Privacy Policy
Last updated: September 26, 2026
Highlighted items are placeholders for company information that must be completed before this document is final.
This policy explains how DevPath Systems processes personal data when you visit devpathsystems.com, contact us or use the website’s AI assistant.
1. Who is responsible for your data
The controller of your personal data is [registered company name], trading as DevPath Systems, with its registered office at [registered office address], registration number (NUIS) [NUIS registration number].
For any question about this policy or your data, contact us at [email protected].
2. What data we collect
We only collect data that you provide or that is technically necessary:
- Contact and quote requests: name, company, email, phone, country, the service you are interested in, budget range, project description and preferred contact method.
- AI assistant: the messages you type, processed to generate answers. If you choose to share your details in the assistant, we receive the name, email and other fields you fill in and, only if you tick the option, the conversation transcript.
- Technical data: IP address and browser information, used for security, abuse prevention and rate limiting. When stored with a request, the IP address is kept only as an irreversible hash.
- Cookies and similar technologies, as described in our Cookie Policy.
3. Why we use your data and on what legal basis
- To answer your request and prepare a proposal — steps taken at your request before a contract, and your consent given in the form.
- To protect the website against spam, fraud and abuse — our legitimate interest in operating a secure service.
- To improve the website through analytics — only with your consent, which you can withdraw at any time.
- To comply with legal obligations, for example accounting and tax rules if we enter into a contract.
4. The AI assistant
The “Ask DevPath AI” assistant answers questions about DevPath Systems. Your messages are sent to our AI technology provider to generate a reply. By default, we do not store conversations after your session ends; your browser keeps the conversation only until you close the tab.
Please do not share sensitive personal data (such as health or financial information) in the assistant. AI answers may contain mistakes and are not binding offers.
5. Who receives your data
We use carefully selected service providers who process data on our behalf and under our instructions:
- Website hosting and infrastructure: [hosting provider]
- Database hosting (when enabled): [database provider]
- Transactional email delivery: [email provider, e.g. Resend]
- AI technology provider for the assistant: [AI provider, e.g. OpenAI]
- Spam protection (when enabled): Cloudflare Turnstile
- Analytics and advertising measurement (only with consent): Google Analytics, Meta
6. International transfers
Some providers may process data outside Albania or the European Economic Area. In that case we rely on appropriate safeguards, such as adequacy decisions or standard contractual clauses approved by the European Commission.
7. How long we keep data
- Contact and quote requests: up to [retention period, e.g. 24 months] after our last exchange, unless a contract follows.
- Data related to a contract: for the period required by law.
- AI assistant conversations: not stored by default. If conversation logging is enabled for quality review, transcripts are deleted after a defined retention period.
- Security logs: for a short period necessary to detect and prevent abuse.
8. Your rights
Subject to applicable law, you have the right to access, correct or delete your data, to restrict or object to its processing, to data portability and to withdraw consent at any time without affecting earlier processing.
To exercise your rights, write to [email protected]. You also have the right to lodge a complaint with a data protection authority — in Albania, the Information and Data Protection Commissioner (IDP); in the EU, the authority of your country of residence, such as the Garante per la protezione dei dati personali in Italy.
9. Security
We protect data with encrypted connections (HTTPS), access controls, server-side validation, rate limiting and by collecting only what is necessary.
10. Changes to this policy
We may update this policy when our services or legal requirements change. The date of the latest version is shown at the top of this page.
