GDPR Compliance & Data Protection
DevRabbit is committed to protecting personal data and complying with applicable data-protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) where it applies.
This page explains DevRabbit's approach to GDPR compliance, the rights available to individuals, and the responsibilities of organizations that engage DevRabbit to process personal data.
This page should be read together with DevRabbit's Privacy Policy, applicable Data Processing Addendum (DPA), Cookie Policy, Terms of Service, and relevant customer or project agreements.
- 1. Our Commitment to GDPR
- 2. When GDPR Applies
- 3. Controller and Processor Roles
- 4. Data Protection Addendum
- 5. Categories of Personal Data
- 6. Lawful Bases for Processing
- 7. Data Minimization and Purpose Limitation
- 8. Security and Technical Safeguards
- 9. Subprocessors
- 10. International Data Transfers
- 11. Data Retention and Deletion
- 12. Data Subject Rights Under GDPR
- 13. How to Exercise Your GDPR Rights
- 14. Right to Lodge a Complaint
- 15. Special Categories of Personal Data
- 16. Automated Decision-Making and Profiling
- 17. Cookies and Tracking Technologies
- 18. Marketing Communications
- 19. Personal Data Obtained From Third Parties
- 20. Personal Data Breaches
- 21. Accountability and Privacy by Design
- 22. Children's Data
- 23. EU Representative
- 24. Data Protection Officer
- 25. Related Privacy Documents
- 26. Updates to This GDPR Page
1. Our Commitment to GDPR
DevRabbit's privacy and security approach is intended to support responsible, secure, and transparent processing of personal data.
Where GDPR applies, our approach is based on core data-protection principles, including:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
DevRabbit applies appropriate technical and organizational measures according to the nature, scope, context, and risks of the processing.
2. When GDPR Applies
The GDPR may apply to DevRabbit where, for example:
- DevRabbit processes personal data of individuals in the EEA in circumstances covered by GDPR.
- DevRabbit offers services to organizations or individuals in the EEA.
- DevRabbit monitors the behavior of individuals in the EEA where GDPR applies.
- DevRabbit processes personal data on behalf of a customer that is subject to GDPR.
The applicability of GDPR depends on the particular processing activity and circumstances.
3. Controller and Processor Roles
DevRabbit as Data Controller
DevRabbit generally acts as a controller when it determines the purposes and means of processing personal data for its own business purposes, such as:
Examples include:
- Managing website visitors and inquiries
- Managing customer and prospect relationships
- Processing contact, assessment, and consultation requests
- Managing accounts where applicable
- Sending permitted marketing communications
- Website and service analytics
- Security monitoring
- Recruitment and business administration
DevRabbit as Data Processor
DevRabbit may act as a processor or service provider when a customer determines the purposes of processing and instructs DevRabbit to process personal data in connection with software development, integrations, cloud services, applications, workflows, APIs, or other customer-configured solutions.
In such circumstances:
- The customer generally determines the purposes of processing.
- The customer determines what personal data is provided to DevRabbit.
- DevRabbit processes personal data according to documented customer instructions and the applicable agreement.
- DevRabbit applies appropriate technical and organizational measures.
- Processing may be governed by a DPA or equivalent data-protection terms.
Customers remain responsible for establishing the lawful basis for processing and providing appropriate privacy notices to data subjects, unless otherwise agreed.
4. Data Protection Addendum
For customers subject to GDPR, DevRabbit should provide appropriate contractual data-protection terms where required. A DPA may address:
- Processing instructions and documented obligations
- Confidentiality
- Security measures
- Subprocessor requirements
- Assistance with data-subject requests
- Personal data breach notification
- International data transfers
- Data deletion and return
- Audits and compliance information
- Controller and processor responsibilities
5. Categories of Personal Data
Depending on the service and relationship, personal data processed by DevRabbit may include:
Identity and Professional Information
- Name
- Business email address
- Telephone number
- Company name
- Job title
- Professional role
Account and Authentication Information
- Username or account identifier where applicable
- Authentication information
- Organization information
- User roles and permissions
Technical Information
- IP address
- Browser and device information
- Operating system
- Device identifiers
- Log information
- Session information
- Security and authentication information
Usage and Service Information
- Website interactions
- Product or application usage
- Workflow and integration activity
- Error and diagnostic information
- Audit and operational information
Communication Information
- Contact-form submissions
- Support requests
- Email communications
- Feedback
- Survey responses where applicable
Integration and Project Data
Where customers configure integrations or applications, DevRabbit may process information transmitted between connected systems. The types of personal data contained in that information are determined by the customer, the project scope, and the connected systems.
