This Privacy Policy describes how Moasy Tech ("moasy", "we") collects, uses, shares, and protects personal data in connection with the moasy website (moasy.tech) and the moasy platform ("Platform", app.moasy.tech), an Engineering Intelligence solution (DORA, Flow Metrics, and SPACE metrics) for technology teams.
This Policy complements, and does not replace, the Terms and Conditions of Use — in case of conflict regarding personal data, this Privacy Policy prevails.
1. Controller and Processor Roles
1.1. For account data (your name, email, login, and activity on the Platform, as described in Section 2 below), moasy acts as the data controller.
1.2. For Connected Data — the operational data a Customer ingests into its Workspace from its own Integration Providers (e.g., who authored a pull request, who is assigned to a work item) — the Customer (the company or organization operating the Workspace) is the data controller, and moasy acts as a data processor, handling that data solely under the Customer's instructions and for the purpose of providing the Platform.
1.3. If you are a developer or contributor whose work activity appears in a Workspace you did not sign up for yourself (because your employer connected an Integration Provider that references you), your employer — not moasy — is the right party to contact about that data; moasy processes it only as instructed by that Customer.
2. Data We Collect
Account data (collected directly from you or from your login provider):
- Name, email address, and avatar, as provided by your chosen OAuth login provider (GitHub, Google, Microsoft, or Slack).
- Your role (ADMIN, GESTOR, or USUARIO) and Workspace membership.
- Login history: timestamp and provider used for each successful login.
- Support interactions and any information you send us directly (e.g., by emailing talk2@moasy.tech).
Connected Data (ingested from Integration Providers a Customer connects, on the Customer's behalf — see Section 1.2):
- Work items, pull requests, deployments, incidents, timeline events, and associated metadata, including references to individual contributors (e.g., usernames, assignee emails) as they appear in the connected Integration Provider.
Billing data: handled directly by our payment processor, Stripe. We do not store full credit card numbers; we retain only what is necessary to display your plan and invoice history (e.g., plan, billing period, subscription status).
Website data (moasy.tech only, not the Platform): pages visited and interactions (e.g., button clicks) collected via Google Analytics — see Section 8 (Cookies) below.
3. How We Use Your Data
- To provide and operate the Platform: authenticate you, enforce role-based access, compute and display the metrics your Workspace is configured for.
- To send transactional communications: invitations, notifications required to operate your account (e.g., a new Terms version requiring acceptance), and support responses.
- To maintain security and prevent abuse, including the audit log described in Section 6.
- To improve the moasy website based on aggregate, non-identifying analytics (Section 8).
- To comply with legal obligations.
4. Legal Basis (LGPD)
We process personal data based on: (a) performance of a contract, for account data necessary to provide the Platform to you or the Customer you belong to; (b) legitimate interest, for security, fraud prevention, and service improvement, always balanced against your fundamental rights; (c) consent, for analytics cookies on the marketing website (Section 8), which you may decline; and (d) compliance with a legal obligation, where applicable.
5. Sharing and Subprocessors
We do not sell personal data. We share data only with service providers who process it on our behalf, under contractual confidentiality and data protection obligations, currently:
| Subprocessor | Purpose |
|---|---|
| Stripe | Payment processing and billing |
| Resend | Transactional email delivery (invitations, notifications) |
| GitHub, Google, Microsoft, Slack | OAuth login (you authenticate directly with them; we only receive your verified identity) |
| Google Analytics | Website traffic analytics (moasy.tech only, see Section 8) |
Integration Providers a Customer connects to its own Workspace (Jira, Linear, GitHub, and others listed in the Terms) are chosen and authorized by the Customer, not by moasy — moasy only ingests the data the Customer has authorized under the Customer's own connection.
6. Security
Account data and Connected Data are technically isolated per Workspace (multi-tenant architecture with row-level access control). Credentials for Integration Providers are stored encrypted. Technical support staff may, when justified, temporarily access a Workspace to diagnose an issue; every such access is individually logged, including the operator's identity, the affected Tenant and user, and every write action performed — see the Terms and Conditions for details.
No security measure is absolute; we cannot guarantee that unauthorized access, loss, or disclosure will never occur, but we adopt reasonable technical and organizational safeguards to reduce that risk.
7. International Data Transfer
Application and database infrastructure is hosted in Brazil (São Paulo region). Some subprocessors listed in Section 5 (e.g., Stripe, Resend, the OAuth login providers, Google Analytics) may process data outside Brazil, including in the United States. Where that occurs, we rely on the safeguards those providers make contractually available for international transfers under Brazilian data protection law (LGPD).
8. Cookies and Analytics (moasy.tech website only)
The moasy marketing website (moasy.tech) uses Google Analytics (GA4) to understand traffic and which calls-to-action are used, via a cookie-based tracker. The moasy Platform (app.moasy.tech) does not use cookies for authentication — it stores your session token in your browser's local storage, not in a cookie.
You can decline Google Analytics tracking using your browser's cookie settings or a browser extension that blocks Google Analytics; declining does not affect your ability to use the website or the Platform.
9. Data Retention
Account data is retained while your account remains active, and for a limited period after account closure to comply with legal, accounting, or dispute-resolution obligations. Connected Data follows the retention period of the Customer's subscribed plan, plus a 3-month grace period, after which it is automatically and permanently purged — see the Terms and Conditions, Section 6, for details.
10. Your Rights
Under the LGPD, you may request, regarding your personal data: confirmation that we process it; access to it; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary or excessive data; portability to another provider; information about the public and private entities with which we share data; and revocation of consent, where applicable. To exercise any of these rights, contact talk2@moasy.tech. If your data appears in a Workspace as Connected Data (Section 1.2), we may direct you to the Customer that controls that Workspace, as they are the appropriate party to fulfill certain requests.
11. Children's Privacy
The Platform and website are not directed to individuals under 18 years of age, and we do not knowingly collect personal data from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes to how we handle Platform account data will be communicated the same way changes to the Terms and Conditions are communicated. Changes to this website-facing document take effect upon publication.
13. Contact
Questions about this Privacy Policy, or requests related to your personal data, may be sent to talk2@moasy.tech.