Privacy Policy
Last updated: August 2, 2026
This Privacy Policy explains how Deevopp ("we", "us" or "our") collects, uses, stores and protects personal data when you visit deevopp.com, use our contact forms, book a discovery call, or otherwise interact with us as a business prospect, customer, partner or supplier. It is designed for business-to-business (B2B) relationships and is aligned with the EU General Data Protection Regulation (GDPR) and the EU AI Act.
For our consumer mobile apps, please see the Mobile App Privacy Policy.
1. Data controller
The data controller responsible for your personal data is Deevopp, operating from the European Union. Our primary place of business is Riga, Latvia.
Contact email: hello@deevopp.com
Data protection contact: privacy@deevopp.com
We do not have a dedicated Data Protection Officer (DPO) because of the nature, scope and volume of our processing. The contact above handles all privacy and data-protection requests.
2. What personal data we collect
We collect only the personal data necessary for our B2B activities:
- Identity and contact data: your name, job title, company name, email address and phone number.
- Professional data: information you provide about your project, team, infrastructure, budget range or technical requirements.
- Communication data: emails, meeting notes, messages sent via contact forms or Calendly, and records of support or sales conversations.
- Technical data: IP address, browser type and version, device type, operating system, referral URL, and limited interaction data collected through cookies and analytics tools.
- Payment and billing data: when required, your company bank details or VAT number for invoicing. We do not store full credit-card data.
We do not collect special categories of personal data (such as health, biometric, racial or ethnic origin, political opinion, religion or trade-union membership) unless you explicitly provide them and we have a valid legal basis to process them.
3. Legal basis for processing
Under GDPR, we process personal data on the following legal bases:
- Legitimate interest: responding to your enquiries, sending relevant information about our services, securing our website, and preventing fraud.
- Consent: when you voluntarily subscribe to a newsletter, download a resource, or accept optional analytics cookies.
- Contractual necessity: when processing is required to prepare, negotiate or perform a contract with you or your company.
- Legal obligation: when we are required to comply with tax, accounting, or regulatory obligations.
4. How we use your personal data
We use personal data for the following purposes:
- Answering questions, providing quotes and scheduling discovery calls.
- Preparing, negotiating and delivering software development, AI deployment and consultancy services.
- Sending project updates, invoices, and contractual documents.
- Maintaining customer records and managing accounts.
- Improving our website, services, and customer experience through analytics and feedback.
- Complying with legal, tax, and regulatory obligations.
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
5. Cookies, analytics and advertising
We use first-party cookies and similar technologies for the following purposes:
- Website analytics: Google Analytics 4 and Google Tag Manager help us understand aggregated traffic patterns, anonymised IP addresses, and user journeys on our website. This data is used to improve content and navigation.
- Advertising, conversion tracking and remarketing: with your consent, we use advertising pixels and tags from platforms such as Google Ads, LinkedIn Campaign Manager and Meta Ads to measure the effectiveness of our campaigns, attribute conversions, and show relevant ads to previous visitors. We only share technical identifiers (such as cookie or pixel IDs) and limited interaction data; we do not upload contact lists or other personal data for advertising purposes without a separate legal basis.
Advertising and analytics storage are denied by default when you first visit the site. We display a cookie banner that lets you accept all cookies, accept analytics only, or reject all non-essential cookies. Your choice is stored in your browser and can be changed at any time by clearing cookies for deevopp.com or using the banner controls.
6. Data retention
We retain personal data only for as long as necessary for the purposes described above, or as required by law:
- Prospects and enquiries: up to 24 months after the last interaction, unless you request deletion earlier.
- Customers and contracts: for the duration of the contract plus the statutory limitation period applicable in Latvia (up to 10 years for tax and accounting records).
- Analytics data: up to 14 months in Google Analytics, after which it is automatically deleted or aggregated.
7. Data sharing and subprocessors
We do not sell personal data. We may share personal data with trusted third-party service providers (“subprocessors”) who help us operate our business and website, under written agreements that include GDPR safeguards:
| Subprocessor | Purpose | Location / Safeguard |
|---|---|---|
| Google Analytics / Google Tag Manager | Website analytics and tag management | USA / EU Standard Contractual Clauses |
| Advertising platforms (e.g. Google Ads, LinkedIn Campaign Manager, Meta Ads) | Conversion measurement, campaign attribution and remarketing with consent | USA / EU Standard Contractual Clauses |
| Calendly | Scheduling discovery calls | USA / EU Standard Contractual Clauses |
| Formspree | Contact form delivery | USA / EU Standard Contractual Clauses |
| GitLab | Project repositories and collaboration | EU / Data Processing Addendum |
We may also disclose personal data when required by law, court order, or to protect our rights, safety, or property.
8. International data transfers
Some of our subprocessors operate outside the European Economic Area (EEA). When we transfer personal data to these providers, we rely on the European Commission’s Standard Contractual Clauses (SCCs) or equivalent adequacy decisions, and we implement additional technical and organisational safeguards where appropriate.
9. Data security
We implement appropriate technical and organisational measures to protect personal data, including:
- Encrypted connections (TLS/SSL) for our website and email.
- Access controls and two-factor authentication for internal systems.
- Regular software updates and security patches.
- Confidentiality clauses in contracts with team members and subprocessors.
No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
10. Your rights under GDPR
Depending on your situation, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure of your personal data (“right to be forgotten”).
- Restrict or object to processing based on legitimate interests.
- Request data portability for data you provided under a contract or consent.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your local data protection authority, such as the Latvian Data State Inspectorate (DVI).
To exercise any of these rights, email us at privacy@deevopp.com. We will respond within one month of receiving your request, free of charge unless the request is manifestly unfounded or excessive.
11. Data Processing Agreement (DPA) for customers
When we provide software development or AI deployment services to your company and process personal data on your behalf, we act as a data processor. Our master service agreement or a separate DPA defines the subject matter, duration, nature and purpose of processing, the types of personal data, the categories of data subjects, and your obligations as the data controller. If you need a signed DPA, please contact us at hello@deevopp.com.
12. Children's privacy
Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or services. The latest version will always be available at this URL, with the “Last updated” date at the top of the page.
14. Contact us
For any questions about this Privacy Policy or how we handle personal data, please contact us at privacy@deevopp.com or hello@deevopp.com.