Privacy policy
Your data stays tied to a clear purpose.
This policy explains what personal data To200 handles, why it is needed, where it goes, and the choices you have.
Effective July 25, 2026
1. Who is responsible
Bizlution AB is the data controller for account administration, billing, service security, product communications, and operation of the To200 website.
When your organization submits source code, logs, monitoring events, or other Customer Content, your organization normally decides why that data is processed. In that context, your organization is the controller and Bizlution AB processes the data to provide To200.
2. Personal data we process
- Account data: name, work email, user identifier, authentication provider, organization, role, and account settings.
- Workspace & integration data: repository names, provider account identifiers, project configuration, permissions, and connection status.
- Operational content: source-code context, commit metadata, errors, stack traces, breadcrumbs, logs, task activity, pull-request evidence, and verification output.
- Billing data: plan, credit balance, usage, transaction identifiers, invoice details, country, and tax information. Stripe handles full payment-card details.
- Communications: support, security, product feedback, and other messages you send us.
- Technical & security data: IP address, browser and device information, authentication events, audit records, and diagnostics needed to protect the service.
- Launch attribution: UTM campaign fields and the page that referred you, when those values are carried into account creation.
3. Why we process personal data
Provide the service
Create accounts, connect tools, run repair workflows, maintain workspaces, and provide support.
Basis: Contract
Secure the service
Authenticate users, prevent abuse, investigate incidents, and maintain audit integrity.
Basis: Legitimate interests
Bill for paid use
Process subscriptions, top-ups, invoices, taxes, credits, and account entitlements.
Basis: Contract & legal obligation
Improve reliability
Diagnose failures, measure product performance, and improve safe stopping and verification.
Basis: Legitimate interests
Communicate
Send transactional messages and respond to requests. Marketing is sent only where permitted.
Basis: Contract, legitimate interests, or consent
Comply with law
Keep required business records and respond to valid legal requests.
Basis: Legal obligation
We do not use your Customer Content to train a public or shared model unless your organization separately agrees to that use.
4. Where data comes from
We receive data directly from you, from your organization’s administrators, and from providers you connect, such as GitHub, Vercel, Supabase, Slack, and Stripe. Operational data may also come from the monitoring script or server endpoint your organization installs.
The exact data available from an integration depends on the provider permissions you approve and your organization’s configuration.
7. International transfers
Some providers may process data outside Sweden or the European Economic Area. When GDPR requires it, transfers rely on an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful safeguard. You may contact us for information about the safeguard relevant to your data.
8. Retention
We keep personal data only as long as needed for the purposes above. Default workspace settings retain operational data for 365 days and audit records for 2,555 days. Workspace retention settings may change those periods within the limits shown in the product.
- Account and workspace data is kept while the account is active and as needed to close it safely.
- Billing and tax records are kept for the period required by applicable accounting and tax law.
- Security records may be kept as needed to investigate abuse, protect users, or establish legal claims.
- Data may remain longer when law requires it, a dispute is active, or deletion would affect another person’s rights or audit integrity.
9. Security
We use controls designed to protect data against unauthorized access, alteration, disclosure, and loss. These include scoped OAuth permissions, Row Level Security, server-side secrets, access checks, signed events, replay protection, branch isolation, and audit trails.
No internet service is risk-free. Report a suspected vulnerability or data incident to security@to200.dev. See the Security model and Trust center for current controls.
10. Your privacy rights
Depending on the processing and applicable law, you may ask for access, correction, deletion, restriction, portability, or an objection. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.
Send a request to security@to200.dev. We may need to verify your identity and your relationship to a customer workspace. If your request concerns data controlled by your employer or another customer, contact that organization first; we will assist it where required.
You may lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority.
11. Customer-controlled data
A customer organization decides what repository and production data it connects, who can access the workspace, which autonomy level is enabled, and how long workspace data is retained. If you use To200 through an employer or client, that organization’s policies also apply.
Organizations that need a data processing agreement or details about subprocessors can contact security@to200.dev.
12. Children
To200 is a professional developer tool and is not directed to children. You must be at least 18 years old to create an account. If you believe a child has provided personal data, contact us so we can investigate and delete it where appropriate.
13. Changes & contact
We may update this policy when the service, providers, or legal requirements change. We will post the new effective date and provide reasonable notice of material changes.
Privacy questions and requests may be sent to security@to200.dev or to Bizlution AB, c/o Albin Holmgren, Kalvhagen 7, 427 50 Billdal, Sweden.