Privacy

Privacy Policy

Last updated: 15 August 2026

1. Controller

The controller responsible for the processing of your personal data within the meaning of Art. 4(7) GDPR is:

  • Controller: StennMedia
  • Chamber of Commerce (KvK): 99876302
  • VAT ID (BTW): NL005416082B66
  • Establishment: Breda, Netherlands. The full registered address is available on request and can be consulted via the Dutch Chamber of Commerce (KvK) under registration number 99876302.
  • Contact: info@stennmedia.nl

For privacy matters, please contact us at info@stennmedia.nl.

2. Data Protection Officer

StennMedia is not required to appoint a Data Protection Officer under Art. 37 GDPR. Questions and data-subject requests can be sent directly to info@stennmedia.nl.

3. Data We Process

We process the following categories of personal data:

  • Account data — name, username, email address, and a one-way hash of your password. Your password is never stored or logged in plaintext.
  • Forgejo account data — to provision your developer account, your username and email (and your chosen password or a generated temporary password on the retry path) are transmitted once, in-process, to create your Forgejo login. This is not stored or logged by gitbuild.dev beyond the hashed Laravel credential.
  • Repository & collaboration data — repositories, issues, comments, organisation membership, and related metadata that you create in Forgejo.
  • Session data — your IP address and user agent are stored in the session store to keep you logged in and for security.
  • IP address — used at signup and operationally for rate limiting, abuse prevention, and security.
  • Billing data — where you purchase a paid plan, Mollie processes your payment. We store your Mollie customer and mandate identifiers, plan, tax information, invoices, and payment status. We do not store full card or bank account numbers.
  • Newsletter data — only when you opt in: your email address, how you subscribed (registration or subscribe form), the locale of the page you subscribed on, and the timestamp of your consent.
  • Security logs — limited operational logs for security and incident response.

4. Purposes & Lawful Basis (Art. 6 GDPR)

  • Art. 6(1)(a) — consent: sending the newsletter to subscribers who opt in, until consent is withdrawn (Art. 7(3)).
  • Art. 6(1)(b) — performance of the contract: creating and operating your Git hosting account, provisioning Forgejo, and providing paid plans.
  • Art. 6(1)(f) — legitimate interests: rate limiting, fraud and abuse prevention, security monitoring, and service integrity.
  • Art. 6(1)(c) — legal obligation: retaining invoices and billing records as required by Dutch tax law.

5. Password Security Check (Have I Been Pwned)

At registration we check your chosen password against the Have I Been Pwned (HIBP) service to detect known-compromised passwords. Only a short prefix of a hash of your password is sent to HIBP; your full password is never transmitted to or shared with HIBP. This is a security measure based on our legitimate interest (Art. 6(1)(f)). HIBP is operated from outside the EU; only a non-reversible hash prefix leaves the EU, not your password or other personal data.

6. Avatars

gitbuild.dev does not use Gravatar or any external avatar service. No hash of your email address is sent to third-party avatar providers.

7. Recipients & Sub-processors

We share personal data only with the following recipients, all located within the EU / EEA except where noted:

  • netcup (Germany) — hosting of the application, Forgejo, and database. Located in Germany; no data leaves the EU / EEA.
  • Hetzner (Germany) — backup storage (Storage Box). Data encrypted at rest and in transit.
  • Have I Been Pwned — password compromise check at registration (only a hash prefix is transmitted; see Section 5).

Apart from the HIBP hash-prefix check, no personal data is transferred to a third country outside the EU / EEA.

Newsletter subscriber data is stored in the same EU database as your account. It is not shared with any email marketing provider or other third party.

8. Cookies

gitbuild.dev uses only strictly necessary cookies — a session cookie and a CSRF token cookie — required to keep you logged in and to protect against cross-site request forgery. These are essential for the service and do not require consent under the ePrivacy Directive. We do not use analytics, marketing, or tracking cookies. If we ever introduce non-essential cookies, we will add a consent mechanism and update this policy.

9. Data Retention

  • Account & repository data — retained for as long as your account is active. When you delete your account, it is deleted immediately and permanently from our live systems, including your Forgejo account; there is no restore window. Residual copies in backups are overwritten on the normal 30-day backup rotation.
  • Billing records & invoices — retained for up to 7 years as required by Dutch tax and accounting law.
  • Newsletter data — retained while your subscription is active. Withdrawing consent removes you from the list: once emails are being sent, every email includes an unsubscribe link; before that, you can withdraw at any time via info@stennmedia.nl.
  • Security & session logs — retained for a short operational window (approximately 30–90 days) for security and incident response.

10. Your Rights

Under the GDPR you have the right to:

  • Access (Art. 15)
  • Rectification (Art. 16)
  • Erasure / "right to be forgotten" (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection (Art. 21)
  • Lodge a complaint with a supervisory authority (Art. 77)

You can exercise most of these rights directly in your account settings (including account deletion). For any other request, email info@stennmedia.nl. In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens.

11. Data Protection by Design

All connections use TLS encryption. Passwords are stored as one-way hashes. Signup is protected by rate limiting and honeypot bot detection. Infrastructure is hosted exclusively in Germany (EU), with backups in the same region.

12. Changes to This Policy

We may update this Privacy Policy. For material changes we will notify you by email at your account address and post the updated date above, with at least 30 days' notice where feasible. Shorter notice may apply for changes required by law or for security reasons. If you do not agree with a change, you may close your account before the change takes effect. Continued use after the effective date constitutes acceptance, except where fresh consent is legally required.

gitbuild.dev is operated by StennMedia, established in the Netherlands. These pages are published in English as the binding version. They are provided for information and do not constitute legal advice.