Privacy Policy
CUBES
Version: 2.0
Effective Date: 29 July 2026
Last Updated: 29 July 2026
1. Who operates CUBES
CUBES is operated by an individual founder residing in Italy (the "Operator", "we", "us", or "our"). At this stage, CUBES is not operated by a registered legal entity.
This Privacy Policy explains how personal data is handled in connection with the CUBES websites, controlled private-beta environment, accounts, software-analysis tools, integrations, reports, support, and related services (collectively, the "Service").
2. Scope and roles
The Service is intended for business and professional use.
CUBES may act in different data-protection roles depending on the processing:
- Controller: for account administration, beta enrollment, customer and representative records, legal acceptances, billing or commercial administration, security, fraud prevention, service operations, support, communications, and compliance records.
- Processor: for personal data contained in repositories, source code, documents, prompts, instructions, and other Customer Content that CUBES processes on behalf of a Customer under its documented instructions.
Where CUBES acts as a processor, the applicable Data Processing Agreement governs that processing and the Customer remains responsible for its instructions, lawful basis, notices, and decisions concerning the personal data it submits.
3. Categories of personal data
Depending on how the Service is used, we may process:
- account and identity data, including name, email address, role, organization, and account identifiers;
- business and legal-profile data, including business name, address, registration or tax details, representative authority, legal acknowledgements, and acceptance evidence;
- authentication and integration data, including GitHub account identifiers, OAuth metadata, installation identifiers, repository permissions, and connection status;
- repository and technical data, including repository names, branches, paths, commit metadata, source code, configuration, documentation, and technical artifacts selected by the Customer;
- Customer Content, including uploaded files, prompts, instructions, and materials submitted for analysis;
- generated reports, findings, classifications, summaries, and other outputs;
- usage, device, network, and log data, including timestamps, IP address, browser or device information, request metadata, audit events, diagnostics, and security signals;
- support, feedback, and communications data;
- payment, invoice, or transaction metadata where applicable; and
- preference, notice-delivery, and legal-compliance records.
CUBES does not intentionally request special-category, health, biometric, payment-card, government-identifier, children's, employee-monitoring, or similarly regulated data during the private beta unless prior written approval and required safeguards are in place.
4. Sources of personal data
We may receive personal data:
- directly from users and authorized representatives;
- from the Customer that provides or connects content;
- from GitHub and other integrations selected by the Customer;
- automatically through use of the Service;
- from service providers supporting authentication, hosting, communications, security, monitoring, or processing; and
- from public or business sources where reasonably necessary to verify organization or contact information.
5. Purposes of processing
We may process personal data to:
- create and administer accounts and the controlled private-beta relationship;
- verify business eligibility, representative authority, legal acceptance, repository authorization, and data eligibility;
- provide, configure, operate, and support the Service;
- access and analyze repositories, documents, and other Customer Content according to the Customer's instructions;
- generate and deliver AI-assisted and automated outputs;
- authenticate users and maintain integrations;
- secure the Service, prevent fraud and abuse, investigate incidents, and enforce access controls;
- maintain audit, evidence, versioning, and compliance records;
- communicate service, legal, security, and operational notices;
- respond to support and rights requests;
- improve reliability, usability, and safety using appropriately limited operational information and feedback;
- establish, exercise, or defend legal claims; and
- comply with applicable law and binding requests.
Customer Content is not used for unrelated advertising or sale of personal data. Any use of Customer Content for model training or broader product development requires a separate lawful basis, appropriate disclosure, and any required agreement or customer authorization.
6. Legal bases where CUBES acts as controller
Depending on the circumstances and applicable law, CUBES relies on one or more of the following legal bases:
- performance of a contract or steps requested before entering into a contract;
- legitimate interests in operating, securing, supporting, and improving a business service, preventing misuse, and protecting legal rights;
- compliance with legal obligations;
- consent, where consent is specifically requested and legally appropriate; and
- establishment, exercise, or defense of legal claims.
Acknowledgement of this Privacy Policy is not treated as consent for processing that relies on another legal basis.
Where CUBES acts as a processor, the Customer determines the lawful basis for personal data included in Customer Content.
7. Repository and integration processing
Before CUBES accesses a repository, the Customer must provide a separate Repository Access and Processing Authorization.
GitHub OAuth or another technical connection authenticates access but does not itself constitute legal authorization. Depending on the selected configuration, repository content and metadata may be retrieved, transmitted, temporarily cached, stored, analyzed, or included in reports.
The Customer must connect only repositories and content it is authorized to provide and must remove secrets, credentials, private keys, unnecessary live personal data, and prohibited regulated data before connection.
8. AI-assisted processing
The Service may use AI providers, automated analysis, heuristics, and software tools to process Customer Content and generate outputs.
AI-assisted outputs may be incomplete or incorrect and must be reviewed by a qualified human before action is taken. CUBES does not use AI-assisted outputs as the sole basis for decisions that produce legal or similarly significant effects concerning individuals on behalf of CUBES.
