Cookies, session recording and ad conversion measurement improve the product. Before you accept we measure page views and anonymous interactions, with no cookies, no recording and no profile. Reject keeps it that way. Cookie policy

Vetoo
ManifestoLive reviewAgent panelMemory & trustPricing
Resources
Competitor comparisonLearn centerDocs
Sign up
Sign inSign up
Legal

Privacy Notice

Who controls your data, which personal data is processed, on what legal basis and for how long, your rights, and the third parties involved.

Last updated · 2026-09-02
I.

Controller

Name of the controller
Coordentra Kft.
Seat
1134 Budapest, Angyalföldi út 5. 2. em. 3. ajtó
Company Registration No.
01-09-457570
Tax ID No.
HU33070885
Data Protection Contact Person
the managing director of the Controller (contact: privacy@vetoo.dev)
Contact email address
privacy@vetoo.dev
Websites
vetoo.dev, app.vetoo.dev, docs.vetoo.dev
II.

Definitions

Personal Data: means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Processing: means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Controller: means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

Consent of the data subject: means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Processor: means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

III.

Nature of the processing, categories of the processed data, purpose of the processing, legal basis, and retention period by category

The Controller operates ‘Vetoo’ software, which provides code review services primarily designed for corporate clients. To a lesser extent, natural persons may also use the free version of the software as sole proprietors or professional users. The Controller processes Personal Data exclusively to the extent strictly necessary for the provision of the services. This primarily encompasses data qualifying as Personal Data of the contact persons of corporate (B2B) partners utilizing the service (e.g., name, email address containing a personal name). For corporate clients, usernames and contact email addresses do not necessarily constitute Personal Data (e.g., a username identical with the company name or email addresses in such form as e.g. office@companyname.hu), in such instances, neither these credentials nor other company related information (e.g., company bank account number, registered office address, tax number) constitute Personal Data. However, where the service is utilized on a limited basis by private entrepreneurs, or when e.g. professional users submit inquiries, their data (such as username, email address, tax identification number, bank account details) will generally qualify as Personal Data.

The Controller does not carry out automated decision-making based on personal data. Based on developer feedback, summaries of conventions are prepared at repository or team level (not tied to any specific individual).

Where the processing of Personal Data is not based on performance of a contract concluded with the data subject or taking steps at the request of the data subject prior to entering into a contract, the data subject’s consent or compliance with a statutory legal obligation, the legal basis is the legitimate interests pursued by the Controller or a third party (see below). For corporate clients, the Personal Data processed pertains to the contact persons (employees or registered representatives) of the client. These individuals disclose their personal data on behalf of the company, frequently pursuant to instructions from their employer, whereas the contractual relationship governing the use of the services is established solely with the company (the employer). In these circumstances, the requirement of freely given consent is not necessarily satisfied. Consequently, the legal basis for processing such data (to the extent it constitutes Personal Data) is not the consent of the data subject, but rather the legitimate interest of the corporate client in accessing and utilizing the service. Furthermore, where processing is necessary to ensure the technical reliability, security, and integrity of the service, the legal basis is the legitimate interest pursued by the Controller and third parties (including clients) in ensuring service quality and security, as well as preventing fraud and abuse.

IMPORTANT NOTICE: In respect of corporate clients, the Controller does not verify whether individuals designated as contact persons or representatives are duly authorized to act on behalf of the company. The client bears sole responsibility for ensuring that the personal data provided pertains exclusively to individuals who possess valid authorization to act on its behalf, and for updating any changes in the system without undue delay. The Controller disclaims all liability for processing the personal data of individuals who lack proper authorization to represent the client. If such an unauthorized individual requests the deletion of their personal data, the Controller shall comply with such request, and if the client fails to designate a duly authorized representative, the Controller shall bear no liability for any service interruptions, failures, or deficiencies arising from the absence of an active contact person or registered representative.

