PRIVACY POLICY

Version: 2.0.0 Effective Date: September 1, 2026 Last Updated: September 2026


1. INTRODUCTION

Devi Devs Technologies S.R.L. ("DeviDevs", "we", "us", "our"), a company incorporated under the laws of Romania, with registered office at Aleea Textiliștilor 7, Bl. MY12, Sc. 2, Et. 8, Ap. 63, Sector 3, București, CUI 48553919, is committed to protecting the privacy of all individuals whose personal data we process.

This Privacy Policy explains how we collect, use, store, and protect personal data in connection with:

  • (A) our website(s) and online presence;
  • (B) ClevMail ("Platform"), a SaaS email marketing and automation service.

This Privacy Policy is provided in compliance with:

  • Regulation (EU) 2016/679 ("GDPR") — Art. 13 and 14
  • Legea nr. 190/2018 (Romania — GDPR implementation)
  • Legea nr. 506/2004 (Romania — electronic communications)
  • Legea nr. 365/2002 (Romania — electronic commerce)

2. OUR DUAL ROLE

We process personal data in two distinct capacities:

2.1. DeviDevs as Data Controller

We act as Data Controller (GDPR Art. 4(7)) for the following data:

  • Personal data of our Clients (agency clients who use the Platform) — account information, billing data, communication history
  • Personal data of website visitors — collected through our website (contact forms, cookies, analytics)
  • Personal data of our employees and contractors

For this data, we determine the purposes and means of processing, and this Privacy Policy describes our practices as Controller.

2.2. DeviDevs as Data Processor

We act as Data Processor (GDPR Art. 4(8)) for the following data:

  • Personal data of our Clients' Subscribers — email addresses, names, tags, consent records, and engagement data stored and processed through the Platform on behalf of our Clients

For Subscriber data, our Client is the Data Controller. We process this data solely on the Client's instructions, as governed by the Data Processing Agreement (DPA). If you are a Subscriber of one of our Clients, please refer to that Client's privacy policy for information about how your data is processed.


3. DATA WE COLLECT AS CONTROLLER

3.1. Client Account Data

Data CategoryExamplesLegal BasisPurpose
Identity dataFull name, company name, job titleArt. 6(1)(b) — contract performanceAccount creation and management
Contact dataEmail address, phone number, postal addressArt. 6(1)(b) — contract performanceCommunication, billing, support
Billing dataCompany fiscal details (CUI, J-number), bank account, invoicing addressArt. 6(1)(b) — contract performance; Art. 6(1)(c) — legal obligationInvoicing, fiscal compliance
Authentication dataEmail, hashed password (via Supabase Auth)Art. 6(1)(b) — contract performanceSecure access to the Platform
Communication dataSupport tickets, emails, feedbackArt. 6(1)(b) — contract performance; Art. 6(1)(f) — legitimate interestService delivery and improvement

3.2. Website Visitor Data

Data CategoryExamplesLegal BasisPurpose
Contact form dataName, email, messageArt. 6(1)(a) — consent; Art. 6(1)(f) — legitimate interestResponding to enquiries
Cookie dataSee Cookie PolicyArt. 6(1)(a) — consent (non-essential); Art. 6(1)(f) — legitimate interest (essential)Website functionality, analytics
Technical dataIP address, browser type, device, OS, referral URLArt. 6(1)(f) — legitimate interestSecurity, analytics, service improvement
Usage dataPages visited, time on site, navigation patternsArt. 6(1)(a) — consent (via analytics cookies)Understanding user behaviour, improving service

3.3. Platform Usage Data (Client Activity)

Data CategoryExamplesLegal BasisPurpose
Activity logsActions performed on the Platform (campaign creation, subscriber imports, settings changes)Art. 6(1)(b) — contract performance; Art. 6(1)(f) — legitimate interestService delivery, audit trail, security
Performance dataEmail delivery rates, bounce rates, complaint ratesArt. 6(1)(b) — contract performanceService delivery, compliance monitoring

4. DATA WE PROCESS AS PROCESSOR (SUBSCRIBER DATA)

When our Clients use the Platform to manage their Subscribers, we process the following data on behalf of and under the instructions of our Clients:

Data CategoryExamples
Subscriber identityEmail address, first name, last name
Subscriber preferencesTags, segments, subscription status
Consent recordsConsent timestamp, consent method
Engagement dataEmail delivery status, open timestamps, click timestamps, bounce information, unsubscribe events
Technical dataIP address at time of subscription (if collected by Client)

Important: We process this data solely as instructed by our Clients. The legal basis, consent, and privacy notices for this processing are the responsibility of the Client (Data Controller). For details, please see our Data Processing Agreement.


