DEVRIM·AUDIT
How it works Pricing Run an audit
Legal

Privacy Policy

Last updated: 28 June 2026

This policy explains what personal data DEVRIM Audit ("we", "us", "our") collects when you use our website-audit service, why we collect it, who we share it with, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We've written it in plain English.

1. Who we are

The data controller for this service is [FILL: company legal name], registered at [FILL: address]. If you have any questions about this policy or your data, contact us at [FILL: contact email].

2. What data we collect

  • The URL you submit. When you run an audit, we collect the website address you ask us to analyse. We fetch and read the public content of that page to produce your report.
  • Your email address. If you provide one, we use it to send your finished audit report and your payment receipt.
  • Payment information. Payments are processed by Stripe. We do not see or store your full card details — Stripe handles that. We receive a payment confirmation, a Stripe customer/session identifier, and the fact that a payment succeeded.
  • The audit we generate. The structured report (findings, copy rewrite, action plan) is stored against your audit record so you can view it.
  • Basic technical data. Standard server logs (e.g. request times, error diagnostics) needed to run and secure the service.

We do not knowingly collect special-category data, and we ask that you don't submit URLs whose content you don't have the right to share with us for analysis.

3. Why we use it, and our legal basis

PurposeData usedLegal basis (UK GDPR)
Run the audit you requested and deliver the reportSubmitted URL, audit result, emailPerformance of a contract (Art. 6(1)(b))
Take paymentPayment confirmation via StripePerformance of a contract (Art. 6(1)(b))
Send the report and receipt by emailEmail addressPerformance of a contract (Art. 6(1)(b))
Keep the service secure and workingTechnical logsLegitimate interests (Art. 6(1)(f))
Meet legal and accounting obligationsTransaction recordsLegal obligation (Art. 6(1)(c))

4. Who processes your data (our sub-processors)

To deliver the service we share the minimum necessary data with the following processors, each acting on our instructions:

ProcessorWhat they doWhat they receive
AnthropicGenerates the audit analysis from the page content (AI model provider)The text content of the page you submitted
StripeProcesses payments and stores card details securelyYour payment and card details, email
Our hosting providerRuns the website and serverless functions, stores audit recordsAudit records, submitted URL, email, logs
Our email providerDelivers your report and receipt emailsYour email address and the email content

Some processors may handle data outside the UK/EEA. Where they do, transfers are protected by appropriate safeguards (such as the UK International Data Transfer Agreement / Addendum or equivalent). We do not sell your personal data.

5. How long we keep it

  • Audit records and submitted URLs: retained while needed to provide and re-display your report, then deleted on request or routinely cleared.
  • Email address: kept until you ask us to erase it, or you unsubscribe.
  • Payment/transaction records: retained for as long as required by UK tax and accounting law (typically six years).

6. Your rights

Under UK GDPR you have the right to access your data, to correct it, to have it erased, to restrict or object to processing, and to data portability. You can:

  • Request erasure (right to be forgotten): we provide a self-service data-deletion request — email us at [FILL: contact email] with the address you used, and we will delete the audit records associated with your email. (Technically this is handled by our data-deletion endpoint, which removes all audits tied to your email address.)
  • Request a copy of your data by contacting us at [FILL: contact email].
  • Unsubscribe from emails using the link in any email we send.

You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe we've mishandled your data.

7. Cookies

We keep cookies to a minimum. We use only cookies that are strictly necessary to run the service and process your payment (for example, Stripe may set cookies needed to complete and secure checkout). We do not use advertising or cross-site tracking cookies. Because we rely on strictly necessary cookies only, no consent banner is required, but you can block cookies in your browser if you prefer (checkout may not work without Stripe's).

8. Security

We use HTTPS for all traffic, rely on reputable processors (Stripe, our hosting and email providers) for sensitive operations, and never store full card numbers. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.

9. Children

This service is intended for businesses and adults. It is not directed at children, and we do not knowingly collect data from anyone under 16.

10. Changes to this policy

We may update this policy from time to time. When we do, we'll change the "last updated" date above. Material changes affecting your rights will be communicated where appropriate.

11. Contact

Data controller: [FILL: company legal name], [FILL: address]. Email: [FILL: contact email].

DEVRIM Audit — IDEA-007. A focused website audit, no fluff. Privacy · Terms · Refunds © DEVRIM Holdings