Privacy Policy
What Intracia Ltd does with your personal data — on this website, in our Intracia product, and in our consulting work.
Last updated 24 August 2026
When we say “we”, we mean Intracia Ltd, registered in Guernsey. We're a small team. Damien Guard is accountable for data protection here, and answers privacy questions himself.
We've written this to the standard of the EU and UK GDPR, the strictest rules that apply to us. That also covers Guernsey's Data Protection Law 2017 and the California Consumer Privacy Act. It sits alongside our Terms of Service, Acceptable Use Policy and Data Processing Agreement.
Intracia is in early access. This describes what happens today.
1. Which part applies to you
- This website — intracia.com. Collects little. Section 3.
- Working with us directly — consulting. Section 4.
- Intracia — the product. Holds your account and the content you manage. Section 5.
None of it is meant for children, and we don't knowingly collect data about anyone under 16. If we find we have, we delete it. If you're a parent and think your child holds an account, write to privacy@intracia.com. We'll ask enough to be sure you're their parent and that the account is theirs, and no more.
2. The roles we play
We're the controller of data about people who hold an account, visit this website, or work with us directly. Your name, email address, sign-in records and billing records are examples. That's what this policy governs.
We're a processor for the content our customers manage in the CMS. If you appear on a company's team page that's hosted with us, that company decided to publish it, and we can't change or remove it without their instruction.
That doesn't leave you stuck. Write to us and we'll pass your request straight on, help them answer it properly, and tell you we've done it. If you're not sure who to write to, send it to us anyway and we'll make sure it reaches them. If they don't respond, you can complain about them to a data protection authority. And a court order or other lawful demand reaches us directly, whatever our contract with them says — see when the law compels us.
3. This website
Our pages are built in advance and served as static files from Cloudflare.
Cloudflare processes your request — your IP address, the page you asked for, your browser — to deliver the page and absorb attacks. Its edge logs hold that for up to 24 hours, then it's gone.
We count visits with PostHog, and nothing else. It runs in a mode
that stores nothing on your device and never learns who you are. The same tool reports errors a page
runs into, so a form that breaks doesn't stay broken quietly.
Section 7 has the detail, and how to switch it off. PostHog's requests go
through p.intracia.com, which is our proxy — the data still ends up with PostHog in the United
States.
Almost everything on the page comes from us. Fonts and images are served from this domain. The exceptions are PostHog, and Cloudflare Turnstile on any page carrying our contact form.
Our contact form
We get your name, email address, an optional organisation name, the kind of enquiry, and your message. What else we ask depends on the kind you pick:
- CMS access — your site's URL, its framework, your Git provider, and where it's deployed
- Consulting — the kind of work you're asking about
- Privacy — the country you live in, which tells us which regulator you can go to
- Report abuse — where the content is, which is usually somewhere on somebody else's site
The country is the only one we insist on, and only on a privacy enquiry. It doesn't decide whether you have rights: everyone gets the same baseline wherever they live. It tells us which authority you can complain to, and what your own jurisdiction adds on top — section 14. We ask rather than work it out from your address, which would be less accurate and more intrusive. An abuse report is usually about another person, so please send what we need to find the content and no more.
Your enquiry arrives as email carrying the country Cloudflare reads from your address at the edge. It's there to help us answer, and your address itself doesn't travel with it. We use your message to reply, and won't add you to a mailing list because you sent one.
Between pressing Send and us reading it, 2 others are involved:
- Cloudflare Turnstile checks a person filled the form in. Cloudflare gets your IP address, user-agent, TLS fingerprint and the form's identifier. It acts as our processor protecting the form, and as its own controller when it uses the same signals to improve bot detection generally. What Cloudflare does with those signals is set out in its Turnstile Privacy Addendum.
- Resend delivers your enquiry as email to
hello@,privacy@orabuse@. Resend is in the United States, so an enquiry passes through there on the way to a mailbox in the EU, and keeps a copy in its sending log for up to 30 days. Writing to those addresses yourself skips that leg.
Your enquiry isn't stored in any database of ours. It becomes an email, and the mailbox is the record.
4. If you work with us directly
Where we do consulting work for you, we hold what any working relationship produces: your name, role and email address, your organisation's details, the billing address and payment details for an invoice, the invoices and accounting records behind them, and proposals, contracts and correspondence.
