Privacy Policy
This policy explains how Digitaldrreamer Hub, a business registered in Nigeria under registration number RC 9225239 and trading as BattleTest ("BattleTest", "we", "us", or "our"), handles personal data when you visit our websites, use our security-review and testing services, contact us, or participate in our referral and affiliate programmes (collectively, the "Service"). BattleTest is the controller of the personal data described here, except where another party, such as our payment provider, acts as an independent controller.
1. Information We Collect
- Account and profile data: name, email address, username, authentication method, avatar, organisation membership, roles, preferences, and account security events.
- Repository and workspace data: repository identifiers and metadata, installation permissions, pull request content, code changes, configuration, and other content you choose to make available for review.
- Security-testing data: authorised targets, test configuration, credentials or test-session material you provide, requests and responses, screenshots, evidence, findings, reports, approvals, and run history.
- Billing and commercial data: plan, subscription status, transaction identifiers, invoices, tax information made available to us, and referral or affiliate records. Paddle collects and processes payment credentials; BattleTest does not receive full card details.
- Communications: support requests, survey responses, feedback, marketing preferences, and other messages you send us.
- Technical and usage data: IP address, device and browser information, timestamps, pages and features used, diagnostic events, security logs, and referral attribution.
We collect this information from you, members of your organisation, your use of the Service, integrations you connect (such as GitHub), our service providers, and publicly available sources used for security research and vulnerability intelligence.
2. How and Why We Use Information
- Provide the Service: authenticate users, connect integrations, run reviews and tests, generate findings, administer organisations, provide support, and deliver requested features.
- Operate and secure the Service: prevent abuse and fraud, enforce authorised-testing boundaries, investigate incidents, debug failures, maintain availability, and protect users and third parties.
- Manage billing: administer plans, entitlements, renewals, invoices, refunds, tax records, affiliates, and referrals.
- Communicate: send service, account, billing, security, support, and policy notices. With your consent where required, we may also send product and marketing communications.
- Improve the Service: understand feature use, evaluate performance and quality, and develop new capabilities.
- Meet legal obligations: keep required records, respond to valid legal process, and establish or defend legal claims.
Depending on the activity and applicable law, we rely on performance of our contract, our legitimate interests in operating and securing the Service, compliance with legal obligations, or your consent. You may withdraw consent at any time without affecting earlier processing.
3. AI-Assisted Processing
BattleTest uses automated systems, including third-party AI services, to analyse code, application behaviour, and security evidence. We send only the content reasonably needed for the requested analysis. Depending on the feature, this may include code changes, target responses, screenshots, prompts, and prior findings. AI-generated results may be incomplete or incorrect and should be reviewed by a qualified person before important decisions are made.
We do not use automated processing to make decisions that produce legal or similarly significant effects about individuals. Information about current providers and high-level data handling is available in our Security & Data Handling documentation.
4. When We Share Information
We do not sell personal data or share it for cross-context behavioural advertising. We may disclose information to:
- Service providers that support hosting, storage, AI inference, communications, analytics, monitoring, customer support, and security operations, under contractual or other appropriate safeguards.
- Paddle, which acts as authorised reseller and merchant of record for purchases and processes buyer data under its own privacy notice.
- Integrations you direct us to use, such as GitHub, according to your settings and those providers' terms.
- Professional advisers and authorities where reasonably necessary to comply with law, protect rights and safety, or establish and defend legal claims.
- A successor organisation in connection with a merger, financing, reorganisation, or sale of all or part of our business, subject to appropriate confidentiality protections.
We may publish or share aggregated or de-identified information that cannot reasonably identify you.
5. International Transfers
BattleTest and its providers may process information in countries other than where you live. Where required, we use recognised transfer mechanisms and contractual, organisational, or technical safeguards. Those countries may have different data-protection laws from your jurisdiction.
6. Retention and Deletion
We keep information only for as long as reasonably necessary for the purposes described above. Retention depends on the type of record, your plan and settings, security and support needs, legal requirements, and whether the information is needed to resolve a dispute.
- Account, organisation, findings, and test records are generally kept while the relevant account or workspace remains active.
- When an account or workspace is deleted, associated customer data is removed from active systems, subject to limited records we must retain for billing, fraud prevention, security, legal compliance, and backup rotation.
- Short-lived execution data and temporary credentials are deleted or expire according to operational retention periods.
- De-identified and aggregated information may be retained for longer where it can no longer reasonably identify you.
You can request deletion at any time. Disconnecting an integration stops future access but does not necessarily delete findings and reports already created; delete those records or your account separately where available.
7. Security
We use administrative, organisational, and technical safeguards designed to protect information in light of its sensitivity and the risks involved. No service can guarantee absolute security. You are responsible for protecting your credentials, limiting integration permissions, and using test credentials rather than production secrets whenever practical. Report suspected security issues to [email protected]. Where required by law, we will notify affected people and authorities of a personal-data breach.
8. Your Privacy Rights
Subject to applicable law, you may have the right to:
- access, correct, delete, or receive a portable copy of your personal data;
- object to or restrict certain processing;
- withdraw consent and opt out of marketing communications; and
- complain to the Nigeria Data Protection Commission or another competent supervisory authority.
Send requests to [email protected]. We may need to verify your identity and authority. Rights are not absolute, and we may retain or continue processing information where permitted by law. You may also manage profile data, integrations, communications, and account deletion from the Service.
9. Cookies, Local Storage, and Analytics
We use first-party cookies and browser storage for authentication, security, navigation state, preferences, onboarding, checkout continuity, and referral attribution. Referral attribution cookies may remain for up to 60 days. We also use first-party product analytics to understand page and feature usage. We do not use third-party advertising cookies or sell analytics data.
10. Communications
Operational messages about your account, billing, security, and requested services are necessary to provide the Service. You can unsubscribe from marketing emails using the link in each message or your account settings. We may still send non-marketing messages after you opt out of marketing.
11. Children
The Service is intended for business users aged 18 or older. We do not knowingly collect personal data from children. Contact us if you believe a child has provided personal data to the Service.
12. Changes to This Policy
We may update this policy to reflect changes in the Service, our practices, or applicable law. We will post the revised policy and update its effective date. Where required by law or where changes materially affect your rights, we will provide additional notice.
13. Contact
Data controller: Digitaldrreamer Hub (RC 9225239), trading as BattleTest, Nigeria.
Privacy questions and rights requests: [email protected]
Legal notices: [email protected]
General support: [email protected]