Privacy Policy
Last updated: 28 June 2026
This policy explains what personal data DEVRIM Audit ("we", "us", "our") collects when you use our website-audit service, why we collect it, who we share it with, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We've written it in plain English.
1. Who we are
The data controller for this service is [FILL: company legal name], registered at [FILL: address]. If you have any questions about this policy or your data, contact us at [FILL: contact email].
2. What data we collect
- The URL you submit. When you run an audit, we collect the website address you ask us to analyse. We fetch and read the public content of that page to produce your report.
- Your email address. If you provide one, we use it to send your finished audit report and your payment receipt.
- Payment information. Payments are processed by Stripe. We do not see or store your full card details — Stripe handles that. We receive a payment confirmation, a Stripe customer/session identifier, and the fact that a payment succeeded.
- The audit we generate. The structured report (findings, copy rewrite, action plan) is stored against your audit record so you can view it.
- Basic technical data. Standard server logs (e.g. request times, error diagnostics) needed to run and secure the service.
We do not knowingly collect special-category data, and we ask that you don't submit URLs whose content you don't have the right to share with us for analysis.
3. Why we use it, and our legal basis
| Purpose | Data used | Legal basis (UK GDPR) |
|---|---|---|
| Run the audit you requested and deliver the report | Submitted URL, audit result, email | Performance of a contract (Art. 6(1)(b)) |
| Take payment | Payment confirmation via Stripe | Performance of a contract (Art. 6(1)(b)) |
| Send the report and receipt by email | Email address | Performance of a contract (Art. 6(1)(b)) |
| Keep the service secure and working | Technical logs | Legitimate interests (Art. 6(1)(f)) |
| Meet legal and accounting obligations | Transaction records | Legal obligation (Art. 6(1)(c)) |
4. Who processes your data (our sub-processors)
To deliver the service we share the minimum necessary data with the following processors, each acting on our instructions:
| Processor | What they do | What they receive |
|---|---|---|
| Anthropic | Generates the audit analysis from the page content (AI model provider) | The text content of the page you submitted |
| Stripe | Processes payments and stores card details securely | Your payment and card details, email |
| Our hosting provider | Runs the website and serverless functions, stores audit records | Audit records, submitted URL, email, logs |
| Our email provider | Delivers your report and receipt emails | Your email address and the email content |
Some processors may handle data outside the UK/EEA. Where they do, transfers are protected by appropriate safeguards (such as the UK International Data Transfer Agreement / Addendum or equivalent). We do not sell your personal data.
5. How long we keep it
- Audit records and submitted URLs: retained while needed to provide and re-display your report, then deleted on request or routinely cleared.
- Email address: kept until you ask us to erase it, or you unsubscribe.
- Payment/transaction records: retained for as long as required by UK tax and accounting law (typically six years).
6. Your rights
Under UK GDPR you have the right to access your data, to correct it, to have it erased, to restrict or object to processing, and to data portability. You can:
- Request erasure (right to be forgotten): we provide a self-service data-deletion request — email us at [FILL: contact email] with the address you used, and we will delete the audit records associated with your email. (Technically this is handled by our data-deletion endpoint, which removes all audits tied to your email address.)
- Request a copy of your data by contacting us at [FILL: contact email].
- Unsubscribe from emails using the link in any email we send.
You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe we've mishandled your data.
7. Cookies
We keep cookies to a minimum. We use only cookies that are strictly necessary to run the service and process your payment (for example, Stripe may set cookies needed to complete and secure checkout). We do not use advertising or cross-site tracking cookies. Because we rely on strictly necessary cookies only, no consent banner is required, but you can block cookies in your browser if you prefer (checkout may not work without Stripe's).
8. Security
We use HTTPS for all traffic, rely on reputable processors (Stripe, our hosting and email providers) for sensitive operations, and never store full card numbers. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.
9. Children
This service is intended for businesses and adults. It is not directed at children, and we do not knowingly collect data from anyone under 16.
10. Changes to this policy
We may update this policy from time to time. When we do, we'll change the "last updated" date above. Material changes affecting your rights will be communicated where appropriate.
11. Contact
Data controller: [FILL: company legal name], [FILL: address]. Email: [FILL: contact email].