1. About PCX IT
PCX IT operates the website https://pushin.eu and the Pushin source-code hosting service. This policy explains how we collect, use, and protect personal data under the General Data Protection Regulation (GDPR) (EU) 2016/679.
PCX IT is the data controller. We are responsible for handling personal data safely and only for the purposes described in this policy.
2. Personal Data We Collect
We collect and process these categories of personal data:
- Account and profile data: username, email address, display name, biography, avatar, and social links you choose to add.
- Credentials: Password hashes and personal access token hashes are stored instead of the original secrets. We also store each TOTP secret, passkey credential ID and public key, SSH public keys, and credential usage timestamps. Access tokens used for an active external provider connection are encrypted at rest.
- Repositories and Git data: repository settings, refs, commits, trees, blobs, tags, Git author and committer details, imports, mirrors, forks, and access permissions.
- Collaboration data: issues, pull requests, comments, reviews, labels, reactions, mentions, assignments, and related activity history.
- Continuous integration data: workflows, runner activity, job metadata, logs, caches, and artifacts.
- Waitlist data: your email address, invitation status, and the proof-of-humanity profile link you submit.
- External provider data: when you sign in through an external source-code hosting provider, we receive your provider login, numeric account ID, email address, and avatar. Imports and mirrors contain the repository data you ask us to retrieve.
- Technical and security data: IP address, browser and operating-system details, request records, error information, security events, and timestamps needed to operate and secure the service.
- Payment and invoice data: when paid plans become available, payment details will be collected and processed by our payment processor. We will store the processor customer reference, subscription plan, and invoice records, not full payment-card details.
We limit collection to data needed to provide, secure, and improve Pushin.
3. Data about people who are not Pushin users
A repository can contain personal data about people who do not have a Pushin account. This includes commit author and committer names and email addresses in pushed Git history, authors of issues or pull requests imported from another forge, and identities recorded in mirrored repositories.
We receive this data from Pushin users who push repositories or start an import or mirror. We process it on the basis of our legitimate interest in operating a version-control hosting service. Git history is designed to preserve authorship and cannot always be changed without rewriting the repository. Developers can reduce exposure by using a private commit email address.
If this section describes you, email get@pushin.eu to object or ask a question about the data.
4. Public by design
Public profiles, public repositories, and their public issues, pull requests, and comments are visible to anyone. Public repository data may be cloned, forked, and indexed by search engines or other services.
Deleting or changing public content on Pushin does not recall copies that other people already hold. Private repository content is available only to authorized users and the limited operational access described in our Terms.
5. How and Why We Process Your Data
We process personal data to:
- Create and secure accounts and authenticate requests.
- Host Git repositories and provide collaboration, import, mirror, and CI features.
- Apply repository visibility and access controls.
- Send account, security, waitlist, and collaboration notifications.
- Provide support, moderate content, and enforce our Terms.
- Diagnose errors, prevent abuse and fraud, and maintain service reliability.
- Administer subscriptions and meet financial record-keeping duties when billing launches.
If we need to use data for a new purpose that is not compatible with the purpose for which it was collected, we will provide the required notice or seek consent first.
6. Legal Basis for Processing
We rely on the following GDPR legal bases:
- Account, credentials, repositories, collaboration, and CI data
- Contract performance (Art. 6(1)(b)) to provide the service you request. Security and abuse prevention also rely on our legitimate interests (Art. 6(1)(f)).
- Waitlist and communications
- Steps at your request before entering a contract (Art. 6(1)(b)) and our legitimate interest in administering access and service messages (Art. 6(1)(f)).
- External provider data
- Contract performance (Art. 6(1)(b)) when you choose provider-based sign-in, import, or mirroring.
- Technical, security, and error data
- Our legitimate interests (Art. 6(1)(f)) in keeping Pushin secure, available, and reliable.
- Data about non-users
- Our legitimate interest (Art. 6(1)(f)) in preserving and serving the Git and forge data that users ask us to host.
- Payment and invoice data
- Contract performance (Art. 6(1)(b)) to administer a paid plan, and legal obligation (Art. 6(1)(c)) for required invoice and tax records.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that was lawful before withdrawal.