We're the controller of all of it. We hold it to do the work and be paid — a contract — and then, once an invoice exists, because tax and company law require it. That's why billing records outlast almost everything else in section 11, and we can't delete them on request. It all lives in Microsoft 365, on our tenant in the European Union.
We don't use it to market to you, don't enrich it from other sources, and it goes no further than our accountant and the authorities entitled to ask.
5. Intracia
Our Intracia product manages a website you already have. Your pages and images live in your own source repository and storage containers, and your site is built and served by whoever builds it today.
We do hold a working copy. To show you your content and keep a draft safe, we cache what we read from your repository, so a copy sits in our database while you use the product. For pages and media, your repository stays the record. One exception: where we built your site and run its infrastructure for you, the repository and bucket may be ours, and your agreement says which applies.
Some things live only here. Schemas, templates, area definitions, queries and media attributes like alt text are created inside Intracia to edit your site with, and exist nowhere else. Ask and we'll send you a copy — at the end of a contract the DPA puts that on a 30 day clock.
A draft you haven't published is the exception. We don't export those — publish it, or copy the Markdown out of the editor.
5.1 Your account
- your email address, and a display name where we have one
- an avatar URL, where your sign-in provider supplies one
- your GitHub handle, if you connect GitHub
- the identity record your sign-in provider returned, listed in section 9
- your role, and which sites and organisations you belong to
- when you last used the product, and your analytics choice
Microsoft sends neither a name nor a picture, so an account created that way may have only an address until you fill in the rest.
5.2 Signing in
You can sign in with an email address and password, with a link emailed to you, or through GitHub, LinkedIn, Facebook or Microsoft. Google is coming shortly. Passwords are handled by Supabase Auth and never stored anywhere we can read them.
We record each sign-in and security event: the IP address and browser, which method you used, whether it worked and the error if it didn't, and the time. You can see this history in the product. Sign-in addresses go to IPGeolocation.io, which returns an approximate country, city, coordinates and network operator, cached for 24 hours.
The address and browser are stripped after 90 days. What's left lasts 12 months, then goes. Cloudflare's rate limiter also counts requests over short windows; those counters are transient and no address is kept.
Cloudflare Turnstile guards the sign-in pages. It runs invisibly: there is no puzzle, and usually nothing for you to click. To tell a person from a bot it receives your IP address, user agent and TLS fingerprint, along with an identifier for the page. Cloudflare acts as our processor here, and as its own controller when it uses the same signals to improve bot detection generally. What it does with them is set out in its Turnstile Privacy Addendum.
5.3 What you do in the product
So your team can see who changed what, we attribute work to your user ID: drafts and snapshots, publishes, pushes, content pulls, media uploads with alt text and tags, and the activity feed. Invitations record the address invited, who invited it, and whether it was accepted.
5.4 What you connect
Connecting a Git provider, bucket or deployment target stores the credential — encrypted, readable only by our servers — and the identity of the remote resource.
Media goes to a storage bucket, and whose depends on your arrangement. Either way we hold the record: filename, path, alt text, tags, size, uploader. Where the bucket is yours, closing your account here doesn't reach into it. Where we host it for you, Cloudflare and GitHub are our sub-processors rather than yours, and you can ask us to switch at any time.
When your repository sends us a webhook, we log the delivery to troubleshoot it — the payload, and a narrow allowlist of headers. Git payloads carry commit metadata including author names and email addresses. That's your content, held as your processor. We strip the payload and headers no later than 30 days after delivery, and keep the bare record up to 90 days.
5.5 Support
Anything you send us, and our replies, lives on Microsoft 365 — Exchange Online for our mailboxes, OneDrive and SharePoint for documents. Our tenant is in the European Union. Resend delivers the automated messages the product sends, and doesn't receive your replies.
Please send only what the problem needs. Anything you paste into an email is then in our mailbox as well as in the product.
5.6 Payments
We don't take payments through Intracia. No card processing, no card details, no billing addresses. When we start charging, we'll name the payment processor here before it handles anything of yours.
5.7 What we don't want
We don't ask for special-category data about account holders — health, race, religion, political opinions, biometrics. Please keep it out of fields that don't call for it, including the AI assistant.
5.8 What your team can see
Intracia is a shared workspace, so some of what we hold is visible to people you work with.
- Administrators see your membership details — name, email address, role, and when you were last active. That means administrators of the site you're a member of. Where an organisation manages that site, it includes that organisation's administrators too.
