SDLC.dev Logo
SDLC.dev
GDPR Compliant

Privacy Policy

Your privacy is important to us. This policy explains how we collect, use, and protect your data.

Last updated: 7/18/2025

Effective date: 7/18/2025

Experimental Platform Notice

Important: SDLC.dev is an experimental platform provided for research and development purposes. This Privacy Policy applies to our experimental services and may be updated frequently as we develop new features.

By using SDLC.dev, you acknowledge that this is an experimental platform and consent to the data practices described in this policy.

Data Controller Information

Service: SDLC.dev (Experimental AI-Powered Development Lifecycle Platform)

Nature: Experimental research and development platform

Purpose: Testing and developing AI-powered SDLC automation tools

Contact: For privacy-related inquiries, please contact us through our platform

Information We Collect

1. Account Information

  • Email address (for authentication)
  • Name (if provided)
  • Authentication tokens from third-party services (GitHub, Google, etc.)
  • Profile information from connected accounts

2. Usage Data

  • Project requirements and descriptions you input
  • Generated documentation and AI responses
  • Integration configurations (JIRA, Confluence, etc.)
  • Usage patterns and feature interactions
  • Error logs and performance metrics

3. Technical Data

  • IP address and location data
  • Browser type and version
  • Device information and screen resolution
  • Operating system
  • Referrer URLs

4. Cookies and Similar Technologies

  • Essential cookies for authentication and security
  • Analytics cookies to understand platform usage
  • Preference cookies to remember your settings
  • Performance cookies to optimize loading times
How We Use Your Information

Legal Basis for Processing (GDPR)

  • Consent: AI model training and improvement
  • Legitimate Interest: Platform security and performance optimization
  • Contract Performance: Providing the experimental services
  • Legal Obligation: Compliance with applicable laws

Specific Uses

  • Generate AI-powered documentation and responses
  • Provide integrations with third-party services
  • Improve our AI models and algorithms
  • Analyze usage patterns to enhance the platform
  • Ensure platform security and prevent abuse
  • Provide customer support and troubleshooting
  • Send important service updates and notifications
Data Sharing and Third Parties

AI Service Providers: We share your input data with AI service providers (OpenAI, Anthropic) to generate responses. These providers have their own privacy policies.

Integration Partners: When you connect third-party services (JIRA, Confluence, GitHub), we share relevant data to provide integration functionality.

Analytics Services: We may use analytics services to understand platform usage patterns.

Legal Requirements: We may disclose data if required by law or to protect our rights and safety.

No Data Sales: We do not sell, rent, or trade your personal data to third parties for marketing purposes.

Data Retention

Account Data: Retained while your account is active and for 30 days after deletion.

Generated Content: Retained for platform improvement and may be used for AI model training.

Usage Analytics: Aggregated and anonymized data may be retained indefinitely for research purposes.

Legal Requirements: Some data may be retained longer to comply with legal obligations.

Experimental Data: As an experimental platform, some data may be retained for ongoing research and development.

Your Rights Under GDPR

If you are in the European Economic Area (EEA), you have the following rights:

  • Access: Request access to your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Portability: Request a copy of your data in a portable format
  • Restriction: Request restriction of processing
  • Objection: Object to processing based on legitimate interest
  • Consent Withdrawal: Withdraw consent for specific processing activities

Note: As an experimental platform, some rights may be limited by our research and development needs, but we will honor all requests to the fullest extent possible.

Cookies Policy

We use cookies and similar technologies to:

  • Essential Cookies: Authentication, security, and basic functionality
  • Analytics Cookies: Understand how you use our platform
  • Preference Cookies: Remember your settings and preferences
  • Performance Cookies: Optimize loading times and performance

You can manage cookie preferences through your browser settings. Note that disabling certain cookies may affect platform functionality.

Our cookie consent banner allows you to accept or reject non-essential cookies in compliance with EU regulations.

Data Security

We implement appropriate technical and organizational security measures:

  • Encryption in transit and at rest
  • Access controls and authentication
  • Regular security audits and monitoring
  • Secure hosting infrastructure
  • Employee training on data protection

Data Breach Notification: We will notify affected users and relevant authorities within 72 hours of discovering a data breach, as required by GDPR.

International Data Transfers

Your data may be transferred to and processed in countries outside the EEA, including the United States, for the following services:

  • AI Services: OpenAI, Anthropic (Claude)
  • Cloud Infrastructure: Hosting and storage providers
  • Analytics: Usage analytics services

We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs)
  • Privacy Shield frameworks where applicable
  • Adequacy decisions by the European Commission
Changes to This Policy

As an experimental platform, this Privacy Policy may be updated frequently. We will:

  • Post updates on this page with the effective date
  • Notify users of significant changes via email or platform notifications
  • Provide 30 days notice for material changes where possible
  • Archive previous versions for reference

Continued use of the platform after changes constitutes acceptance of the updated policy.

Contact Information

For questions about this Privacy Policy or to exercise your rights, please contact us:

Platform: Use the contact form within SDLC.dev

Subject: Privacy Policy Inquiry

Response Time: We aim to respond within 72 hours

Data Protection Officer: As an experimental platform, we do not currently have a designated DPO, but privacy inquiries are handled by our development team.

This Privacy Policy is designed to comply with GDPR and other applicable privacy laws.

SDLC.dev - Experimental AI-Powered Development Lifecycle Platform