Privacy notice · updated 2026-07-28
Data handling is part of the evidence model.
Data we process
We process account identity, workspace membership, billing identifiers, integrations, agent and delegated identities, tool-call metadata, policy decisions, approvals, and audit events you choose to record. We use this information to authenticate users, provide the service, prevent abuse, and support your workspace.
Storage and subprocessors
The service uses the configured authentication, model, billing, integration, infrastructure, backup, and email providers. Model execution can be disabled, routed to a customer-VPC OpenAI-compatible endpoint with no third-party model provider, or routed to the approved OpenRouter account. Raw ABAP source is excluded from Copilot prompts by default. Managed OAuth providers hold third-party authorization while Adranum stores workspace-scoped connection identifiers.
Retention and deletion
Workspace owners control retention within plan and safety limits and can delete the workspace. Deletion removes application records and retained objects; independently encrypted backups expire under the operational recovery policy.
Operator and contact
the operator identified at checkout operates the service. Privacy, access, correction, and deletion requests may be sent to the privacy contact shown at checkout.