- They also see roughly where you signed in from. A site's team settings and an organisation's member list show the city and country from your most recent sign-in, within the last 90 days. Not the address itself: that's resolved on our servers and only the place name reaches the page. It's there so someone responsible for a site can spot an account being used from somewhere it shouldn't be. It isn't a location history, editors can't see it, and it's used for nothing else.
- Anyone who can edit a site sees what you did to it. Drafts, publishes, uploads and the activity feed are attributed to you by name.
Organisations widen that circle. Members of an organisation reach every site in it — content, media, drafts, history — without being added individually, and an organisation administrator holds admin rights on all of them. That's a real disclosure, so it should be a decision rather than a surprise.
6. The AI features
Only 2 features send data to a model, and they run when you ask them to. Both use Google's Gemma 3 12B, through Cloudflare AI Gateway and OpenRouter. Schema and template assistance sends the schema or template plus what you type. Alt-text suggestions send the address of the image rather than the image: the provider fetches it from the public location your own site already serves it from, so no copy passes through us.
A site can switch both off for everyone. “AI assistance” in site settings turns them off for that site and every member of it, enforced on our servers rather than by hiding buttons. They're on unless somebody turns them off.
We don't train models on your content, and choose providers whose terms exclude training on data passed through their APIs. That second part is their promise, not ours, so what we stand behind is the choosing and the checking. Nothing goes to a model in the background.
7. Cookies and storage
On this website
You can read this site without answering a cookie banner. Nothing is stored on your device by default.
The rules behind cookie banners — Article 5(3) of the ePrivacy Directive, and PECR in the UK — cover storing information on your device and reading it back. We do neither: a visit is counted against a number worked out on PostHog's servers, described below. Our reading is that this falls outside those rules. The European Data Protection Board's Guidelines 2/2023 reads Article 5(3) more broadly, so treat this as our analysis.
| What we store | Where | Why | Basis |
|---|---|---|---|
| Your choice to stop counting, once you make it | Local storage | So it still applies after you leave the page | Strictly necessary |
| A Cloudflare bot check, on any page with our contact form | Cookie | Telling a person from a bot | Strictly necessary |
How we count a visit. PostHog runs here in cookieless mode. Each event gets a number its servers work out by hashing 5 things: our account, the day's secret, your IP address, your user-agent, and this website's name. The secret is deleted each night, so the number can't be recreated and a reader today stays separate from the same reader yesterday. The site's name is in the hash too, so the same person elsewhere gets a different number.
Your IP address goes into that hash, so PostHog receives it in the United States. What PostHog keeps is the number — we've switched off IP storage on that project.
What we learn. Which pages you read, which links and buttons you click, where the pointer went — clicks, movement and scroll depth, as coordinates — and errors that break a page, with the message and the place in our code it came from. We're told the contact form went through, and not which kind of enquiry it was. Click tracking covers links and buttons only, so what you type into our contact form stays yours. Session replay is off here, in the code and in the project settings. Nothing here reaches the product: they're separate PostHog projects with no identifier that could join them.
How to switch it off. Choose Analytics in the footer. One click, every page, straight away. We keep your answer in your browser so you only give it once, and clearing your storage starts counting again. We honour Global Privacy Control and Do Not Track — if your browser sends either, PostHog stays unloaded.
Our basis is legitimate interest, not consent, because nothing is stored on your device. That gives you a right to object whenever you like, without a reason, and the footer switch is exactly that.
In Intracia
| What | Where | Why | Basis |
|---|---|---|---|
| Supabase authentication session | Cookie | Keeps you signed in | Strictly necessary |
| Theme and active site | Cookie | Remembers how you left the workspace | Strictly necessary |
| Analytics choice | Your account, on our servers | Remembers your answer on every device you sign in from | Strictly necessary |
| PostHog analytics and client-side error reports | Set by PostHog once enabled | Page and feature usage; errors in your browser | Consent |
| PostHog session replay | Set by PostHog while a recording runs | A recording you started from the Support menu | Only when you start it |
PostHog starts switched off, for everyone, everywhere. It's loaded opted out, a banner asks on your first sign-in, and nothing is captured until you answer. You can change your mind from Telemetry & error reporting in Account > Settings, and a signed-in account's preference follows you between devices.
What “product analytics” covers. The pages and features you use, what you click, how quickly pages rendered and how long their requests took, and as a heatmap, where you clicked and how far you scrolled. Your IP address is attached to those events, which is where this differs from the website. What it doesn't include is what you type.