5. HOW WE USE YOUR DATA (AS CONTROLLER)

We use personal data for the following purposes:

5.1. Service Provision (Art. 6(1)(b) — Contract Performance)

  • Creating and managing your account
  • Providing the Platform services as described in the Terms of Service
  • Processing payments and issuing invoices
  • Providing technical support and responding to enquiries

5.2. Legal Obligations (Art. 6(1)(c) — Legal Obligation)

  • Fiscal and accounting compliance (Romanian fiscal law)
  • Responding to lawful requests from authorities
  • Maintaining records as required by law

5.3. Legitimate Interests (Art. 6(1)(f) — Legitimate Interest)

  • Improving the Platform's functionality, performance, and security
  • Detecting and preventing fraud, abuse, and security incidents
  • Enforcing our Terms of Service and policies
  • Aggregated analytics and reporting (no individual identification)

We balance our legitimate interests against your rights and freedoms before relying on this legal basis. You have the right to object to processing based on legitimate interest (see Section 8).

5.4. Consent (Art. 6(1)(a) — Consent)

  • Sending you marketing communications about DeviDevs services (only with your explicit opt-in)
  • Placing non-essential cookies on your device (see Cookie Policy)

You may withdraw your consent at any time (see Section 8).


6. DATA SHARING AND RECIPIENTS

6.1. Sub-processors

We share personal data with the following categories of Sub-processors to provide the Service:

CategorySub-processor(s)LocationTransfer Mechanism
DatabaseSupabase, Inc.EU (Frankfurt)N/A (data in EU)
Backend hostingRender Inc.EU (Frankfurt)N/A (data in EU)
Frontend hostingVercel Inc.USA (Edge: global)EU-US DPF + SCCs
Email deliveryResend (Plus Five Five, Inc.)USA (sending from the EU region; data stored in the USA)EU-US DPF + SCCs
AI contentAnthropic, PBCUSASCCs
AI contentGoogle LLC (Gemini)USAEU-US DPF + SCCs
Email delivery (optional)Plus Five Five, Inc. d/b/a ResendUSASCCs

A complete list with details is available in Annex 3 of the Data Processing Agreement.

6.2. Other Recipients

We may also share personal data with:

  • (a) Professional advisors — lawyers, accountants, auditors, under confidentiality obligations
  • (b) Authorities — when required by law, regulation, or court order (e.g., ANSPDCP, ANAF, courts)
  • (c) Business transfers — in connection with a merger, acquisition, or asset sale (with prior notice)

6.3. No Selling of Data

We do not sell, rent, or trade personal data to third parties for their marketing purposes.


7. INTERNATIONAL DATA TRANSFERS

7.1. Primary Storage

Your data is primarily stored in the European Union:

  • Database: Supabase PostgreSQL in EU (Frankfurt, eu-central-1)
  • Backend processing: Render in EU (Frankfurt)

7.2. Transfers Outside the EEA

Some of our Sub-processors are located in the United States. For these transfers, we rely on:

  • (a) EU-US Data Privacy Framework (DPF) — for Sub-processors certified under the framework (adequacy decision of 10 July 2023)
  • (b) Standard Contractual Clauses (SCCs) — adopted pursuant to Commission Implementing Decision (EU) 2021/914, as a supplementary or alternative safeguard
  • (c) Transfer Impact Assessments (TIAs) — conducted for each transfer to assess adequacy of protection

7.3. Safeguards

We ensure that all transfers to third countries provide an adequate level of data protection through:

  • contractual obligations (SCCs, DPAs);
  • technical measures (encryption in transit and at rest);
  • regular assessment of Sub-processor compliance.

8. YOUR RIGHTS

Under GDPR, you have the following rights regarding your personal data:

RightDescriptionArticle
Right of accessRequest a copy of your personal data and information about how it is processedArt. 15
Right to rectificationRequest correction of inaccurate or incomplete personal dataArt. 16
Right to erasureRequest deletion of your personal data ("right to be forgotten")Art. 17
Right to restrictionRequest restriction of processing in certain circumstancesArt. 18
Right to data portabilityReceive your data in a structured, commonly used, machine-readable formatArt. 20
Right to objectObject to processing based on legitimate interest or direct marketingArt. 21
Right to withdraw consentWithdraw consent at any time (without affecting the lawfulness of prior processing)Art. 7(3)
Right not to be subject to automated decision-makingNot be subject to decisions based solely on automated processing with legal or significant effectsArt. 22
Right to lodge a complaintLodge a complaint with the Supervisory AuthorityArt. 77

8.1. How to Exercise Your Rights

You may exercise your rights by:

  • Email: privacy@devidevs-agency.com
  • Post: Aleea Textiliștilor 7, Bl. MY12, Sc. 2, Et. 8, Ap. 63, Sector 3, București
  • Platform: Using self-service tools for data export and deletion (for Platform account holders)

We will respond to your request within one (1) month of receipt. This period may be extended by two further months if the request is complex or numerous requests are received, in which case we will inform you within the first month (GDPR Art. 12(3)).

8.2. Verification

To protect your privacy, we may need to verify your identity before fulfilling your request. We will not charge a fee for exercising your rights, except in cases of manifestly unfounded or excessive requests (GDPR Art. 12(5)).