6. Lawful Bases for Processing
Where GDPR applies, DevRabbit may process personal data on one or more of the following bases under Article 6:
Performance of a Contract
- Provide requested services
- Managing customer relationships and accounts
- Provide support
- Processing transactions
- Perform contractual obligations
Legitimate Interests
- Protecting the security of our services
- Preventing fraud and abuse
- Improving products and services
- Managing business relationships
- Maintaining service reliability
- Conducting appropriate B2B communications
- Defending legal claims
- Protecting our systems and property
Consent
Where required, DevRabbit may rely on consent for non-essential cookies, certain analytics technologies, certain marketing communications, and other optional processing. Consent may be withdrawn at any time.
Legal Obligations
DevRabbit may process personal data where necessary to comply with legal, regulatory, accounting, tax, security, or law-enforcement obligations.
7. Data Minimization and Purpose Limitation
DevRabbit seeks to process only the personal data reasonably necessary for defined and legitimate purposes.
Where DevRabbit processes customer data as a processor, customer-configured applications, integrations, and workflows determine what information is transmitted. DevRabbit will not intentionally use customer personal data for unrelated purposes except as permitted by the applicable agreement or law.
8. Security and Technical Safeguards
DevRabbit implements technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, disclosure, destruction, or unlawful processing.
- Encryption in transit and, where applicable, at rest
- Authentication and access controls
- Role-based access controls
- Security monitoring and logging
- Incident response procedures
- Backup and recovery controls
- Vulnerability and security management
- Confidentiality obligations
- Secure application and API practices
The precise safeguards may vary according to the service, project, customer environment, and risk profile. The existing DevRabbit privacy policy publicly references firewall barriers, encryption techniques, and authentication procedures.
9. Subprocessors
DevRabbit may engage third-party service providers to support the delivery and operation of its services. Depending on the service, these providers may support:
- Cloud infrastructure and hosting
- Storage
- Authentication
- Security
- Monitoring
- Customer support
- CRM
- Analytics
- Communications
- Payment processing
- Other essential business functions
Where DevRabbit acts as a processor, subprocessors should be engaged subject to applicable contractual and data-protection requirements.
10. International Data Transfers
DevRabbit may process or transfer personal data outside the EEA, including to the United States.
Where GDPR restricts an international transfer, DevRabbit will use an appropriate transfer mechanism recognized under applicable law.
Depending on the circumstances, this may include:
- An adequacy decision;
- EU Standard Contractual Clauses (SCCs).
- Appropriate supplementary safeguards.
- An applicable certification or approved mechanism.
- Another lawful transfer mechanism recognized under GDPR.
Where required, DevRabbit will assess transfer risks and implement appropriate technical, contractual, and organizational safeguards.
11. Data Retention and Deletion
DevRabbit retains personal data only for as long as necessary for the applicable processing purpose, unless a longer period is required or permitted by law.
Retention may depend on:
- Purpose of processing
- Nature of the information
- Sensitivity of the data
- Contractual requirements
- Legal obligations
- Security requirements
- Regulatory requirements
- Dispute resolution
- Establishment or defense of legal claims
When personal data is no longer required, DevRabbit will delete, anonymize, or securely dispose of it in accordance with applicable procedures.
For customer data processed as a processor, deletion and return requirements should be governed by the applicable DPA, statement of work, service agreement, and customer instructions.
12. Data Subject Rights Under GDPR
Individuals whose personal data is subject to GDPR may have the following rights:
Right of Access
You may request confirmation of whether DevRabbit processes your personal data and, where applicable, request access to that information.
Right to Rectification
You may request correction of inaccurate or incomplete personal data.
Right to Erasure
You may request deletion of personal data in circumstances provided by GDPR. This right is subject to applicable exceptions, including legal obligations and the establishment, exercise, or defense of legal claims.
Right to Restriction
You may request restriction of processing in circumstances provided by GDPR.
Right to Data Portability
Where applicable, you may request personal data you provided to DevRabbit in a structured, commonly used, and machine-readable format.
Right to Object
You may object to certain processing based on legitimate interests or other applicable grounds. You may object to direct marketing at any time.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw consent at any time.
Rights Regarding Automated Decision-Making
Where applicable, GDPR provides rights relating to decisions based solely on automated processing, including profiling, where such processing produces legal or similarly significant effects.
