A rights workflow needs an owner, a basis, and a record.
This page maps the GDPR questions a production Devopsify operator must answer. It is a transparent demo placeholder, not a completed controller notice or data processing agreement.
Controller and processor roles
The production service operator must identify the controller for website and account processing. For customer-provided infrastructure, workspace, and operational data, the customer and service provider may have different controller or processor roles depending on the documented service and instructions. The role allocation must be reflected in a signed agreement where required.
Legal bases
The relevant basis depends on the purpose and relationship. A completed notice may rely on:
- Contract: providing an account or requested service features.
- Legitimate interests: securing, operating, and improving the service after balancing the rights and expectations of individuals.
- Consent: optional communications, non-essential cookies, or other processing that requires a freely given choice.
- Legal obligation: retaining or disclosing information when required by applicable law.
The operator must document the chosen basis, any special-category condition, and the applicable balancing or consent record. This demo does not make that determination for a production deployment.
Your rights
Subject to applicable law and its conditions, an individual may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where consent is the basis. Individuals may also complain to a competent supervisory authority.
Requests should identify the account or workspace involved without sending passwords, tokens, or unnecessary sensitive data. The production operator must verify identity, track the request, apply the statutory response timeline, and explain any lawful limitation or refusal.
Retention schedule placeholder
| Record | Planning rule | Production decision required |
|---|---|---|
| Account and access | Keep while the account is active, then delete or anonymize when no longer needed. | Exact deletion trigger, backup handling, and legal holds. |
| Workspace and audit | Keep for the documented operational, security, and customer purpose. | Retention period, tenant export, and deletion propagation. |
| Support requests | Keep for triage, follow-up, and abuse or security review. | Maximum period, attachment handling, and redaction process. |
These are planning rules, not a claim about current production retention. The operator must publish a specific schedule and make it consistent with contracts, backups, incident response, and legal obligations.
DPA and international transfers
No production data processing agreement is incorporated into this demo. A customer or processor DPA placeholder must define processing instructions, confidentiality, security measures, subprocessors, assistance with rights and incidents, deletion or return, audit support, and transfer safeguards where relevant.
Production deployment documentation must also identify subprocessors, hosting regions, transfer mechanisms, and how changes are notified. None are asserted by this demo page.