Cloud

Privacy notice

Version 2026-10-06, effective 2026-10-06

Draft for review. This document is not yet in effect.

Who we are and how to contact us

Dvelopin LLC is a single-member limited liability company based in Arizona, USA. [to be confirmed]

Dvelopin is the controller of the personal data in its own customer accounts: the people who sign up with us, our customers' billing contacts, and the invoices and payments for our service.

If you use the portal as a member of one of our customers' organizations, that organization decides how your data is used and is its controller. Dvelopin runs the portal for it as its processor, and that organization's privacy notice applies to you.

  • Privacy contact: [to be confirmed]
  • Postal address: [to be confirmed]
  • We have not appointed an EU representative (GDPR Art. 27) or a data protection officer (GDPR Art. 37). We will name them here if we appoint them. [to be confirmed]

What personal data we collect and where we get it

  • Email address, first name, last name, phone number, company name, US two-letter tax state: you, when you register or edit My account
  • Organization memberships and roles: you, or the organization admin who adds you
  • Invited email address: the organization admin who invites you
  • Billing contact email: your organization's owner or billing admin
  • Sign-in security settings: passkey device names, authenticator app enrollment, recovery codes (stored as hashes): you
  • Display preferences: you
  • Email address, IP address, user agent at each sign-in: your browser, when you sign in
  • IP address, user agent per session: your browser
  • IP address, user agent per API token: the app or script that uses the API
  • IP address, user agent, event detail for refused requests: your browser
  • Request details and IP address, only when request capture is switched on (off by default): your browser
  • IP address and email address as rate-limit keys: your browser
  • Names, email addresses and IP addresses in the staff action log: our staff's actions on accounts
  • Emails we send you: to, cc, from, subject: our email system
  • Delivery, bounce and complaint notices from Amazon SES, which contain mailbox addresses: Amazon Web Services
  • Addresses we must not email again after a bounce, a complaint or a staff decision: Amazon Web Services, or our staff
  • Stripe customer ID: Stripe
  • Saved payment method: card brand, last four digits, expiry month and year, wallet type: Stripe. We never receive or store full card numbers
  • Raw Stripe event messages about payments and customers: Stripe
  • Invoices, payments and subscriptions: our billing system

Why we process it and the lawful basis

No processing on the portal relies on your consent.

  • Run your account and your organization's service on the portal: performance of a contract (GDPR Art. 6(1)(b))
  • Send service emails (verification, password reset, invitations, security notices, receipts and payment notices): performance of a contract (Art. 6(1)(b))
  • Billing and payment processing (Stripe): performance of a contract (Art. 6(1)(b))
  • Security: sign-in logs, rate limits, bot checks, abuse prevention, incident response: legitimate interests (Art. 6(1)(f)): "ensuring network and information security" (Recital 49)
  • Audit trail of actions on accounts and records, kept for security and legal claims: legitimate interests (Art. 6(1)(f), Recital 49) [to be confirmed]
  • Keep billing records after an account or organization closes: legal obligation (Art. 6(1)(c)) or legitimate interests (Art. 6(1)(f)) in handling refunds, disputes and other legal claims [to be confirmed]
  • Record which version of this notice and our terms you were shown: [to be confirmed]
  • Track and answer your privacy requests [ships with G5]: [to be confirmed]
  • Keep a suppression list so we never email a bounced or complaining address again: [to be confirmed]

Who we share it with: service providers (processors)

  • Amazon Web Services (Lightsail, S3, SES): hosting, file storage, backups and email. [to be confirmed]
  • Stripe: payment processing. Stripe is also an independent controller for fraud prevention, anti-money-laundering, know-your-customer checks and analytics, under its own privacy policy.
  • Telnyx or Twilio: text messages, only if SMS is switched on for an organization and that provider is chosen. Each is also an independent controller for account and usage data (Telnyx: including message logs; Twilio: including message content for limited purposes). [to be confirmed]

Full sub-processor list

Who we share it with: independent controllers

They decide how they use the data; you can contact them under their own notices.

  • Stripe (fraud, anti-money-laundering, know-your-customer, analytics)
  • Telnyx (account and usage data, including message logs), when used
  • Twilio (account, usage, and message content for limited purposes), when used
  • Google Pay, only if you choose it when adding a payment method on the billing page (inside Stripe's Express Checkout, under Google's own API terms)
  • Apple Pay is offered in the same Express Checkout. [to be confirmed]
  • Let's Encrypt (issues the security certificates for the portal's web addresses; acts for its own purposes)

Providers we plan to add

Planned, not used today (add only once built): Anthropic for AI features [ships with AI1]; Square and PayPal for payments [ships with I1].

Where your data is stored, and transfers outside the EU

Dvelopin is a US company. Our servers, file storage, email sending and backups are all with Amazon Web Services in the United States (region us-east-2). Stripe says it may store and process data "in any country where we do business".

If you are in the EU, the UK or Switzerland, your data therefore goes to the United States. The safeguards in each vendor's own terms are:

Dvelopin itself is not certified under the DPF today. The safeguard for data you give Dvelopin directly, and whether the DPF covers these onward transfers, is [to be confirmed]. Where SCCs are used, a transfer impact assessment is done. To get a copy of the safeguards: [to be confirmed]

We do not run an EU-region instance today. One could keep hosting, storage, email and SMS in the EU (AWS) if a customer needs it, but transfers to Stripe would remain.

