Last updated 3 August 2026
Privacy Policy
This policy explains what data Pacia ("we", "us") collects when you use the Pacia Engineering Intelligence platform and its integrations, why we collect it, and what choices you have. It applies to app.pacia.io, our API, and our Microsoft Teams application.
Who we are
Pacia is operated by Pacia. For any privacy question, or to exercise any of the rights described below, contact us at hello@pacia.io.
What we collect
Account data
Name, email address, organisation name, and role. Used to authenticate you and control what you can see.
Engineering metadata from connected tools
When you connect a source control provider (such as GitHub), we read pull request metadata — titles, authors, branches, timestamps, review and comment activity, commit references, and file/line counts.
Deployment and CI metadata
Branch pushes, pipeline results and deployment events, used to calculate delivery metrics.
AI tool usage metrics
Where you connect an AI coding assistant (such as GitHub Copilot), we read aggregate usage and licence/seat data made available by that provider.
Microsoft Teams data
If you install our Teams application, we store the identifiers needed to deliver notifications — your Microsoft tenant ID, and the team, channel and conversation identifiers for the channels you choose.
Operational logs
Standard application and security logs, including IP address and timestamps, used to run and protect the service.
What we do not store
We do not store your source code. Pull request comment text and commit messages are fetched live from your provider when you view a pull request and are not retained in our database.
How we use it
To provide the service — delivery metrics, insights and forecasts for your team. To send the notifications you have configured, including Microsoft Teams messages. To secure the service, investigate abuse, and diagnose faults. To communicate with you about your account and material changes to the service.
We do not sell your data. We do not use your data or your organisation’s code metadata to train machine learning models for other customers.
Credentials and access tokens
Access tokens you provide (for example a GitHub personal access token) are encrypted at rest and are used only to make the API calls needed to deliver the service. You can revoke them at any time, either in Pacia or directly with the provider.
Sharing
We share data only with infrastructure and service providers who process it on our behalf in order to run Pacia (for example hosting, database and email delivery), and where we are required to do so by law. Your data is kept logically separated per organisation, and users only ever see data belonging to organisations they are a member of.
Retention
We retain your data for as long as your organisation has an active account. If you close your account or disconnect an integration, the associated data is deleted or anonymised. You may request deletion at any time by contacting us.
Your rights
Depending on your location, you may have the right to access, correct, export or delete the personal data we hold about you, and to object to or restrict certain processing. To make a request, email hello@pacia.io. If you are in the UK or EEA and are unhappy with our response, you may complain to your local data protection authority.
Security
We use encryption in transit, encryption at rest for credentials, role-based access control, and optional multi-factor authentication. No system is perfectly secure, but we work to protect your data and will notify you of any breach affecting it as required by law.
International transfers
Your data may be processed in countries other than your own. Where that happens, we take steps to ensure an appropriate level of protection for it.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated to account administrators, and the "last updated" date above will change.
Contact
Questions about this policy? Email hello@pacia.io.