Vai al contenuto




Dichiarazione sulla protezione dei dati

Ultimo aggiornamento: ottobre 2026

Questa dichiarazione spiega come Changeloop raccoglie, usa e protegge i dati personali, in conformità al Regolamento (UE) 2016/679 (GDPR).

What is the GDPR?

The GDPR (Regulation (EU) 2016/679) is the European data protection regulation. It governs how organisations may collect, use, and store the personal data of people in the European Union, and what rights those people have over their data.

What data does Changeloop store?

We store your account data, the data from your source integrations (for GitHub, the installation ID and repository metadata; for GitLab and Bitbucket, the project path, the address of your self-managed GitLab server where you use one, the branch you name and the webhook secret we issue) and the changelog drafts written for you. We use the titles and bodies of merged pull requests or merge requests and, in push mode on Bitbucket, the messages of pushed commits to write those drafts, and we delete them once drafting finishes. The one exception is the title of a change we skip or that arrives over your plan's limit, which we keep so you can review it. We also use the title and body of a GitHub issue you label for the roadmap to draft its roadmap item, and delete them once drafting finishes, whether or not the draft succeeds. We do not store your source code. You can view this data by logging into your account. We also store the invoices issued for each payment, for accounting purposes. If you use our feedback widget on your own site, we also store data submitted by your visitors through it; see the next question.

Do you collect data about my customers' visitors too?

Yes, if you use our feedback widget on your own site. When one of your visitors submits feedback through it, we store their email address and message, a randomly generated submission reference, and, once one is created, the GitHub issue it results in. We automatically remove the visitor's email address from their message before it is used to classify the submission or included in the GitHub issue we create in your repository, so neither your issue tracker nor our AI classification provider ever sees it. For this data we act as your processor, and you are the controller; please treat any request from your own visitor about their submission the way you would any other data request about your site, and we're happy to help. Your visitor can check the status of their own submission using the private link they were given when they submitted it; we do not currently send them status update emails ourselves.

Why does Changeloop store this data?

We use this data for account login, drafting and publishing changelog entries from your merged pull requests, managing your subscription, and, where you have enabled the feedback widget, for processing your visitors' feedback submissions on your behalf as described above.

How to reach us?

You can write to us at any time at contact@changeloop.dev for anything regarding your data.

How to withdraw your consent?

If you would like to withdraw your consent for us processing your data, write to us at contact@changeloop.dev and we will action your request.

Where do we have your data from?

Most of the data we hold was provided to us by you:
  • when you created your account on the Changeloop platform;
  • when you connected your repositories through the GitHub App, or through a webhook or Connect with Bitbucket for GitLab and Bitbucket.
If you use our feedback widget, we also receive data directly from your visitors when they submit feedback through it, on your behalf.

Why are you emailing me?

The emails you receive from us are:
  • notifications about your account and the changelog entries you publish;
  • emails about the subscription you have with us.

How do I request access to my data?

To request access to your data:

Who are the sub-processors that Changeloop uses?

To provide the service, we work with the following sub-processors:
  • Stripe: secure payment processing;
  • Amazon AWS: secure hosting and storage of data and invoices;
  • OpenAI: drafting changelog entries from your merged pull requests, and classifying feedback-widget submissions by type and priority (message text only; the submitter's email address is removed before it is sent to OpenAI);
  • our email provider: sending notifications and transactional messages.
All our sub-processors are GDPR compliant.

Who is the Data Protection Officer for Changeloop?

The controller of your personal data is LoadFocus LTD, trading as Changeloop, a company registered in England and Wales under company number 09554514, with its registered office at 4 Grayscroft Road, London SW16 5UP, United Kingdom. For any request regarding the protection of personal data, contact us at contact@changeloop.dev.