Category of Personal DataPersonal DataPurpose of processingLegal basisRetention period
Customer account dataFull name, email address (to the extent it constitutes Personal Data), Organization ID, role/positionContact and communication, provision of the service, establishment, exercise, or defense of legal claimsIn the case of natural person clients (e.g. private entrepreneurs), performance of contract concluded or to be concluded with the data subject (Article 6(1)(b) GDPR)In the case of non-natural person clients, legitimate interests pursued by the Controller or a third party (Article 6(1)(f) GDPR)Maximum 90 days from termination of contract or account deletion; in the event of a dispute, until the final resolution of the dispute (e.g., settlement agreement, non-appealable conclusion of court proceedings)
Billing dataBilling name and address, other obligatory invoice data, tax identification number, issued invoicesBilling, compliance with statutory accounting obligationsCompliance with legal obligations under accounting and tax laws (Article 6(1)(c) GDPR)Retention period set forth in the applicable accounting and tax laws (8 years)
Billing dataSubscription status, credit balance and associated movements, usage metrics, payment identifiersProvision of the service, billing, enforcement of legal claimsCompliance with legal obligations under accounting and tax laws (Article 6(1)(c) GDPR)Legitimate interests pursued by the Controller or a third party (Article 6(1)(f) GDPR)Maximum 90 days from termination of contract or account deletion; in the event of a dispute, until the final resolution of the dispute (e.g., settlement agreement, non-appealable conclusion of court proceedings)
Customer service dataContent of the inquiry, attachments (images and videos, up to 100 MB), email threadsProvision of the service, handling customer complaints, responding to inquiriesIn the case of natural person clients (e.g., sole traders), performance of contract concluded or to be concluded with the data subject (Article 6(1)(b) GDPR)In the case of non-natural person clients, legitimate interests pursued by the Controller or a third party (Article 6(1)(f) GDPR)Maximum 90 days from termination of contract or account deletion; in the event of a dispute, until the final resolution of the dispute (e.g., settlement agreement, non-appealable conclusion of court proceedings)
Developer data processed in the course of providing code review servicesAuthors of pull requests, user namesDeveloper names and email addresses listed in commitsComment textCode snippets listed in feedback records along with the commenter’s nameProviding services, maintaining contact, answering questions, and handling feedbackLegitimate interests pursued by the Controller or a third party (Article 6(1)(f) GDPR)Maximum 90 days from termination of contract or account deletion (with the exceptions listed below); in the event of a dispute, until the final resolution of the dispute (e.g., settlement agreement, non-appealable conclusion of court proceedings):Raw feedback observations: 90 daysWebhook delivery records: 7 daysOperator logs: 365 daysApplication logs: 90 daysDatabase backups: 90 days
Technical dataOperator logs, telemetry, web analytics, technical logs, OAuth tokens of connected integrations, client API key (in case of BYOK, bring-your-own-key usage)Provision of the service, quality assurance, IT security, fraud and abuse prevention, service integrityIn the case of natural person clients (e.g., sole traders), performance of contract concluded or to be concluded with the data subject (Article 6(1)(b) GDPR)In the case of non-natural person clients, legitimate interests pursued by the Controller or a third party (Article 6(1)(f) GDPR)Maximum 90 days from termination of contract or account deletion (with the exceptions listed below); in the event of a dispute, until the final resolution of the dispute (e.g., settlement agreement, non-appealable conclusion of court proceedings):Raw feedback observations: 90 daysWebhook delivery records: 7 daysOperator logs: 365 daysApplication logs: 90 daysDatabase backups: 90 days
MarketingContact data: name, email addressNewsletter, special offerConsent of data subject (Article 6(1)(a) GDPR)In the case of non-natural person clients, legitimate interests pursued by the Controller or a third party (Article 6(1)(f) GDPR)Until withdrawal of consent or unsubscribe
IV.

Rights of the data subject

a) Information and access to personal data: The data subject has the right to obtain access to the following information regarding the processing of their personal data:

  • purposes of the processing;
  • categories of personal data concerned;
  • recipients or categories of recipients to whom the personal data have been disclosed;
  • envisaged period of storage;
  • data subject’s rights concerning the processing.

The Controller shall provide the data subject with a copy of the personal data undergoing processing. Where the request is submitted by electronic means, the Controller shall provide the information in a commonly used electronic format. The Controller may charge a reasonable fee for any additional copies requested. The right to obtain a copy shall not adversely affect the rights and freedoms of others.

b) Right to rectification: Under the GDPR, the data subject shall have the right to obtain from the Controller without undue delay the rectification of inaccurate personal data concerning them, and to have incomplete personal data completed.

c) Erasure of Personal Data ("Right to be Forgotten"): Under the GDPR, the data subject is entitled to request the erasure of their personal data from the Controller in the following circumstances:

  • the personal data are no longer required for the purposes for which they were originally collected or processed, and no alternative legal ground exists;
  • the data subject revokes the consent constituting legal basis to the processing, provided no other legal basis applies;
  • the data subject exercises their right to object to processing carried out under Article 6(1)(e) or (f) of the GDPR;
  • the data have been processed unlawfully; or
  • erasure is mandatory in order to comply with a statutory legal obligation under applicable European Union or Member State law.

Data subjects are advised, however, that applicable data protection legislation may require or authorize the Controller to retain and continue processing personal data notwithstanding an erasure request (for instance, where necessary for compliance with a statutory legal obligation, reasons of public interest, or for the establishment, exercise, or defense of legal claims).

d) Right to Restriction of Processing: Under the GDPR, the data subject is entitled to request that the Controller restrict the processing of their personal data in any of the following circumstances:

  • the data subject contests the accuracy of the personal data, in which case processing is restricted for a period necessary for the Controller to verify its accuracy;
  • the processing is unlawful, but the data subject opposes the erasure of the data and requests the restriction of its use instead;
  • the Controller no longer requires the personal data for processing purposes, but the data subject requires it for the establishment, exercise, or defense of legal claims; or
  • the data subject has raised an objection to the processing based on grounds relating to their particular situation, in which case the restriction shall remain in effect until it is verified whether the Controller’s legitimate grounds override those of the data subject.

