Privacy Notice
What personal data Git.eu holds about you as an individual — your account, invoices, logs, and correspondence — and why.
Privacy Notice
Articles 13 and 14 of Regulation (EU) 2016/679 · Version 1.1 · In force from 8 September 2026
0. How to read this notice
0.1 This notice describes the personal data we hold about you as a person: your account, your invoices, the logs that keep the service running, and the messages you send us. We are the controller for that data, which means we decide why it exists and what happens to it.
0.2 It does not describe what is inside your repositories. There the roles are reversed: you decide, and we carry out your instructions. That processing is governed by the Data Processing Agreement at docs.git.eu/legal/dpa.html, and clause 2.2 of that agreement draws the line this notice starts from. Section 5 explains where the line falls, in plain terms.
0.3 It is published at git.eu/privacy, in English, and is readable in full before you open an account. This English version is the sole authoritative version; a French translation is also made available for convenience and, in the event of a discrepancy between the two, this English version prevails. It says what we do, not what we would be permitted to do.
1. Who we are
1.1 The controller is Atyk, a société par actions simplifiée (SAS) currently being registered with the Strasbourg trade and companies register, trading as Git.eu France, whose registered office is in Strasbourg, France. \[SIREN to follow on registration.\] French law applies to this processing and the CNIL is our supervisory authority.
1.2 Write to dpo@git.eu about anything in this notice. We answer in English.
1.3 We have not appointed a data protection officer, and we are not required to: this processing is not carried out by a public authority, it does not involve regular and systematic monitoring on a large scale, and it does not involve special categories of data on a large scale. Appointing one voluntarily would bring the full obligations of Articles 37 to 39, including notification to the CNIL, and we prefer to say plainly what we do rather than to claim a role we do not staff. dpo@git.eu is a contact address, read by us; it is not the address of a designated officer. If we appoint one, this notice will say so on the day it happens.
2. What we hold, why, and for how long
Everything we hold about you as a person is in this table. There is no second list.
| What | Why | Legal basis | How long |
|---|---|---|---|
| Your account: username, display name, email address, a hash of your password, the SSH and GPG public keys you add, and the tokens and sessions that keep you signed in. | To give you an account, let you sign in, and let you push. | Performance of the contract, Article 6(1)(b). For the retention described opposite, legal obligation, Article 6(1)(c). | Until you delete the account. Deletion then follows clause 14.2 of the DPA: 30 days. For accounts opened during the open beta, the published retrieval period runs to 31 January 2027. Two things outlive that, and not by our choice. French law requires anyone who hosts content made available to the public — which is what a public repository is — to keep the email address of the account for 5 years after it closes, and the username for 1 year. Article 6 of the law of 21 June 2004, and the decree of 20 October 2021. They are kept for one purpose, which is to answer a judicial requisition, and for no other. Everything else goes at 30 days: display name, password hash, public keys, tokens, sessions. There is nothing further to keep, because we ask you for nothing further. |
| Your billing details: billing name and address, VAT number where you have one, invoices and transaction records. No card number ever reaches us. Card details are entered with our payment provider and are never transmitted to or stored by git.eu. | To charge you, issue an invoice, and keep the accounts. | Contract, Article 6(1)(b), and legal obligation, Article 6(1)(c). | Invoices and accounting records for the period French commercial and tax law requires, which outlives your account. |
| Student verification: an email address at the domain of a higher-education institution. Nothing else. We never ask for a document. There is no card to photograph, no file to upload, and nothing for us to lose. We record that the check passed, the institution, and the date. We ask again at the start of each academic year. | To establish that you qualify for the higher-education student plan. | Contract, Article 6(1)(b). | The result of the check, for as long as the student account exists. No document is ever collected, so none is stored. |
