PRIVACY POLICY
Version: 2.0.0 Effective Date: September 1, 2026 Last Updated: September 2026
1. INTRODUCTION
Devi Devs Technologies S.R.L. ("DeviDevs", "we", "us", "our"), a company incorporated under the laws of Romania, with registered office at Aleea Textiliștilor 7, Bl. MY12, Sc. 2, Et. 8, Ap. 63, Sector 3, București, CUI 48553919, is committed to protecting the privacy of all individuals whose personal data we process.
This Privacy Policy explains how we collect, use, store, and protect personal data in connection with:
- (A) our website(s) and online presence;
- (B) ClevMail ("Platform"), a SaaS email marketing and automation service.
This Privacy Policy is provided in compliance with:
- Regulation (EU) 2016/679 ("GDPR") — Art. 13 and 14
- Legea nr. 190/2018 (Romania — GDPR implementation)
- Legea nr. 506/2004 (Romania — electronic communications)
- Legea nr. 365/2002 (Romania — electronic commerce)
2. OUR DUAL ROLE
We process personal data in two distinct capacities:
2.1. DeviDevs as Data Controller
We act as Data Controller (GDPR Art. 4(7)) for the following data:
- Personal data of our Clients (agency clients who use the Platform) — account information, billing data, communication history
- Personal data of website visitors — collected through our website (contact forms, cookies, analytics)
- Personal data of our employees and contractors
For this data, we determine the purposes and means of processing, and this Privacy Policy describes our practices as Controller.
2.2. DeviDevs as Data Processor
We act as Data Processor (GDPR Art. 4(8)) for the following data:
- Personal data of our Clients' Subscribers — email addresses, names, tags, consent records, and engagement data stored and processed through the Platform on behalf of our Clients
For Subscriber data, our Client is the Data Controller. We process this data solely on the Client's instructions, as governed by the Data Processing Agreement (DPA). If you are a Subscriber of one of our Clients, please refer to that Client's privacy policy for information about how your data is processed.
3. DATA WE COLLECT AS CONTROLLER
3.1. Client Account Data
| Data Category | Examples | Legal Basis | Purpose |
|---|---|---|---|
| Identity data | Full name, company name, job title | Art. 6(1)(b) — contract performance | Account creation and management |
| Contact data | Email address, phone number, postal address | Art. 6(1)(b) — contract performance | Communication, billing, support |
| Billing data | Company fiscal details (CUI, J-number), bank account, invoicing address | Art. 6(1)(b) — contract performance; Art. 6(1)(c) — legal obligation | Invoicing, fiscal compliance |
| Authentication data | Email, hashed password (via Supabase Auth) | Art. 6(1)(b) — contract performance | Secure access to the Platform |
| Communication data | Support tickets, emails, feedback | Art. 6(1)(b) — contract performance; Art. 6(1)(f) — legitimate interest | Service delivery and improvement |
3.2. Website Visitor Data
| Data Category | Examples | Legal Basis | Purpose |
|---|---|---|---|
| Contact form data | Name, email, message | Art. 6(1)(a) — consent; Art. 6(1)(f) — legitimate interest | Responding to enquiries |
| Cookie data | See Cookie Policy | Art. 6(1)(a) — consent (non-essential); Art. 6(1)(f) — legitimate interest (essential) | Website functionality, analytics |
| Technical data | IP address, browser type, device, OS, referral URL | Art. 6(1)(f) — legitimate interest | Security, analytics, service improvement |
| Usage data | Pages visited, time on site, navigation patterns | Art. 6(1)(a) — consent (via analytics cookies) | Understanding user behaviour, improving service |
3.3. Platform Usage Data (Client Activity)
| Data Category | Examples | Legal Basis | Purpose |
|---|---|---|---|
| Activity logs | Actions performed on the Platform (campaign creation, subscriber imports, settings changes) | Art. 6(1)(b) — contract performance; Art. 6(1)(f) — legitimate interest | Service delivery, audit trail, security |
| Performance data | Email delivery rates, bounce rates, complaint rates | Art. 6(1)(b) — contract performance | Service delivery, compliance monitoring |
4. DATA WE PROCESS AS PROCESSOR (SUBSCRIBER DATA)
When our Clients use the Platform to manage their Subscribers, we process the following data on behalf of and under the instructions of our Clients:
| Data Category | Examples |
|---|---|
| Subscriber identity | Email address, first name, last name |
| Subscriber preferences | Tags, segments, subscription status |
| Consent records | Consent timestamp, consent method |
| Engagement data | Email delivery status, open timestamps, click timestamps, bounce information, unsubscribe events |
| Technical data | IP address at time of subscription (if collected by Client) |
Important: We process this data solely as instructed by our Clients. The legal basis, consent, and privacy notices for this processing are the responsibility of the Client (Data Controller). For details, please see our Data Processing Agreement.
