Privacy Policy for the Azure DevOps Extension – "Automations"
Effective Date: September 3, 2026
Last Updated: September 10, 2026
Thank you for using the "Automations" extension for Azure DevOps (the "Extension"). This Privacy Policy describes how data is handled and protected when you use the Extension and the Documentero hosted services that run your automations (together, the "Service"). It applies only to the Automations Extension; other Documentero products have their own policies. The Extension is currently offered in Preview and free of charge.
The Extension requires an Azure DevOps organization connected to Microsoft Entra ID; organizations that use Microsoft personal accounts only ("MSA-only organizations") are not supported. Automations let your team define a trigger (an Azure DevOps work item event or a schedule), optional conditions, and a chain of actions (for example: create or update work items, add comments, copy fields, update tags, run a shared query, or send a customized email). When an event or schedule matches, our hosted backend runs those actions in your Azure DevOps organization as the Workflow Automation service principal (the "Automation Identity"), not as the person who created the automation.
The Extension's user interface runs inside Azure DevOps. Receiving events (Azure DevOps Service Hooks), executing automations, and sending emails are hosted services operated by Documentero on Google Cloud Platform in the European Union.
We process Azure DevOps data only to run the automations your organization has configured and to operate, secure, and support the Service. We do not sell your data. Key points:
Changes stay in your Azure DevOps organization: Work item updates and comments performed by automations are written directly to your Azure DevOps organization through Microsoft APIs, using the Automation Identity. We do not keep a copy of your work items.
Event data is processed transiently: Events sent by Azure DevOps are used to match your automations and queue a run, then discarded. Only short-lived duplicate-detection markers and compact Execution Logs are kept.
Connect authorization is temporary: A Project Collection Administrator signs in to Documentero's multi-tenant Microsoft Entra application when connecting the organization or changing its selected projects. That authorization is used to provision or update the Automation Identity and project access, then discarded.
Runtime tokens are not persistently stored: Automation execution uses short-lived tokens obtained server-side through the Microsoft Entra client credentials flow. We do not persist Azure DevOps Personal Access Tokens, organization user access tokens, or refresh tokens.
Extension sign-in uses your Azure DevOps session: The Extension user interface uses a short-lived Azure DevOps access token from your session to identify you, your organization, and your project. This token is not stored as an organization credential and is not used to execute automations.
The table below summarizes the data processed by the Service, where it comes from, why it is processed, and how long it is kept.
| Category | Source | Purpose | Retention |
|---|---|---|---|
| Organization ID and name, project ID and name | Azure DevOps | Tenant isolation, scoping of automations, settings, and logs | Until your organization stops using the Extension or requests deletion |
| Microsoft Entra tenant ID, Automation Identity summary, selected-project scope, and connection status | Connect and Microsoft APIs | Provision the Automation Identity in the correct directory and limit execution to selected projects | Until Disconnect; project references may also remain with stored automations and settings |
| User identifiers (Azure DevOps user descriptor, display name) | Extension session | Authenticate the Extension UI, apply access settings, record who last changed settings | Session; "last modified by" on settings |
| Organization contact email | Entered by an Organization Administrator | Operational notices (e.g. connection problems, important service notices) | Until changed or removed |
| Automation definitions | Authored by your users | Run your workflows | Until deleted by you |
| Project access settings (Azure DevOps group references) | Project Administrators | Control which additional groups may manage Automations and who may view Automations and Logs | Until changed |
| Execution Logs (status, timestamps, step summaries, identifiers and fields of work items used in the run, errors) | Generated by the Service | Run history, troubleshooting | Approximately 30 days |
| Service Hook subscription references | Generated by the Service | Track subscriptions created in your organization | While the subscriptions are needed |
| Event data (Service Hook payloads) | Azure DevOps | Match automations, queue runs | Transient; duplicate-detection and loop-protection markers (identifiers and revision numbers) up to 7 days |
| Usage counters (daily execution counters, run counts per automation) | Derived | Quota enforcement and display in the automation list | Daily counters: current day (UTC); run counts: with the automation |
| Email content and recipients | Your automation configuration and resolved values | Deliver the email | Transmitted to our email provider; no archive kept in our database; provider retains delivery logs per its terms |
| Operational and error diagnostics | Cloud logging | Reliability, security | Typically 30–90 days |
Automation definitions may include email subjects and bodies, recipient addresses, search conditions, references to shared queries, and field values entered by your users. Please avoid placing secrets or unnecessary personal data in automation configuration.
The "Send customized email" action sends messages from notifications@documentero.com to the recipients configured in your automation, with the subject and body defined by your automation (including any work item fields or other Smart Values inserted into the message). Your organization decides who receives these emails and what they contain, and is responsible for having a lawful basis to contact each recipient. The action is intended for operational notifications related to your Azure DevOps work, not for marketing or bulk messaging. Emails are transmitted through our email delivery provider (see Section 6); we do not keep an archive of sent messages. We may rate-limit, filter, or suspend email sending to prevent misuse.
The Extension works with two identities:
The signed-in user (Extension scopes): While you use the Extension inside Azure DevOps, it can only read Azure DevOps resources that you can already see. These scopes support the user interface, including the automation builder, identity and group selection, project context, and organization settings. They are not used to execute automations.
The Automation Identity: Connect provisions the Workflow Automation service principal as a Stakeholder user in your Azure DevOps organization and adds it to Project Administrators on projects selected by a Project Collection Administrator. Automation actions are limited to those selected projects and run under this identity.
