Last updated: 14-09-2026

Privacy Policy

1. Who We Are

DevSynth is the trading name of DEVSYNTH LLC, a limited liability company registered in the State of Florida, United States, with its registered address at St. Petersburg, FL 33702 United States. In this policy, “DevSynth”, “we”, “us”, and “our” refer to that company.

We are a software development consultancy. We build web applications, mobile applications, cloud infrastructure, and AI systems for business clients, primarily in the United States and Canada.

This policy explains what information we collect through devsynth.us, why we collect it, who we share it with, how long we keep it, and what rights you have over it.

2. Scope of This Policy

This policy covers:

  • The devsynth.us website, including all location pages, service pages, case studies, and forms
  • Enquiries, proposals, and communications with prospective clients
  • Information we hold about client contacts during and after an engagement
  • Applications and enquiries sent to us by individuals

This policy does not cover:

  • Data we process inside a client’s own product or systems while working under a signed agreement. In those cases the client is the data controller and we act as a processor under that agreement. Section 12 explains this in more detail
  • Third party websites that we link to. Their own policies apply

3. Information We Collect

3.1 Information you give us directly

When you complete a contact or Get Started form, book a call, email us, or message us on a professional network, we may collect:

  • Full name
  • Business email address
  • Company or organisation name
  • Job title or role
  • Phone number, where you provide it
  • Country or region
  • Project details you choose to share, such as budget range, timeline, target platforms, and technical requirements
  • Any files, documents, or briefs you attach
  • The content of your messages and our replies

3.2 Information collected automatically

When you browse devsynth.us we and our analytics providers may collect:

  • IP address, which may be truncated or anonymised depending on the tool
  • Approximate location derived from IP address, usually at city or region level
  • Browser type and version, operating system, device type, and screen resolution
  • Referring URL and exit pages
  • Pages viewed, time on page, scroll depth, and clicks
  • Date and time of visit
  • Cookie identifiers and similar device identifiers

3.3 Information from third parties

We may receive limited information from:

  • Business networking and advertising platforms, where you interact with our page or ads
  • Publicly available business directories and company registries, used to verify prospective client details
  • Referral partners who introduce you to us, where they have a lawful basis to share your details

3.4 What we do not collect

We do not knowingly collect payment card numbers through this website. Invoicing and payment are handled through named third party providers under a signed engagement. We do not seek special category data such as health, biometric, racial or ethnic origin, religious belief, or political opinion, and we ask that you do not send it to us through our forms.

4. Why We Use Your Information

Purpose

Examples

Legal basis where GDPR or UK GDPR applies

Respond to enquiries

Replying to a form submission, scoping a project, sending a proposal

Steps taken at your request before entering a contract

Deliver services

Project communication, delivery, invoicing, support

Performance of a contract

Improve the website

Understanding which location and service pages perform, fixing errors

Legitimate interests

Marketing

Sending relevant updates to business contacts who have opted in

Consent, or legitimate interests for existing clients

Security

Detecting spam submissions, abuse, and attempted intrusion

Legitimate interests

Legal and accounting

Retaining records required by Florida and US federal law

Legal obligation

5. Cookies and Similar Technologies

We use a limited set of cookies and similar technologies:

  • Strictly necessary. Required for the site to function, including session handling, security, and form submission. These cannot be switched off
  • Analytics. Used to understand traffic and page performance through Google GA4. These help us decide which markets and services to build pages for
  • Advertising. Where we run paid campaigns, platform pixels may record that you visited a page so we can measure campaign performance and show relevant ads
  • Preference. Remember settings such as cookie choices

You can control cookies through our cookie banner where one is shown, and through your browser settings. Blocking strictly necessary cookies may break parts of the site, including forms.

6. How We Share Information

We do not sell your personal information. We share it only in these situations:

  • Service providers. Hosting, email, analytics, scheduling, and communication tools that process data on our instructions under written terms
  • Our team. DevSynth operates a distributed senior team. Team members in Asia, North America, and the Middle East may access enquiry and project information where it is necessary for their role. All team members are bound by confidentiality obligations
  • Subcontractors. Where a project requires specialist input, and only under confidentiality terms
  • Professional advisers. Accountants, auditors, insurers, and lawyers, where necessary
  • Legal and regulatory. Where required by law, court order, or a lawful request from a public authority
  • Business transfer. If DevSynth is involved in a merger, acquisition, or asset sale, your information may transfer to the successor entity under the same protections

7. International Data Transfers

DevSynth is registered in the United States and our team is distributed across Asia, North America, and the Middle East. Your information may be accessed from, stored in, or transferred to any of these countries.