e) Right to Data Portability: Under the GDPR, where processing is carried out by automated means and is based either on the data subject’s consent or on the performance of a contract, the data subject is entitled to receive their personal data provided to the Controller in a structured, commonly used, and machine-readable format. The data subject further has the right to transmit such data to another controller without hindrance from the Controller. The exercise of this right shall not adversely affect the rights and freedoms of third parties.

f) Right to Object: Under the GDPR, the data subject is entitled to object, on grounds relating to their particular situation, to the processing of their personal data where such processing relies on the legitimate interests of the Controller or a third party, or on public interest grounds. Upon receipt of such an objection, the Controller shall cease processing the data unless it demonstrates compelling legitimate grounds for continued processing that override the interests, fundamental rights, and freedoms of the data subject, or where processing is necessary for the establishment, exercise, or defense of legal claims.

g) When utilizing the service, the provision of personal data by the client is voluntary. However, failure to provide certain necessary information may render communication or the provision of the service impossible. Furthermore, the processing of specific data categories is mandatory pursuant to statutory obligations (particularly compliance with applicable accounting and tax laws).

h) The data subject has the right at any time to lodge a complaint regarding the processing by the Controller with the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH; address: Falk Miksa utca 9-11, H-1055 Budapest, Hungary; tel.: +36 1 391 1400; email: ugyfelszolgalat@naih.hu), and to seek a judicial remedy before a court pursuant to the applicable statutory provisions (before the regional court having jurisdiction over the registered seat or branch office of the Controller, or, at the choice of the data subject, before the regional court having jurisdiction over the data subject’s domicile or place of residence).

i) Requests regarding the exercise of data subject rights may be submitted by the data subject via the Controller’s contact details below:

Contact e-mail address
privacy@vetoo.dev
V.

Data Transfer

The provision of services by the Controller requires the involvement and services of third parties. These third parties access certain data or have such data shared with them in order to provide their own services; however, only a minor portion of the shared data qualifies as Personal Data. Personal Data for the processing of which third-country service providers are engaged include: data of natural persons, contact person details in the case of corporate clients, and customer support data. Some of the third parties listed below have their place of business in a so-called "third country" outside the EU; therefore, data transfers to a third country may also occur. These third parties operate mainly within the territory of the United States, in which case either the EU-U.S. Data Privacy Framework Program (DPF) or Standard Contractual Clauses (SCC) accepted by European Commission ensure safe and secure data transfers.

Third parties to whom data are transferred (or who have access to data) for the purpose of providing the service:

Service Provider, ApplicationType of activity and dataPlace of establishmentLegal guarantees of non-EU data transfer DPF or SCC
Amazon Web ServicesCloud infrastructure: application hosting, databases, data storage, and sending and receiving emailIreland
ClerkAuthentication and user managementUSA and EUDPF
StripePayment processing and subscription lifecycle managementUSA and EUDPF
BillingoInvoicing and tax authority data reportingHungary
DatadogSystem logging, distributed tracing, and client-side browser telemetryEU, Frankfurt
PostHogProduct analytics, session recordings, and server-side telemetryEU, FrankfurtDPF
Google AdsAdvertising conversion measurement after cookie consent: the click identifier from an ad and the address of the page visitedUSA and EUDPF
LinearCustomer support ticketingUSASCC
Google WorkspaceCorporate email communications and document managementUSA and EUSCC

The code review process does not generally involve the processing of personal data. Data processors are involved in the code review process, and the code may be forwarded to them. As part of this process however, communication takes place with developers, who e.g. may ask questions and share opinions and comments; consequently, data classified as personal data (see Section III) may also be transferred to these data processors. The list of the data processors in question is included in the Appendix (vetoo.dev/subprocessors).

Please note: Data processing by third-party service providers engaged in the provision of the service is governed by these providers’ data processing policies and the retention periods they apply; in particular, customer service attachments stored in Linear’s system may remain with Linear even after they have been deleted by the Data Controller, in accordance with Linear’s own retention policy.

In addition to the third parties listed above, the Controller transfers Personal Data to its accounting service provider and legal counsel strictly to the extent necessary for utilizing their services. These service providers do not qualify as third-country service providers.

Version history

  • 2026-09-02in force
TermsPrivacySub-processorsCookiesLegal notice

Clear the review queue
before it forms.

Connect your first repository and let Vetoo do the rest.

Connect your repository
Vetoo

Product

ManifestoLive reviewAgent panelMemory & trustPricingFAQ

Resources

All resourcesWhat is AI code review?Code review checklistVetoo vs CodeRabbitVetoo vs GreptileVetoo vs Bugbot

Developers

Docs

Company

Contact

Legal

PrivacyTermsSub-processorsCookie PolicyLegal notice