7. Data Sharing and Processors
We do not sell personal data or share it with third parties for their own marketing. Processors act only on our instructions and are bound by data-processing agreements under GDPR Article 28.
| Provider | Purpose | Location | Safeguard |
|---|---|---|---|
| Scaleway | Hosting, databases, object storage, and transactional email | European Union | Article 28 agreement and EEA processing |
| Sentry | Error reports, application logs, and diagnostic context | EU region | Article 28 agreement and EU-region project |
| Private Captcha | Proof-of-humanity verification and waitlist abuse prevention | European Union | Article 28 agreement and EU verification endpoint |
We may also disclose data when required by law or when necessary to establish, exercise, or defend legal claims. We will add the payment processor here before paid subscriptions launch.
8. International Data Transfers
We store and process personal data within the European Economic Area (EEA).
When you sign in through an external source-code hosting provider or import from one, we receive data from that provider. We do not send your Pushin data to external providers as part of repository imports or mirrors.
If our transfer practices change, we will update this policy and put appropriate safeguards in place before the change takes effect.
9. Data Retention
We keep data only as long as needed for the purpose described here or to meet a legal obligation.
Retention by category
- Account and profile data is kept while the account is active and while an erasure request is handled.
- Issues, pull requests, comments, reviews, and reactions remain until they are deleted or an applicable erasure request is completed, subject to the Git and third-party-copy limits below.
- Repository metadata and Git objects remain until the repository owner deletes the repository. Git history can retain author details because changing them requires rewriting history.
- CI log retention is selected in repository settings, with a maximum of 24 hours. Artifact retention is selected by the repository, with a maximum of 90 days. Expired data is removed by scheduled cleanup workers.
- Unsaved, completed notifications are retained for 150 days. Saved notifications remain until unsaved or deleted. Processed notification events and completed email batches are retained for 30 days.
- Waitlist entries remain while we administer an invitation. You may ask us to erase a waitlist entry under the rights process below.
- Access and application logs, error reports, and backups follow operational rotation schedules and are removed when no longer needed for security, diagnosis, or recovery.
- Invoice records will be retained for 7 years once paid plans are available, as required for tax and accounting records.
When data is no longer needed, we securely delete or anonymize it.
10. Your Rights Under GDPR
Depending on the circumstances, you may have rights of access, rectification, erasure, restriction, portability, and objection, as well as the right to withdraw consent and complain to a supervisory authority.
Deleting your account and data
Account deletion is not currently available as a self-service action. Please email get@pushin.eu to request erasure or account closure. We will respond within one month and explain any data we must retain or cannot remove.
Git history may contain author names and email addresses and cannot be changed without rewriting the repository. A private commit email address can reduce exposure in future commits. Erasure also cannot recall forks, clones, search indexes, mentions, or other copies held by third parties. Backup copies disappear through the normal backup rotation rather than immediately.
Access and portability
You can export repositories with git clone at any time. For a copy of other personal data, or to exercise another right, email get@pushin.eu.
12. Security Measures
Pushin uses TLS in transit, access controls, hashed passwords and personal access tokens, encrypted stored external-provider credentials, and encrypted production storage for the on-disk Git pack cache and Git working data. Access to object storage is restricted to the service.
Accounts can use two-factor authentication with an authenticator app or passkey. No online service can guarantee absolute security, so please report suspected account or data exposure promptly.
13. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects about you.
14. Children's Privacy
Our services are only available to individuals who are 18 years of age or older.
We do not knowingly collect personal data from anyone under the age of 18. If you believe a person under 18 provided us with personal data, contact us and we will take appropriate steps to remove it.
15. Changes to This Policy
We may update this policy when our service, providers, or legal obligations change. For material changes, we will post the updated policy, change the date below, and provide an additional notice when appropriate.
Last updated: 5 September 2026
16. Contact Us
For questions about this policy or your personal data, contact:
PCX ITKwikstaartlaan 42, Box A6252
3704GS Zeist
The Netherlands
get@pushin.eu
You may also complain to the supervisory authority where you live or work. A list is available on the European Data Protection Board website.