Trust Center - Privacy Policy

Privacy Policy — DevOpsSystems Trust Center

Last updated:

This Privacy Policy explains how DevOpsSystems GmbH processes personal data when you visit our Trust Center, request access to security documentation, or subscribe to updates. It supplements our general Privacy Policy.

1. Who is responsible for your data?

The controller responsible for the processing described in this policy is:

DevOpsSystems GmbH
Saarpfalz-Park 1
66450 Bexbach, Germany
Email: info@devopssystems.de

Please contact us at this email address with any privacy questions or requests.

2. What personal data do we process?

Depending on your use of the Trust Center, we process:

  • Contact and business information: Your name, business email address, company name, and information submitted with an access request.

  • Access information: Access requests, approval decisions, permissions, authentication records, and access expiration dates.

  • Technical and activity information: IP address, browser and device information, visit timestamps, and records of documents viewed or downloaded.

  • Confidentiality records: Information relating to non-disclosure agreements, including acceptance or signature details where required.

  • Subscription information: Your email address, subscription preferences, and records of consent and withdrawal.

  • Correspondence: Information you provide when contacting us about the Trust Center.

We receive this information directly from you or generate it through your use of the Trust Center.

3. Why do we process your data?

We use your information to provide security and compliance materials, assess access requests, protect confidential documents, administer confidentiality agreements, respond to enquiries, and investigate misuse.

These activities generally rely on our legitimate interests under Article 6(1)(f) GDPR: securely sharing information with customers and prospective customers, protecting confidential materials, supporting security assessments, and maintaining access audit trails.

Where processing is necessary for a contract with you personally, or for steps you request before entering into such a contract, we rely on Article 6(1)(b) GDPR. When you act on behalf of an organization, we generally rely on legitimate interests instead.

Optional email update subscriptions rely on your consent under Article 6(1)(a) GDPR. You may withdraw consent using the unsubscribe option or by contacting us. Withdrawal stops future subscription emails without affecting necessary communications about your access or enquiries.

Where processing is necessary to meet an applicable legal obligation, we rely on Article 6(1)(c) GDPR.

Acknowledging this Privacy Policy does not constitute consent to optional processing.

4. Vanta and other recipients

We use Vanta to operate our Trust Center. Vanta’s published Data Processing Addendum identifies the provider as:

Vanta, Inc.
655 Montgomery Street, Suite 1600
San Francisco, CA 94111, United States

For personal data processed on our behalf, Vanta acts as our processor and may engage authorized subprocessors. Further information is available in Vanta’s Data Processing Addendum and subprocessor list.

Within DevOpsSystems, access is limited to personnel who need the information for the purposes described in this policy. Information may also be disclosed to professional advisers or competent authorities where necessary and legally permitted.

We do not use additional connected applications to receive visitor data from our Trust Center. This does not exclude the subprocessors Vanta uses to provide its platform.

5. International transfers

Our Trust Center uses Vanta’s EU environment. Supporting services and subprocessors may nevertheless process personal data outside the European Economic Area, including in the United States.

Transfers are subject to applicable safeguards. Vanta’s published DPA provides for EU Standard Contractual Clauses for transfers not covered by an adequacy decision. You may contact us for information about applicable safeguards and how to obtain a copy. See Vanta’s Data Processing Addendum.

6. How long do we retain your data?

We apply the following retention periods:

Data category

Retention period

Access requests, visitor profiles, granted permissions, and document access history

While a request is being assessed and for the duration of the access period, then for up to twelve months after access ends. If access is not granted, the period starts when the request is rejected, withdrawn, or closed. Records are retained only for as long as necessary to support compliance and audit trails, including SOC 2 assessments.

General technical logs, excluding document access history

No longer than one calendar month after the recorded event.

Correspondence

Until the enquiry is resolved, then no longer than one calendar month.

Update subscriptions

While the subscription is active. Subscription emails stop upon withdrawal; subscription profile data is deleted within one calendar month, subject to the limited exceptions below.

Confidentiality agreements

For as long as necessary to administer and enforce the agreement, including applicable statutory limitation or retention periods.

Specific records may be retained longer where necessary to comply with a legal obligation, investigate a documented security incident, or establish, exercise, or defend legal claims. Limited evidence of consent or withdrawal may also be retained where necessary to demonstrate compliance or respect your communication preferences.

These exceptions apply only to the relevant records and only for as long as the additional purpose requires. Access to retained records is restricted accordingly.

When retention is no longer necessary, we delete or irreversibly anonymize the personal data.

You may request erasure of your personal data at any time by contacting info@devopssystems.de. Where erasure is required under applicable data protection law, we use Vanta’s data deletion process to revoke access and delete or de-identify identifying information in the relevant Trust Center records. Any remaining personal data is assessed separately and remains subject to the retention limits and exceptions described above.

7. Cookies and similar technologies

The Trust Center uses strictly necessary technical cookies and session storage mechanisms provided by Vanta to support secure authentication, protection against cross-site request forgery (CSRF), and session persistence.

We do not use third-party analytics or marketing cookies on the Trust Center.

Storage of, and access to, information on your device is based on Section 25(2), no. 2 TDDDG, as these technologies are strictly necessary to provide the service you request. Associated personal data is processed under Article 6(1)(f) GDPR, based on our legitimate interest in operating a secure Trust Center and protecting restricted information.

You can manage cookies and site storage through your browser settings. Blocking these technologies may prevent authentication or access to restricted documents.

8. Your rights

Subject to the applicable legal conditions, you may request access to, correction of, deletion of, or restriction of processing of your personal data. You may also have a right to data portability.

You may object to processing based on legitimate interests on grounds relating to your particular situation. We will stop that processing unless there are overriding legitimate grounds or it is necessary for legal claims. You may object to direct marketing at any time.

Where processing relies on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

To exercise your rights, contact info@devopssystems.de.

You may also lodge a complaint with a data protection supervisory authority, particularly in the country of your habitual residence, place of work, or the alleged infringement. Further information is available from the European Commission.

9. Is providing your data required?

Providing information is voluntary. However, we may be unable to grant access to restricted documents without the information necessary to verify your request or complete a required confidentiality agreement.

Subscribing to optional updates is not a condition of access.

10. Changes to this policy

We may update this policy to reflect changes to the Trust Center or our processing activities. The current version will be available through the Trust Center, with the revision date shown above.