5. HOW WE USE YOUR DATA (AS CONTROLLER)
We use personal data for the following purposes:
5.1. Service Provision (Art. 6(1)(b) — Contract Performance)
- Creating and managing your account
- Providing the Platform services as described in the Terms of Service
- Processing payments and issuing invoices
- Providing technical support and responding to enquiries
5.2. Legal Obligations (Art. 6(1)(c) — Legal Obligation)
- Fiscal and accounting compliance (Romanian fiscal law)
- Responding to lawful requests from authorities
- Maintaining records as required by law
5.3. Legitimate Interests (Art. 6(1)(f) — Legitimate Interest)
- Improving the Platform's functionality, performance, and security
- Detecting and preventing fraud, abuse, and security incidents
- Enforcing our Terms of Service and policies
- Aggregated analytics and reporting (no individual identification)
We balance our legitimate interests against your rights and freedoms before relying on this legal basis. You have the right to object to processing based on legitimate interest (see Section 8).
5.4. Consent (Art. 6(1)(a) — Consent)
- Sending you marketing communications about DeviDevs services (only with your explicit opt-in)
- Placing non-essential cookies on your device (see Cookie Policy)
You may withdraw your consent at any time (see Section 8).
6. DATA SHARING AND RECIPIENTS
6.1. Sub-processors
We share personal data with the following categories of Sub-processors to provide the Service:
| Category | Sub-processor(s) | Location | Transfer Mechanism |
|---|---|---|---|
| Database | Supabase, Inc. | EU (Frankfurt) | N/A (data in EU) |
| Backend hosting | Render Inc. | EU (Frankfurt) | N/A (data in EU) |
| Frontend hosting | Vercel Inc. | USA (Edge: global) | EU-US DPF + SCCs |
| Email delivery | Resend (Plus Five Five, Inc.) | USA (sending from the EU region; data stored in the USA) | EU-US DPF + SCCs |
| AI content | Anthropic, PBC | USA | SCCs |
| AI content | Google LLC (Gemini) | USA | EU-US DPF + SCCs |
| Email delivery (optional) | Plus Five Five, Inc. d/b/a Resend | USA | SCCs |
A complete list with details is available in Annex 3 of the Data Processing Agreement.
6.2. Other Recipients
We may also share personal data with:
- (a) Professional advisors — lawyers, accountants, auditors, under confidentiality obligations
- (b) Authorities — when required by law, regulation, or court order (e.g., ANSPDCP, ANAF, courts)
- (c) Business transfers — in connection with a merger, acquisition, or asset sale (with prior notice)
6.3. No Selling of Data
We do not sell, rent, or trade personal data to third parties for their marketing purposes.
