Legal
Privacy policy
Last updated 8 October 2026
This policy explains what personal data Devvion Inc. collects through devvion.com, why, and the rights you have over it. It applies to visitors, people who contact us, and prospective clients. It does not cover TAPYA (tapya.ai), which has its own policy.
Who is responsible
The controller of your personal data is Devvion Inc., a Delaware corporation, 1111B S Governors Ave #47523, Dover, DE 19904-6903, United States. Our team operates from Switzerland and Portugal.
Contact for anything in this policy: info@devvion.com. Data protection contact: [DPO_CONTACT]. EU representative or establishment for GDPR purposes: [EU_REPRESENTATIVE].
What we collect
| Category | Examples | Source |
|---|---|---|
| Contact details | Name, work email, company, company size | You, through the contact form or by email |
| Message content | What you tell us about your work and your process | You |
| Technical data | IP address, browser type, pages requested, timestamps | Your browser, through our hosting provider's server logs |
| Consent record | Your cookie choices and when you made them | The cookie banner, stored in your browser |
We do not collect special categories of data, and we ask you not to send them. The site has no analytics or advertising scripts today. If that changes, they will only run after you opt in.
Why we use it, and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Reply to your enquiry and discuss a possible engagement | Contact details, message content | Steps at your request before a contract (Art. 6(1)(b)); your consent for the form (Art. 6(1)(a)) |
| Keep the site secure and working, prevent abuse of the form | Technical data | Our legitimate interest in running a secure website (Art. 6(1)(f)) |
| Remember your cookie choices | Consent record | Legal obligation to record consent (Art. 6(1)(c)) and legitimate interest |
| Keep business records if we work together | Contact details, correspondence | Contract (Art. 6(1)(b)) and legal obligations (Art. 6(1)(c)) |
We do not sell personal data, share it for cross-context behavioral advertising, or use it for automated decisions that have legal or similarly significant effects on you.
International transfers
Devvion Inc. and some of our providers are in the United States. Where personal data from the European Economic Area, the UK or Switzerland is transferred there, we rely on the EU-U.S. and Swiss-U.S. Data Privacy Frameworks where the recipient is certified, or on the European Commission's Standard Contractual Clauses. You can ask us for a copy of the safeguards.
If you contact us from a country in the Middle East or North Africa, your data is handled under this policy and, where it applies, your local data-protection law (for example, the UAE PDPL or Saudi Arabia's PDPL).
How long we keep it
| Data | Retention |
|---|---|
| Enquiries that don't lead to work | 24 months from our last exchange, then deleted |
| Client correspondence and records | For the engagement, then as long as tax and corporate law require (usually up to 7 years) |
| Server logs | Up to 30 days, as set by our hosting provider |
| Cookie consent record | 6 months, then you are asked again |
Your rights
Depending on where you live, you can:
- Access the personal data we hold about you and get a copy.
- Correct data that is wrong or incomplete.
- Ask us to delete it.
- Restrict or object to how we use it, including for any marketing.
- Receive it in a portable format.
- Withdraw consent at any time, without affecting what we did before.
- Swiss residents have the same rights under the revised Federal Act on Data Protection (nFADP).
- California residents: know, delete and correct personal information, and not be discriminated against for using these rights. We do not sell or share personal information as the CCPA defines those terms.
Email info@devvion.com to use any of these rights. We reply within one month (45 days under the CCPA) and may need to confirm your identity first. You can also complain to a supervisory authority: in Portugal, the Comissão Nacional de Proteção de Dados (cnpd.pt); in Switzerland, the Federal Data Protection and Information Commissioner (edoeb.admin.ch).
Security
We use encryption in transit (HTTPS with HSTS), strict security headers, access controls on our accounts, and form validation and rate limits. No system is perfectly secure; if a breach affects your data, we will tell you and the relevant authority as the law requires.
Children
This site is for businesses. It is not directed at children under 16, and we do not knowingly collect their data.
Changes to this policy
We will update this page when our practices change and change the date at the top. Significant changes will be flagged on the site.