Privacy Policy
This policy explains what personal data ARUKU processes when you use rickub, why, on what legal basis, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR).
1. Who is responsible
The data controller for your account data is ARUKU, a French société à responsabilité limitée (SARL, share capital €5,000) registered in France under SIREN 538 461 476 (RCS Nanterre). You can reach our data protection contact at dpo@rickub.com or privacy@rickub.com.
2. What we process and why
| Data | Purpose | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Account data — handle, email, display name, bio, password hash | Create and secure your account; sign you in | Performance of a contract |
| Authentication data — sessions, personal access tokens, SSH and GPG public keys, two-factor secrets | Authenticate git and web access; protect your account | Performance of a contract; legitimate interest in security |
| Repository and collaboration data — repositories, organizations, teams, issues, merge requests, CI runs | Provide the hosting and collaboration features | Performance of a contract |
| Billing data — organization plan, seat counts, payment references | Process payments and invoicing for paid plans | Performance of a contract; legal obligation (accounting) |
| Security and audit logs — sign-in events, administrative and organization actions, request metadata | Detect and investigate abuse; meet security obligations | Legitimate interest in security; legal obligation |
| Support correspondence | Answer your questions | Legitimate interest in supporting you |
We do not use advertising trackers or sell personal data, and we do not build behavioural profiles of you. See our Cookie Policy.
3. Where your data is processed
Your account and repository data is hosted and processed within the European Union (France). Where a subprocessor is involved we choose EU-based providers; our current subprocessors, their purpose and location are listed on the Subprocessors page. The one exception is our own mailboxes, which are hosted by Proton AG in Switzerland — a country the European Commission has recognised as providing an adequate level of data protection, so no additional transfer mechanism is required. It affects only correspondence you choose to send us; transactional mail we send you is handled by an EU provider.
4. How long we keep it
We keep account and repository data for as long as your account is active. When you delete your account we erase or irreversibly anonymise your personal data within 30 days, except records we must retain by law (for example accounting records, kept for the statutory period) and minimal accountability records of your data-subject requests. Security logs are retained for a limited period proportionate to their purpose and then deleted.
5. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate data (edit most of it directly in Settings);
- erase your data (“right to be forgotten”);
- receive your data in a portable, machine-readable format;
- restrict or object to certain processing;
- withdraw consent where processing is based on consent.
You can exercise the two most common rights yourself, right now, from Settings → Privacy & data: download a machine-readable export of your account data, or request account deletion. For anything else, email privacy@rickub.com. You also have the right to lodge a complaint with a supervisory authority — in France, the CNIL (www.cnil.fr).
6. Security
We protect personal data with encryption in transit and at rest, deny-by-default access control, and audit logging. Our Security & trust page describes these measures. No system is perfectly secure; git is distributed, so keeping your own clones is a sensible backstop.
7. Children
rickub is not intended for children under 16 and we do not knowingly collect their data.
8. Changes
We will post updates here and, for material changes, notify account holders. The effective date above reflects the current version.