Privacy Policy

Laatst bijgewerkt: 14 juni 2026  ·  Last updated: 14 June 2026

1. Who we are

PBI Docs is a service operated by Dividata, a company registered in the Netherlands. We provide automated Power BI documentation generation for software teams.

Contact:
Dividata
KvK-nummer: 77770005
E-mail: privacy@dividata.nl

Dividata acts as the verwerkingsverantwoordelijke (data controller) within the meaning of the General Data Protection Regulation (GDPR / AVG).

2. What data we collect

We collect only the data necessary to provide the service:

  • Account data — your name and email address, obtained from your OAuth provider (Microsoft, GitHub, or Google) when you sign in.
  • Workspace data — workspace name and email address you provide when creating a workspace.
  • Repository configuration — repository URLs, branch names, and documentation output paths you configure.
  • Job history — timestamps, commit SHAs or trigger labels, job status, and error messages from each documentation run.
  • Generated documentation — the Markdown files produced by each run, stored in Azure Blob Storage.
  • Billing data — a Stripe customer reference and subscription status. We do not store full payment card details; these are held exclusively by Stripe.
  • Usage data — basic server logs including IP addresses and request paths, retained for security and debugging.

We do not collect or process the contents of your Power BI reports beyond what is necessary to generate the documentation you have requested.

3. Legal basis for processing

  • Performance of a contract (art. 6(1)(b) GDPR) — account data, workspace data, repository configuration, and job history are processed to deliver the service you have subscribed to.
  • Legal obligation (art. 6(1)(c) GDPR) — billing records are retained as required by Dutch tax law (Wet op de omzetbelasting) for a minimum of seven years.
  • Legitimate interests (art. 6(1)(f) GDPR) — server logs are processed to protect the security and reliability of the service.

4. How we use your data

  • Authenticate you and maintain your session.
  • Generate Power BI documentation on your behalf.
  • Send transactional emails (job completion, failures, billing receipts).
  • Manage your subscription and process payments via Stripe.
  • Diagnose errors and improve the reliability of the service.

We do not use your data for advertising or profiling, and we do not sell it to third parties.

5. Third-party processors

We share data with the following sub-processors, each bound by a data processing agreement:

ProcessorPurposeLocation
Microsoft AzureInfrastructure, storage, queuing, key managementEU (West Europe)
StripePayment processing and subscription managementEU / US (SCCs)
AnthropicAI-assisted documentation generationUS (SCCs)
Microsoft (OAuth)Authentication via Microsoft accountsEU / US (SCCs)
GitHub (OAuth)Authentication via GitHub accountsUS (SCCs)
Google (OAuth)Authentication via Google accountsEU / US (SCCs)

SCCs = Standard Contractual Clauses (art. 46(2)(c) GDPR)

6. Retention periods

  • Account data — retained for the duration of your account. Anonymised upon a verified erasure request.
  • Generated documentation — deleted upon a verified erasure request or when the workspace is deactivated.
  • Job history and billing records — retained for seven years to comply with Dutch fiscal law.
  • Server logs — retained for 30 days, then deleted automatically.

7. Your rights under the AVG / GDPR

As a data subject you have the following rights, which you may exercise free of charge:

  • Right of access (inzage) — request a copy of the personal data we hold about you.
  • Right to rectification (rectificatie) — ask us to correct inaccurate data.
  • Right to erasure (vergetelheid) — request deletion of your personal data. See section 6 for what is retained for legal reasons.
  • Right to restrict processing (beperking) — ask us to pause processing in certain circumstances.
  • Right to data portability (overdraagbaarheid) — request your data in a structured, machine-readable format.
  • Right to object (bezwaar) — object to processing based on legitimate interests.

To exercise any of these rights, email privacy@dividata.nl. We will respond within 30 days.

8. Cookies

  • Session cookie — strictly necessary to keep you signed in. Does not require consent under art. 11.7a Telecommunicatiewet.
  • Consent preference — stores your cookie choice in your browser's local storage. Not transmitted to our servers.

We do not use tracking, advertising, or analytics cookies.

9. Security

We apply appropriate technical and organisational measures including TLS encryption in transit, secrets management via Azure Key Vault, and role-based access controls. In the event of a personal data breach likely to result in a risk to your rights, we will notify the Autoriteit Persoonsgegevens within 72 hours (art. 33 GDPR) and inform affected individuals without undue delay where required by art. 34 GDPR.

10. Complaints

If you believe we are not handling your data correctly, you have the right to lodge a complaint with the Dutch supervisory authority:

Autoriteit Persoonsgegevens
Postbus 93374, 2509 AJ Den Haag
www.autoriteitpersoonsgegevens.nl

11. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email or by a prominent notice in the dashboard at least 14 days before they take effect. The date at the top of this page always reflects the most recent version.