Our Privacy Policy

INTRODUCTION

This Privacy Policy describes how Copilot4DevOps (including Copilot4DevOps Plus and Copilot4DevOps Ultimate) collects, uses, stores, and protects your information. We are committed to maintaining the confidentiality, integrity, and availability of personal data and organizational data processed through our products and services.

By using Copilot4DevOps websites or services, you acknowledge that Copilot4DevOps may process your information in the United States, Canada, the United Kingdom, Germany, and other jurisdictions where we operate. This policy complies with the EU’s General Data Protection Regulation (GDPR) and aligns with security standards such as SOC 2 and ISO 27001.

INFORMATION WE COLLECT

Account Information

When registering for Copilot4DevOps Plus or Ultimate, we collect:

  • Name, email address, and organization details.
  • Billing and contact information (where applicable).
  • Credentials to secure your account.


Automatically Collected Information

When you access our websites or products, we collect:

  • IP address, device identifiers, browser type, and session logs.
  • Usage data (pages visited, features accessed, error logs).
  • Cookies and analytics data (see Cookies Policy).


Location Information

We may collect location-related data (e.g., IP-based geolocation) to provide localized services, comply with legal requirements, and prevent fraud.

Personal Information

We do not sell or rent personal information. We only collect and process what is required to provide and improve services, comply with law, or fulfill contractual obligations.

BRING YOUR OWN DATA (BYOD)

Copilot4DevOps provides a Bring Your Own Data (BYOD) feature, allowing customers to upload documents, Azure DevOps wikis, and work items for custom Large Language Model (LLM) training.

Data Ownership and Control

  • Customers retain full ownership and control of all BYOD data.
  • BYOD data is used exclusively within the customer’s environment to improve contextual accuracy.
  • Copilot4DevOps does not use BYOD data to train global or cross-tenant models.


Data Storage and Segregation

  • BYOD data is stored in tenant-isolated environments.
  • Logical and physical controls prevent cross-customer data access.


Encryption and Protection

  • All BYOD data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
  • Encryption keys are managed under strict security policies.


Access Controls

  • Role-based access controls (RBAC) ensure only authorized users and personnel can access BYOD data.
  • All access is logged, monitored, and subject to audit.


Retention and Secure Disposal

  • BYOD data is retained only as long as necessary to provide services.
  • Upon customer request or contract termination, data is securely deleted following industry standards (e.g., NIST SP 800-88).


Monitoring and Incident Response

  • Systems handling BYOD data are continuously monitored for threats.
  • In the event of a security incident affecting BYOD data, customers will be notified promptly in compliance with applicable laws.

HOW WE USE INFORMATION

We process personal and organizational data based on the following legal grounds:

  • To fulfill contractual obligations under our Terms of Service.
  • To comply with legal and regulatory requirements.
  • To pursue legitimate business interests, including product development, analytics, and fraud prevention.
  • With your explicit consent, where required by law.


We use information to:

  • Provide, support, and optimize Copilot4DevOps services.
  • Secure our platforms and protect against unauthorized access.
  • Communicate service updates and relevant product information.
  • Improve performance, reliability, and user experience.

SECURITY & DATA PROTECTION

Copilot4DevOps maintains industry-standard security controls, including:

  • Encryption: Data is encrypted at rest and in transit.
  • Access Controls: Role-based access, least privilege, and multi-factor authentication where applicable.
  • Monitoring: Continuous monitoring, logging, and intrusion detection.
  • Auditing: Regular internal and third-party audits aligned with SOC 2 requirements.
  • Incident Response: Formal procedures to investigate, contain, and notify customers of incidents.

COOKIES

We use cookies and third-party analytics to improve performance and user experience. See our Cookies Policy for details.

DIRECT MARKETING & OPT-OUT

From time to time, Copilot4DevOps may send communications about products or services.

  • You may opt out at any time via the unsubscribe link or account settings.
  • We will never sell your personal data for marketing purposes.

DATA RETENTION

We retain personal and organizational data only as long as necessary for the purposes outlined in this policy, unless longer retention is required by law.

PRIVACY POLICY UPDATES

This policy may be updated periodically. Any material changes will be communicated to customers directly or via our website. Previous versions are available upon request.

CONTACT US

Privacy Officer
Copilot4DevOps / Modern Requirements
500-7030 Woodbine Ave, Markham, ON L3R 6G2
Phone: 416.469.3131
Email: info@modernrequirements.com