Contact Sales
Privacy & GDPR

Privacy Policy

Effective Date: April 2026 · Version 1.0

The protection of your personal data is a core concern for us. This Privacy Policy informs you in accordance with Art. 13 and 14 of the General Data Protection Regulation (GDPR) about how, why, and on what legal basis we process your data.

1. Data Controller and Contact

The data controller within the meaning of the GDPR for the processing of your personal data is:

DEV AutomationsHoteser Weg 8
47918 Tönisvorst, Germany

Email: david@dev-automations.com
Website: www.dev-automations.com

If you have any questions about data protection, you can contact us at any time by email at david@dev-automations.com. We reserve the right to appoint an external Data Protection Officer upon recommendation of the data protection authority or when the relevant thresholds are met. Currently, no legally required Data Protection Officer has been appointed.

2. Overview of Data Processing

DEV Automations processes personal data in the following contexts:

  • Website Operation: Technical usage data when visiting our website (web server logs, cookies).
  • Customer Management (CRM): Contact details, company information, and communication history of prospects and customers.
  • Contract Processing: Billing and payment data to fulfill existing contracts.
  • Platform Usage: Usage data, telemetry, and log data from our AI automation platform.
  • AI Systems: Data processed through our AI agents (chatbot, voice, email), including conversation content.
  • Marketing: Email communications and newsletters (only with explicit consent).

We process only the data that is necessary to achieve the respective processing purpose (principle of data minimisation). Processing for other purposes only takes place if it is compatible with the original purpose, you have given consent, or there is a legal basis.

4. Categories of Data Collected

Depending on the nature of your use of our services, we collect the following categories of personal data:

Master Data: Name, first name, company, position/function, industry
Contact Data: Email address, phone number, postal address
Contract Data: Type of contract, scope of services, contract duration, offer history
Payment Data: Billing address, payment method (processed via Stripe, without storing full card details on our side)
Usage Data: API calls, usage duration, accessed features, error logs, timestamps
Communication Data: Emails, chat transcripts, voice transcripts within AI automations (potentially on behalf of the customer)
Technical Data: IP address, browser type, operating system, device information, voice queries to our AI systems

We do not process special categories of personal data within the meaning of Art. 9 GDPR (e.g., health data, biometric data, political opinions) unless this is exceptionally required as part of our service and explicit consent has been given.

5. Website Usage and Cookies

Server Logs: When you visit our website, our web server automatically stores access logs (web server logs). These contain the IP address, date and time of access, the URL accessed, the HTTP status code, and (if present) the referrer URL. This data is processed exclusively for technical operational security, error diagnosis, and to defend against attacks. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in operational security). Logs are deleted after a maximum of 7 days.

Cookies: We use cookies and similar technologies. We distinguish between:

  • Technically Necessary Cookies: These are strictly required for the operation of the website (e.g., session cookies, CSRF protection). They are set without your consent. Legal basis: Art. 6(1)(f) GDPR.
  • Analytics Cookies: With your consent, we may use anonymized analytics data (e.g., to measure page views) to improve our website. Legal basis: Art. 6(1)(a) GDPR.
  • Marketing Cookies: Currently, no third-party marketing or tracking cookies are set.

You can disable or delete cookies in your browser settings at any time. Please note that disabling technically necessary cookies may impair the functionality of the website.

Google reCAPTCHA: On certain forms on our website, we use the CAPTCHA service "reCAPTCHA" provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). This service processes technical data from your browser (including your IP address) and uses cookies to distinguish automated requests from human ones. The data may be transmitted to Google servers in the USA. The legal basis is our legitimate interest in preventing spam and automated abuse (Art. 6(1)(f) GDPR). Google is certified under the EU-US Data Privacy Framework. Please refer to Google's privacy policy at policies.google.com/privacy.

6. Contact and Forms

When you contact us via our contact form or by email, the data you provide (name, email address, company, message) is stored and processed by us to handle your inquiry. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) and, if applicable, Art. 6(1)(f) GDPR (legitimate interest in processing inquiries).

Demo Bookings: When you initiate a demo request through our website, your contact details and the information you provide (e.g., company size, requirements) are used to prepare and conduct the demo. This data is stored in our CRM system and retained for a maximum of 24 months following the conclusion of the relevant sales activity, unless a contract relationship is established.

Newsletter: If you sign up for our newsletter, we use the so-called double opt-in procedure. After signing up, you will receive a confirmation email in which you must actively confirm your registration. The legal basis for sending the newsletter is your consent pursuant to Art. 6(1)(a) GDPR. You can withdraw your consent at any time by unsubscribing via the unsubscribe link in the newsletter or by sending us an email.

7. AI-Supported Data Processing

As part of our AI automation solutions, personal data may be processed by automated systems (AI agents, chatbots, voice agents, email automations). This happens either:

  • On behalf of our customers (data processing pursuant to Art. 28 GDPR): When customers use our platform to process data of their own customers, employees, or partners, we act as a data processor. In this case, the customer is the controller. For this setup, we enter into a Data Processing Agreement (DPA) that fully meets the documentation requirements of the GDPR.
  • For our own purposes (as data controller): When we use AI-supported communication to process inquiries addressed to us.

Zero Data Retention at LLM Providers: We have concluded strict Data Processing Agreements with our AI model providers (e.g., OpenAI, Anthropic) ensuring that your data is not used for training foundation models. Prompt data and responses are only held in working memory at these providers for the duration of the API processing (typically a few seconds to minutes).

Automated Decision-Making: To the extent that our AI systems make automated decisions that have a legal or similarly significant effect on you, we will inform you separately and — where required — ensure a legal basis in accordance with Art. 22 GDPR. Upon request, you may request a manual review of automated decisions.