13. How to Exercise Your GDPR Rights
To submit a GDPR request, contact:
Privacy Contact: security@devrabbit.com
Please include, where relevant:
- Your name
- Contact information
- Organization, if relevant
- The right you wish to exercise
- Sufficient information to help us identify the relevant personal data
We may request additional information where reasonably necessary to verify your identity and protect personal data against unauthorized disclosure.
Where GDPR applies, we generally respond to valid requests without undue delay and, in principle, within one month. Where permitted, this period may be extended by up to two additional months where necessary because of the complexity or number of requests.
14. Right to Lodge a Complaint
You have the right to lodge a complaint with a competent data-protection supervisory authority if you believe DevRabbit's processing of your personal data violates applicable law.
You may generally contact the supervisory authority in the country where you live, work, or believe an infringement occurred.
You are not required to contact DevRabbit before exercising this right. However, we encourage individuals to contact us first so we can investigate and attempt to resolve privacy concerns.
15. Special Categories of Personal Data
DevRabbit does not intentionally request special-category personal data for general website or marketing activities.
Special categories under GDPR include information concerning:
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade-union membership
- Genetic data
- Biometric data used for uniquely identifying an individual
- Health data
- Sex life or sexual orientation
Customers may configure applications or integrations that transmit information containing special-category data. Where DevRabbit acts as a processor, such processing is performed according to customer instructions and applicable contractual requirements.
Customers are responsible for ensuring that they have an appropriate legal basis and, where required, an additional condition under Article 9 GDPR.
16. Automated Decision-Making and Profiling
DevRabbit may use automation, analytics, and AI-assisted functionality in connection with product development, workflow automation, mapping, data analysis, service improvement, security, and operational processes.
DevRabbit does not intend to use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
Where such processing is introduced and GDPR requirements apply, DevRabbit will provide appropriate information and implement applicable safeguards and individual rights.
18. Marketing Communications
DevRabbit may send marketing communications where permitted by applicable law. These may include:
- Service and product announcements
- Educational resources
- Webinars and events
- Industry content
- Company updates
- Product- or service-related offers
You may opt out at any time using the unsubscribe mechanism in marketing communications or by contacting DevRabbit.
Withdrawal from marketing communications does not affect essential service, security, transactional, or account-related communications.
19. Personal Data Obtained From Third Parties
DevRabbit may receive personal data from third-party sources where permitted by applicable law. These sources may include:
- Customers
- Business partners
- Referral partners
- Professional networking platforms
- Publicly available business sources
- Recruiting providers
- Lead-generation providers
- Analytics providers
- CRM and marketing platforms
- Third-party applications connected by customer solutions
Where required under GDPR, DevRabbit will provide appropriate information concerning the source of personal data and the purposes and legal basis for processing.
20. Personal Data Breaches
DevRabbit maintains procedures designed to identify, assess, contain, investigate, and respond to personal-data incidents.
Where DevRabbit acts as a processor, DevRabbit will notify affected customers of qualifying personal-data breaches in accordance with the applicable DPA and legal requirements.
Where DevRabbit acts as a controller, DevRabbit will assess notification obligations and notify the relevant supervisory authority and affected individuals where required by applicable law.
21. Accountability and Privacy by Design
DevRabbit incorporates privacy and security considerations into its technology and operational processes where appropriate.
- Data minimization
- Access controls
- Privacy-conscious system design
- Security by design
- Purpose limitation
- Retention controls
- User permissions
- Auditability
- Risk-based security controls
Where required by GDPR, DevRabbit may conduct Data Protection Impact Assessments (DPIAs) or other privacy-risk assessments for processing activities likely to result in a high risk to individuals.
22. Children's Data
DevRabbit's existing privacy policy states that its services are not directed to persons under 18.
DevRabbit does not knowingly collect children's personal data where prohibited by applicable law. If we become aware that personal data has been collected from a child in circumstances where collection is unlawful, we will take appropriate steps to delete it.
23. EU Representative
- Name: DevRabbit Compliance Team
- Email: compliance@devrabbit.com
24. Data Protection Officer
- Name: DevRabbit Compliance Team
- Email: compliance@devrabbit.com
26. Updates to This GDPR Page
DevRabbit may update this GDPR page from time to time to reflect changes to:
- Applicable privacy laws
- Regulatory guidance
- DevRabbit products and services
- Data-processing activities
- Security practices
- International transfer mechanisms
- Privacy rights and procedures
The Effective Date and Last Updated date at the beginning of this page identify the current version. Where required, DevRabbit may provide additional notice of material changes.
We work with your preferred vendor












