Privacy Policy
Last updated: 2026-10-01
- Controller. DevKit Srl, Via Teodoro Valfrè 11, 00165 Roma, Italy, support@devkit.dev.
- What we collect and why.
- Waitlist: email address, optional company name and what you ship. Purpose: sending early-access updates you asked for. Legal basis: consent (double opt-in). Withdraw any time via the unsubscribe link; the address is then deleted within 30 days, except for a suppression entry at our email provider that prevents further emails.
- Account: work email, company name, sign-in timestamps, API key metadata. Purpose: providing the Service under the contract. Legal basis: contract.
- Customer Data: SBOMs and records you upload. They normally contain component names, versions and licenses, not personal data. If they do, you are the controller and we process on your instructions under the Data Processing Addendum.
- Billing: handled by Paddle as merchant of record; we receive subscription status and invoice references, not card numbers.
- Service logs: IP address, user agent, request metadata, error reports. Purpose: security, abuse prevention, debugging. Legal basis: legitimate interest. Retention: 30 days for access logs; error reports for up to 90 days.
- Emails: we send transactional email (sign-in links, vulnerability alerts you enabled, account notices) through Postmark (USA). We do not use open or click tracking. Alerts have an unsubscribe and "manage alerts" link.
- Support: when you write to support@devkit.dev, our email provider Postmark receives the message and passes it to us. We keep the sender's address and name, the subject, the text and the number of attachments; attachments themselves are not kept. Purpose: answering you. Legal basis: contract, or legitimate interest if you are not a customer. Retention: 12 months after the request is closed.
- Cookies. One strictly necessary session cookie after sign-in, and one for the language you chose. No advertising or third-party analytics cookies. On the checkout page, Paddle's payment window and script may set their own cookies, covered by Paddle's privacy notice.
- Where data is processed. Customer Data and account data are stored in Frankfurt, Germany (DigitalOcean). Where personal data is transferred outside the EU/EEA, the transfer relies on an adequacy decision (including the EU-US Data Privacy Framework for certified US companies) or on standard contractual clauses.
Processors. These providers process personal data on our behalf:
Provider Purpose Personal data Location Transfers outside the EU/EEA DigitalOcean, LLC (USA) Hosting of the Service, its database and backups All data described in section 2 Frankfurt, Germany; backups in the same datacenter Data is stored in the EU. Access by DigitalOcean or its sub-processors from outside the EU relies on the EU-US Data Privacy Framework, with standard contractual clauses as fallback AC PM LLC (Postmark, an ActiveCampaign company, USA) Delivery of sign-in, waitlist and alert emails; receipt of email sent to our support address Email address, name, email content, delivery and bounce data United States EU-US Data Privacy Framework; standard contractual clauses as alternative Functional Software, Inc. (Sentry, USA) Error monitoring Technical error reports; we configure it not to send IP addresses, user identities or request contents Frankfurt, Germany (Sentry EU data region); account metadata in the United States EU-US Data Privacy Framework, with standard contractual clauses as fallback Independent controller. Payments are processed by Paddle as merchant of record. Paddle acts as an independent controller for checkout data under its own privacy notice (paddle.com/legal/privacy):
Provider Purpose Personal data Location Transfers outside the EU/EEA Paddle.com Market Limited (United Kingdom); Paddle.com Inc. (USA) or Paddle.com (Canada) Ltd. for buyers in those countries Checkout, payment, invoicing, VAT and buyer support Name, email, billing address, payment details, IP address and other checkout data United Kingdom; USA or Canada for buyers there United Kingdom: EU adequacy decision. Paddle's onward transfers: standard contractual clauses We also use Doppler (secrets management), GitHub (source code) and UptimeRobot (availability checks of our public pages). They do not receive personal data of our users.
- Sharing. We do not sell personal data. We share it only with the processors above, with authorities where the law requires, and with a successor in a merger or acquisition under the same commitments.
- Retention. Account data for the life of the account plus 90 days; waitlist data until you unsubscribe or we close the waitlist; invoices as required by Italian tax law (10 years, held by Paddle and in our accounting); support messages 12 months after the request is closed.
- Your rights. Access, rectification, erasure, restriction, portability and objection under the GDPR; complaint to the Italian supervisory authority (Garante per la protezione dei dati personali) or your local authority. Write to support@devkit.dev.
- Security. Encrypted transport (TLS), backups kept in the same EU datacenter, least-privilege access, no passwords stored (email sign-in links), API keys stored as hashes.
- Changes. We announce material changes by email or on this page 30 days before they take effect.
DevKit Dossier