7. INTERNATIONAL DATA TRANSFERS
7.1. Primary Storage
Your data is primarily stored in the European Union:
- Database: Supabase PostgreSQL in EU (Frankfurt, eu-central-1)
- Backend processing: Render in EU (Frankfurt)
7.2. Transfers Outside the EEA
Some of our Sub-processors are located in the United States. For these transfers, we rely on:
- (a) EU-US Data Privacy Framework (DPF) — for Sub-processors certified under the framework (adequacy decision of 10 July 2023)
- (b) Standard Contractual Clauses (SCCs) — adopted pursuant to Commission Implementing Decision (EU) 2021/914, as a supplementary or alternative safeguard
- (c) Transfer Impact Assessments (TIAs) — conducted for each transfer to assess adequacy of protection
7.3. Safeguards
We ensure that all transfers to third countries provide an adequate level of data protection through:
- contractual obligations (SCCs, DPAs);
- technical measures (encryption in transit and at rest);
- regular assessment of Sub-processor compliance.
8. YOUR RIGHTS
Under GDPR, you have the following rights regarding your personal data:
| Right | Description | Article |
|---|---|---|
| Right of access | Request a copy of your personal data and information about how it is processed | Art. 15 |
| Right to rectification | Request correction of inaccurate or incomplete personal data | Art. 16 |
| Right to erasure | Request deletion of your personal data ("right to be forgotten") | Art. 17 |
| Right to restriction | Request restriction of processing in certain circumstances | Art. 18 |
| Right to data portability | Receive your data in a structured, commonly used, machine-readable format | Art. 20 |
| Right to object | Object to processing based on legitimate interest or direct marketing | Art. 21 |
| Right to withdraw consent | Withdraw consent at any time (without affecting the lawfulness of prior processing) | Art. 7(3) |
| Right not to be subject to automated decision-making | Not be subject to decisions based solely on automated processing with legal or significant effects | Art. 22 |
| Right to lodge a complaint | Lodge a complaint with the Supervisory Authority | Art. 77 |
8.1. How to Exercise Your Rights
You may exercise your rights by:
- Email: privacy@devidevs-agency.com
- Post: Aleea Textiliștilor 7, Bl. MY12, Sc. 2, Et. 8, Ap. 63, Sector 3, București
- Platform: Using self-service tools for data export and deletion (for Platform account holders)
We will respond to your request within one (1) month of receipt. This period may be extended by two further months if the request is complex or numerous requests are received, in which case we will inform you within the first month (GDPR Art. 12(3)).
8.2. Verification
To protect your privacy, we may need to verify your identity before fulfilling your request. We will not charge a fee for exercising your rights, except in cases of manifestly unfounded or excessive requests (GDPR Art. 12(5)).
8.3. For Subscribers of Our Clients
If you are a Subscriber of one of our Clients and wish to exercise your rights regarding the data processed through the Platform:
- Please contact the Client (Data Controller) directly. They are responsible for responding to your request.
- If you contact us directly, we will redirect your request to the relevant Client.
- We will assist the Client in fulfilling your request as described in the DPA.
9. DATA RETENTION
We retain personal data only for as long as necessary for the purposes set out in this Privacy Policy:
| Data Category | Retention Period | Basis |
|---|---|---|
| Client account data | Duration of the account + 3 years | Contract performance + legal obligations (fiscal records) |
| Billing and invoice data | 5 years after the fiscal year | Legal obligation (Romanian fiscal law — Legea 82/1991, as amended by Legea 36/2023) |
| Contact form submissions | 12 months after resolution | Legitimate interest |
| Audit and security logs | 12 months | Legitimate interest (security) |
| Cookie consent records | 3 years | Legal obligation (proof of consent — GDPR Art. 7(1)) |
Subscriber data retention is governed by the DPA and the Client's instructions. Upon termination of the Service Agreement, Subscriber data is deleted within 30 days (or returned to the Client upon request).
10. DATA SECURITY
We implement appropriate technical and organisational measures to protect personal data, including:
- Encryption: TLS 1.2+ for data in transit; AES-256 for data at rest; Fernet encryption for sensitive credentials
- Access control: JWT-based authentication, Row Level Security (RLS) at database level, multi-tenant isolation with client_id scoping
- Infrastructure security: Database in EU (Frankfurt), automated backups, health monitoring
- Personnel: Confidentiality obligations, limited access on need-to-know basis
- Incident response: Documented breach detection and notification procedures
For a detailed description of our security measures, see Annex 2 of the Data Processing Agreement.