Transcripts: Chat and voice transcripts generated during AI interactions are stored by default for 30 days. Customers can configure different retention periods in their workspace settings.

8. Data Processors (Subprocessors)

To provide our services, we engage carefully selected service providers who process personal data on our behalf (processors pursuant to Art. 28 GDPR). We have entered into appropriate contracts with each processor ensuring compliance with the GDPR and an equivalent level of data protection.

ProviderPurposeLocation
AWS (Amazon Web Services)Cloud infrastructure, data storageEU (Frankfurt)
OpenAIAI language models (LLM)USA (SCCs + DPA)
AnthropicAI language models (LLM)USA (SCCs + DPA)
Stripe, Inc.Payment processingUSA (SCCs + DPA)
CloudflareCDN, DDoS protectionUSA (DPF-certified)
Google Ireland LimitedreCAPTCHA Spam ProtectionUSA/EU (DPF-certified)
n8nWorkflow automation (self-hosted)EU / own infrastructure

This list is subject to change. The current, complete subprocessor list is available upon request. In the event of material changes to the subprocessor list, customers with a DPA will be informed in advance by email.

9. International Data Transfers

Some of our processors are located in third countries outside the European Economic Area (EEA), particularly in the USA. For these transfers, we always ensure an adequate level of data protection through:

  • EU Standard Contractual Clauses (SCCs): Pursuant to the EU Commission's implementing decision (Decision 2021/914).
  • EU-US Data Privacy Framework (DPF): For US providers certified under this adequacy decision (e.g., Cloudflare).
  • Adequacy Decisions by the EU Commission: For countries for which a valid adequacy decision exists.

Upon request, we will provide you with the relevant safeguards (e.g., copies of the SCCs). Please contact us at david@dev-automations.com.

10. Retention Periods and Deletion

We store personal data only as long as necessary for the respective processing purpose or as required by statutory retention obligations:

  • Customer data (active contracts): For the duration of the contractual relationship plus statutory retention periods (generally 10 years under commercial and tax law).
  • Prospects (without contract): Up to 24 months after the last contact.
  • AI transcripts: 30 days by default; configurable by customers (minimum 7 days, maximum 180 days).
  • Server logs: Maximum 7 days.
  • Newsletter subscribers: Until withdrawal of consent, followed by immediate deletion.
  • Applicant data: Up to 6 months after the conclusion of the application process.

After the respective retention period expires, data is securely and irrevocably deleted or anonymized, provided no statutory retention obligation prevents this.

11. Your Rights as a Data Subject

Under the GDPR, you have the following rights, which you may exercise against us at any time:

Right of Access (Art. 15 GDPR)You have the right to obtain confirmation as to whether we are processing personal data concerning you, and if so, to receive information about such data.
Right to Rectification (Art. 16 GDPR)You have the right to demand the immediate correction of inaccurate or the completion of incomplete personal data concerning you.
Right to Erasure (Art. 17 GDPR)You have the right, under certain conditions, to demand the immediate deletion of your personal data (right to be forgotten).
Right to Restriction (Art. 18 GDPR)You have the right, under certain conditions, to demand restriction of the processing of your data.
Right to Data Portability (Art. 20 GDPR)You have the right to receive the data you have provided in a structured, commonly used, machine-readable format and to transfer it to another controller.
Right to Object (Art. 21 GDPR)You have the right, on grounds relating to your particular situation, to object at any time to processing of your data based on a legitimate interest. For direct marketing, you have an unconditional right to object.
Right to Withdraw Consent (Art. 7(3) GDPR)Where processing is based on your consent, you may withdraw it at any time with effect for the future without affecting the lawfulness of prior processing.
Right to Lodge a Complaint (Art. 77 GDPR)You have the right to lodge a complaint with the competent data protection supervisory authority for your place of residence or our registered office.

To exercise your rights, please contact us in writing or by email at david@dev-automations.com. We will respond to your request within 30 days. For complex requests or high volumes, we may extend this period by up to 2 months, of which we will inform you. Identification may be required to process your request.

12. Data Security

We implement appropriate technical and organisational measures (TOMs) pursuant to Art. 32 GDPR to protect your personal data against unauthorised access, loss, destruction, or manipulation. Our security measures include, in particular:

  • Encryption: All data transmissions use TLS 1.3. Data at rest is encrypted (AES-256).
  • Access Controls: Role-based access management (RBAC), multi-factor authentication (MFA) for administrators, and the principle of least privilege.
  • Monitoring: Continuous security monitoring, intrusion detection systems, and regular penetration tests by external specialists.
  • Backup & Recovery: Daily encrypted backups with defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).
  • Employee Training: Regular data protection and IT security training for all employees.
  • Incident Management: A defined process for reporting and handling data breaches. Reportable incidents are notified to the competent supervisory authority within 72 hours (Art. 33 GDPR).

13. Minors

Our services are directed exclusively at businesses and persons who have reached the age of 18. We do not knowingly collect personal data from minors under the age of 18. Should we learn that data of a minor has been inadvertently stored, we will delete it immediately. If you are a parent or guardian and believe your child has submitted data to us, please contact us at david@dev-automations.com.

14. Changes to this Privacy Policy

We reserve the right to update this Privacy Policy to reflect changes in legal requirements, technological developments, or new processing activities. The current version is always available on our website. For material changes that affect your rights, we will inform you in advance by email. We recommend reviewing this Privacy Policy regularly.

The current version of this Privacy Policy was last updated in April 2026.

→ Terms of Service→ Imprint→ Contact