01GDPR Commitment Statement
The General Data Protection Regulation (GDPR) is a comprehensive data privacy law in the European Union (EU) that regulates how personal data is collected, handled, and protected.
At Devopstrio, we prioritize the trust, security, and privacy of our global client network. We are fully aligned with the requirements of the GDPR. We ensure that all personal data belonging to EU citizens and residents processed by our co-engineering pipelines, cloud orchestration platforms, and consulting teams is handled with the highest standards of confidentiality, integrity, and safety.
02Core Data Protection Principles
All personal data processing activities conducted by Devopstrio adhere strictly to the fundamental principles set forth in Article 5 of the GDPR:
- Lawfulness, Fairness, and Transparency: We process data lawfully and fair, explaining all data collection operations clearly.
- Purpose Limitation: Personal data is collected only for specified, explicit, and legitimate business purposes, and is not processed in a manner incompatible with those intentions.
- Data Minimization: We limit personal data collection to what is strictly necessary in relation to the purposes for which they are processed.
- Accuracy: We take every reasonable step to ensure inaccurate personal data is erased or corrected without delay.
- Storage Limitation: Data is kept in a form which permits identification of data subjects for no longer than is necessary.
- Integrity and Confidentiality: We handle data using appropriate technical and organizational security measures to prevent accidental loss, damage, or unauthorized access.
03Your Data Subject Rights
Under the GDPR, individuals residing in the European Economic Area (EEA) have specific enforceable rights regarding their personal data:
You can request confirmation as to whether your personal data is being processed, and request a structured copy of that data.
You have the right to request that we correct any inaccurate or incomplete personal data about you.
Also known as the “Right to be Forgotten,” you can request that we delete your personal data under certain legal grounds.
You have the right to receive your personal data in a structured, commonly used, machine-readable format to transfer to another entity.
To submit a Data Subject Access Request (DSAR), please contact our DPO at dpo@devopstrio.com. We will respond to your request within 30 days.
04Processor vs Controller Roles
Depending on how we interact with your data, Devopstrio operates under two legal statuses:
- As a Data Controller: We act as a controller for the personal data of our website visitors, newsletter subscribers, job applicants, and client account managers. In these cases, we determine the purposes and means of processing.
- As a Data Processor: We act as a processor when rendering engineering, DevOps, and cloud services for our enterprise clients. In this capacity, we process personal data strictly in accordance with the client's documented instructions and the executed Data Processing Agreement (DPA).
05International Transfers & SCCs
Devopstrio is a global company. In order to provide continuous 24/7 technical engineering, support, and consulting services, personal data may be accessed or processed by our personnel in engineering centers located outside the EU/EEA (such as in the USA and India).
To ensure all personal data receives an adequate level of protection when transferred outside the EEA, we implement:
- Standard Contractual Clauses (SCCs): We use the EU-approved Standard Contractual Clauses for transfers of personal data to controllers and processors established in third countries.
- Supplementary Measures: We apply supplementary security measures, such as encryption before transmission, to shield the data from unauthorized access in transit.
06Technical & Organizational Security Measures
To comply with Article 32 of the GDPR, we have implemented state-of-the-art technical and organizational measures to ensure a level of security appropriate to the risks of data processing:
- Data Encryption: Encryption of all personal data in transit using TLS 1.3 and at rest using AES-256.
- Access Control: Implementing strictly enforced multi-factor authentication (MFA) and Least-Privilege access profiles.
- Security Auditing: Regular vulnerability scanning, internal network pen-testing, and SOC 2 Type II audit alignments.
- Employee Training: Mandatory annual security and privacy compliance training for all Devopstrio developers and engineers.
07Data Breach Notification Protocol
In the event of a confirmed security incident resulting in the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data, Devopstrio will invoke its Incident Response Protocol. Under this policy, we commit to notifying the relevant supervisory authorities within 72 hours of becoming aware of the breach, and notifying impacted clients and individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
08Authorized Sub-Processors
Devopstrio works with third-party service providers (sub-processors) to deliver cloud hosting, CRM services, and website analytics. All sub-processors are vetted for security and are required to enter into DPAs that match our GDPR commitments.
| Entity Name | Service Provided | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud Infrastructure Hosting | USA / EU (Ireland) |
| Google Cloud Platform (GCP) | Data Analytics & Staging | USA / EU (Frankfurt) |
| Microsoft Azure | Enterprise Dev Environments | USA / EU (Netherlands) |
| HubSpot | Client Relationship Management (CRM) | USA |
09Data Protection Officer (DPO)
Devopstrio has appointed a dedicated Data Protection Officer to supervise compliance with data protection laws and serve as a direct point of contact for regulatory bodies and data subjects.
Devopstrio Data Protection Officer
Attention: Legal & Trust Department
Email: dpo@devopstrio.com
Address: Devopstrio Limited, One World Trade Center, Floor 85, New York, NY 10007, USA
Have questions about our terms or practices?
Our dedicated trust, risk, and compliance department is here to help address any inquiries regarding data protection, security controls, or service definitions.
