This notice covers personal data. The inspection results themselves are computed from public repository, hosting-platform and package-registry data and are published as a public record.
Who is responsible
The controller is Vitalii Stepanenko, established in Spain, operating this service under the name inspect.software:
- Calle Vicente Tormo Alfonso, 4, 46015 València, Spain
- NIF Z1828056K (EU VAT ESZ1828056K)
mail@inspect.software
Requests are answered within one month.
What is processed, why, and for how long
| Data | Purpose | Legal basis | Kept |
|---|---|---|---|
| Contributor login and commit counts | The public record of who maintains a project | Legitimate interest | Published |
| Contributor and owner profile fields (name, location, company, organizations) | Identity resolution; maintainer and jurisdiction signals | Legitimate interest | Replaced on each rescan; removed on objection |
| Maintainer contact addresses | Reaching the people responsible for a project | Legitimate interest | Until objection; never published |
| Account profile and email | Operating an account | Contract | Until deletion is requested |
| Balance and transactions | Billing and accounting | Contract; legal obligation | Statutory accounting period |
| Audience measurement | Traffic counts | Legitimate interest | 90 days |
| Server access logs | Operation, diagnostics, abuse | Legitimate interest | 30 days |
Data about people, obtained from public sources
Contributor and owner profile fields, and maintainer contact addresses, come from GitHub's public API and from package registries — not from the person concerned (Art. 14). Profile fields are used to identify who maintains a project and, where a self-published location falls within the Russia, Iran or North Korea policy scope, to compute an aggregate jurisdiction signal. Public reports show country and role counts only: profile fields and contact addresses are excluded from every published page and API response. The service does not infer nationality, citizenship, sanctions status or individual trustworthiness.
Contact addresses are used only to tell a maintainer that their project entered the record. They are not published, sold, or used for marketing.
Individual notification is not possible at the scale involved and would require processing more data about more people than the signals themselves use (Art. 14(5)(b)), which is why this notice is published here. Anyone may object at contact: the profile fields or the address are deleted and excluded from later scans.
Account data
Signing in uses GitHub OAuth with one read-only scope, email addresses (user:email). The service stores the profile basics an account needs — username, display name, avatar, account identifiers — plus the balance and its transactions. The access token is used only to read public data: the account's own public repositories, and repository ownership when a scan is covered by developer-program membership.
Cookies and analytics
A signed session cookie keeps an account signed in. It is set only after a sign-in, is strictly necessary for that purpose, and needs no consent.
Audience measurement sets no cookie and stores no identifier in the browser. It records page views with the referring site and details derived from the request — browser, operating system, device type, language and country — for 90 days.
If notifications are requested when a scan is queued, the notification service stores its subscription data in the browser. Permission can be withdrawn in the browser's site settings.
Recipients and transfers
The service runs on rented servers, and its hosting provider processes what passes through them. GitHub, Stripe (payments) and OneSignal (notifications and transactional email) are processors in the United States; transfers rely on the EU–US Data Privacy Framework and the standard contractual clauses in their data processing agreements. There is no advertising network, and audience measurement is not outsourced.
Rights
Access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interest — including the profile fields and contact addresses described above. Where processing rests on consent, it may be withdrawn at any time without affecting what was lawful before.
Requests go to contact. Account data and sessions are deleted on request; published reports of public repositories are records of public data and remain published (see the terms).
A complaint may be lodged with a supervisory authority — for this service the Spanish Agencia Española de Protección de Datos, or the national authority of the complainant's own country.
Changes
Material changes are announced on this page with an updated date.