Connect and Manage projects use a temporary administrator authorization to add or remove the Automation Identity's selected-project access. This provisioning permission belongs to Documentero's Microsoft Entra application and is separate from the Extension UI scopes. Project Administrators may manage Automations by default and may allow additional groups; project members may view Automations and Logs unless that access is restricted.
Service Hook subscriptions are created and removed by the Service automatically as automations are enabled or disabled. Because subscriptions are project-scoped, you can review them for the relevant project under Azure DevOps Project Settings → Service Hooks. The Extension's organization settings page also shows their status.
The signed-in user's Extension scopes are grouped as follows:
Work and project context (vso.work, vso.project): read work items, queries, fields, states, projects, and teams needed by the builder.
Identity and settings (vso.identity, vso.graph, vso.hooks, vso.features_write, vso.memberentitlementmanagement): support identity and group selection, access checks, Service Hook status, navigation visibility, and organization user visibility.
Other declared read scopes (vso.wiki, vso.build, vso.release): reserved for future wiki and pipeline selectors; current automation actions do not use these scopes for execution. The Extension does not request vso.code.
We use subprocessors (third-party services) to assist in providing the Service. They are subject to contractual data-protection and confidentiality obligations appropriate to their role. Currently, the following subprocessors are used:
| Subprocessor | Role | Data Involved |
|---|---|---|
| Google Cloud Platform (including Firebase) | Hosting, database, serverless compute, task queues, secret and key management, operational logging. Located in the European Union. | Organization, tenant, project and connection records, automation definitions, execution logs, and operational logs |
| Brevo | Outbound email delivery for the "Send customized email" action | Recipient addresses, subject, and message body as configured by your automation |
Microsoft (Azure DevOps, Microsoft Entra ID) provides your own Azure DevOps organization and identity platform. The Service calls Microsoft APIs on your behalf to read and update your work items, run queries, and manage Service Hook subscriptions. Microsoft processes this data under your organization's agreement with Microsoft, not as our subprocessor.
We do not share your data with third parties for their own purposes. We may disclose data where required by law or to protect the rights, safety, or security of the Service, our users, or third parties. The subprocessor list on this page may be updated from time to time.
Retention periods for each category of data are listed in Section 3. Before uninstalling the Extension, we recommend disabling or deleting your automations and using Disconnect in the Extension's organization settings. Disconnect clears Documentero's connection state, removes Service Hooks created by Documentero, and stops execution, but does not remove the Automation Identity from Azure DevOps Users or remove the Enterprise application from your Microsoft Entra directory. Delete the Azure DevOps user to release its Stakeholder seat; you may also disable or remove the Enterprise application. To request deletion of remaining organization data, contact support@documentero.com.
All backend processing and storage for the Extension take place in Google Cloud regions located in the European Union (primary region: europe-west1, Belgium). The Extension currently does not offer a selectable processing location. Your Azure DevOps data itself remains in the Microsoft region chosen for your organization. Current processing locations are described in the version of this Policy then in effect.
Data is encrypted in transit (HTTPS/TLS) and at rest. Service credentials are protected server-side, short-lived runtime tokens are not persistently stored, inbound events are authenticated, and changes to automations and settings go through authenticated server-side functions. Details are described in our Security & Data Protection Statement.
Where required by applicable law or an applicable Data Processing Addendum, we will notify affected organizations without undue delay after confirming a personal data breach affecting their data. Notices may be sent to the contact email provided in the Extension or through other appropriate channels and will contain the information reasonably available at that time.
The Service is intended for business use and is not directed at children. It is not intended for processing special categories of personal data. Work item fields that your organization includes in automations or emails may contain personal data (for example assignee names or email addresses); your organization is responsible for the content of its Azure DevOps work items and automation configuration.
Where the General Data Protection Regulation (GDPR) applies, the following roles and controls apply:
Roles: Your organization is the data controller for the Azure DevOps content and automation configuration processed by the Service; Documentero acts as a data processor on your organization's instructions. For limited operational data such as the organization contact email and usage statistics, Documentero acts as a controller for the purpose of operating and securing the Service. A Data Processing Addendum covering the Extension is available on request.
Data Subject Rights: You have the right to access, rectify, and erase your personal data. You can exercise these rights by contacting us at support@documentero.com. Where we act as a processor, requests should generally be directed to your organization; Documentero will assist as required by applicable law or an applicable Data Processing Addendum.
Your Controls: Organization Administrators can manage selected projects, change the contact email, and use Disconnect; authorized users can edit, disable, or delete automations according to project access settings; Execution Logs expire automatically. Complete offboarding steps are described in Section 7.
Data Transfer: The Service is hosted in the European Union. We do not transfer your personal data to regions not providing an adequate level of data protection unless adequate safeguards are in place.
The Extension is currently offered free of charge while in Preview, and we do not collect payment or card information for it. If paid plans are introduced, any payment-data processing will be governed by the privacy disclosures in effect when that data is collected.
If you have any questions or concerns regarding this Privacy Policy or the data processing practices of our Azure DevOps extension, or if you would like to request a data flow diagram describing how data moves between Azure DevOps, the Extension, our backend, and our subprocessors, please contact us at support@documentero.com.
We may update this Privacy Policy from time to time to reflect changes in our practices (including when the Extension leaves Preview, when new regions or features become available, or when subprocessors change) or for other operational, legal, or regulatory reasons. Changes take effect when posted or on any later date stated in the updated Policy, subject to applicable law. The Last Updated date identifies the current published version.
Security & Data Protection Statement | End-User License Agreement | Support Policy