Privacy Policy
Effective date: July 6, 2026
This Privacy Policy explains how Lumio Software FZ-LLC, a company registered in the Ras Al Khaimah Economic Zone (RAKEZ), United Arab Emirates ("Lumio", "we", "us"), collects and processes personal data in connection with theSitrep, including thesitrep.dev, thesitrep.app, and related services (the "Service").
Contact for privacy matters: support@thesitrep.dev
1. Our two roles
We process personal data in two distinct capacities:
- As a controller for data about visitors to our website and the people who sign up for and administer accounts (e.g. your name, email, and billing records).
- As a processor for data about the members of a customer's workspace that we analyze on the customer's behalf (e.g. commit, pull request, ticket, and calendar activity of a team). For this data, your employer or the organization that runs your workspace is the controller, and we process it under their instructions and our Data Processing Agreement (available on request).
If you are a team member with questions about how your work activity is analyzed, please contact your workspace administrator first; we will assist them in responding.
2. Data we collect
Account data. Name, email address, password hash, workspace name, and role, provided when you create an account or join a waitlist.
Billing data. Purchases are processed by our merchant of record, Paddle.com Market Limited. Paddle collects your payment details directly; we never receive full card numbers. We receive transaction records (plan, amount, country, tax status) needed to operate your subscription. Paddle's privacy policy applies to payment processing: https://www.paddle.com/legal/privacy
Connected tool data. When a workspace administrator connects tools such as source control (e.g. GitHub), issue trackers (e.g. Jira), or calendars, we collect content and metadata from those tools to provide the Service: commits and code changes, pull request activity and reviews, ticket status and history, and meeting times and attendance. We use this to compute the insights the Service provides (progress, risk, rework, AI-authorship estimates, meeting load).
Usage data. Log data, device and browser type, and product interaction events, used for security, debugging, and improving the Service.
We do not intentionally collect special categories of personal data, and the Service is not directed at children under 16.
3. Purposes and legal bases
We process personal data to: provide and operate the Service (performance of contract, or the controller's instructions for workspace data); bill and manage subscriptions (contract, legal obligation); secure the Service and prevent abuse (legitimate interests); improve the Service using aggregated, de-identified data (legitimate interests); send service communications (contract) and, with your consent where required, product news (consent, withdrawable anytime).
4. Sharing and subprocessors
We do not sell personal data. We share data only with:
- Amazon Web Services (AWS): cloud hosting and storage of the Service and Customer Data.
- Paddle.com Market Limited: merchant of record for payments, billing, and tax.
- Service providers for email delivery and privacy-respecting product analytics, bound by data processing terms.
- Authorities where required by law, and successors in the event of a merger or acquisition (with notice).
A current subprocessor list is available on request at support@thesitrep.dev.
5. International transfers
We operate globally and store data on AWS infrastructure. Where personal data subject to GDPR or UK GDPR is transferred internationally, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and, where applicable, the UK Addendum.
6. Retention
Account data is kept for the life of the account and deleted or anonymized within 90 days of account closure. Connected tool data is kept while the relevant integration and workspace remain active and is deleted within 90 days after workspace deletion, integration disconnection (for further collection, with previously derived analytics retained until workspace deletion), or a verified deletion request from the controller. Billing records are retained as required by tax and accounting law. Backups roll off within 35 days.
7. Security
We follow SOC 2-aligned security practices, including encryption in transit (TLS) and at rest, least-privilege access controls, audit logging, and periodic access reviews. No system is perfectly secure; we will notify affected customers of a personal data breach without undue delay and in accordance with applicable law.
8. Your rights
Depending on your location (including under GDPR and UK GDPR), you may have rights to access, correct, delete, or receive a copy of your personal data, restrict or object to processing, and withdraw consent. To exercise them, email support@thesitrep.dev. If we process your data as a processor for your employer, we will refer your request to them and assist. You may also lodge a complaint with your local data protection authority.
9. Cookies
The website uses strictly necessary cookies and, where used, privacy-respecting analytics. We do not use third-party advertising cookies. The application uses cookies necessary for authentication and session management.
10. Changes
We may update this policy from time to time. Material changes will be notified by email or in-app notice before they take effect. The effective date above always reflects the current version.
11. Contact
Lumio Software FZ-LLC (RAKEZ, Ras Al Khaimah, United Arab Emirates)
Email: support@thesitrep.dev