11. CHILDREN'S DATA
The Platform and our website are not directed at children. We do not knowingly collect personal data from children under the age of sixteen (16) (the default age of digital consent under GDPR Art. 8(1); Romania has not exercised the national derogation to lower this age).
If we become aware that we have collected personal data from a child under 16 without valid parental consent, we will take steps to delete that data promptly.
12. AUTOMATED DECISION-MAKING
12.1. The Platform uses automated processing for the following purposes:
- (a) Bounce management: Automatic deactivation of subscriber addresses that permanently bounce
- (b) Spam/abuse detection: Automated monitoring of complaint rates and sending patterns
- (c) AI content generation: Automated generation of newsletter content based on Client instructions
12.2. These automated processes:
- do not produce legal effects or similarly significant effects on data subjects;
- are subject to human oversight (Clients review generated content, manage subscribers);
- can be overridden by manual intervention.
12.3. We do not use profiling that produces legal or similarly significant effects on individuals.
12.4. In compliance with Regulation (EU) 2024/1689 ("EU AI Act"):
- (a) AI-generated content produced through the Platform is subject to human editorial review by the Client (Data Controller) before distribution to Subscribers;
- (b) DeviDevs maintains AI literacy programmes for personnel involved in operating AI systems, as required by Art. 4 of the EU AI Act;
- (c) where required by Art. 50 of the EU AI Act, AI-generated content is identified as such.
13. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated through:
- a notice on our website;
- email notification to registered Clients;
- at least thirty (30) days before the effective date.
We encourage you to review this Privacy Policy periodically.
14. CONTACT AND COMPLAINTS
14.1. Contact Us
For any questions about this Privacy Policy or how we process your personal data:
- Email: privacy@devidevs-agency.com
- Address: Aleea Textiliștilor 7, Bl. MY12, Sc. 2, Et. 8, Ap. 63, Sector 3, București
14.2. Data Protection Contact
As a micro-enterprise (fewer than 10 employees), DeviDevs is not required to appoint a Data Protection Officer (DPO) under GDPR Art. 37. For data protection inquiries, please contact:
- Email: privacy@devidevs-agency.com
14.3. Supervisory Authority
You have the right to lodge a complaint with the Romanian Data Protection Authority:
Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)
- Address: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, cod postal 010336, Bucharest, Romania
- Phone: +40.318.059.211
- Email: anspdcp@dataprotection.ro
- Website: https://www.dataprotection.ro
You also have the right to lodge a complaint with the supervisory authority in your EU Member State of habitual residence, place of work, or place of the alleged infringement (GDPR Art. 77).
15. LEGAL REFERENCES
- Regulation (EU) 2016/679 (GDPR) — Art. 6, 7, 12-22, 28, 32-34, 44-49, 77, 82
- Regulation (EU) 2024/1689 (EU AI Act) — Art. 4 (AI literacy), Art. 50 (transparency)
- Regulation (EU) 2023/2854 (Data Act) — Chapter VI (switching and data portability)
- Legea nr. 190/2018 (Romania) — GDPR implementation
- Legea nr. 506/2004 (Romania) — Art. 4, 12 (cookies, electronic communications)
- Legea nr. 365/2002 (Romania) — Electronic commerce
- Legea nr. 82/1991 (Romania), as amended by Legea nr. 36/2023 — Accounting law (data retention for fiscal records: 5 years)
- Directive 2002/58/EC (ePrivacy) — Art. 5(3), Art. 13
- Commission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
- EDPB Guidelines 05/2020 — Consent
- EDPB Guidelines 07/2020 — Controller and Processor concepts
Document ID: PP-v2.0.0 Classification: Public This document does NOT constitute legal advice and should be reviewed by a qualified legal professional before publication.