In short
Mazylon Pulse is B2B delivery governance software. We only collect data necessary to that mission — no aggressive marketing tracking, no resale to third parties, no advertising profile.
Your data is hosted in the European Union, encrypted at rest and in transit, and deleted on request within legal timelines.
- Data controller
- Mazylon SAS —
- Privacy / DPO contact
- privacy@mazylon.com
1. Data collected
We distinguish two types of data: what you explicitly entrust to us, and what Pulse retrieves through the connectors you authorize.
Account data
Professional email, first and last name, role in your organization. Provided at account creation or by your administrator.
Delivery data (via OAuth)
Jira ticket metadata (status, assignee, sprint, description), GitHub/GitLab/Bitbucket pull requests (title, branch, review), Teams messages (only those addressed to the bot or posted in a channel where Pulse is invited), indexed Confluence pages. No source code is collected or analyzed.
Technical data
IP address, user-agent, connection timestamps — for security (detecting abnormal connections) and application operation. No cross-site tracking.
2. Purposes of processing
We only process your data for the uses described below.
Provide the service
Analyze your sprints, detect blockers, generate digests, answer questions asked to the Teams bot. This is the primary purpose.
Improve the product
Aggregated and anonymized usage metrics (which signals get dismissed, which Teams intents recur) to prioritize the roadmap. No individual analysis.
Security and compliance
Security logs to detect intrusions, audit trail of sensitive actions, response to legal obligations (judicial request, GDPR).
3. Legal basis
Processing of your data is based on the performance of the contract binding us to your organization (art. 6.1.b GDPR), our legitimate interest in securing and improving the service (art. 6.1.f), and compliance with our legal obligations (art. 6.1.c).
4. Retention periods
We apply an automatic nightly purge policy — our commitment to data minimization.
| Donnée / Data | Rétention / Retention |
|---|---|
| Account data | Duration of contractual relationship + 3 years (commercial statute of limitations) |
| Raw delivery metadata (activity_event) | 120 days |
| Closed / expired signals | 90 days |
| Teams bot conversation history | 30 days |
| LLM call logs (audit) | 180 days |
| Security logs (access, audit) | 1 year |
On request, we can adjust these durations for your tenant (Enterprise contract). Export of your data is available at any time on request.
5. Recipients and sub-processors
Your data is accessible to the Mazylon team strictly for service operation, and to our sub-processors listed below. No data is sold, exchanged or transmitted to third parties for marketing purposes.
Our main sub-processors:
- Compute + storage hosting: Scaleway (Paris, France)
- Database: Aiven managed PostgreSQL (Frankfurt, Germany)
- LLM (AI analysis): Anthropic (EU residency activatable for Enterprise, otherwise US)
- Transactional emails: [TO COMPLETE: SendGrid / Postmark / Mailgun / SES — EU]
- Privacy analytics: Umami / Plausible (self-hosted EU, no cookie)
The exhaustive and up-to-date list is published on our Security page. You are notified by email 30 days before any sub-processor addition or replacement.
6. Transfers outside the European Union
By default, all your data stays in the EU. The only potential non-EU transfer concerns calls to the Anthropic Claude API (United States) for LLM analysis — governed by the European Commission's Standard Contractual Clauses. For Enterprise contracts, we activate Anthropic's EU residency as soon as available for your region, or we switch to an LLM hosted on our own infrastructure (vLLM/RunPod EU).
7. Your rights
You have the following rights over your data at any time:
Right of access
Obtain a copy of the personal data we hold about you.
Right to rectification
Correct any inaccurate or incomplete information.
Right to erasure (right to be forgotten)
Delete your data when its retention is no longer justified. Cascade purge on your tenant.
Right to portability
Retrieve your data in a structured, machine-readable format (JSON/CSV).
Right to object and restrict
Object to certain processing or restrict its scope.
Right to lodge a complaint
With the CNIL (www.cnil.fr) if you believe your rights are not respected.
To exercise your rights, write to privacy@mazylon.com. We respond within 30 days (art. 12.3 GDPR).
8. Security
TLS 1.3 encryption in transit, AES-256 at rest, OAuth tokens encrypted column-by-column via pgcrypto, multi-tenant isolation via PostgreSQL Row-Level Security, MFA required for administrators. Full details on our Security page.
9. Changes to this policy
We update this policy when our practices or regulations evolve. Material changes are notified by email to all active users 30 days before entering into force.
Last update: 22 July 2026.