1. Introduction
DevLyft Ltd ("DevLyft", "we", "our", or "us") is committed to protecting your privacy and handling personal data responsibly.
This Privacy Policy explains how we collect, use, disclose, store and protect personal information when you use the DevLyft Platform and Services.
This Policy forms part of the DevLyft Terms of Service.
DevLyft Ltd is the data controller responsible for your personal data. Where applicable, DevLyft also acts as a Data Processor under the UK General Data Protection Regulation ("UK GDPR"), the EU General Data Protection Regulation ("EU GDPR"), the Data Protection Act 2018 and other applicable data protection laws.
2. Scope
This Privacy Policy applies to:
- Visitors to our website;
- Customers;
- Account administrators;
- End users interacting directly with DevLyft-operated services;
- Individuals who contact DevLyft.
This Policy does not apply to data processed solely on behalf of Customers within their hosted applications, where DevLyft acts only as a processor.
3. Information We Collect
Depending on your use of the Services, we may collect:
Account Information
- Name
- Business name
- Email address
- Telephone number
- Billing address
- Country
- VAT number (where applicable)
Some information is required to create and maintain an account. Failure to provide mandatory information may prevent us from providing the Services.
Payment Information
Payments are processed by Stripe.
DevLyft does not store full payment card details.
We may receive:
- payment status;
- transaction identifiers;
- invoice information;
- limited billing metadata.
Technical Information
- IP addresses;
- Browser type;
- Device information;
- Operating system;
- API usage;
- Login timestamps;
- Authentication logs;
- Session identifiers.
Your password is never stored in plain text. We hash passwords using Argon2id, a memory-hard hashing algorithm, before storing them. This means DevLyft cannot view, export or recover your original password, only you know it.
Infrastructure and Workload Information
To operate, secure and support the platform, we may process:
- deployment metadata;
- resource allocation records;
- audit logs;
- network telemetry;
- infrastructure diagnostics.
We also collect two categories of data generated by running your workloads on the Services:
- Container logs, collected through our log aggregation pipeline. Logs from each organisation are isolated from other organisations' logs and are used for troubleshooting, platform security and support.
- Infrastructure and workload metrics, collected through our metrics pipeline, covering resource usage such as CPU, memory and network activity for your fleets and pods.
Because logs and metrics are generated by your own applications, they may incidentally contain personal data if your application writes it to standard output, request logs or similar, for example, if your own code logs a user's email address. DevLyft does not inspect this data for any purpose other than operating, securing and supporting the platform, and does not use it to build profiles of your end users.
Communications
Where you contact us, we may retain:
- emails;
- support tickets;
- live chat transcripts (if applicable);
- attachments;
- call notes.
4. Sources of Personal Data
We collect personal data:
- directly from you when you create an account or contact us;
- automatically through your use of the Services;
- from payment providers in connection with billing;
- from authentication providers where you choose to sign in using third-party services.
5. Information We Do Not Intentionally Collect
DevLyft does not intentionally collect:
- special category personal data unless voluntarily provided;
- biometric information;
- government-issued identification except where required for legal or fraud prevention purposes;
- payment card numbers.
6. How We Use Personal Data
We process personal data for purposes including:
- providing Services;
- account administration;
- identity verification;
- fraud prevention;
- customer support;
- billing;
- security monitoring;
- legal compliance;
- improving our Services;
- communicating important service information.
We do not sell personal information.
7. Legal Bases for Processing
Where UK GDPR or EU GDPR applies, we rely upon one or more of the following lawful bases:
- performance of a contract;
- compliance with legal obligations;
- legitimate interests;
- consent (where required);
- protection of vital interests.
Our legitimate interests include maintaining platform security, preventing fraud, improving our services and communicating with customers.
8. Customer Content
Applications, databases, files and other content hosted by Customers remain the property of the Customer.
DevLyft does not routinely access Customer Content.
Access may occur only where reasonably necessary to:
- provide requested support;
- investigate security incidents;
- comply with legal obligations;
- enforce the Terms of Service;
- protect the integrity of the platform.
9. Sessions and Local Storage
DevLyft does not use cookies to authenticate you. When you sign in, your session token is stored in your browser's local or session storage (not a cookie) and is sent with API requests to keep you signed in.
- Choosing "remember me" stores the session in local storage, so it persists across browser restarts.
- Otherwise, the session is stored in session storage and is cleared when you close the browser tab.
We do not currently use third-party advertising or analytics cookies or trackers on the DevLyft website or dashboard. If this changes, we will update this Policy and, where required by law, seek your consent first.
10. Sharing Personal Data
We share personal data with a limited number of service providers who help us run the Services. Where practical, these are:
- Stripe, payment processing and billing (payment status, transaction and invoice data).
- Google Cloud, cloud infrastructure hosting for the platform, including our production environment hosted in the London (europe-west2) region.
- Cloudflare, content delivery, DNS and network-edge security for devlyft.io.
- professional advisers (e.g. accountants, lawyers);
- regulators and law enforcement agencies where legally required.
