PRIVACY POLICY
Privacy Policy
Last updated: September 15, 2026
This Policy explains what personal data Octopus DevOps S.A.S. collects, how we use it, who we share it with, and what rights you have over it.
1. Data Controller
Octopus DevOps S.A.S., Tax ID (NIT) 901.873.899-8, registered at Calle 3 # 22 - 01, Chía, Cundinamarca, Colombia, is the Data Controller of your personal data under Colombian Law 1581 of 2012 and Decree 1377 of 2013. For users in the European Union or United Kingdom, we act as Controller under the GDPR where applicable.
2. Data We Collect
- Account data: username, email address, full name, profile picture, bio, company, job title, location, timezone, website, and phone number.
- Authentication data: encrypted password, or a login identifier when you choose to sign in with Google, Microsoft, or GitHub.
- Platform usage data: projects created, deployment configuration, execution history, and security scan results.
- Billing data: managed directly by Paddle.com Market Limited as Merchant of Record — Octopus does not store card numbers or full financial data.
- Technical data: IP address, browser type, and access logs, for security and support purposes.
3. How We Collect Data
Directly, when you register or complete your profile; automatically, as you use the platform; through single sign-on (SSO) providers when you authorize them; and through Paddle when you make a payment.
4. How We Use Your Data
To provide and maintain the Service; authenticate users and protect accounts; process payments and manage subscriptions; send you transactional communications (confirmations, deployment alerts, plan-expiration notices); provide technical support; improve the platform; comply with legal and contractual obligations; and prevent fraud or misuse.
5. Legal Basis for Processing
Performance of the service contract (our Terms of Service); your consent where required (e.g., marketing communications); our legitimate interest (security, fraud prevention, product improvement); and compliance with legal obligations.
6. Who We Share Your Data With
We work with the following processors and sub-processors, each with access limited to what is strictly necessary to provide their service:
- Google Cloud Platform (Firestore, Cloud SQL/PostgreSQL, Secret Manager, Cloud Storage) — data infrastructure and secure credential storage.
- OpenAI, L.L.C. — AI-assisted interpretation of deployment and security results, never including credentials or secrets.
- Paddle.com Market Limited — payment processing, billing, and taxes, as Merchant of Record.
- Google LLC (Gmail/Workspace) — transactional email delivery.
- Jenkins — orchestration of your own organization's CI/CD pipelines, run on the infrastructure you connect or that Octopus provisions on your behalf.
Octopus DevOps does not sell personal data to third parties under any circumstance.
7. International Data Transfers
Some of these providers (Google Cloud, OpenAI, Paddle) process data outside Colombia, including in the United States and the European Union. We adopt reasonable contractual and technical safeguards — including these providers' own standard contractual clauses — to protect transferred data, as permitted under Colombian data protection law.
8. Data Retention and Deletion
We retain your organization's data for as long as your account is active. If a plan expires and is not renewed, your organization has a 60-day grace period before we permanently and irreversibly delete associated roles, permissions, invitations, teams, deployment history, projects, folders, users, and secrets stored in Google Cloud Secret Manager, after notifying the account owner by email.
9. Information Security
We encrypt data in transit (TLS); store passwords and secrets in Google Cloud Secret Manager, never in plain text in the database; apply role-based access control (RBAC); and isolate data between different organizations.
10. Your Rights
Under Colombian Law 1581 of 2012, and the GDPR where applicable, you have the right to:
- Know, update, and rectify your personal data.
- Request proof of the authorization granted for processing.
- Be informed about how your data has been used.
- File complaints with Colombia's Superintendencia de Industria y Comercio (SIC).
- Revoke your authorization and/or request deletion of your data, where no legal or contractual duty prevents it.
- Access your personal data free of charge.
If you are located in the European Union or United Kingdom, you additionally have the right to data portability and to object to processing. To exercise any of these rights, write to us at contacto@octopusdevops.com.
11. Cookies and Tracking Technologies
The application console (console.octopusdevops.com) does not use cookies: authentication is handled via tokens stored locally in your browser.
The marketing website (octopusdevops.com) uses Google Ads / Google Tag Manager, which may set third-party cookies to measure advertising campaign effectiveness. You can manage these cookies from your browser settings.
12. Children's Privacy
The Service is intended for businesses and professionals and is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified at least 15 days in advance.
14. Contact
Octopus DevOps S.A.S. — Tax ID (NIT) 901.873.899-8
Calle 3 # 22 - 01, Chía, Cundinamarca, Colombia
contacto@octopusdevops.com — +57 300 992 0223





