AcquiCode diligence

Privacy

Last updated 28 September 2026.

This page explains what personal data AcquiCode at acquicode.infinityore.com processes, why, for how long, and your rights. The controller is the operator of this AcquiCode deployment. For source code and dossiers, your organisation decides what is analysed and we act on its behalf.

What we collect

DataSourceWhyKept for
GitHub account id, username, display name, verified primary emailGitHub, when you sign inSigning you in; showing who did what; invitationsUntil you ask us to delete your account
Google account identifier, verified email, display nameGoogle, only when you choose Google sign-inSigning you in; showing who did whatUntil you ask us to delete your account
Session records: a hash of your session token, IP address, browser user agentYour browserKeeping you signed in; securityUntil the session expires, then deleted automatically
Audit events: who did what, when, and from which IP addressYour actions in the app, share-link viewsSecurity and accountability for your organisationLife of your organisation (append-only)
Repository contentsRepositories you connect or uploadProducing a dossierOnly for the duration of an analysis, then deleted
Contributor names and email addresses from git historyCommit metadata in your repositoriesThe contributor register in the dossier (who wrote the code, under which agreement)Inside dossiers, for your organisation's retention period
Dossiers, declarations, IP registers you uploadYou and the analysisThe serviceYour organisation's retention period (7–3,650 days, set in Settings); declarations until deleted
Billing detailsYou, at checkoutPaymentHeld by the payment provider; we keep the plan and customer reference

We use no advertising or third-party analytics, and set only the cookies needed to sign in and remember your selected organisation.

Contributors named in git history

Dossiers list the people who committed code, because ownership of code depends on who wrote it. Their data comes from the repository your organisation chose to analyse, and is processed on your organisation's behalf for its legitimate interest in establishing ownership of its software. If you are a contributor and have a question, contact the organisation that analysed the repository, or us.

Legal bases

Performing our contract with you (running the service), our legitimate interests (security, preventing abuse, improving reliability) and legal obligations (tax and accounting records). Where we rely on legitimate interests you may object.

Who else receives data

Only the subprocessors needed to run this deployment, for the purposes stated there. No language model or machine-learning vendor receives your code or dossiers, and nothing is used to train models.

Security

Encryption in transit and at rest, per-organisation isolation enforced in the database, short-lived read-only repository tokens, and an append-only audit log. Details on the security page.

Your rights

You can access, correct, export or delete your data. Organisation owners can delete repositories, dossiers or the whole organisation in the app at any time. For anything else, including deleting your account, write to the operator of this deployment. You may also complain to your data-protection authority.