We require service providers processing personal data on our behalf to implement appropriate safeguards. This list reflects the providers we use today; it does not include every possible future subprocessor, and we will update this Policy if our use of subprocessors changes materially.
11. International Data Transfers
As DevLyft serves customers worldwide, personal data may be transferred outside the United Kingdom or European Economic Area, for example, Stripe and Cloudflare are global providers that may process data outside the UK/EEA as part of delivering their services.
We do not publish the precise data-centre locations of our providers, as these can change and are set by the providers themselves, but we select providers who offer appropriate contractual safeguards.
Where required, such transfers will be protected using appropriate safeguards, including:
- adequacy regulations;
- Standard Contractual Clauses;
- the UK International Data Transfer Agreement (IDTA);
- other lawful transfer mechanisms.
12. Security
DevLyft implements commercially reasonable technical and organisational measures designed to protect personal data against:
- unauthorised access;
- accidental loss;
- alteration;
- destruction;
- unlawful disclosure.
Examples include:
- encryption in transit using TLS;
- encryption at rest where appropriate;
- access controls;
- least-privilege access;
- audit logging;
- multi-factor authentication for administrative systems;
- security monitoring.
Card payment details are never processed or stored on DevLyft's own systems, they are entered directly into Stripe's payment fields and reach Stripe, not DevLyft.
No method of electronic transmission or storage can guarantee absolute security.
13. Data Retention
We keep personal data only for as long as we have a reason to, and the period depends on the type of data:
- Account and profile information is retained for as long as your account is active, and for a limited period afterwards in case you wish to reactivate the account or raise a dispute.
- Billing and accounting records (invoices, transaction identifiers, payment status) are retained for six years from the end of the relevant accounting period, consistent with UK accounting and tax record-keeping requirements, even after account closure.
- Support, security and audit records (support tickets, authentication logs, security incident records) are retained for as long as reasonably necessary for security, fraud-prevention, audit and legal-compliance purposes.
- Container logs and infrastructure/workload metrics are retained only for a limited operational window needed for troubleshooting and platform security, after which they are deleted. We are finalising the exact retention window as part of our logging and metrics infrastructure configuration; this Policy will be updated with the specific figure once it is set, and we will not represent a longer retention period than the one actually configured.
- Deleted accounts and organisations: when an account or organisation is deleted, associated workload data, logs and metrics are deleted or become inaccessible within our normal operational cycle, and personal data is deleted or anonymised, except where we must keep specific records (e.g. billing records, as above) to meet a legal obligation or resolve an active dispute.
Following expiry of the relevant retention period, personal data will be securely deleted or anonymised where reasonably practicable.
14. Customer Rights
Where applicable, individuals may have the right to:
- access personal data;
- request correction of inaccurate information;
- request deletion;
- restrict processing;
- object to processing;
- request data portability;
- withdraw consent where processing is based on consent;
- lodge a complaint with a supervisory authority.
Requests may be submitted using the contact details below.
DevLyft may request information necessary to verify identity before responding.
15. Marketing Communications
We send two categories of email communications, which are treated differently.
Transactional communications
These relate to your account and use of the Services, and are necessary to provide the Services. Examples include:
- invoices;
- password resets;
- security alerts.
Marketing communications
These are optional communications about DevLyft. Examples include:
- newsletters;
- feature announcements;
- promotions.
Only marketing communications are opt-out. They may be withdrawn at any time using the unsubscribe mechanism provided or by contacting DevLyft. Transactional communications cannot generally be opted out of where they are necessary to provide the Services.
16. Automated Decision Making
DevLyft may use automated systems for:
- fraud detection;
- abuse prevention;
- spam filtering;
- security monitoring.
These systems are used to protect the platform and Customers.
Where legally required, Customers may request human review of significant automated decisions.
17. Children's Privacy
DevLyft Services are not intended for individuals under sixteen (16) years of age.
We do not knowingly collect personal information from children.
If we become aware that personal data relating to a child has been collected unlawfully, we will take reasonable steps to delete it.
18. Security Incidents
Where a personal data breach occurs that is likely to result in a risk to the rights and freedoms of individuals, DevLyft will:
- investigate the incident;
- contain the issue;
- notify the appropriate supervisory authority where required;
- notify affected individuals where legally required.
19. Third-Party Websites
The DevLyft Platform may contain links to third-party websites or services.
DevLyft is not responsible for the privacy practices of third parties.
Users should review the privacy policies of those services independently.
20. Changes to this Privacy Policy
DevLyft may amend this Privacy Policy from time to time.
Material changes will be published on the DevLyft website with an updated effective date.
Continued use of the Services following the effective date constitutes acceptance of the revised Policy.
21. Contact Details
Questions regarding this Privacy Policy, or requests relating to the processing of your personal data, should be directed to:
DevLyft Ltd
Email: info@devlyft.io
If you are located in the United Kingdom and believe your concerns have not been addressed, you may also have the right to lodge a complaint with the Information Commissioner's Office (ICO) or another competent supervisory authority where applicable.