Sprinno
Legal

Privacy Policy

Last updated: July 20, 2026

privacy-policy.md

This Privacy Policy describes how Veesta Labs (“Sprinno”, “we”, “us”, or “our”) collects, uses, stores, and protects information when you use the Sprinno platform and services. As a technical due diligence platform that analyses source code repositories, we understand the sensitivity of the data entrusted to us and have designed our practices accordingly.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Name and email address
  • Organisation name and role
  • Authentication credentials (hashed and salted — never stored in plaintext)
  • Billing information (processed by our payment provider; we do not store full payment card details)

1.2 Repository & Technical Data

When you connect a repository for analysis, we access and process:

  • Dependency manifests (e.g., package.json, requirements.txt, Gemfile, go.mod)
  • Configuration and infrastructure files
  • Commit metadata (authors, timestamps, message content, branch structure)
  • Pull request and merge history
  • Test configuration and coverage report outputs
  • CI/CD pipeline configurations
  • Licence declarations and NOTICE files

Important: We do not store, copy, or retain the full source code of connected repositories. Our analysis processes code in-memory for structural and risk indicators, then discards the raw source. Only derived metadata and scoring outputs are persisted.

1.3 Usage Data

We automatically collect:

  • Pages visited and features used within the platform
  • Device type, browser, and operating system
  • IP address and approximate geographic location
  • Referring URLs and navigation paths
  • Timestamps of interactions

2. How We Use Your Information

We use collected information for the following purposes:

Providing the Services

Performing technical due diligence analysis, generating risk scores, producing reports, maintaining your IP & licence register, and delivering continuous monitoring.

Account Management

Creating and maintaining your account, authenticating access, managing subscriptions and billing, and communicating service-related information.

Platform Improvement

Improving analysis accuracy, developing new features, optimising performance, and enhancing user experience based on aggregated usage patterns.

Security & Compliance

Detecting and preventing fraud, abuse, or security incidents, enforcing our Terms of Service, and complying with legal obligations.

3. Data Sharing & Disclosure

We do not sell your personal information or repository data. We share information only in the following limited circumstances:

  • Service Providers: Trusted third-party services that help us operate the platform (cloud hosting, payment processing, email delivery). These providers are bound by contractual obligations to protect your data.
  • Report Recipients: When you choose to share a diligence report via a shareable link, recipients can view the report contents you have made available.
  • Legal Requirements: When required by applicable law, regulation, legal process, or governmental request.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred to the successor entity under equivalent privacy protections.
  • With Your Consent: In any other circumstance where you have provided explicit consent.

4. Data Security

Given the sensitivity of technical infrastructure data, we implement robust security measures:

  • All data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Repository access tokens stored in isolated, encrypted vaults
  • Role-based access controls within the platform
  • Regular security audits and penetration testing
  • Incident response procedures with defined notification timelines
  • Infrastructure hosted on SOC 2-compliant cloud providers
  • Minimal data retention — analysis artifacts that are no longer needed are purged automatically

No system is perfectly secure. While we employ industry-standard protections, we cannot guarantee absolute security. We will notify affected users promptly in the event of a data breach involving personal information.

5. Data Retention

We retain information according to the following schedule:

  • Account data: Retained while your account is active, deleted within 30 days of account deletion
  • Analysis results & reports: Retained while your account is active or until you delete specific reports
  • Repository connection data: Deleted immediately upon disconnection of the repository
  • Usage analytics: Aggregated and anonymised after 24 months
  • Billing records: Retained for 7 years as required by applicable tax and financial regulations

6. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data (subject to legal retention requirements)
  • Portability: Request your data in a structured, machine-readable format
  • Restriction: Request that we limit processing of your data in certain circumstances
  • Objection: Object to processing based on our legitimate interests
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent

To exercise any of these rights, contact us at aw@sprinno.xyz. We will respond within 30 days.

7. Repository-Specific Privacy Measures

Because we handle sensitive technical infrastructure data, we maintain additional safeguards:

  • No source code storage: Full source code is never persisted — only structural metadata and derived analysis outputs
  • Isolated analysis environments: Each repository analysis runs in an isolated, ephemeral compute environment
  • Access token scoping: We request the minimum permissions required for read-only analysis
  • Immediate revocation: You can disconnect a repository at any time, immediately revoking our access
  • No cross-client data mixing: Analysis data from one customer is never visible to or used for another customer

8. International Data Transfers

Sprinno operates from Uganda and may process data using infrastructure located in multiple jurisdictions. Where data is transferred internationally, we ensure appropriate safeguards are in place, including standard contractual clauses and data processing agreements with our service providers. We comply with applicable data protection laws regarding cross-border data transfers.

9. Third-Party Integrations

Sprinno integrates with third-party services (e.g., GitHub, GitLab) to provide its functionality. When you authorise these integrations:

  • We access only the data necessary for our analysis services
  • The third party’s own privacy policy governs their handling of your data
  • You can revoke integration permissions at any time through both our platform and the third party’s settings
  • We do not access private messages, issues, or data unrelated to technical analysis

10. Children’s Privacy

The Services are not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 18, we will take steps to delete that information promptly.

11. Cookies & Tracking Technologies

We use cookies and similar technologies to maintain sessions, remember preferences, and understand usage patterns. For comprehensive details on the cookies we use and how to manage them, please see our Cookie Policy.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 14 days before taking effect. The “Last updated” date at the top of this page indicates when the policy was most recently revised.

13. Contact Us

For questions about this Privacy Policy or to exercise your data rights, contact us:

Veesta Labs
Email: aw@sprinno.xyz
Website: sprinno.xyz

© 2026 By Veesta.Diligence OS — Technical Due Diligence, Continuous.