1. Scope
This privacy policy applies to use of the Devctrl platform (console, API, and gateway) during the private beta. A separate Website Privacy Policy applies to visits of the informational website devctrl.ai. We process personal data only to the extent necessary to operate, secure, and improve the platform.
2. Data controller
The data controller under the GDPR is the operator named in the Imprint. For privacy-related questions, contact [email protected].
3. Hosting, authentication, and database (subprocessors)
We use the following external service providers on the basis of Art. 6(1)(b) GDPR (necessary for contract performance or pre-contractual steps) and Art. 6(1)(f) GDPR (legitimate interest in a secure, stable platform). Where a provider is based in the USA, transfers rely on Standard Contractual Clauses and, where certified, the EU-US Data Privacy Framework. AI processing can be restricted to a region inside the EU.
Railway (platform infrastructure hosting)
Railway Corp., 2261 Market St #4008, San Francisco, CA 94114, USA. Railway provides the application infrastructure and processes server log files and IP addresses.
Details: https://railway.app/legal/privacy
Cloudflare (CDN, DDoS protection, SSL)
Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare delivers content through its CDN, encrypts the connection, and protects against DDoS attacks; IP addresses and metadata are processed for that purpose.
Google Cloud (AI processing)
Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland. Google Cloud performs the AI processing, handling prompts, document content and tool results. The processing region is chosen by the organisation and can be restricted to the EU. Content is not used to train models.
Details: https://cloud.google.com/terms/cloud-privacy-notice
Tavily (web search)
Tavily, USA. Tavily performs web searches when a task requires research. The search query is transmitted; the transfer relies on Standard Contractual Clauses.
Details: https://tavily.com/privacy
Neon (serverless PostgreSQL)
Neon, Inc., USA. Neon provides the database used to store platform data (policies, identities, tasks, audit logs, user mappings).
Details: https://neon.tech/privacy-policy
4. Data collected and processed
Registration and access data
When you sign up we process in particular your email address, optionally your name, authentication metadata, and session tokens.
Content data
All data you actively create in the platform is stored in the Neon database — including organizations, teams, connection configurations, policies, tasks, identities/credentials, and audit logs.
Log and telemetry data
For attack protection, debugging, and capacity planning, Railway and Cloudflare log IP addresses, timestamps, user agent information, and request paths.
No production data in the beta
During the private beta, under our Beta Terms of Use, users must not upload production data, real special-category data (e.g. health data, financial data), or personal data of third parties to the platform. The platform is explicitly not approved for regulated or sensitive data processing during the beta.
5. Google user data (Google API Services User Data Policy)
When you connect a Google account (Google Calendar, Google Drive, Gmail) to the platform, Devctrl accesses your Google data through Google APIs, only on your instruction and only with the permissions you granted on Google's consent screen. Devctrl's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Limited Use
- Google user data is used only to provide the features you see and trigger in the platform, such as creating an event, summarising a document or preparing a reply as a draft.
- It is not transferred to others except as necessary to provide those features, for security purposes or to comply with the law.
- It is not used for advertising.
- Humans do not read your Google data except where you asked for it, where your organisation's audit log records the actions carried out on your instruction, for security purposes or to comply with the law.
AI processing and model training
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Google user data is never used to develop, improve or train generalised or non-personalised AI or machine learning models.
AI processing is performed exclusively by Google Cloud (Vertex AI) within a Google Cloud project we operate, in an EU region. No third-party AI service receives Google user data. Under the Google Cloud terms, Google does not use our prompts and outputs to train its models.
Withdrawing access
Access tokens are stored encrypted. You can withdraw access at any time under “Connections” in the platform or in your Google account settings at https://myaccount.google.com/permissions. Devctrl then no longer accesses your Google data.
6. Retention
We store personal data only for as long as necessary for the purposes stated above or as required by statutory retention periods. Audit-log entries on the platform are retained according to the platform's configured retention (currently 7 days during beta). After termination of your account, your personal data will be deleted within a reasonable period, unless statutory retention duties apply.
7. Beta disclaimer
Please note that this is a beta version. Despite strong technical and organisational safeguards, complete protection of data against unauthorised access cannot be guaranteed. Use of the platform is at your own risk; see also the Beta Terms of Use.
8. Your rights
Under the GDPR, you have in particular the following rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Complaint to a supervisory authority (Art. 77 GDPR)
To exercise these rights, please contact [email protected].
9. Changes to this policy
We may update this privacy policy when technical or legal conditions change. The current version is always available on this page.