8.3. For Subscribers of Our Clients

If you are a Subscriber of one of our Clients and wish to exercise your rights regarding the data processed through the Platform:

  • Please contact the Client (Data Controller) directly. They are responsible for responding to your request.
  • If you contact us directly, we will redirect your request to the relevant Client.
  • We will assist the Client in fulfilling your request as described in the DPA.

9. DATA RETENTION

We retain personal data only for as long as necessary for the purposes set out in this Privacy Policy:

Data CategoryRetention PeriodBasis
Client account dataDuration of the account + 3 yearsContract performance + legal obligations (fiscal records)
Billing and invoice data5 years after the fiscal yearLegal obligation (Romanian fiscal law — Legea 82/1991, as amended by Legea 36/2023)
Contact form submissions12 months after resolutionLegitimate interest
Audit and security logs12 monthsLegitimate interest (security)
Cookie consent records3 yearsLegal obligation (proof of consent — GDPR Art. 7(1))

Subscriber data retention is governed by the DPA and the Client's instructions. Upon termination of the Service Agreement, Subscriber data is deleted within 30 days (or returned to the Client upon request).


10. DATA SECURITY

We implement appropriate technical and organisational measures to protect personal data, including:

  • Encryption: TLS 1.2+ for data in transit; AES-256 for data at rest; Fernet encryption for sensitive credentials
  • Access control: JWT-based authentication, Row Level Security (RLS) at database level, multi-tenant isolation with client_id scoping
  • Infrastructure security: Database in EU (Frankfurt), automated backups, health monitoring
  • Personnel: Confidentiality obligations, limited access on need-to-know basis
  • Incident response: Documented breach detection and notification procedures

For a detailed description of our security measures, see Annex 2 of the Data Processing Agreement.


11. CHILDREN'S DATA

The Platform and our website are not directed at children. We do not knowingly collect personal data from children under the age of sixteen (16) (the default age of digital consent under GDPR Art. 8(1); Romania has not exercised the national derogation to lower this age).

If we become aware that we have collected personal data from a child under 16 without valid parental consent, we will take steps to delete that data promptly.


12. AUTOMATED DECISION-MAKING

12.1. The Platform uses automated processing for the following purposes:

  • (a) Bounce management: Automatic deactivation of subscriber addresses that permanently bounce
  • (b) Spam/abuse detection: Automated monitoring of complaint rates and sending patterns
  • (c) AI content generation: Automated generation of newsletter content based on Client instructions

12.2. These automated processes:

  • do not produce legal effects or similarly significant effects on data subjects;
  • are subject to human oversight (Clients review generated content, manage subscribers);
  • can be overridden by manual intervention.

12.3. We do not use profiling that produces legal or similarly significant effects on individuals.

12.4. In compliance with Regulation (EU) 2024/1689 ("EU AI Act"):

  • (a) AI-generated content produced through the Platform is subject to human editorial review by the Client (Data Controller) before distribution to Subscribers;
  • (b) DeviDevs maintains AI literacy programmes for personnel involved in operating AI systems, as required by Art. 4 of the EU AI Act;
  • (c) where required by Art. 50 of the EU AI Act, AI-generated content is identified as such.

13. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated through:

  • a notice on our website;
  • email notification to registered Clients;
  • at least thirty (30) days before the effective date.

We encourage you to review this Privacy Policy periodically.


14. CONTACT AND COMPLAINTS

14.1. Contact Us

For any questions about this Privacy Policy or how we process your personal data:

14.2. Data Protection Contact

As a micro-enterprise (fewer than 10 employees), DeviDevs is not required to appoint a Data Protection Officer (DPO) under GDPR Art. 37. For data protection inquiries, please contact:

14.3. Supervisory Authority

You have the right to lodge a complaint with the Romanian Data Protection Authority:

Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)

You also have the right to lodge a complaint with the supervisory authority in your EU Member State of habitual residence, place of work, or place of the alleged infringement (GDPR Art. 77).


15. LEGAL REFERENCES

  • Regulation (EU) 2016/679 (GDPR) — Art. 6, 7, 12-22, 28, 32-34, 44-49, 77, 82
  • Regulation (EU) 2024/1689 (EU AI Act) — Art. 4 (AI literacy), Art. 50 (transparency)
  • Regulation (EU) 2023/2854 (Data Act) — Chapter VI (switching and data portability)
  • Legea nr. 190/2018 (Romania) — GDPR implementation
  • Legea nr. 506/2004 (Romania) — Art. 4, 12 (cookies, electronic communications)
  • Legea nr. 365/2002 (Romania) — Electronic commerce
  • Legea nr. 82/1991 (Romania), as amended by Legea nr. 36/2023 — Accounting law (data retention for fiscal records: 5 years)
  • Directive 2002/58/EC (ePrivacy) — Art. 5(3), Art. 13
  • Commission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
  • EDPB Guidelines 05/2020 — Consent
  • EDPB Guidelines 07/2020 — Controller and Processor concepts

Document ID: PP-v2.0.0 Classification: Public This document does NOT constitute legal advice and should be reviewed by a qualified legal professional before publication.