Privacy Policy

    Your data, your rights, our commitment.

    Last updated: March 27, 2026Effective immediately

    Our Privacy Commitment

    We collect only what we need, we never sell your data, and we give you full control over your information. Transparency and trust are at the core of everything we do.

    1.Introduction

    This Privacy Policy describes how DevsDoCode ("Company", "we", "us", or "our") collects, uses, stores, and protects the personal information of users ("you" or "your") who visit our website, use our services, or interact with us in any capacity.

    • We are committed to protecting your privacy and handling your data with transparency and integrity.
    • This policy applies to all data collected through our website, contact forms, service engagements, dashboard interactions, and any other communications with our company.
    • By using our Services, you acknowledge that you have read and understood this Privacy Policy.
    • If you do not agree with our data practices, please discontinue use of our Services.

    2.Information We Collect

    Information You Provide Directly

    • Name, email address, phone/WhatsApp/Telegram number submitted through contact forms or during onboarding.
    • Company name, job title, website URL, and business details relevant to service delivery.
    • Social media account credentials (Instagram only, when required for ad management).
    • Payment information processed through secure third-party payment gateways.
    • Communication content — messages sent through our contact forms, emails, or chat.

    Automatically Collected Data

    • IP address, browser type and version, operating system, and device identifiers.
    • Referring URLs, pages visited, time spent on pages, and interaction patterns.
    • Geographic location data derived from IP address (city/country level only).
    • Session duration, click patterns, and navigation flow across our website.

    Third-Party Data

    • Authentication data from sign-in providers when you choose social login.
    • Analytics data from privacy-respecting providers used to improve our services.
    • Information from professional networks if you connect them to your account.

    3.Lawful Basis for Processing

    We process your personal data only when we have a valid legal basis to do so:

    • Contract — when processing is necessary to deliver services you have requested.
    • Consent — for marketing communications and optional features you opt into.
    • Legitimate interest — to improve our services, prevent fraud, and ensure security.
    • Legal obligation — to comply with applicable laws, tax requirements, and regulations.

    4.How We Use Your Data

    We use your information to deliver the services you request and continually improve them.

    • Provision and maintenance of our AI infrastructure, freelancing, and mentorship services.
    • Account creation, authentication, and ongoing account administration.
    • Processing payments, billing, and managing subscriptions or project invoices.
    • Responding to inquiries, providing technical support, and resolving disputes.
    • Sending transactional emails, security notifications, and important service updates.
    • Analyzing usage patterns to enhance product features, performance, and reliability.
    • Detecting and preventing fraud, abuse, and unauthorized access to accounts.

    5.Data Sharing & Third Parties

    We do not sell your personal information. We share it only in the limited circumstances below, and only with vetted partners bound by strict confidentiality terms.

    • Service providers who help us operate the platform — hosting, payment processing, email delivery, analytics, and customer support.
    • Professional advisors such as legal counsel, auditors, and accountants under confidentiality.
    • Authorities when required by valid legal process, court order, or governmental request.
    • Successors in interest in the event of a merger, acquisition, or business transfer (you will be notified).

    6.Social Media Credential Handling

    For our promotion and brand management services, we may handle Instagram account credentials with extraordinary care.

    • Stored using bank-grade encryption (AES-256) in secure, access-controlled vaults.
    • Used solely for the agreed promotional and ad management activities.
    • Never shared with third parties or used for unauthorized purposes.
    • Permanently deleted within 30 days of project completion or upon written request.
    • We strongly recommend enabling two-factor authentication and rotating credentials post-engagement.

    7.AI Platform Data Usage

    When you use our AI infrastructure, the following principles apply to your data:

    • API requests and prompts are processed to deliver responses, not used to train shared models without explicit consent.
    • Uploaded files are encrypted in transit and at rest, accessible only by you and authorized account members.
    • Usage statistics are anonymized and aggregated for capacity planning and abuse prevention.
    • Fine-tuning and custom models trained on your data remain your property and are not reused for other customers.

    8.Data Retention

    We retain personal data only as long as needed for the purposes described in this policy.

    • Account data — for the lifetime of your account plus 90 days after deletion.
    • Billing and tax records — for 7 years to comply with financial regulations.
    • Support communications — for 24 months from last contact.
    • Marketing data — until you withdraw consent or 24 months of inactivity, whichever comes first.
    • Backup copies — purged on a rolling 35-day schedule.

    9.Data Security

    Protecting your data is foundational to our work, not an afterthought.

    • TLS 1.3 encryption for all data in transit and AES-256 for data at rest.
    • Role-based access controls with the principle of least privilege for all internal systems.
    • Continuous monitoring, intrusion detection, and quarterly third-party security audits.
    • Mandatory two-factor authentication for all team members with access to production systems.
    • Documented incident response plan with notification within 72 hours of confirmed breach.

    10.Cookies & Tracking

    We use cookies and similar technologies to operate our site and improve your experience.

    • Essential cookies — required for authentication, security, and core site functionality.
    • Functional cookies — remember your preferences such as theme and language.
    • Analytics cookies — help us understand how the site is used so we can improve it.
    • You can manage cookie preferences through your browser settings or our cookie banner.

    11.Analytics & Performance

    We use privacy-respecting analytics to understand product usage and improve quality.

    • Aggregated metrics on page views, feature usage, and conversion paths.
    • Performance telemetry such as load times, error rates, and API latency.
    • All analytics IDs are hashed and IP addresses are truncated before storage where feasible.

    12.International Data Transfers

    We operate globally and may transfer your data across borders to deliver our services.

    • Transfers to countries outside your region are protected by Standard Contractual Clauses.
    • We assess each transfer to confirm an adequate level of data protection.
    • EU/UK residents — your data is protected under GDPR and UK GDPR equivalents.

    13.Your Privacy Rights

    Depending on your jurisdiction, you have several rights over your personal data.

    • Access — request a copy of the personal data we hold about you.
    • Rectification — correct inaccurate or incomplete information.
    • Erasure — ask us to delete your data, subject to legal retention requirements.
    • Restriction — request that we limit how we process your data.
    • Portability — receive your data in a structured, machine-readable format.
    • Objection — object to processing based on legitimate interest or direct marketing.
    • Withdraw consent — at any time, where processing is based on consent.

    14.Children's Privacy

    Our services are not intended for children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with information, please contact us and we will promptly delete it.

    15.Breach Notification

    In the unlikely event of a data breach affecting your personal information, we will notify you and the relevant authorities within 72 hours of confirming the breach. Notifications will detail the nature of the incident, the data involved, and the steps we are taking to mitigate harm.

    16.California Privacy (CCPA/CPRA)

    California residents have additional rights under the California Consumer Privacy Act and CPRA.

    • The right to know what personal information is collected, used, shared, or sold.
    • The right to delete personal information held by us, subject to legal exceptions.
    • The right to opt out of the sale or sharing of personal information.
    • The right to non-discrimination for exercising any CCPA right.

    17.Policy Changes

    We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via email or a prominent notice on our website at least 30 days before they take effect.

    18.Contact & Data Protection Officer

    For privacy questions, requests, or concerns, reach our Data Protection Officer:

    • Privacy team — privacy@devsdocode.com
    • General support — support@devsdocode.com
    • Response time — within 48 hours for most requests.
    • You also have the right to lodge a complaint with your local data protection authority.

    This document forms part of the agreement between you and DevsDoCode. We may update it from time to time; the “Last updated” date above reflects the most recent revision. Continued use of our services after changes constitutes acceptance of the revised terms.