Some of these countries have not received an adequacy decision from the European Commission or the UK Government. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards, including Standard Contractual Clauses and, where relevant, the UK International Data Transfer Addendum, together with supplementary technical and organizational measures such as access controls and encryption in transit.

You can request a copy of the safeguards we use by writing to Info@devsynth.oceanwebdesigns.com.

8. How Long We Keep Information

Data

Retention

Enquiries that do not convert

24 months from last contact, then deleted or anonymised

Client contact and project records

Duration of the engagement plus 7 years to meet US tax and record-keeping requirements

Signed contracts and invoices

7 years from the end of the financial year in which they were issued

Website analytics

Up to 26 months, or the retention period set by the analytics provider

Marketing contacts

Until you unsubscribe, plus a suppression record so we do not contact you again.

Job or collaboration enquiries

12 months, unless you ask us to keep them on file

9. Security

We apply technical and organisational measures proportionate to the risk, including encrypted connections (TLS) across the website, access controls on a need-to-know basis, multi-factor authentication on business-critical accounts, credential management for team members across all locations, and regular review of third-party access.

No method of transmission or storage is completely secure. If we become aware of a breach affecting your personal data, we will notify you and any relevant regulator where the law requires it.

10. Your Rights

Depending on where you live, you may have some or all of the following rights:

  • Access. Request a copy of the personal information we hold about you
  • Correction. Ask us to fix information that is inaccurate or incomplete
  • Deletion. Ask us to delete information where we no longer have a lawful reason to keep it
  • Restriction. Ask us to limit how we use your information while a query is resolved
  • Objection. Object to processing based on legitimate interests, including direct marketing
  • Portability. Receive certain information in a structured, machine readable format
  • Withdraw consent. Where we rely on consent, withdraw it at any time without affecting earlier processing
  • Non discrimination. We will not treat you differently for exercising any of these rights

To exercise any right, email info@devsynth.oceanwebdesigns.com with the words “Privacy Request” in the subject line. We will respond within 30 days, or within 45 days for requests under California law, and will tell you if we need an extension. We may ask you to verify your identity before we act.

10.1 California residents (CCPA and CPRA)

If you are a California resident you may request disclosure of the categories and specific pieces of personal information we have collected, the categories of sources, our business purpose, and the categories of third parties with whom we share it. You may also request deletion or correction, and you may limit the use of sensitive personal information.

We do not sell personal information and we do not share personal information for cross context behavioural advertising in the sense defined by the CPRA. You may designate an authorised agent to make a request on your behalf, with written proof of authorisation.

10.2 Residents of the EEA and the United Kingdom

You have the rights listed in section 10 under the GDPR and UK GDPR. You also have the right to lodge a complaint with your national supervisory authority, or with the Information Commissioner’s Office in the United Kingdom.

10.3 Canadian residents

Under PIPEDA you may access the personal information we hold about you and challenge its accuracy. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada.

11. Marketing Communications

We send marketing email only to business contacts who have asked to hear from us or who have an existing commercial relationship with us. Every marketing email includes an unsubscribe link. Unsubscribing from marketing does not stop service and project emails relating to an active engagement.

12. Client Project Data

When we work on a client’s product, that client’s end user data may pass through systems we build, configure, or maintain. In those cases the client decides why and how that data is processed, so the client is the controller and DevSynth acts as a processor. Our responsibilities are set by the signed agreement, which may include a Data Processing Addendum.

If you are an end user of a product DevSynth helped build, please contact the operator of that product to exercise your rights. We will support our client in responding.

13. Children

Our website and services are aimed at businesses. We do not direct our services to children and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact info@devsynth.oceanwebdesigns.com and we will delete it.

14. Third Party Links

Our website links to third party sites such as portfolio platforms, professional networks, and client products. We are not responsible for their content or privacy practices. Read their policies before sharing information with them.

15. Automated Decision Making

We do not make decisions that produce legal or similarly significant effects about you using automated processing alone.

16. Changes to This Policy

We may update this policy to reflect changes in our services, technology, or the law. The effective date at the top shows when it was last revised. Material changes will be flagged on this page for a reasonable period. Continued use of devsynth.us after an update means you accept the revised policy.

17. Contact Us

For any privacy question or request: DevSynth (DEVSYNTH LLC) St. Petersburg, FL 33702 United States Email: >info@devsynth.oceanwebdesigns.com General enquiries: info@devsynth.oceanwebdesigns.com Phone: +1 (727) 405-4545