Devopstrio logoDevopstrio
Devopstrio Governance & Trust

GDPR Compliance

How Devopstrio adheres to European data protection standards, safeguarding rights, implementing DPAs, and establishing secure technical boundaries.

Last Updated: June 16, 2026

01GDPR Commitment Statement

The General Data Protection Regulation (GDPR) is a comprehensive data privacy law in the European Union (EU) that regulates how personal data is collected, handled, and protected.

At Devopstrio, we prioritize the trust, security, and privacy of our global client network. We are fully aligned with the requirements of the GDPR. We ensure that all personal data belonging to EU citizens and residents processed by our co-engineering pipelines, cloud orchestration platforms, and consulting teams is handled with the highest standards of confidentiality, integrity, and safety.

02Core Data Protection Principles

All personal data processing activities conducted by Devopstrio adhere strictly to the fundamental principles set forth in Article 5 of the GDPR:

  • Lawfulness, Fairness, and Transparency: We process data lawfully and fair, explaining all data collection operations clearly.
  • Purpose Limitation: Personal data is collected only for specified, explicit, and legitimate business purposes, and is not processed in a manner incompatible with those intentions.
  • Data Minimization: We limit personal data collection to what is strictly necessary in relation to the purposes for which they are processed.
  • Accuracy: We take every reasonable step to ensure inaccurate personal data is erased or corrected without delay.
  • Storage Limitation: Data is kept in a form which permits identification of data subjects for no longer than is necessary.
  • Integrity and Confidentiality: We handle data using appropriate technical and organizational security measures to prevent accidental loss, damage, or unauthorized access.

03Your Data Subject Rights

Under the GDPR, individuals residing in the European Economic Area (EEA) have specific enforceable rights regarding their personal data:

Right of Access

You can request confirmation as to whether your personal data is being processed, and request a structured copy of that data.

Right to Rectification

You have the right to request that we correct any inaccurate or incomplete personal data about you.

Right to Erasure

Also known as the “Right to be Forgotten,” you can request that we delete your personal data under certain legal grounds.

Right to Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format to transfer to another entity.

To submit a Data Subject Access Request (DSAR), please contact our DPO at dpo@devopstrio.com. We will respond to your request within 30 days.

04Processor vs Controller Roles

Depending on how we interact with your data, Devopstrio operates under two legal statuses:

  • As a Data Controller: We act as a controller for the personal data of our website visitors, newsletter subscribers, job applicants, and client account managers. In these cases, we determine the purposes and means of processing.
  • As a Data Processor: We act as a processor when rendering engineering, DevOps, and cloud services for our enterprise clients. In this capacity, we process personal data strictly in accordance with the client's documented instructions and the executed Data Processing Agreement (DPA).

05International Transfers & SCCs

Devopstrio is a global company. In order to provide continuous 24/7 technical engineering, support, and consulting services, personal data may be accessed or processed by our personnel in engineering centers located outside the EU/EEA (such as in the USA and India).

To ensure all personal data receives an adequate level of protection when transferred outside the EEA, we implement:

  • Standard Contractual Clauses (SCCs): We use the EU-approved Standard Contractual Clauses for transfers of personal data to controllers and processors established in third countries.
  • Supplementary Measures: We apply supplementary security measures, such as encryption before transmission, to shield the data from unauthorized access in transit.

06Technical & Organizational Security Measures

To comply with Article 32 of the GDPR, we have implemented state-of-the-art technical and organizational measures to ensure a level of security appropriate to the risks of data processing:

  • Data Encryption: Encryption of all personal data in transit using TLS 1.3 and at rest using AES-256.
  • Access Control: Implementing strictly enforced multi-factor authentication (MFA) and Least-Privilege access profiles.
  • Security Auditing: Regular vulnerability scanning, internal network pen-testing, and SOC 2 Type II audit alignments.
  • Employee Training: Mandatory annual security and privacy compliance training for all Devopstrio developers and engineers.

07Data Breach Notification Protocol

In the event of a confirmed security incident resulting in the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data, Devopstrio will invoke its Incident Response Protocol. Under this policy, we commit to notifying the relevant supervisory authorities within 72 hours of becoming aware of the breach, and notifying impacted clients and individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms.

08Authorized Sub-Processors

Devopstrio works with third-party service providers (sub-processors) to deliver cloud hosting, CRM services, and website analytics. All sub-processors are vetted for security and are required to enter into DPAs that match our GDPR commitments.

Entity NameService ProvidedLocation
Amazon Web Services (AWS)Cloud Infrastructure HostingUSA / EU (Ireland)
Google Cloud Platform (GCP)Data Analytics & StagingUSA / EU (Frankfurt)
Microsoft AzureEnterprise Dev EnvironmentsUSA / EU (Netherlands)
HubSpotClient Relationship Management (CRM)USA

09Data Protection Officer (DPO)

Devopstrio has appointed a dedicated Data Protection Officer to supervise compliance with data protection laws and serve as a direct point of contact for regulatory bodies and data subjects.

Devopstrio Data Protection Officer

Attention: Legal & Trust Department

Email: dpo@devopstrio.com

Address: Devopstrio Limited, One World Trade Center, Floor 85, New York, NY 10007, USA

Have questions about our terms or practices?

Our dedicated trust, risk, and compliance department is here to help address any inquiries regarding data protection, security controls, or service definitions.

Contact Trust Team
GDPR Compliance | Devopstrio