Privacy Policy
Effective 3 August 2026 · Version 1.0
We sell transparency compliance for a living, so this page is written to be read rather than filed. It covers what we hold, where it sits, who can reach it, and when it goes away.
If you are a client and want the contractual version — the one your legal team will ask for — that is the Data Processing Agreement. This page describes the same handling in plain terms.
1. Who we are
DeployerProof is a one-person compliance-engineering practice. The operator and legal entity behind it is Amiya Krishna Bera, trading as DeployerProof — a sole proprietorship established in India. Contact: hello@deployerproof.com.
Registered trading address: Basantia, East Midnapore, West Bengal, India, PIN 721442.
We are the controller for the data described in section 2 — enquiries, client billing details, and our own records. When we handle personal data that belongs to a client's systems, the client is the controller and we act as their processor under the DPA.
No EU representative under GDPR Article 27 is currently appointed. We say that plainly rather than leave a placeholder: the appointment is under review, and if one is made, the representative will be named here and active clients told. In the meantime, data subjects and supervisory authorities reach the operator directly at privacy@deployerproof.com — which in a one-person practice is the same inbox a representative would forward to anyway.
2. What we collect
Visiting this site
Nothing. There are no cookies, no analytics, no tracking pixels, no embedded chat. That is also why you did not get a consent banner — there is nothing to consent to. Our host keeps standard server logs containing IP addresses for a short period as a matter of operating a web server; we do not read them for any purpose beyond fixing a broken deployment.
The page does load web fonts from Google Fonts, which means your browser makes a request to Google's servers and Google sees your IP address in doing so. If that matters to your threat model, a content blocker stops it and the page still works.
Getting in touch
If you email us or reply to our outreach, we keep the message: your name, email address, company, job title, and whatever you chose to write. We use it to answer you and, if the conversation turns into an engagement, to deliver the work. The legal basis is our legitimate interest in responding to business enquiries, and steps taken at your request before entering a contract.
Buying a gap-scan
The scan runs on what you show us: public URLs, a walkthrough of your product, screenshots or recordings you choose to send, and your description of how the AI features work. Plus a billing contact and an invoicing address.
The evidence log
The evidence-log service stores configuration metadata and nothing else:
- Disclosure text versions and their placement configuration
- Locale and jurisdiction flags per product
- Public URLs of the products being tracked
- SHA-256 hashes forming the tamper-evident chain
- RFC 3161 timestamp tokens from a third-party timestamping authority
- Event timestamps, and the login email address of the account holder
No conversation content. No screenshots of user sessions. No end-user personal data, no IP addresses of your users, no identifiers of any kind belonging to the people who use your bot. This is not a setting you could switch on by accident: the database has no columns for that data, and adding them would be a redesign rather than a configuration change.
Payment
Engagements are invoiced and settled by bank transfer — SEPA for EU clients. There is no card checkout, so no card number ever reaches us and none is stored. What we hold is the invoice and its matching transaction record: your billing name, invoicing address, amount, date, and country. Tax and accounting law is why we keep it.
Cross-border collection runs through Skydo, which issues the account details printed on your invoice and settles the funds to our Indian bank. Skydo sees the payment details it needs to do that, under its own terms.
3. Where it lives
| Data | Where | Region |
|---|---|---|
| Evidence log, account records | Supabase (managed Postgres) — the evidence-log service, which is not live yet | EU — Frankfurt |
| Scan materials and delivered reports | The mailbox they arrive in, plus the operator's workstation while the report is being written | Mailbox per Hostinger (see below); workstation in India |
| Invoices and payment records | Our accounting records and Skydo (collection) | India · funds routed through Skydo's banking partners |
| Email correspondence | Hostinger Business Email mailbox | Determined by Hostinger — we make no EU-residency claim for mail |
| Outreach records (who we contacted, when, and what they said) | A tracker file in our private source repository, hosted by GitHub | Per GitHub's own infrastructure and terms |
EU-region hosting is a fixed architectural commitment for the evidence log. That is the one place the Frankfurt claim belongs, and it is not a plan setting we would revisit for a cheaper tier.
It does not extend to the mailbox. Hostinger decides where mail is stored, we have not verified which region that is, and we are not going to write “EU” on a page like this without having checked — that is precisely the kind of unverified claim we get paid to find in other people's products. Until it is confirmed, assume correspondence may sit outside the EU. It is also why the scan is designed not to need your users' data: the material you send us is public URLs, configuration, and a walkthrough, and none of that gets more sensitive for being stored in the wrong place.
4. Who can see it
One person: the operator, working from India. There are no employees, no contractors, no offshore support desk, no sales-intelligence tools chewing through the mailbox. Nothing is sold, rented, or shared with advertisers or data brokers — an easy promise to keep, since none of it would be worth anything to them.
Accounts holding client data are protected by multi-factor authentication. Database access is scoped per organization by row-level security, so one client's records are not reachable from another's session.
5. Transfers out of the EU
The evidence log sits in Frankfurt. Correspondence sits with our mail provider, in a region we have not verified, and scan material sits on the operator's workstation while a report is being written. In every one of those cases the person who works on it is in India, and India has no adequacy decision from the European Commission. Remote access from India is therefore an international transfer under Chapter V of the GDPR, and we treat it as one rather than pretending a hosting region settles the question.
Where we act as a processor for an EU client, the transfer runs on the Commission's Standard Contractual Clauses, Module Two, as set out in Implementing Decision (EU) 2021/914. They are incorporated in the DPA, with the annexes populated there. The supporting argument is short: what crosses the border is configuration metadata and business-contact details, never the content of anyone's conversations.
6. How long we keep things
| What | Retention |
|---|---|
| Enquiry and outreach correspondence | 24 months after the last message, then deleted |
| Scan input material you sent us | 90 days after report delivery, then deleted — earlier on request |
| The delivered report itself | 24 months, so we can answer follow-up questions and reissue it |
| Evidence-log records | Life of the subscription plus 30 days; you get an export before deletion |
| Invoices and payment records | As long as tax and accounting law requires |
7. Your rights
If you are in the EU, EEA, or UK, you can ask for a copy of what we hold, ask us to correct it, ask us to delete it, ask for it in a portable format, object to processing based on legitimate interest, or ask us to restrict processing while a dispute is sorted out. Email privacy@deployerproof.com and say what you want. The legal deadline is one month; in a practice this size it is usually a day or two.
You can also complain to your national data protection authority. We would rather you told us first, but that right does not depend on us.
If your request concerns data we hold on a client's behalf — evidence-log records, for instance — we will point you to that client, since they decide what happens to it.
8. Security
Encryption in transit and at rest, EU-region managed Postgres with row-level security scoped per organization, multi-factor authentication on every account that touches client data, and no shared credentials because there is nobody to share them with.
The measure that matters most is the one built into the product: the sensitive categories are never collected. A breach of the evidence log would expose disclosure texts, hashes, timestamps, and public URLs. There is no conversation content in there to leak.
If a breach affecting your data does happen, you hear from us without undue delay — for client data processed under the DPA, within 48 hours of us becoming aware.
9. Changes
This page is versioned and dated. Material changes get emailed to active clients rather than quietly published; the version number at the top tells you whether you are looking at what you agreed to.
10. Questions
Write to privacy@deployerproof.com for anything about your data, or hello@deployerproof.com for anything else — both land with the same person. Privacy questions get answered by the person who built the system, not by a ticket queue.