  • Amazon Web Services: Standard Contractual Clauses (SCCs) Modules 2 and 3, UK Addendum, EU-US Data Privacy Framework (DPF)
  • Stripe: DPF first, then SCC Modules 1 to 3, UK Addendum
  • Telnyx: SCC Modules 1 to 3, UK Addendum, DPF
  • Twilio: DPF, Binding Corporate Rules, SCC Modules 1 to 3, UK Addendum
  • Google Pay, Let's Encrypt: not stated in their terms

How long we keep it today

  • Account profile, memberships, sign-in security settings: while your account is open
  • Sign-in log: 365 days
  • Security events: 180 days
  • Email log: 400 days
  • Amazon SES delivery notices: message content removed after 30 days; record deleted after 90 days
  • Request capture log (off by default): 90 days
  • Rate-limit keys: 24 hours
  • Session records: deleted when the session ends or after 15 minutes without activity
  • Expired sessions: deleted once expired
  • API tokens: deleted 7 days after they expire
  • Billing records: kept; the period is [to be confirmed]
  • Staff action log, email suppression list, invitations, Stripe event messages: not deleted today; see the planned schedule
  • Backups: daily; database backups expire after 7 days and are permanently deleted about 7 days later (about 14 days in all) [to be confirmed]

Planned retention schedule [ships with G7 unless marked otherwise]

  • Your account after you delete it: personal details removed or anonymized; the row stays, with no name, email, phone or company [ships with G3]
  • A closed organization's data: destroyed after the closure grace period, except billing records [ships with G3]
  • Billing records: kept for the period counsel sets, then destroyed [to be confirmed]
  • Audit trail: 730 days by default, never less than 365
  • Personal data export: never stored: it is built when you download it [ships with G2]
  • Organization exports: deleted after 7 days [ships with G2]
  • Invitations: deleted 90 days after they expire
  • Staff action log: IP addresses and names or emails cleared after 365 days
  • Stripe event messages: content cleared after 90 days; the record and its IDs are kept
  • Email suppression list: kept so we never email that address again, stored as a keyed hash instead of the address
  • Backups: an age-out date recorded for each; if a backup taken before you deleted your account is ever restored, your deletion is applied again [ships with G3]

Your rights

Requests are free, unless they are clearly unfounded or excessive.

  • Access: get a copy of the personal data we hold about you
  • Rectification: correct inaccurate data
  • Erasure: have your data deleted
  • Restriction: ask us to limit how we use your data, for example while a dispute is open
  • Portability: receive the data you gave us in a structured, machine-readable format
  • Objection: object to processing based on legitimate interests
  • Withdraw consent: no processing on the portal relies on consent today. If we add a consent-based feature, you can withdraw consent at any time
  • Complain to a supervisory authority: you can complain to a data protection authority

How to use your rights

  • Correct your details: edit your name, company and phone number in My account at any time
  • Change your email address: in My account. We send a confirmation link to the new address and a notice to the old one, and the new address works only once confirmed. Profile changes are logged [ships with G4]
  • Download your data: in My account, as JSON with a CSV file per table. You confirm your identity again before the download [ships with G2]
  • Delete your account: in the danger zone of My account. You confirm your identity, then a 14-day grace period starts, and the email we send has a link to cancel. After that your personal data is erased. If you are the last owner of an organization, you must first hand ownership to someone else or close the organization. Billing records are kept (see above) [ships with G3]
  • Everything else (access without an account, restriction, objection, or any other request): contact [to be confirmed]. We confirm your identity through your account sign-in or a confirmation code, not copies of ID documents. We answer within one month (GDPR) or 45 days (US state laws), whichever is earlier. We may extend by two further months (GDPR) or once by 45 days (US state laws), and if so we tell you within the first period [request tracking ships with G5]

Cookies and device access

We set one cookie of our own: a session cookie (PHPSESSID) on your first visit to any portal page. It has no expiry date and ends when you close your browser. It is Secure, HttpOnly and SameSite=Lax. It is needed to keep you signed in and to protect forms. Your session also ends on our side after 15 minutes without activity.

On the billing page only, Stripe.js sets cookies (__stripe_mid and __stripe_sid; see the full cookie list) to prevent fraud. Google Pay and Apple Pay also load there if available. Whether Stripe's fraud cookies are strictly necessary is [to be confirmed].

We do not use analytics or advertising cookies, or any other tracking.

Full cookie list

Automated decision-making

We do not make decisions about you by automated means that have legal or similarly significant effects (GDPR Art. 22). If we add AI features, we will review this and update this notice first.

US state privacy rights

Some US states (including California, Colorado, Texas and Virginia) give residents the right to know, delete and correct their personal data, and to opt out of its sale or sharing. These laws apply to businesses above certain size thresholds. [to be confirmed] The tools above are available to every user.

  • Sale or sharing: we do not sell your personal data or share it for advertising, so there is nothing to opt out of. For the same reason, a Global Privacy Control signal changes nothing here.
  • How to ask: use the tools above or contact [to be confirmed]. We answer within 45 days, and may extend once by 45 days with notice.
  • Appeal: if we turn down your request, you can appeal by [to be confirmed]. Virginia, Colorado and Texas residents have a right to appeal.

Changes to this notice

We update this notice when our practices change. Each version has a number and a date. When you register, accept an invitation or finish setting up your account, we record which version you were shown.