Events are tied to your account identifier, and your email address is attached to the PostHog profile when you sign in. So this isn't anonymous statistics: what you did in the product can be traced back to you by anyone with access to our PostHog project. Nobody who isn't signed in gets a profile at all.
Server error reports follow the same answer. The exception and its context go to PostHog so we can fix it. The report is anonymous — the route and the shape of the failure, never your user ID or email — and if you've declined analytics it isn't sent.
Session replay only runs when you start it. It lives in the Support menu. We tell you what it captures and link you here first, and you confirm. A blinking indicator stays on screen while it runs, it stops itself after 10 minutes, and you can stop it sooner. We watch a recording to find the fault you were demonstrating, and for nothing else — not to profile you, not to report on how anyone is working, and nobody outside the people building Intracia sees them.
A recording holds less than your screen in one way and more in another. Less, because text you type into fields is masked before it leaves your browser. More, because the browser's console log travels with it, so a message naming a file or failing request can appear though it was never on screen. The masking isn't perfect, and the workspace exists to show you your content, so a recording can contain that content. That's why it's yours to start. Recordings are kept 30 days.
8. Why we use it, and our legal basis
Split the same three ways as the rest of this policy: this website, working with us directly, and our Intracia product.
Support and legal requests run across all three. We answer them from the correspondence itself, on legitimate interests, or on a legal obligation where the law requires an answer.
Where we rely on legitimate interests below, we've weighed them against your rights. You can object at any time — section 13.
8.1 This website
| Purpose | Data | Legal basis |
|---|---|---|
| Serve the page, and keep it up | Your IP address, the page you asked for, your browser, at Cloudflare's edge | Legitimate interests |
| Answer your enquiry | Contact form fields, and the country Cloudflare reads from your address | Legitimate interests; and where you're asking about hiring us, steps taken at your request before a contract |
| Tell a person from a bot | IP address, user agent, TLS fingerprint, to Turnstile | Legitimate interests |
| Count visits | Pages viewed, links and buttons clicked, heatmap coordinates, against a daily-rotating number | Legitimate interests — nothing is stored on your device, so on our reading no consent is needed, and you can switch it off in the footer |
| Fix what breaks | The error, its message, and where in our code it came from, against the same number | Legitimate interests — the same footer switch turns this off too |
8.2 If you work with us directly
| Purpose | Data | Legal basis |
|---|---|---|
| Do consulting work, and invoice for it | Contact and billing details, proposals, correspondence | Contract |
| Keep financial records | Invoices and the data behind them | Legal obligation |
8.3 Intracia
| Purpose | Data | Legal basis |
|---|---|---|
| Give you an account and run the product | Account and profile; authoring records | Contract |
| Sign you in through a provider | The identity record it returns, listed in section 9 | Contract |
| Authenticate you and keep accounts secure | Sign-in records, IP address, user agent | Legitimate interests |
| Show a team who has access, and roughly where from | Name, email, role, last-access time, sign-in city | Contract and legitimate interests |
| Rate limiting and abuse prevention | Transient counters, account and site identifiers; Turnstile's signals on the sign-in pages — IP address, user agent, TLS fingerprint | Legitimate interests |
| Understand how the product is used | Events tied to your user ID — pages and features used, clicks, page and request timings, heatmap coordinates, and the IP address the event came from | Consent — off until you say yes |
| Record your screen to show us a fault | A recording tied to your user ID | Consent — for that recording only |
| Diagnose server failures | Server-side exception reports | Legitimate interests |
| Send transactional email | Email address, name, site name | Contract / legitimate interests |
| Run the AI features you invoke | The image, schema or text you submit | Contract |
8.4 Where we got it, if not from you
- An invitation. Somebody typed your email address in before you had an account. The record keeps who invited you and when. If it's unwelcome, tell us and we'll delete the address rather than leave it pending.
- Your sign-in provider. Section 9 lists exactly what arrives from each.
- Somebody else's finance department. Your name, work email, billing address or purchase-order reference often comes from a colleague rather than from you.
- Derived rather than collected. The city and country against a sign-in come from IPGeolocation.io resolving the address the request arrived from, and the country on a contact-form enquiry from Cloudflare doing the same at the edge
None of it comes from a data broker, a scraped list or an enrichment service. We don't buy, rent or build lists. Ask and we'll tell you which applies to your record.
