Privacy Policy
Last updated: October 1, 2026
This Privacy Policy describes how information is handled through Bacumi.com when you use our website, contact us, or use our Azure DevOps extensions.
1. Publisher and privacy contact
Bacumi.com is the publishing name used for this website and the extensions. Privacy requests can be sent to support@bacumi.com.
Product-specific processing, hosting, and contractual details are provided where applicable. Publishing this page does not by itself represent a certification or replace product-specific agreements.
2. Azure DevOps extensions
This section covers the Bacumi extensions for Azure DevOps: PR Pulse Free, Treefold, and Tagfold. These extensions run in your browser, inside your own Azure DevOps organization.
- The extensions call your own Azure DevOps organization's APIs with the signed-in user's Azure DevOps sign-in and permissions. Read and write actions are limited by that user’s permissions and the extension’s requested scopes.
- Bacumi does not operate a server for these extensions. Bacumi does not receive pull request, work item, query, or tag data from them.
- No usage analytics, telemetry or automatic crash reports are sent to Bacumi.com by these free extensions.
- Treefold workbooks are generated in your browser and saved to your own device.
Each extension requests only the Azure DevOps scope it needs:
- PR Pulse requests vso.code, read-only access to repositories and pull requests.
- Treefold requests vso.work, read-only access to work items and queries.
- Tagfold requests vso.work_write, read and write access to work items, used to rename, merge, and delete tags.
Preferences the extensions remember:
- Column widths may be saved in local storage for the extension in this browser. The free production extension does not persist pull request content or saved reports there. Dashboard data is held in browser memory while the extension runs.
- Per-user preferences are saved in your organization’s Azure DevOps extension data storage: query identifiers and column layouts (up to 50 saved layouts), hierarchy mode, rich-text and text-wrap choices, a successful-export counter, and review-prompt dismissal or snooze state. The counter controls the review invitation; it is not transmitted to Bacumi.com as telemetry.
- Tagfold stores a small review-prompt state document in Azure DevOps extension data scoped to your user: the completed merge count (mergeCount) and whether you dismissed the prompt. This state controls the review prompt and is not sent to Bacumi as telemetry. Tagfold does not archive a separate copy of work item data. Changes you confirm are stored in Azure DevOps itself and may appear in its work item history or service logs.
Azure DevOps and the Visual Studio Marketplace are operated by Microsoft, which processes data in those services under its own terms and privacy statement.
If you contact support@bacumi.com about an extension, we handle the information you choose to send as support and communications data under this policy.
3. Data categories
- Contact messages may include your email address, name, selected category or product, and the message you choose to send.
- Limited technical data used to secure the forms and diagnose failures, such as request time and a protected identifier derived from a trusted client address. Website hosting and email delivery also involve network and service records such as IP addresses, browser information, timestamps and email routing metadata.
4. Purposes and legal bases
We process data for the following purposes:
- Respond to contact messages and support requests.
- Understand demand for published Bacumi products and programs.
- Protect the forms from abuse and maintain short-lived diagnostic records.
Applicable legal bases include:
- Responding to ordinary enquiries and voluntary support requests: legitimate interests in communicating with users and resolving problems.
- Taking pre-contractual steps specifically requested by you: Article 6(1)(b) GDPR, where applicable.
- Abuse prevention and limited diagnostics: legitimate interests in protecting the website and keeping forms reliable.
- Required retention or disclosure: legal obligation, where applicable. Separate optional activities requiring consent will explain the choice before processing.
5. Retention
Website contact-form messages are scheduled for deletion within 180 days, unless an earlier deletion is appropriate or a legal obligation requires longer retention. Form abuse counters expire within 24 hours and contact diagnostic events within 30 days. Direct support emails and attachments are kept while handling the request and any necessary follow-up or legal claim, then reviewed for deletion; these form deletion schedules do not automatically apply to email or provider logs.
6. Subprocessors and transfers
Website hosting and form submissions use Microsoft Azure hosting and storage services. Email providers process correspondence sent to support; relevant information may also be disclosed where legally required. We do not sell support information or share it for advertising. Azure Communication Services may send a limited internal notification containing a submission type, product or category, and reference. The notification does not include the message, use case, or email address. When the contact form is enabled, the open-source ALTCHA widget performs a small calculation in your browser to help limit automated abuse. Bacumi verifies the result in its own Azure backend; no external CAPTCHA verification service receives the result, message or email address. Short-lived verification identifiers and keyed hashes of network addresses are used to prevent reuse and limit requests.
Hosting and email providers may process service data internationally. Any transfer of personal data outside the EEA must have an applicable legal basis and safeguards, such as an adequacy decision or standard contractual clauses. Contact support@bacumi.com for information about providers and safeguards relevant to your enquiry.
7. Your rights
- Access and receive a copy of your personal data.
- Request correction of inaccurate personal data.
- Request deletion where legal grounds apply.
- Object to processing or request processing restrictions where applicable.
- Request portability where legally applicable.
- Lodge a complaint with a supervisory authority.
To exercise privacy rights, contact support@bacumi.com. We respond without undue delay and normally within one month under GDPR. If a lawful extension is needed, we explain it within that first month. We request only proportionate identity verification when needed. You may withdraw consent for consent-based processing without affecting earlier lawful processing. Providing contact details and a message is voluntary, but we need enough information to reply.
You can complain to the supervisory authority where you live or work, or where an alleged infringement occurred. In Romania, see the ANSPDCP complaints procedure.
8. Website storage and automated decisions
The website does not include usage analytics or advertising trackers. Fonts and site assets are bundled locally. When enabled, the contact form uses the bundled ALTCHA anti-abuse widget and a same-origin verification endpoint. No marketing cookie consent is requested for this implementation. We do not use support information to make decisions with legal or similarly significant effects solely by automated processing.