| Technical logs: the IP address the connection came from and the protocol it used, and alongside them the user agent, the time of the request, what was reached, and errors. | To keep the service available and secure — to find faults, and to stop abuse. | Legitimate interest, Article 6(1)(f): running the service you are asking us to run. For the one-year retention described opposite, legal obligation, Article 6(1)(c). | Two periods, because two different things are being asked of us. The IP address and the protocol: one year. The decree of 20 October 2021 requires it of anyone who hosts content made available to the public, for one purpose — answering a judicial requisition — and we keep them for no other. Everything else in the log: 30 days in the live systems. Backups that contain them are overwritten on the 30-day backup cycle. |
| What you write to us: support requests, messages to support@, and our replies. | To answer you, and to remember what was said the next time you write. | Contract, Article 6(1)(b), and legitimate interest, Article 6(1)(f). | Three years from the last message in the exchange. That covers what you wrote, our reply, and anything attached to either. |
| Announcement emails: your address, and which list you asked to be on. | To write to you when something you asked about exists. | Consent, Article 6(1)(a). One click unsubscribes, and the link is in every message. | Until you unsubscribe, and then only to remember not to write to you again. |
| Two-factor authentication: your TOTP secret and recovery codes, if you turn MFA on. | To let you use a second factor when you sign in. | Performance of the contract, Article 6(1)(b). | For as long as MFA is active on your account. See Annex II of the DPA for how the secret is encrypted and the recovery codes are hashed. |
| Connection history: the device, approximate origin, and time of each sign-in to your account, shown to you in your account settings. | So you can see the recent activity on your account and notice anything you do not recognise. | Legitimate interest, Article 6(1)(f): letting you monitor your own account's security. | 30 days, the same period as the technical logs described above. |
2.1 We do not ask for a postal address, a telephone number or a date of birth during the beta, and there is no field for any of them.
2.2 We do not process special categories of personal data within the meaning of Article 9, and we do not want them. Do not place them in the service.
3. What we do not do
This section is short because the list is what we sell.
3.1 We run no third-party analytics and no advertising trackers, on the site or in the product. There is no measurement pixel in our emails: we do not know whether you opened one, and the setting that would tell us is off at the provider that sends them.
3.2 We do not sell, rent or share your personal data, and we do not profile you.
3.3 We do not use your personal data, or the content of your repositories, to train machine learning models, ours or anyone else’s. This is clause 9 of the DPA — a contractual undertaking that survives a change in the ownership of the company, not a line on a web page.
3.4 We take no decision about you by automated means that produces a legal or similarly significant effect.
3.5 We engage no processor that is not named in section 7. There are no undisclosed ones, and we do not treat analytics or error-monitoring providers as an exception to that rule, because we use none.
4. Cookies and local storage
Four things are stored in your browser, and here they all are. Three are cookies. The fourth is not a cookie but session storage, which the law treats the same way, so it is listed with the others.
| What | What it does | Kind | How long it lasts |
|---|---|---|---|
| \_csrf | Proves that an action came from a page we served you, and not from another site acting in your name. Without it the service cannot safely accept anything you submit. | Cookie, set by git.eu. | The session. It goes when you close the browser. |
| giteu_session | Keeps you signed in from one page to the next. It is set when you sign in and at no other moment, which is why it does not appear if you only look at the pages that are open to everyone. | Cookie, set by git.eu. | The session, or until you sign out. |
| lang | Remembers which language you chose for the pages that describe the service, so that the choice outlives the page on which you made it. | Cookie, set by git.eu. | Eleven months and thirty days. |
| htmx-current-path-for-history | Lets the back button give you the page you came from without fetching it again. | Session storage, not a cookie. Set by git.eu. | The tab. It goes when you close it. |
| giteu_remember | Keeps you signed in when you check 'Remember me', so the site recognises you on return visits. | Cookie, set by git.eu. | Thirty days, whether or not you close the browser. |
4.1 The language cookie belongs to the site, not to the forge. The pages at git.eu that describe the service are published in French and in English, and lang remembers which of the two you chose. The forge itself is in English only and offers no such choice, so it sets nothing of the kind.
