Privacy Policy
Version: 1.0
Last updated: 2026-08-20
1. Scope
This Privacy Policy describes how Magnus Opera processes personal data through:
- https://magnusopera.io
- https://terrabuild.io
- The Insights application at https://insights.magnusopera.io
- Related support, authentication, billing, GitHub integration, and operational services
Insights is a business-to-business service. Business customers are responsible for ensuring that their authorized users, personnel, contractors, repository contributors, and other relevant persons receive appropriate information about the customer’s use of Insights.
2. Controller and Privacy Contact
Magnus Opera SASU
106 avenue Carnot, 78500 Sartrouville, France
SIREN: 953 872 322
Email: contact@magnusopera.io
Privacy questions and data-subject requests may be sent to:
dpo@magnusopera.io
Magnus Opera acts as controller for data used to manage its websites, user accounts, subscriptions, billing, support, security, abuse prevention, and its own service operations.
For personal data that a business customer submits, generates, or synchronizes in a workspace for its own purposes, the business customer generally acts as controller and Magnus Opera acts as processor on its behalf. Persons seeking to exercise rights concerning that workspace data should normally contact the relevant business customer first. Magnus Opera will assist the customer where required by applicable law.
3. Data We Process
Depending on the services and features used, Magnus Opera processes the following categories.
Account and authentication data
- Name and email address
- Password hash and email-verification status
- Session, invitation, and password-reset records
- Public passkey credential material, authenticator metadata, and counters
- Workspace membership, role, team, and display-name information
- Hashed API tokens, token permissions, and revocation information
Private passkey keys remain on the user’s authenticator. Magnus Opera does not receive them.
Business and billing data
- Business or billing contact name and email
- Company name, country, and VAT number
- Subscribed product, price, seats, storage allowance, status, and billing history
- Stripe customer, checkout, subscription, price, invoice, tax, and event identifiers
Payment-card details are collected and processed by Stripe. Magnus Opera does not store complete payment-card details.
Workspace and service data
- Workspace identity, configuration, membership, and tenant allocation
- Terrabuild build, graph, project, target, timing, status, cache, and usage metadata
- Repository, branch, tag, commit, author, and contributor information
- Build-actor identifiers, names, decisions, and observation times used for seat enforcement
- Artifact names, keys, sizes, checksums, lifecycle state, and associations
- Release, deployment, engineering-health, and related derived information
Terrabuild encrypts managed artifact contents on the client before upload. The artifact master key is not sent to Insights. This client-side encryption does not apply to the service metadata listed above, which must remain readable by Insights to provide the service.
GitHub integration data
When a business customer installs and authorizes the Insights GitHub App, Insights may process:
- Installation, organization, account, and repository identifiers
- Repository names and configuration
- Commits and parent relationships
- Pull requests, reviews, comments, files, authors, and timestamps
- GitHub webhook delivery and synchronization state
The business customer controls which GitHub organization and repositories are made available to the App, subject to GitHub’s own controls.
Communications, security, and operational data
- Transactional emails and delivery information
- Support requests and correspondence
- Administrator identity, action, target, timestamp, detail, and IP address in audit logs
- Request, queue, deployment, backup, and security logs
- Technical error, stack, browser, device, request, and performance information sent to Sentry when error reporting is enabled
Website analytics data
Magnus Opera uses Google Analytics on the public websites magnusopera.io and terrabuild.io. Google Analytics is not installed or used on the Insights application at insights.magnusopera.io. Depending on browser settings, Google Analytics may process:
- Online identifiers and analytics cookies
- IP-derived approximate location
- Browser, device, operating-system, and language information
- Referring page, visited pages, navigation, and interaction events
- Visit times, session information, and campaign parameters
Magnus Opera uses this information to understand website audiences and improve website content. Magnus Opera does not display advertising on these websites and does not use this information for advertising or to make decisions about an Insights account or workspace.
4. Sources of Data
Data is obtained:
- Directly from users and business customers
- From Terrabuild clients acting under a business customer’s authority
- From GitHub when a customer authorizes the Insights GitHub App
- From Stripe in connection with checkout, tax, invoicing, and subscription events
- From Google Analytics when a person visits magnusopera.io or terrabuild.io
- Automatically from browsers, authenticators, application requests, and operational systems
- From workspace owners or administrators who invite or administer other users
5. Purposes and Legal Bases
Magnus Opera processes personal data for the following purposes:
| Purpose | Legal basis when Magnus Opera is controller |
|---|---|
| Create accounts, authenticate users, provide workspaces, storage, integrations, support, and subscribed features | Performance of a contract or steps requested before entering a contract |
| Administer subscriptions, payments, invoices, tax, and accounting records | Performance of a contract and compliance with legal obligations |
| Protect accounts, prevent abuse and fraud, enforce permissions, investigate incidents, and maintain audit trails | Legitimate interests in securing and administering the service and, where applicable, legal obligations |
| Diagnose failures, monitor reliability and capacity, reconcile storage, and improve service operation | Legitimate interests in operating a reliable and secure B2B service |
| Send verification, password-reset, invitation, billing, security, and service messages | Performance of a contract, legitimate interests, or legal obligations depending on the message |
| Measure audiences and understand use of magnusopera.io and terrabuild.io through Google Analytics | Legitimate interests in understanding public website use, subject to applicable rules governing cookies and similar technologies |
| Establish, exercise, or defend legal claims and enforce service terms | Legitimate interests and compliance with legal obligations |
Where Magnus Opera acts as processor, it processes workspace data on the documented instructions of the relevant business customer and relies on the customer’s lawful basis.
