Who is responsible
Pillion Ltd, Unit 4, Kingsland Studios, 118 Richmond Road, London E8 3HN, United Kingdom, is the controller for personal data we process for our own purposes. If Pillion processes data in your content on behalf of your organization, the organization is the controller and our DPA applies.
Data we collect
- Account data: name, email address, verification status, passkeys, SSH keys, organization membership, and authentication records.
- Customer content: the repository data and personal data a customer chooses to store in repositories, issues, pull requests, comments, attachments, workflow logs, artifacts, and audit records.
- Service data: IP address, user agent, request timing, security events, and error and delivery metadata needed to operate and protect the service.
- Commercial data: organization, seat, invoice, and payment transaction data. Full card numbers are entered into Mollie’s hosted checkout and are not stored by Pillion.
- Communications: messages and attachments sent to support, security, legal, or abuse contacts.
Why we use it
We use personal data to provide the service, authenticate users, secure the platform, enforce repository permissions and quotas, send transactional mail, respond to support and legal requests, process organization billing, comply with law, and maintain operational records. We use the legal basis that applies to the activity: contract, legal obligation, legitimate interests, or consent where required.
Pillion does not sell personal data, place third-party advertising in the authenticated product, or use customer content to train models.
Sharing and transfers
We share data with providers in the subprocessor list only for their stated roles. Mollie receives billing data through hosted checkout and acts as an independent controller for payment transactions; Mollie’s privacy terms govern that processing. Core Git and product stores are operated in allowed geography. External integrations, webhooks, identity providers, and customer-attached runners may receive data when enabled by the customer.
Retention and deletion
We retain account and transaction records for as long as needed to provide the service and meet legal, security, accounting, and dispute obligations. Customer content is retained until the customer or an authorized administrator deletes it or the account ends, subject to configured artifact, cache, and backup retention. Contact info@pillion.dev for a request or export question.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection. If Pillion processes your data for a customer, contact that customer first; Pillion will assist the customer as required by the DPA. You may also complain to the UK Information Commissioner’s Office or your local data-protection authority.
Cookies and changes
The marketing site uses only cookies and storage strictly needed for operation. The authenticated product has no third-party advertising or analytics. We may update this policy and will publish the new effective date and material changes on the site or status page. Privacy and DPO requests go to info@pillion.dev; our external DPO is Bergmann & Voss, Berlin. You may complain to the UK Information Commissioner’s Office or your local data-protection authority.