4.2 Nothing else. No analytics cookie, no advertising cookie, no third-party script, and nothing set by any domain other than git.eu. We do not follow you across sites, because we do not measure you at all — section 3 says the same thing from the other side.
4.3 That is why there is no cookie banner. Consent is required for trackers that are not necessary to the service you asked for; it is not required for the ones that are. Authentication, the security token that protects a session, and remembering an interface choice such as a language are all on the CNIL’s list of trackers exempt from consent. Everything above is on that list, and we set nothing that is not.
4.4 A banner would ask you for a permission we do not need, for cookies you could not refuse and still sign in. We would rather publish the list.
5. Your repositories, and the line between us
5.1 What you put in your repositories, issues and merge requests is yours. You decide what goes in, who may reach it, and how long it stays. We hold it and serve it back to you. In the vocabulary of the GDPR you are the controller of that content and we are your processor, and the DPA at docs.git.eu/legal/dpa.html sets out what we owe you there.
5.2 We do not read, inspect or index the content of your repositories, issues or merge requests, except where it is strictly necessary to provide the service, to answer a support request you have made, or to comply with a legal obligation. Any such access is limited to what the purpose requires. That is clause 3.4 of the DPA.
Git records who you are, in every commit
5.3 This part is not our doing and we cannot undo it, so it is better said plainly. Every commit carries an author name and an author email address, and a committer name and address, written into the commit itself. They are part of the object. They travel with every clone, and if the repository is public they are public — readable by anyone, and copied by anyone who clones it.
5.4 We cannot remove them from your history, because removing them means rewriting the history, which changes every commit identifier after the one you touched. That is your decision to make and yours to carry out; we will not do it to your repository.
5.5 If you would rather not publish your address, set a different one before you commit — git config user.email — because what is recorded is the value in force at the moment of the commit, not the address on your git.eu account. Changing your account address later does not change what is already in your history.
5.6 A public repository is public. Your username, display name, avatar, repositories, issues and comments can be read and copied by anyone, including by people who keep their copy after you delete yours. Deleting something here does not reach the copies.
6. If your personal data is in someone else’s repository
6.1 We are not the controller of what an account holder puts in their repositories — they are. So we cannot decide, on our own initiative, to erase or correct something inside another customer’s repository, and you would not want us to be able to.
6.2 Write to us anyway. We forward the request to the account holder within 5 working days, we tell you that we have, and we assist them in answering it. That is clause 10.3 of the DPA.
6.3 This is separate from unlawful content. If material on git.eu is unlawful, write to dpo@git.eu and we act under the law that applies to us, which is French and European law.
7. Who else handles this data
Six companies, and here they all are. The list is exhaustive at the date of this version, and it is Annex III of our Data Processing Agreement, which is its single source. We give 30 days’ notice before adding or replacing any of them.
| Company | Established in | What it does | What it sees |
|---|---|---|---|
| Scaleway SAS | France | Hosts and operates the infrastructure the service runs on, in Paris. | Everything stored in the service. |
| Billit NV/SA | Belgium | Issues invoices to customers in the European Union. | Billing identity, address, VAT number, and the contents of your invoices. |
| Mollie B.V. | Netherlands | Card payments. | Billing identity, email address, transaction data. Card numbers are never transmitted to or stored by git.eu. |
| Wise Europe SA | Belgium | Bank transfers. | Billing identity, bank account details, transaction data. |
| Infomaniak Network SA | Switzerland | Hosts the @git.eu mailboxes and handles email sent to those addresses; sends the newsletter. | Messages sent to an @git.eu address, along with their sender and content. Email addresses of newsletter recipients, and its content. |
| o2Switch SAS | France | Sends transactional and service email (sign-up confirmations, password resets, notifications) | Name, email address, and the content of the messages we send you. |
7.1 Five of the six are established in the European Union. The sixth hosts our @git.eu mailboxes and handles the email sent to them, and is established in Switzerland, a country the European Commission has recognised as offering an adequate level of protection since 2000, confirmed in January 2024.