Data identified as required for account creation, authentication, subscription, billing, security, or a requested integration must be provided for the corresponding feature to operate. Optional profile, integration, and configuration information may be omitted, but the related feature may be unavailable or less complete.
6. Recipients and Service Providers
Access is limited to authorized Magnus Opera personnel and to providers that require data to perform their services. Depending on the features used, recipients include:
- Cloudflare: website and Worker delivery, D1 databases, R2 object storage, Queues, Workflows, security, and infrastructure services
- Stripe: checkout, payments, tax, subscriptions, invoices, customer portal, and billing events
- Mailgun: transactional email delivery through its European endpoint
- Sentry: application error and performance monitoring when enabled
- GitHub: customer-authorized repository integration and synchronization
- Google: Google Analytics for magnusopera.io and terrabuild.io, and authentication of specifically authorized Magnus Opera backoffice administrators
- Professional advisers, auditors, insurers, courts, regulators, or authorities where reasonably necessary or legally required
Magnus Opera does not sell personal data.
7. Location and International Transfers
Insights D1 databases and R2 storage buckets are configured with Cloudflare’s European Union jurisdiction restriction. The live control database and tenant databases use that restriction, and D1 read replication is disabled.
Cloudflare, Stripe, Sentry, GitHub, Google, and their subprocessors may process limited personal data from locations outside the European Economic Area. Where a restricted transfer occurs, Magnus Opera relies on the transfer mechanism applicable to the provider and processing, such as an adequacy decision, the EU-US Data Privacy Framework where applicable, or European Commission Standard Contractual Clauses with appropriate supplementary measures. Information about applicable safeguards may be requested at dpo@magnusopera.io.
8. Retention
Retention depends on the category and purpose of the data:
- Account, workspace, membership, build, GitHub, usage, and service metadata is retained while the relevant account or workspace is active and afterwards only for an agreed recovery or export period, security investigation, dispute, or applicable legal obligation.
- Managed artifact contents follow the retention selected by the workspace. The current service permits a period from 1 to 3,650 days, defaults to 10 days, or permits expiry to be disabled. Stale incomplete and orphaned artifact objects are normally removed after one day.
- Authentication sessions, invitations, verification records, reset links, signed URLs, and temporary checkout records expire according to their configured validity periods.
- Contractual and billing evidence may be retained for the applicable limitation period. Invoices and accounting records are retained for the period required by French law.
- Security and administrator audit data is retained for as long as necessary to investigate incidents, demonstrate authorized changes, protect the service, and establish or defend legal claims.
- Daily control-database exports are retained for 35 days. First-of-month exports are retained for approximately one year. A deletion may therefore remain in encrypted or access-restricted backups until normal backup rotation.
- Support correspondence is retained for the time required to resolve the request and, where necessary, establish or defend legal claims.
- Google Analytics event and user-level data is retained according to the configured Analytics property retention, for no longer than 14 months. Aggregate reports may remain available for longer where they no longer directly identify a visitor.
- Provider-side telemetry and delivery records follow the configured retention in the relevant provider account and are reviewed against the operational purpose for which they were collected.
Data may be retained longer where required by law, a legal hold, an unresolved dispute, fraud prevention, or a security investigation. When retention ends, data is deleted or irreversibly anonymized where technically appropriate.
9. Cookies and Similar Storage
Insights uses essential, secure authentication and session cookies. The application and websites may also store local preferences, such as the selected visual theme. These mechanisms are required for requested functionality and are not used for advertising.
magnusopera.io and terrabuild.io use Google Analytics. Google Analytics may set or read analytics cookies and similar identifiers to distinguish visits, measure navigation, and produce audience reports. The Insights application at insights.magnusopera.io does not use Google Analytics.
Stripe, GitHub, Google, or other external services may set their own cookies when a user is redirected to or interacts with those services. Their policies apply to that processing.
Magnus Opera does not display advertising on magnusopera.io or terrabuild.io and does not use analytics data collected through these websites for advertising.
10. Automated Seat Enforcement
Insights automatically accepts or rejects a newly observed build actor according to the number of seats available to the workspace for the current billing period. Previously accepted actors remain accepted for that period, and rejected attempts are recorded. This decision controls whether the actor may use the relevant build service but does not produce legal or similarly significant effects outside the contracted service.
A workspace administrator may inspect actor-seat records. Questions or requests for human review may be sent to support@magnusopera.io.
11. Rights
Subject to the conditions and exceptions in applicable law, individuals may request:
- Access to their personal data
- Rectification of inaccurate data
- Erasure
- Restriction of processing
- Objection to processing based on legitimate interests
- Portability of data they provided where the legal conditions apply
- Withdrawal of consent at any time where processing relies on consent
Requests may be sent to dpo@magnusopera.io. Magnus Opera may request information necessary to verify identity and authority. Requests concerning business-customer workspace data may be referred to the relevant customer as controller.
Individuals may lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL): https://www.cnil.fr.
12. Security
Magnus Opera uses measures appropriate to the nature of the service, including access controls, hashed credentials and API tokens, secure session cookies, least-privilege service bindings, audit logging, EU-restricted storage, backups, and client-side encryption of managed artifact contents.
No system can guarantee absolute security. Business customers and users must protect their passwords, passkeys, API tokens, GitHub access, and Terrabuild master keys and must notify Magnus Opera promptly of a suspected compromise.
13. Changes
This policy may be updated when the service, providers, processing activities, or legal requirements change. The version and last-updated date identify the current text. Material changes affecting existing business customers will be communicated through an appropriate service or contractual channel.