1. Who we are
devkyn is the controller for the website, sales, and account data described in this policy. You can contact us at contact@devkyn.com.
When we process personal data inside a client's product or systems only on that client's instructions, the client may be the controller and devkyn may act as its processor. Those responsibilities are addressed in the applicable service agreement or data-processing terms.
2. Data we collect
- Enquiries and sales: your name, email, company or website, project details, stack, preferred timing, referral source, and anything else you choose to send.
- Scheduling: the appointment information you submit through the embedded Google booking flow.
- Accounts and access: name, email, organization membership, role, login and verification timestamps, and security/session information.
- Client workspace: requests, descriptions, comments, attachments, priorities, status history, review decisions, and related activity.
- Service and billing: proposal, contract, invoice, payment, support, and delivery records needed to run the engagement and meet legal obligations.
- Technical data: IP address, browser and device information, timestamps, request logs, security events, diagnostics, and error reports.
- Analytics, if accepted: page views, interactions, approximate location, referrer, campaign parameters, and similar usage information loaded through Google Tag Manager.
Please do not send special-category, regulated, production customer, or other highly sensitive data through the contact form or a request unless we have agreed the handling requirements in writing first.
3. Why we use personal data
- To respond to enquiries and take steps you request before an engagement, such as discussing scope and preparing a proposal.
- To create accounts, authenticate users, provide the portal, deliver services, invoice, and support an engagement under our contract.
- To secure, debug, maintain, and improve the site and service based on our legitimate interests in operating them safely and reliably.
- To meet tax, accounting, regulatory, dispute, and other legal obligations.
- To measure website use through non-essential analytics only after you have given consent. You can refuse or withdraw that choice.
We do not sell personal data. We do not use portal or enquiry content to make solely automated decisions that produce legal or similarly significant effects about you.
6. International transfers
Some providers may process data outside your country or the European Economic Area. Where data-protection law requires it, we use a recognized transfer mechanism, such as an adequacy decision or contractual safeguards, and assess additional protections appropriate to the data and service.
7. How long we keep data
We keep personal data only for as long as needed for the purpose it was collected, including the duration of an account or engagement, a reasonable period for follow-up, security and dispute records, and any tax, accounting, or other mandatory retention period. The exact period depends on the record, our relationship, and applicable law.
When data is no longer required, we delete or anonymize it, subject to backups and records we must retain. You may ask about the period for a particular category at the contact address above.
8. Security
We use technical and organizational measures intended to protect data, including access controls, scoped roles, authenticated sessions, tenant separation in the client portal, audit records, and encrypted transport where supported. No system is risk-free, so please report a suspected security issue promptly to contact@devkyn.com.
9. Your rights
Depending on where you live and the legal basis involved, you may have rights to be informed, access, correct, erase, restrict, object, or receive a portable copy of your personal data, and to withdraw consent without affecting earlier lawful processing.
Email contact@devkyn.com to exercise a right. We may need to verify your identity and may retain information where an exception or legal duty applies. You may also complain to your local data-protection authority; in Portugal, this is the Comissão Nacional de Proteção de Dados.
10. Children
The site and services are for businesses and are not directed to children. Do not submit a child's personal data unless an engagement specifically requires it and appropriate terms and safeguards have been agreed first.
11. Changes to this policy
We may update this policy when the site, providers, or legal requirements change. The date at the top shows the latest revision. Material changes will be highlighted where reasonably practical.