Its Loading...
Its Loading...
Your data rights under the General Data Protection Regulation
9
Data Subject Rights
30 Days
Response Time
100%
Encrypted
GDPR
Compliant
The General Data Protection Regulation (GDPR) is the EU regulation on data protection and privacy. It applies to all organizations processing personal data of individuals in the European Union.
Under GDPR, you have comprehensive rights regarding your personal data. We are committed to facilitating the exercise of these rights.
We work with carefully selected processors to help us provide our services. All processors are bound by GDPR-compliant Data Processing Agreements.
You have the right to obtain confirmation as to whether or not personal data concerning you is being processed, and access to that data.
Under GDPR Article 30, we maintain a record of all data processing activities. Here's a summary:
Purpose:
Understanding user behavior and improving website performance
Legal Basis:
Consent / Legitimate InterestData Types:
Retention Period:
26 months
Recipients:
Google Analytics, Internal analytics team
International Transfers:
EEA to USA (Standard Contractual Clauses)
Purpose:
Sending newsletters and product updates to subscribers
Legal Basis:
ConsentData Types:
Retention Period:
Until unsubscription + 30 days
Recipients:
Email service provider, Marketing team
International Transfers:
Within EEA
Purpose:
Providing personalized services and maintaining user accounts
Legal Basis:
Contract PerformanceData Types:
Retention Period:
Duration of account + 90 days after deletion
Recipients:
Internal operations team, Cloud hosting provider
International Transfers:
EEA to USA (Standard Contractual Clauses)
Purpose:
Responding to inquiries and providing technical support
Legal Basis:
Legitimate Interest / Contract PerformanceData Types:
Retention Period:
3 years from last interaction
Recipients:
Support team, CRM system
International Transfers:
Within EEA
Purpose:
Processing payments for premium features
Legal Basis:
Contract Performance / Legal ObligationData Types:
Retention Period:
7 years (legal requirement)
Recipients:
Payment processor, Accounting team
International Transfers:
Global (Payment processor compliance)
Purpose:
Protecting our services and users from security threats
Legal Basis:
Legitimate Interest / Legal ObligationData Types:
Retention Period:
12 months
Recipients:
Security team, Security service providers
International Transfers:
Within EEA
Under GDPR Article 6, we must have a lawful basis for processing your personal data. Here are the legal bases we rely on:
You have given clear, specific, informed, and unambiguous consent for us to process your personal data for a specific purpose.
Examples:
Your Rights:
Processing is necessary for the performance of a contract to which you are party, or to take steps at your request before entering into a contract.
Examples:
Your Rights:
Processing is necessary for compliance with a legal obligation to which we are subject.
Examples:
Your Rights:
Processing is necessary for our legitimate interests or those of a third party, except where such interests are overridden by your interests or fundamental rights.
Examples:
Balancing Test:
Your Rights:
Processing is necessary to protect the vital interests of you or another natural person.
Examples:
Note: We rarely rely on this basis and only in emergency situations.
Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.
Examples:
Note: This legal basis is not commonly used for our commercial services.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place.
We use the European Commission approved Standard Contractual Clauses for transfers to countries without adequacy decisions.
Details:
Used for:
Google (USA), Cloud hosting providers, Analytics services
We may transfer data to countries that the European Commission has deemed to provide adequate protection.
Details:
Applicable Countries:
UK, Switzerland, Canada, Japan, Israel, New Zealand
Internal rules adopted by multinational companies for transfers within their group.
Details:
We conduct assessments to ensure adequate protection for international transfers.
Process:
For any questions about GDPR compliance, to exercise your rights, or to submit a Data Subject Access Request (DSAR), please contact our DPO.
Email:
dpo@devtoolshub.comResponse Time:
Within 30 days
GDPR
Compliant
ISO 27001
Certified
SOC 2
Type II
Privacy Shield
Principles