7.2 None of the six is, to our knowledge, subject to a law of a third country that would require it to hand your data to that country's authorities.
8. Where it is processed
8.1 Production processing takes place in Paris, France. Backup copies are held in France, at a site other than the production site, on hardware git.eu owns and operates itself. The single exception is the hosting of our @git.eu mailboxes and the email sent to them, handled from Switzerland under the adequacy decision described above.
8.2 No data is transferred to a country outside the European Economic Area that is not covered by an adequacy decision. If such a transfer ever became necessary, we would say so 30 days beforehand and would not proceed without a transfer mechanism under Chapter V of the GDPR.
8.3 The point is not the map. It is which court can compel access to what is inside the building — and here the answer is a European one.
9. When an authority asks
9.1 If a public authority or a third party asks us for your data, we disclose nothing unless we are legally required to.
9.2 We tell you without undue delay and, wherever it is lawful, before we respond, so that you can challenge it yourself. Where we are forbidden to tell you, we use every lawful means to have that prohibition lifted.
9.3 We challenge requests that are manifestly unlawful, overbroad, or that do not follow the procedure the law requires, and we disclose only the minimum the binding instrument demands.
9.4 We make no voluntary disclosure to any authority, in any country.
10. Your rights, and how to use them
You have the right to ask for a copy of your data, to have it corrected, to have it erased, to have its processing restricted, to receive it in a portable form, and to object to processing we base on legitimate interest. Where we rely on your consent, you may withdraw it at any time, and withdrawing it does not affect what was done before.
10.1 Most of it you can do yourself, without asking us: the service gives you the means to see, correct, export and delete what your account holds.
10.2 For anything else, one email to dpo@git.eu is enough. There is no form, and no third-party site to sign in to. We answer within one month; if a request is complex we may take two more, and we tell you inside the first month if we do. It is free.
10.3 We will ask you to confirm that the account is yours before we act. That is the only reason we would ask you for anything extra.
10.4 If you are not satisfied, you may complain to the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or at cnil.fr, or to the supervisory authority of the Member State where you live. We would rather you wrote to us first, but that is your choice and not a condition.
11. How it is kept safe
11.1 The technical and organisational measures in force are published in full, as Annex II of the DPA at docs.git.eu/legal/dpa.html. They are not summarised here, because two descriptions of the same measures drift apart and one of them is then wrong.
11.2 Everything we hold is backed up daily, off site, in France, on hardware we own and run ourselves — no other company holds a copy. The copies are encrypted, and the keys are kept away from the machines that hold them. Backups cover loss on our side. They are not a substitute for the clone on your own machine, which remains the fastest way to get back a branch you deleted yourself. There is no self-service restore; if you need something recovered, ask us and we will do it.
12. Age
12.1 git.eu is for people aged 16 or over. We do not knowingly hold data about anyone younger, and if we learn that we do, we close the account and delete it.
12.2 We chose sixteen rather than inherited it. French law sets the digital consent age at fifteen, but our processing rests on the contract rather than on consent, so that threshold does not settle the question. Sixteen sits above it in any event, and it fits the people this service actually reaches: the student plan is for higher education only, where first-year students are sometimes seventeen and almost never younger.
13. Changes to this notice
13.1 Each version carries a number and a date. Previous versions stay available at git.eu/privacy, and if you ask which version applied on a given date, we answer.
13.2 We give at least 30 days’ notice by email before a material change takes effect. Changes to the list in section 7 follow clause 6.3 of the DPA, which gives you the right to object and, failing agreement, to leave with a refund of the unused period.
14. Contact
dpo@git.eu for anything in this notice.
hello@git.eu for everything else, read by the same people.