Legal
Last updated: 23 July 2026 · Effective: 23 July 2026
Note before publishing: this policy is a thorough GDPR-aligned template. Replace every [bracketed] placeholder with your real details (legal name, registration number, registered address, DPO contact, exact sub-processors and their locations) and have it reviewed by a qualified lawyer or DPO before you rely on it. Laws and your processing can change.
This policy explains how DevCore (“DevCore”, “we”, “us”) collects and uses personal data through our website www.devcore-enterprise.site, our client portal (portal.devcore-enterprise.site), and the services we provide.
Data controller: DevCore [legal entity name], [registered address, Bucharest, Romania], company no. [reg. no.]. Contact: hello.devcore-enterprise@outlook.com. [Data Protection Officer / representative, if appointed].
We act as a data controller for the personal data of website visitors, prospects and portal account holders. For the end-user conversation data processed by the chatbots and websites we build and operate for our clients, we act as a data processor on behalf of the client (who is the controller) under a separate Data Processing Agreement (see section 10).
| Who | Data | Source |
|---|---|---|
| Website visitors / prospects | Name, business/institution, email, phone (optional), the message you send, and the page you sent it from. Basic technical data (approximate location, browser/device) if privacy-friendly analytics are enabled. | You, via our contact and “request access” forms; your device. |
| Portal account holders (our clients’ staff) | First/last name, username, email, phone, job title, the company you belong to, role, and activity within the portal (bills, tickets, project access). | Provided by you or set up by DevCore staff when your project starts. |
| Billing | Company billing details, invoice records, payment status and wire-reference metadata. We do not collect or store card numbers. | The client relationship. |
| End-users of clients’ chatbots/websites | Conversation transcripts, evaluation results, and technical metadata (country, device, OS, browser, timestamps). Processed on behalf of the client. | The client’s end-users; processed via Voiceflow and/or website analytics. |
The public website uses no advertising or tracking cookies. The client portal uses a single strictly necessary session cookie to keep you signed in; it cannot be switched off without breaking sign-in and requires no consent. If we enable analytics on a client’s website, we prefer cookieless, privacy-friendly tools; any provider that sets non-essential cookies will only run after you consent via the cookie banner.
We use a small set of vetted providers to run the service. We do not sell personal data. Current sub-processors include:
| Provider | Purpose | Location |
|---|---|---|
| MongoDB Atlas | Database hosting (portal accounts, bills, tickets, submissions) | EU region [confirm] |
| Fly.io / [hosting provider] | Application hosting | [region] |
| Cloudflare | DNS, TLS, CDN, security | Global edge |
| Voiceflow | Chatbot runtime and conversation analytics (processed on the client’s behalf) | United States |
| Microsoft / Outlook | Transactional email (invoices, notifications) | EU/US [confirm] |
| Plausible Analytics [if used] | Privacy-friendly website traffic analytics | EU (self-hostable) |
We may also share data where required by law, to enforce our agreements, or in connection with a corporate transaction, subject to appropriate safeguards.
Some providers (e.g. Voiceflow) may process data outside the EEA, including in the United States. Where that happens, we rely on an adequacy decision where available, or on Standard Contractual Clauses and supplementary measures, to protect your data. You can request a copy of the relevant safeguards from hello.devcore-enterprise@outlook.com.
Under the GDPR you have the right to: access your data; have it corrected; have it erased; restrict or object to processing; data portability; and to withdraw consent at any time where processing is based on consent (without affecting prior processing). To exercise any right, email hello.devcore-enterprise@outlook.com. If you are an end-user of a client’s chatbot or website, please contact that client (the controller); we will assist them as their processor.
You also have the right to lodge a complaint with a supervisory authority — in Romania, the National Supervisory Authority for Personal Data Processing (ANSPDCP, dataprotection.ro) — or the authority in your EU country of residence.
We use encryption in transit (TLS), hashed passwords (bcrypt), role-based access control, least-privilege access to secrets and API keys, and reputable hosting with security controls. No system is perfectly secure, but we take appropriate technical and organisational measures under Art. 32 GDPR. In the event of a personal data breach that is likely to result in a risk to your rights, we will notify the relevant authority within 72 hours where required, and affected individuals without undue delay where the risk is high.
When we build and run chatbots or websites for a client, the client is the controller of its end-users’ personal data and we process that data only on the client’s documented instructions, under a Data Processing Agreement that reflects Art. 28 GDPR (confidentiality, security, sub-processor terms, assistance with data-subject requests, deletion/return on termination). Clients can request our current DPA and sub-processor list at hello.devcore-enterprise@outlook.com.
Our website and services are directed at businesses and institutions, not children, and we do not knowingly collect data from children. Clients are responsible for any age-appropriate handling within their own audiences.
We may update this policy from time to time. We will post the new version here with an updated “Last updated” date and, for material changes affecting account holders, notify you through the portal or by email.
Questions or requests: hello.devcore-enterprise@outlook.com · DevCore, [registered address], Bucharest, Romania.