devopsify
PlatformCapabilitiesSecurityFAQContactDocs
Sign inStart free
DATA RIGHTS / GDPR

A rights workflow needs an owner, a basis, and a record.

This page maps the GDPR questions a production Devopsify operator must answer. It is a transparent demo placeholder, not a completed controller notice or data processing agreement.

Public demo documentationLast reviewed 05 August 2026

Controller and processor roles

The production service operator must identify the controller for website and account processing. For customer-provided infrastructure, workspace, and operational data, the customer and service provider may have different controller or processor roles depending on the documented service and instructions. The role allocation must be reflected in a signed agreement where required.

Legal bases

The relevant basis depends on the purpose and relationship. A completed notice may rely on:

  • Contract: providing an account or requested service features.
  • Legitimate interests: securing, operating, and improving the service after balancing the rights and expectations of individuals.
  • Consent: optional communications, non-essential cookies, or other processing that requires a freely given choice.
  • Legal obligation: retaining or disclosing information when required by applicable law.

The operator must document the chosen basis, any special-category condition, and the applicable balancing or consent record. This demo does not make that determination for a production deployment.

Your rights

Subject to applicable law and its conditions, an individual may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where consent is the basis. Individuals may also complain to a competent supervisory authority.

Requests should identify the account or workspace involved without sending passwords, tokens, or unnecessary sensitive data. The production operator must verify identity, track the request, apply the statutory response timeline, and explain any lawful limitation or refusal.

Retention schedule placeholder

RecordPlanning ruleProduction decision required
Account and accessKeep while the account is active, then delete or anonymize when no longer needed.Exact deletion trigger, backup handling, and legal holds.
Workspace and auditKeep for the documented operational, security, and customer purpose.Retention period, tenant export, and deletion propagation.
Support requestsKeep for triage, follow-up, and abuse or security review.Maximum period, attachment handling, and redaction process.

These are planning rules, not a claim about current production retention. The operator must publish a specific schedule and make it consistent with contracts, backups, incident response, and legal obligations.

DPA and international transfers

No production data processing agreement is incorporated into this demo. A customer or processor DPA placeholder must define processing instructions, confidentiality, security measures, subprocessors, assistance with rights and incidents, deletion or return, audit support, and transfer safeguards where relevant.

Production deployment documentation must also identify subprocessors, hosting regions, transfer mechanisms, and how changes are notified. None are asserted by this demo page.

Need to submit a demo question?Open contact and support guidance →
2024-2026 All Rights Reserved Devopsify.Net
ContactPrivacyGDPRCookiesTermsSecurityPlatform admin