8.5 Do you have to give it to us?
On this website, nothing is asked of you. Our contact form is the only thing that takes a name.
In Intracia, an email address and display name are a requirement of the contract. We can't create an account without something to identify it by, or show your colleagues who changed a page without a name. If you decline, we can't give you an account.
Everything after that is optional, and declining costs you only that feature. Connecting a Git provider, bucket or deployment target is your choice. Analytics and recordings are off until you say otherwise. An avatar and a GitHub handle are conveniences.
For consulting work, billing details are a legal requirement too. We can't raise a compliant invoice, or keep the records tax law demands, without them.
9. Who else sees it
These providers process personal data on our instruction, each under a data processing agreement, each getting only what its job needs.
| Provider | What it does | Data involved | Where |
|---|---|---|---|
| Cloudflare | Hosting, caching, rate limiting, Turnstile, and the AI Gateway our model requests pass through | Requests and IP addresses at the edge, Turnstile's signals, cached lookups, and the model requests routed through the gateway | Global network |
| Supabase | Authentication and the main database | Account, security and authoring data | United States — Ohio |
| PostHog | Product analytics, error tracking and session replays in the CMS; visit counts and browser errors on this website. 2 separate projects | CMS: events tied to your user ID carrying your IP address, with your email on the profile; clicks, timings, heatmap coordinates; exception context; recordings you start, with that session's browser console log. Website: pages viewed, links and buttons clicked, heatmap coordinates, and errors that break a page, against a number hashed from your IP address, user agent and a daily secret — no profile, no account, nothing on your device | United States |
| Resend | Transactional email, and contact-form enquiries | Recipient address, inviter and site name; enquiry contents and reply-to address | United States |
| Microsoft | Microsoft 365 — mailboxes and working documents | Enquiries, support correspondence, replies; consulting proposals, contracts, client records | European Union |
| GitHub | Git integration — the GitHub App and webhooks | GitHub identity, repository and commit metadata | United States |
| IPGeolocation.io | Approximate location for sign-in addresses | IP address | United States |
| OpenRouter, via Cloudflare AI Gateway | Schema and template assistance, and alt-text suggestions | The schema or template, and what you type into the assistant; the address of an image you ask for alt text on, which it fetches to read | United States |
That table, plus the sign-in providers below, is the list. It isn't a summary of something fuller held elsewhere, and you don't have to be a customer to see it. Our Data Processing Agreement points here rather than keeping a private copy that could drift.
Customers get at least 7 days' notice before we add a row, and can object under the DPA.
Microsoft's row covers Microsoft 365 only, which nothing in the product reads from or writes to. Microsoft also appears below as a sign-in provider, and so does GitHub — different services, different reasons, no data passing between them.
Sign-in providers
The table above is our sub-processors. The sign-in providers aren't. When you choose “Sign in with GitHub”, GitHub runs its own authentication under its own terms as its own controller, and hands us the result. We send it nothing about you, and couldn't tell it what to keep. So for the part of the sign-in that's theirs, your rights are exercised against them.
There are 5: GitHub, Microsoft, LinkedIn, Meta for Facebook sign-in, and Google.
We ask for a sign-in and nothing that reaches into the account — no contacts, connections, repositories, calendar or posts, and nothing that lets us write anywhere. What comes back is more than the email address we asked for:
- an identifier that provider uses for you, and which provider it is
- your email address, and whether they treat it as verified
- your display name — from all except Microsoft, which sends none. LinkedIn sends first and last names separately; Facebook adds a nickname
- your profile picture's address — again from all except Microsoft
- from GitHub, your handle. From LinkedIn, your language and country preference
- where the account belongs to an organisation, something identifying it — from Google the domain of its Workspace, from Microsoft its tenant identifier. Which is to say: where you work
- a flag recording that no phone number is verified. None is sent, and we hold none
Google is listed before the button exists. It isn't switched on yet, and is named now because this section undertakes to list a provider before it handles anything of yours.
Using one of these tells that provider you use Intracia, and we can't change that. You never have to: an email address and password work identically. You can revoke Intracia's access at any of them, which stops them confirming who you are but doesn't close your account here.
When the law compels us
A court order or other lawful demand can require us to hand something over. We comply with valid ones, and check they're valid. Where we're allowed to tell you, we will, before we disclose anything. Sometimes we're legally forbidden from saying anything; then we say nothing, because the alternative is a criminal offence. We won't volunteer your data to anyone who hasn't compelled it.
