Harmonia Repo Ready
Terms Privacy Cookies Security
Legal · Privacy

Privacy Policy

How Harmonia Repo Ready handles personal data and repository-related information.

← Back to site Company Details Terms and Conditions Privacy Policy Cookie Policy Acceptable Use Policy AI & Data Processing Notice Security Policy Refunds and Cancellation Subprocessors Disclaimer
Your data, in plain terms: we keep what we need to run the audit service, send the minimum to AI providers (never your full source code or live secrets), and never sell your data. The detail is below — if anything is unclear, email support@multivohub.com.

Data controller: MultivoHub Limited (registered in England & Wales, company no. 17236540), 340 Poplars Avenue, Warrington, WA2 9UF, United Kingdom.

Data protection contact: support@multivohub.com.

Last updated: 27 June 2026.

1. Scope

This Privacy Policy explains how Harmonia Repo Ready collects, uses, stores and shares personal data when you visit the website, create an account, use the Service, connect repositories, contact us or interact with reports and integrations.

2. Personal data we collect

CategoryExamples
Account dataName, email address, organisation, role, login metadata.
Repository metadataRepository name, owner, branch names, file paths, commit metadata, pull request metadata, issues, configuration signals.
Customer ContentSource code, documentation, config files, logs, prompts, uploaded files and analysis inputs you submit or authorise us to access.
Usage dataPages viewed, actions taken, audit runs, API calls, timestamps, device/browser information, IP address.
Billing dataPlan, invoices, payment status and limited payment metadata. Full card details are processed by the payment provider.
Support dataEmails, chat messages, screenshots, support tickets and feedback.

3. How we use personal data

  • To provide, operate and secure the Service.
  • To authenticate users and manage account access.
  • To analyse repositories and generate reports, scores and remediation plans.
  • To maintain audit history, usage limits, billing and subscriptions.
  • To provide customer support and respond to enquiries.
  • To improve the Service, debug issues and monitor performance.
  • To comply with legal obligations and protect rights, safety and security.

4. Lawful bases

Depending on context, we rely on contract, legitimate interests, legal obligation and consent. For example, account and audit processing is usually necessary to perform the contract; security logging and fraud prevention may rely on legitimate interests; cookie consent is used where required for optional cookies or similar technologies.

5. AI processing

Where repository content or prompts are processed by AI providers, this is described in the AI & Data Processing Notice and Subprocessors page. We aim to minimise data sent to AI providers and avoid sending secrets where detection is possible.

Where you enable AI semantic analysis or verified-repair features, Harmonia may send minimised audit data to an enabled AI provider. This may include README excerpts, repository metadata, finding names, severities, paths, audit facts, prompts and generated outputs. We do not intentionally send full source code or live secret values to AI providers unless a specific feature requires it, you have enabled that feature, and this is clearly disclosed.

Harmonia supports integrations with up to 11 AI providers (OpenAI, Anthropic, Google Gemini, Groq, xAI, Mistral AI, Cohere, Perplexity, OpenRouter and DeepSeek). This is a capability ceiling — not every supported provider receives customer data. The provider that actually processes your data depends on active production configuration, the feature you use, licensing and routing. The providers currently active for your account are listed on the Subprocessors page.

Llama-family models are not a provider: they are accessed through an OpenAI-compatible host (such as OpenRouter or another configured host), and that host — not Meta — is the data recipient. DeepSeek is treated as a high-risk international transfer and is not enabled for UK/EU customer content unless and until MultivoHub Limited has completed and documented provider due diligence, data-processing terms, an international-transfer assessment, content minimisation and customer-facing disclosure.

6. Cookies and similar technologies

We use strictly necessary cookies and local storage for site operation and cookie preference storage. Optional analytics or marketing cookies are only used where enabled and lawful. See the Cookie Policy.

7. Sharing personal data

We may share personal data with service providers that help us operate the Service, including hosting, database, authentication, email, payment, analytics, AI processing, monitoring and support providers. We may also share data if required by law, to protect rights/security or as part of a business transfer.

8. International transfers

Some providers may process data outside the UK or EEA. Where required, we will use appropriate safeguards such as adequacy regulations, standard contractual clauses, the UK International Data Transfer Agreement or other lawful transfer mechanisms.

9. Data retention

We keep personal data only as long as necessary for the purposes described in this Policy. As a guide: account data is kept while your account is active and for a reasonable period after closure; audit results and repository analysis data are kept according to your plan's retention settings or until you delete them; billing records are kept for the period required by UK tax and accounting law (typically six years). Data sent to AI providers for a request is not retained by us beyond what is needed to return and store the result, and is minimised as described above. On verified account-deletion request, we delete or anonymise your personal data except where we must retain it for legal, accounting or dispute-resolution reasons.

10. Security

We use reasonable technical and organisational security measures including access controls, encryption in transit, secrets controls, monitoring, audit logs and least-privilege practices where applicable. No service can guarantee absolute security.

11. Your rights

Subject to applicable law, you may have rights to access, rectify, erase, restrict, object to processing, request portability and withdraw consent. You may also complain to the Information Commissioner’s Office in the UK.

12. Children

The Service is intended for business and professional users and is not directed to children.

13. Changes

We may update this Policy from time to time. Material changes will be notified where appropriate.

© MultivoHub Limited
Terms Privacy Cookies Acceptable Use