Privacy Policy

Last updated: August 2, 2026

This Privacy Policy explains how Deevopp ("we", "us" or "our") collects, uses, stores and protects personal data when you visit deevopp.com, use our contact forms, book a discovery call, or otherwise interact with us as a business prospect, customer, partner or supplier. It is designed for business-to-business (B2B) relationships and is aligned with the EU General Data Protection Regulation (GDPR) and the EU AI Act.

For our consumer mobile apps, please see the Mobile App Privacy Policy.

1. Data controller

The data controller responsible for your personal data is Deevopp, operating from the European Union. Our primary place of business is Riga, Latvia.

Contact email: hello@deevopp.com
Data protection contact: privacy@deevopp.com

We do not have a dedicated Data Protection Officer (DPO) because of the nature, scope and volume of our processing. The contact above handles all privacy and data-protection requests.

2. What personal data we collect

We collect only the personal data necessary for our B2B activities:

We do not collect special categories of personal data (such as health, biometric, racial or ethnic origin, political opinion, religion or trade-union membership) unless you explicitly provide them and we have a valid legal basis to process them.

3. Legal basis for processing

Under GDPR, we process personal data on the following legal bases:

4. How we use your personal data

We use personal data for the following purposes:

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

5. Cookies, analytics and advertising

We use first-party cookies and similar technologies for the following purposes:

Advertising and analytics storage are denied by default when you first visit the site. We display a cookie banner that lets you accept all cookies, accept analytics only, or reject all non-essential cookies. Your choice is stored in your browser and can be changed at any time by clearing cookies for deevopp.com or using the banner controls.

6. Data retention

We retain personal data only for as long as necessary for the purposes described above, or as required by law:

7. Data sharing and subprocessors

We do not sell personal data. We may share personal data with trusted third-party service providers (“subprocessors”) who help us operate our business and website, under written agreements that include GDPR safeguards:

Subprocessor Purpose Location / Safeguard
Google Analytics / Google Tag Manager Website analytics and tag management USA / EU Standard Contractual Clauses
Advertising platforms (e.g. Google Ads, LinkedIn Campaign Manager, Meta Ads) Conversion measurement, campaign attribution and remarketing with consent USA / EU Standard Contractual Clauses
Calendly Scheduling discovery calls USA / EU Standard Contractual Clauses
Formspree Contact form delivery USA / EU Standard Contractual Clauses
GitLab Project repositories and collaboration EU / Data Processing Addendum

We may also disclose personal data when required by law, court order, or to protect our rights, safety, or property.

8. International data transfers

Some of our subprocessors operate outside the European Economic Area (EEA). When we transfer personal data to these providers, we rely on the European Commission’s Standard Contractual Clauses (SCCs) or equivalent adequacy decisions, and we implement additional technical and organisational safeguards where appropriate.

9. Data security

We implement appropriate technical and organisational measures to protect personal data, including:

No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

10. Your rights under GDPR

Depending on your situation, you have the right to:

To exercise any of these rights, email us at privacy@deevopp.com. We will respond within one month of receiving your request, free of charge unless the request is manifestly unfounded or excessive.

11. Data Processing Agreement (DPA) for customers

When we provide software development or AI deployment services to your company and process personal data on your behalf, we act as a data processor. Our master service agreement or a separate DPA defines the subject matter, duration, nature and purpose of processing, the types of personal data, the categories of data subjects, and your obligations as the data controller. If you need a signed DPA, please contact us at hello@deevopp.com.

12. Children's privacy

Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or services. The latest version will always be available at this URL, with the “Last updated” date at the top of the page.

14. Contact us

For any questions about this Privacy Policy or how we handle personal data, please contact us at privacy@deevopp.com or hello@deevopp.com.