If the company changes hands
If Intracia is bought or merges, the data described here moves with it. We'd tell you before it happened, and whoever acquired it would be held to this policy until they published their own. Your content is in your own Git repository already.
We don't sell your personal data, and don't share it for cross-context behavioural advertising, as California law defines those terms.
10. Sending information abroad
We're established in Guernsey, which the EU and UK both recognise as adequate — the highest status a country outside the EEA can hold, and the only one that removes the transfer restriction rather than papering over it. Transfers into Guernsey need no further safeguard.
Several providers in section 9 are in the United States, including the database holding your account. For those we rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum; on the provider's Data Privacy Framework certification where it holds one; and on encryption in transit and at rest either way. Email us for the safeguards covering a particular provider.
Our Microsoft 365 tenant is in the European Union. We won't overstate that: Microsoft's terms permit limited access from outside the EU for support and security, covered by the Standard Contractual Clauses in their data protection addendum. Storage in the EU isn't the same promise as no access from anywhere else.
11. How long we keep it
| Data | Retention |
|---|---|
| Requests to this website at Cloudflare's edge | Up to 24 hours, then deleted by Cloudflare |
| Account and profile data | Life of the account, then deleted within 30 days of closure |
| Sign-in and security records | IP address and browser up to 90 days then stripped; the rest up to 12 months then deleted |
| Cached IP geolocation | Up to 24 hours |
| Product analytics events | PostHog's retention for our project is 7 years — see below. It isn't what decides how long yours are kept: they're attached to your user ID, so they go in full when you close your account or ask |
| The daily secret a website visit is counted against | Deleted at the end of that day, by PostHog |
| Website visit counts | The same 7 years, equally PostHog's figure. Once the secret is deleted nothing left connects to you, and there's no person record to delete because none was created |
| Diagnostic logs | Up to 30 days, a period we set and PostHog enforces |
| Error reports | These reach PostHog as events, so the 7 years above covers them |
| Session replays | Up to 30 days — the shortest period PostHog offers |
| Webhook delivery logs | Payload and headers up to 30 days then stripped; the delivery record up to 90 days |
| Content and media you author | As long as your site holds it — deleted on your instruction, or at contract end as the DPA provides |
| Database backups | Daily, kept up to 7 days rolling, then overwritten |
| Enquiries and support correspondence | Up to 24 months after the matter closes |
| An enquiry in Resend's sending log | Up to 30 days, then deleted by Resend |
| Consulting proposals and contracts | The engagement, then 6 years |
| Invoices and accounting records | 7 years — required by law, and not something we can shorten |
| Record of what you agreed to, and when | As long as we rely on it, then 6 years — see below |
These are maximums, not minimums. Where something can go sooner it does. The rows running the other way are the ones the law fixes from below.
The record of your choices notes what you were asked, which version you saw, what you decided and when. It has to outlive the decision it describes, because it's the only thing that could show we didn't switch analytics on without asking — and equally what you'd rely on if you thought we had. So it survives account closure, and an erasure request won't normally reach it. You also have a right to object, so if you ask, we'll weigh your reasons against ours and tell you what we're keeping and why. It holds an identifier, a decision, a document version, a timestamp and roughly which country you were in.
7 years is PostHog's figure rather than one we chose, and we can't change it — their retention settings cover recordings and logs, not events. What we control is deletion, and that's what decides how long your data lasts.
12. Keeping it safe
Every tenant table enforces row-level security, so one customer's rows are unreachable from another's session. Every API route authenticates the caller and checks their role. The elevated database credential is server-only and never reaches a browser. Credentials you give us are encrypted at rest. Traffic is encrypted in transit. We keep secrets, tokens and request bodies out of logs and analytics.
One deliberate exception. The webhook delivery log holds the body of the webhook your Git provider sends, because a failed delivery can't be diagnosed from the fact that it failed. It's the only request body we keep. The headers beside it exclude the signature and anything credential-shaped, and the body is stripped on the schedule above.
If something goes wrong, we'll notify the relevant supervisory authority within 72 hours of becoming aware, where the law requires it, and tell affected people directly without undue delay where the breach is likely to put them at high risk. Where it concerns content we hold as processor, we notify the customer who controls it. We keep a record of every breach, notifiable or not.