Customers must not use the Service as the sole decision-maker for employment, credit, healthcare, insurance, legal, financial, safety-critical, or other high-impact decisions.
9. Recipients and service providers
Personal data may be disclosed to authorized service providers that support:
- cloud hosting, storage, databases, and content delivery;
- authentication and repository integrations, including GitHub;
- AI and software-analysis processing;
- email and operational communications;
- monitoring, logging, diagnostics, and security;
- customer support and business operations; and
- legal, accounting, insurance, or professional advice.
Providers may process data only for the relevant services and subject to applicable contractual and legal requirements. Current provider or subprocessor information may be identified in the Data Processing Agreement, Security Statement, subprocessor notice, or applicable service documentation.
We may also disclose personal data where required by law, to protect rights or safety, in connection with a proposed incorporation or business transfer, or with the Customer's instruction or authorization.
10. International data transfers
Some providers may process personal data outside Italy or the European Economic Area.
Where required, appropriate safeguards will be used, such as an adequacy decision, standard contractual clauses, or another lawful transfer mechanism. The applicable Data Processing Agreement may provide additional terms for Customer Content.
The private beta should not be used for regulated or restricted data unless the relevant transfer, security, and contractual requirements have been reviewed and approved.
11. Retention
Personal data is retained only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Service, maintain security and auditability, comply with law, resolve disputes, and enforce agreements.
Retention periods may vary by data category. In general:
- active account and customer records are retained while the relationship continues;
- legal acceptances, repository authorizations, audit events, and compliance evidence may be retained for the applicable limitation, legal, or defense period;
- security and diagnostic logs are retained for a limited operational or security period;
- Customer Content and generated artifacts are retained according to the configured service, deletion request, applicable agreement, and technical deletion cycle; and
- backups may persist temporarily until overwritten through normal backup rotation.
When data is no longer required, it is deleted, anonymized, or isolated from active use, subject to lawful retention obligations.
12. Security
CUBES uses technical and organizational measures appropriate to the nature of the Service and the risks of processing, which may include access controls, authentication, logging, encryption in transit, provider security controls, restricted administrative access, and incident-response procedures.
No system is completely secure. Customers remain responsible for account security, repository permissions, secret removal, lawful configuration, and independent backups.
Suspected security incidents should be reported promptly using the current contact details on the Legal / Contact page.
13. Data subject rights
Subject to applicable law, individuals may have rights to:
- obtain information about processing and access personal data;
- correct inaccurate or incomplete data;
- request deletion;
- restrict or object to certain processing;
- receive portable data where applicable;
- withdraw consent where processing is based on consent, without affecting prior lawful processing; and
- lodge a complaint with a competent data-protection authority.
Requests concerning data for which CUBES acts as controller should be submitted using the Privacy Contact listed on the Legal / Contact page.
Where a request concerns Customer Content for which CUBES acts as processor, the request may need to be directed to the relevant Customer. CUBES will provide reasonable assistance as required by the applicable Data Processing Agreement and law.
Identity or authority may be verified before fulfilling a request.
14. Account deletion and Customer Content deletion
An authorized user may request account deletion through the available product process or current contact channel.
Deletion may remove or deactivate active account data and associated Customer Content, subject to:
- the Customer's instructions and administrator rights;
- technical deletion cycles and backup rotation;
- retention of legal, security, billing, audit, or dispute records; and
- data that must be retained to comply with law or protect legal rights.
Deleting an account does not automatically revoke another Customer's rights to records or content controlled by that Customer.
15. Cookies and similar technologies
The Service may use cookies or similar local technologies that are necessary for authentication, session continuity, security, preferences, and core functionality.
Non-essential analytics or marketing technologies should be used only with any notice and choice required by applicable law. Additional information may be provided in a Cookie Policy or consent interface where applicable.
16. Children
The Service is intended only for authorized business users who are at least eighteen (18) years old. CUBES does not knowingly offer the Service to children or intentionally collect children's personal data during the private beta.
17. Automated decision-making
CUBES may use automated tools to generate technical findings and recommendations about software and repositories. CUBES does not intend to make solely automated decisions about individuals that produce legal or similarly significant effects.
Customers are responsible for ensuring that their use of outputs includes appropriate human review and complies with laws governing automated decision-making.
18. Changes to this Policy
We may update this Privacy Policy to reflect changes in law, processing, providers, security practices, or the Service.
Each version will identify its version number and effective date. Material changes may be communicated through the Service or email and may require a new acknowledgement where appropriate. Continued use alone is not treated as consent where consent is legally required.
19. Contact and complaints
Privacy requests, questions, complaints, and security notices should be submitted using the current Privacy Contact or Legal Contact published on the CUBES Legal / Contact page.
Individuals in the European Economic Area may also complain to the data-protection authority in the country of their habitual residence, place of work, or the alleged infringement.
End of Privacy Policy