GitHub, when you sign in | Signing you in; showing who did what; invitations | Until you ask us to delete your account |
| Google account identifier, verified email, display name | Google, only when you choose Google sign-in | Signing you in; showing who did what | Until you ask us to delete your account |
| Session records: a hash of your session token, IP address, browser user agent | Your browser | Keeping you signed in; security | Until the session expires, then deleted automatically |
| Audit events: who did what, when, and from which IP address | Your actions in the app, share-link views | Security and accountability for your organisation | Life of your organisation (append-only) |
| Repository contents | Repositories you connect or upload | Producing a dossier | Only for the duration of an analysis, then deleted |
| Contributor names and email addresses from git history | Commit metadata in your repositories | The contributor register in the dossier (who wrote the code, under which agreement) | Inside dossiers, for your organisation's retention period |
| Dossiers, declarations, IP registers you upload | You and the analysis | The service | Your organisation's retention period (7–3,650 days, set in Settings); declarations until deleted |
| Billing details | You, at checkout | Payment | Held by the payment provider; we keep the plan and customer reference |
We use no advertising or third-party analytics, and set only the cookies needed to sign in and remember your selected organisation.
Contributors named in git history
Dossiers list the people who committed code, because ownership of code depends on who wrote it. Their data comes from the repository your organisation chose to analyse, and is processed on your organisation's behalf for its legitimate interest in establishing ownership of its software. If you are a contributor and have a question, contact the organisation that analysed the repository, or us.
Legal bases
Performing our contract with you (running the service), our legitimate interests (security, preventing abuse, improving reliability) and legal obligations (tax and accounting records). Where we rely on legitimate interests you may object.
Who else receives data
Only the subprocessors needed to run this deployment, for the purposes stated there. No language model or machine-learning vendor receives your code or dossiers, and nothing is used to train models.
Security
Encryption in transit and at rest, per-organisation isolation enforced in the database, short-lived read-only repository tokens, and an append-only audit log. Details on the security page.
Your rights
You can access, correct, export or delete your data. Organisation owners can delete repositories, dossiers or the whole organisation in the app at any time. For anything else, including deleting your account, write to the operator of this deployment. You may also complain to your data-protection authority.