13. Your rights
Subject to the conditions in the law that applies to you, you can ask us to:
- give you a copy of what we hold about you
- correct anything inaccurate
- delete it
- restrict what we do with it, or object to processing based on legitimate interests
- port it, in a structured machine-readable format
- withdraw consent at any time, which doesn't affect what was done before
- complain to a supervisory authority — section 15
We don't make solely automated decisions with legal or similar effects.
Email privacy@intracia.com. We'll verify who you are proportionately, without demanding documents we don't need, and respond within one month. Complex requests can extend that by up to 2 further months if we tell you why.
Deletion reaches the copies outside our database. Your PostHog profile goes in full — person record, events and any recordings — along with your delivery records at our email provider. It reaches our mailbox too: correspondence in Exchange Online and documents in OneDrive and SharePoint are searched and removed on the same request. Deleted mail sits briefly in Microsoft's recoverable-items store before purging, and a message you sent us is also in your own sent items, which we can't reach.
A copy of your data never includes credentials. API keys, tokens and provider secrets open systems that aren't ours, and usually belong to an organisation rather than one person. They're stored encrypted and never sent to a browser, so not even you can read one back. Replace or revoke them yourself in the product.
One limit we can't engineer around. Git records an author's name and email inside every commit, and a commit's identifier is a hash over that plus the commit before it. The repository is your organisation's, held with your own provider, so rewriting its history isn't our decision — and copies others have cloned are beyond anyone's reach. Erasure removes you from our systems, not from commits you authored.
If your request concerns content on a customer's site, we'll forward it to that customer and help them answer.
14. Where you live
The rights in section 13 are what we offer everyone. Some places add to them.
California and other US states. In the last 12 months we've collected the categories in sections 3 to 7 — identifiers, internet and network activity, commercial and professional information — for the purposes in section 8, disclosed only to the providers in section 9. We don't sell your personal information or share it for cross-context behavioural advertising, so there's no “Do Not Sell or Share” action to take. You have the right to know, access, delete and correct, and to limit the use of sensitive personal information, which we don't collect. You won't be treated differently for exercising these rights, and you may use an authorised agent whose authority we'll verify.
Virginia, Colorado, Connecticut, Texas, Oregon, Montana and others give materially the same rights, plus opt-outs of sale, targeted advertising and significant automated decisions — none of which we do.
If we turn a request down, you can appeal. Reply to our refusal, or write to us with “appeal” in the subject line. There's no form and you don't need a lawyer. Damien Guard looks at it again and you'll have a written answer within 45 days, the shortest deadline any of those states sets. If we still decline, the answer says why and tells you, with a link, that you can complain to your state Attorney General.
Global Privacy Control. Several states treat a GPC signal as an opt-out of sale, sharing and targeted advertising, none of which we do — so there's nothing for it to switch off, and we honour it anyway.
The EU, EEA and UK. The rights in section 13 come from the EU and UK GDPR and apply in full. Your data leaves the EEA and UK — not “may”, it does. The database holding your account runs in the eastern United States and most providers in section 9 are US companies. There's no EEA-hosted option to choose. You can complain to your own national authority, or the ICO, without coming to us first.
Guernsey. The Data Protection (Bailiwick of Guernsey) Law 2017 gives you equivalent rights, and the ODPA is both our home authority and your route to complain about us.
Anywhere else. Write to us anyway. We'll handle your request as though the EU and UK GDPR applied: access, correction, deletion, a portable copy, the right to object, and an answer within a month. You won't be asked to prove where you live.
15. Contact us
We're always glad to hear from you. Come to us first if you can — privacy@intracia.com — and we'll try to put it right. Damien Guard reads that address and answers it himself. There's no queue.
You can also complain to a supervisory authority: the Office of the Data Protection Authority in Guernsey, the Information Commissioner's Office in the UK, your local authority in the EEA, or in California the Privacy Protection Agency or Attorney General.
We're established in Guernsey, which is neither in the UK nor the EEA. If you're in either, that email address reaches the person who decides, and those authorities are open to you without coming to us first.
Intracia Ltd, Ohana, La Route du Coutanchez, St Peter Port, GY1 2TX, Guernsey. Company number 124060.
16. Changes
This page carries the date it was last revised, at the top. If it hasn't moved, nothing has changed.
If we hold an email address for you, we'll write to you about anything material — a new sub-processor, a new category of data, a change in what we do with what we already have. If we don't, we can't: there's no cookie, no profile and no mailing list that would let us reach you. That's the trade, and the date at the top is how you check.