by Winch Labs

Legal

Privacy Policy

Winch Labs FZ-LLC
Registered address: HD18B, First Floor, in5 Tech, Dubai Internet City, King Salman Bin Abdulaziz Al Saud Street, Al Sufouh 2, Dubai, United Arab Emirates.
Licensed by Dubai Development Authority.

Last updated: 6 October 2026 · v1.2. This policy explains what Winch Labs FZ-LLC ("Winchlabs", "we") collects, why, and what your rights are. Two roles matter throughout: for this website and your account, we are the controller; for the repository content your organisation connects to Deltz, your organisation is the controller and we are its processor, acting on its instructions under our Data Processing Addendum.

What we collect on this website

Access and sales requests: we store the email, optional company and message, selected plan or deployment interest, a fixed campaign-channel label and a timestamp. We use these details to respond to your request, not to subscribe you to marketing. Request removal at hello@winchlabs.io. Signed unsubscribe links for the legacy waitlist also remove associated request rows. Legacy waitlist: existing rows contain email, referring page/URL, UTM query, browser user-agent and timestamp. Unsubscribing deletes the associated waitlist and request rows. Aggregate counters: page views, plan clicks and accepted requests are stored as daily counts by fixed event and channel labels, without cookies, visitor identifiers or IP addresses in the analytics tables. Counts do not identify unique visitors. Abuse prevention: a temporary counter keyed by your IP address is held for up to ten minutes to limit repeated submissions; it is separate from analytics. Your theme preference stays in your browser’s localStorage. We run no advertising trackers. The site is served by Cloudflare, whose edge produces operational logs under its policy.

What we collect in the Deltz service

Account and organisation data (we are controller): your email, a password hash or your single-sign-on subject, organisation membership and role, and the audit trail of actions taken (which records the acting user's email — that is its purpose).

Customer content (we are processor for your organisation): when Deltz reviews or scans, it clones the repository to a temporary directory, parses it, and deletes the clone when the scan completes — repository source is not retained at rest. What persists are the governance records the product exists to keep, all scoped to your organisation: findings with file-and-line evidence including short code excerpts; derived context documents (conventions with evidence); hash-chained, signed governance receipts; review coverage records; episodic memory of merges and fixes (capped diff digests and text embeddings that ground later drafts); cost estimates; and gate override and policy decisions. If your organisation stores its own Anthropic API key with us, it is held server-side and protected by encryption at rest.

Session: the app uses one strictly-necessary, HttpOnly session cookie to keep you signed in. No advertising or analytics cookies.

Why, and on what legal basis

To provide the service you asked for (contract); to keep the service and its tenants secure, to maintain audit and governance records, and to improve the product from operational signals (legitimate interests); to send you the updates you signed up for (consent — withdrawable by unsubscribing); and to meet legal obligations. We do not sell or share personal data for advertising, run no profiling, and make no automated decisions with legal or similarly significant effect — Deltz's findings are advisory input to your own engineers.

Subprocessors and recipients

ProviderPurposeLocation
Amazon Web ServicesHosting for the Deltz service (compute, database, storage)Frankfurt, Germany (eu-central-1)
AnthropicLLM drafting for Fix and Forge (relevant file content and conventions are sent to generate a draft) — only when using our keys; bring-your-own-key processing runs under your own Anthropic agreementUnited States
OpenRouterText embeddings for episodic recall on hosted installsUnited States
CloudflareWebsite hosting, waitlist storage, rate-limit countersGlobal edge

Your Git provider (GitHub or GitLab) processes your data under your own agreement with them — we access repositories through the app permissions you grant and can revoke. Self-hosted deployments use none of our subprocessors and send us nothing — there is no telemetry or phone-home.

International transfers

Service data is processed in the EEA (Frankfurt). Where processing involves the United States (Anthropic, OpenRouter) or Cloudflare's global edge, we rely on the 2021 EU Standard Contractual Clauses and the providers' data-protection terms, with the UK Addendum where UK data is in scope, and equivalent safeguards under the UAE Personal Data Protection Law for transfers out of the UAE.

Retention

DataKept
Access or sales requestUntil you ask us to delete it; account and contractual records, if subsequently created, follow their own retention rules below
Waitlist rowUntil you unsubscribe (deleted, not flagged)
Repository clonesDuration of the scan only
Reviews, receipts, context documents, episodesLife of the organisation, or your organisation's configured retention window
Audit log and coverage recordsForever by default; organisations can configure a retention window (each pruning is itself recorded)
After account/organisation deletionExport window of 30 days, then deletion from live systems within 30 days; short-lived backups age out on their own schedule

Your rights

Depending on where you live (including under the EU/UK GDPR, the UAE PDPL, and the CCPA/CPRA), you may have rights to access, correct, delete, restrict, or port your personal data, to object to processing, and to complain to a supervisory authority. Write to hello@winchlabs.io with "Privacy" in the subject; we respond within 30 days (45 for CCPA requests). We verify requests and never discriminate for exercising rights. California residents: we do not sell or share personal information as those terms are defined in the CPRA. If your data is in an organisation's Deltz records, we may refer the request to that organisation as its processor.

Breach notification, children, changes

Where we are controller, we notify the competent authority within 72 hours of becoming aware of a reportable personal-data breach and affected people without undue delay when the risk is high; where we are processor, we notify the affected organisation without undue delay. The service is for organisations and is not directed at children under 16. Material changes to this policy are announced on the changelog and by email to account holders before they take effect.

Contact

Winch Labs FZ-LLC, Dubai, United Arab Emirates · hello@winchlabs.io (subject "Privacy").