Lyxor Privacy Policy

Privacy Policy

A product of P99Soft

1. Introduction

This Privacy Policy explains how P99Soft ("P99Soft," "we," "us," or "our") collects, uses, discloses, and protects information in connection with Lyxor, our AI-powered pull request intelligence and code review platform (the "Service"), including our website, web application, GitHub App, Jira/Atlassian integration, and related tools.

Lyxor connects to source control and project management systems to analyze pull requests, code changes, and acceptance criteria, and to surface developer productivity and code-quality insights for organizations using the Service.

This Policy applies to users, customer administrators, prospective customers, and website visitors. It does not apply to third-party services such as GitHub or Jira, which have their own privacy policies.

2. Scope and Roles

When a Customer organization uses Lyxor, that Customer is generally the controller of its user and repository data, while P99Soft acts as a processor/service provider on the Customer's instructions.

For account, billing, marketing, and website data we collect directly, P99Soft acts as the controller.

If you access Lyxor through your employer or organization, your organization's internal policies may also apply.

3. Information We Collect

  • Account and profile information (name, work email, job title, organization, authentication identifiers, login history)
  • Billing and transactional records (payment card details are handled by our payment processor)
  • Support and communications data (tickets, questionnaire responses, onboarding and demo correspondence)
  • Integration data from GitHub/Jira/Atlassian based on granted scopes (metadata, webhook events, ticket and criteria context)
  • Source code and PR content from connected repositories, PR metadata, and derived analysis outputs
  • Usage analytics, diagnostics, performance logs, and cookie/local storage data

4. How We Use Information

  • Provide, operate, and maintain Lyxor
  • Authenticate users and enforce organization-level access controls
  • Generate review suggestions, risk/quality scores, and acceptance-criteria matching
  • Improve performance, reliability, and security
  • Respond to support, procurement, and due-diligence requests
  • Detect fraud, abuse, and security incidents
  • Comply with legal obligations and enforce terms

5. How We Share Information

We do not sell personal information. We share data only as needed with service providers/subprocessors, integration platforms, authorized users within a customer organization, for legal/safety reasons, for business transfers, or with your consent.

Where AI/LLM providers are used for review features, relevant data is processed under contractual confidentiality and data-use restrictions for service delivery.

6. Source Code and Repository Data — Additional Commitments

  • We access only what your organization's granted scopes allow
  • Code/PR content is processed for your organization's analysis results
  • Code/PR content is not shared with other customers without explicit consent
  • Access to raw code/PR content is restricted on a need-to-know basis
  • Data is encrypted in transit and at rest
  • On disconnect/uninstall/termination, related repository data is deleted or de-identified within retention windows, subject to legal/security needs

7. Data Retention

We retain data while your account is active or as required to provide the Service. After termination/disconnection, we delete or de-identify data within standard retention windows, except where longer retention is needed for legal, security, or operational purposes.

8. Data Security

We use administrative, technical, and physical safeguards including encryption, role-based access controls, and ongoing security review. No method of transmission or storage is completely secure.

9. International Data Transfers

Lyxor may process data in countries outside your own. Where required, we apply appropriate safeguards for cross-border transfers under applicable law.

10. Your Rights and Choices

If you use Lyxor via your organization, some requests may need to be handled by your administrator.

  • Access your personal information
  • Correct inaccurate information
  • Request deletion
  • Object to or restrict certain processing
  • Request portability where applicable
  • Opt out of marketing communications

11. Children's Privacy

Lyxor is a business/developer tool and is not directed to children under 18 (or the age of majority in their jurisdiction).

12. Third-Party Links and Integrations

Lyxor may link to or integrate with third-party services such as GitHub and Atlassian. Their privacy practices are governed by their own policies.

13. Changes to This Policy

We may update this policy from time to time for legal, operational, or regulatory reasons. Material changes will be communicated before they take effect.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:

P99Soft — Lyxor
Attn: Privacy / Data Protection Contact
Email: lyxor@p99soft.com