Metacenta — Privacy notice

Last updated: 2026-09-19. Effective: 2026-09-19.

This notice covers data processing for metacenta.com, the Data & AI technical review. The sico-wide privacy notice applies in addition.

1. What data we collect

  • Client contact data — the email address of each person invited to read a review, and their name where given. Access is by invitation only; there is no signup. We record when each person last signed in.
  • dbt artefactsmanifest.json, and optionally run_results.json, sources.json and catalog.json, supplied by the client. These describe project structure: models, sources, tests, columns, and what the last build did.
  • Repository metadata — read through a read-only token the client supplies: file tree, languages, contributor counts, presence of CI configuration. Nothing is cloned. The only file contents fetched are named dbt configuration files (dbt_project.yml, packages.yml).
  • Findings — the review, the per-finding worklist and the delivered PDF, held so the client can retrieve them later.
  • Enquiries — email address, optional company name, and the message submitted through the enquiry form on metacenta.com.

2. What we deliberately do not collect

No warehouse credentials, no production data and no query results. There is no connection to a client warehouse and no mechanism to request one. profiles.yml is excluded by filename because it is the one dbt configuration file that holds warehouse credentials.

A run_results.json contains compiled SQL. It is read for pass/fail status and discarded at the parsing boundary — the structure it is read into has no field to hold SQL — so it is never stored and never transmitted onward.

3. Legal basis

Processing is necessary to perform the engagement contract (UK GDPR Art. 6(1)(b)). Contact data for invited readers is processed on the basis of legitimate interests (Art. 6(1)(f)) in delivering the commissioned work to the client organisation that named them.

4. Personal data in the artefacts

dbt projects can name people: a groups: entry or an exposure carries an owner name and email, and a meta.owner is often an address. These are read so the review can say who is accountable for each data asset, and they appear in the client's own worklist. They are never included in the optional AI pass — see §5 — and are not shared with anyone outside the engagement.

5. AI processing — off by default

A review runs with zero calls to any language model by default, and a run with none produces the complete document. An optional interpretive pass sends a findings digest — check identifiers, severities, counts, and example model, source and file names — to Anthropic. It is off unless the client agrees to it, the delivered report states what was sent, and owner names and email addresses are excluded from it by construction rather than by filtering. No file contents, no SQL and no query results are sent on either path.

6. Data retention

Findings and the documents built from them are retained while the client wants to be able to retrieve them, and deleted on request — there is no period we are obliged to keep them for. The supplied artefacts are not retained beyond producing the review. Findings are isolated per client at the database level, so one client's data is not reachable from another's session.

7. Sub-processors

  • Hetzner — VPS hosting; data stored in EU.
  • Anthropic — the optional interpretive pass over the findings digest only, and only where the client has agreed to it.
  • GitHub — read via a client-supplied read-only token to collect repository metadata.
  • Resend — sign-in links and transactional email.
  • SuperTokens — self-hosted authentication; holds the email address used to sign in.

8. Contact

Privacy queries: privacy@sico.software. Deletion and access requests are handled by a person; see the data deletion policy.