Privacy
Privacy policy
Last updated: 28 July 2026
This policy describes how personal data is processed in connection with the Gabel website, dashboard app, contact form, and the brief service. Gabel is operated by Emmanouil Gketsim (Switzerland). Swiss data protection law (revDSG) applies. Where the GDPR applies to you, the same principles below are followed.
Controller
Emmanouil GketsimVorderuttenberg 6
8934 Knonau
Switzerland
[email protected]
What this policy covers
- The public website at gabel.app (including the contact form)
- The dashboard at app.gabel.app
- Email correspondence about trials, support, and onboarding
- The Gabel brief service for customers who connect their tools
Data collected on the website (contact form)
When you submit the contact form, the following fields are processed:
- Name
- Work email address
- Message content
Credentials (Jira tokens, git tokens, Slack webhooks) are never collected on the public website. Customers connect integrations via OAuth (and paste a Slack webhook) in the authenticated app.
Purpose: to respond to your request and communicate about setup or support.
Legal basis: steps prior to a contract at your request, and legitimate interest
in operating a B2B product (Art. 6(1)(b) and (f) GDPR where applicable; Art. 31 revDSG).
Retention: contact submissions are kept for up to 24 months after the last contact, unless a longer period is needed for an active customer relationship or legal obligation.
No marketing list: submitting the form does not subscribe you to a newsletter. Product updates are sent only in direct reply to your enquiry or customer relationship.
Account and workspace data (dashboard)
When you use the app we process:
- Account authentication via Amazon Cognito (email and sign-in data)
- Workspace settings you configure (team name, team size, schedule, board and repository selections)
- Billing identifiers and status via Stripe (customer and subscription ids; card data stays with Stripe)
- Optional delivery addresses (for example Slack webhook URL or email destination) needed to send briefs
Integration credentials are stored in AWS Systems Manager Parameter Store as encrypted SecureString parameters. They are not stored in the tenant database or returned to the browser app after save.
Data processed for the brief service
For connected workspaces, Gabel reads metadata from connected systems:
- Jira: issue metadata, sprint fields, status transitions (API access granted via OAuth)
- Git: pull request metadata (open, merge, review timing) from Bitbucket or GitHub
The product does not fetch repository file contents or Jira description fields today. Digests may include issue keys, PR identifiers, and team/workspace names that appear in that metadata.
Digests are team-level aggregates. They are not designed as individual employee performance monitoring.
Purpose: to generate and deliver the subscribed brief.
Legal basis: performance of the service agreed with your organisation (contract).
Hosting and processors
Personal data may be processed by service providers acting on instructions:
- Netlify — hosting of the static website and contact form submissions
- Amazon Web Services (AWS) — app API and scheduled brief execution, Cognito auth, DynamoDB tenant config, encrypted credential storage (SSM Parameter Store), and optional S3 digest history
- Stripe — checkout, subscriptions, and billing portal
- Atlassian, GitHub, Bitbucket — OAuth connection to systems you authorize
- Email — direct email from [email protected] for support messages; optional HTML email delivery of briefs when configured
- Slack — delivery to your workspace when you provide an Incoming Webhook URL (data is sent to Slack under your control)
Processors are used under contractual terms that require appropriate security and processing only on documented instructions.
International transfers
Website and cloud infrastructure may involve processing in the EU, United States, or other countries where these providers operate. Appropriate safeguards (such as standard contractual clauses or provider certifications) are relied on where required.
Cookies and analytics
The public website does not use non-essential analytics or advertising cookies at the time of this policy. Essential technical storage for form submission may apply via the host. The dashboard uses authentication session storage required to keep you signed in. If analytics are added later, this policy will be updated and consent obtained where required.
Your rights
Depending on applicable law, you may have the right to:
- Access personal data held about you
- Request correction or deletion
- Restrict or object to certain processing
- Data portability where applicable
- Lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), or your local EU supervisory authority
Requests: [email protected]
Security
Integration credentials are stored as encrypted AWS Parameter Store parameters (KMS-backed SecureStrings). Dashboard APIs require Cognito authentication and owner checks. Access to production systems is limited to the AWS roles that operate Gabel. No system is perfectly secure; incidents will be handled in line with applicable breach-notification duties. You can revoke provider access anytime in Jira, GitHub/Bitbucket, or Slack.
Changes
This policy may be updated when the service, processors, or legal requirements change. The date at the top will be revised.