1. Who is responsible for your data
137 Web Design LLC (trading as DA Services, "we", "us", "our") is the controller of the personal data described in this policy. Registered office: Lovech, Bulgaria. Registration: UIC 206358807. Contact: operations@daservices.services.
Where we work inside systems you own and handle personal data belonging to your users, you are the controller and we act as your processor. Section 8 of this policy and Section 11.3 of the Terms cover that case.
2. What this policy covers
It covers our marketing site, the sign-in flow, the client dashboard and the project board, and the email we send you. It does not cover the products we build for you, which you operate under your own privacy policy, or third-party sites we link to.
3. What we collect
3.1 Information you give us
- Account data. Your email address. If you sign in with Google, we also receive your name, profile picture and whether your email is verified.
- Project content. Requests, comments, project and file names, and any files, screenshots or documents you attach to the board.
- Credentials you store. Access details for third-party services you add to a project so we can work on it. These are encrypted at rest and every reveal is logged.
- Communications. Emails you send us, and information you give when booking an intro call.
3.2 Information we collect automatically
- Technical data. IP address, browser and device type, referring page, pages viewed, and timestamps.
- Security and diagnostic logs. Sign-in attempts, verification-code requests, errors and API activity, used to keep the account secure and the service working.
We do not run advertising pixels, cross-site trackers or third-party analytics on this site. If that changes, we will update this policy before turning anything on.
3.3 Information from others
- Stripe. Subscription status, plan, billing country, and the card brand and last four digits. Stripe processes the payment itself. We never see or store your full card number.
- Google. The profile fields listed above, where you choose Google sign-in.
- Calendly. The details you enter when you book a call.
5. Why we use your data, and our legal basis
- Providing the service (creating your account, running the board, delivering work, support). Basis: performance of a contract.
- Authentication and security (login codes, session cookies, abuse and fraud prevention, logging). Basis: performance of a contract, and our legitimate interest in keeping accounts secure.
- Billing and subscription management. Basis: performance of a contract, and legal obligation for invoicing and tax records.
- Service email (login codes, delivery and comment notifications, changes to terms). Basis: performance of a contract.
- Improving the service (diagnosing errors, measuring delivery performance, planning capacity). Basis: our legitimate interest in operating and improving a reliable service.
- Marketing email, where you ask for it. Basis: consent, which you can withdraw at any time from the unsubscribe link in every message.
- Complying with law and establishing, exercising or defending legal claims. Basis: legal obligation, and legitimate interest.
Where we rely on legitimate interests, we have weighed them against your rights and freedoms. Ask us for the assessment at any time.
6. Project content and stored credentials
Board content, attachments and files are private to your account and to the members of our team working on your project. Files are held in private object storage and served only through short-lived signed links, so an object cannot be read without an authorisation check first.
Credentials you store on a project are encrypted with AES-256-GCM before they are written to the database, decrypted only when an authorised user reveals them, and each reveal is recorded. Rotate any credential after a project ends, which is good practice regardless of who held it.
7. Aggregated and de-identified data
We produce aggregated and de-identified statistics from running the platform, such as delivery times, queue volumes and error rates. Once data is in that form it no longer identifies anyone and is not personal data, and we use it as described in Section 11 of the Terms. We do not attempt to re-identify it.
8. AI-assisted development
We use AI coding assistants when we build. Project content may be processed by those tools where it is needed to do the work. We select providers whose terms exclude customer content from training their models, and our confidentiality obligations under Section 12 of the Terms apply whatever tooling is involved. Tell us in writing if you want your project excluded from AI-assisted tooling and we will confirm whether we can accommodate it.
10. International transfers
Some processors are outside the European Economic Area, mainly in the United States. Where data leaves the EEA we rely on an adequacy decision where one applies, or on the European Commission's Standard Contractual Clauses with supplementary technical measures such as encryption in transit and at rest. Ask us for a copy of the safeguards for a particular transfer.
11. How long we keep it
- Login codes. 10 minutes, then they expire and are overwritten.
- Session cookies. 30 days, or until you sign out.
- Account data. While your account is open, then up to 3 years after closure for legal claims and records.
- Project content, attachments and stored credentials. While your account is open, and for 60 days after termination, after which we delete them from active systems. Backups age out on a rolling schedule.
- Billing and invoice records. For the period Bulgarian accounting and tax law requires, currently up to 10 years for accounting records.
- Security and diagnostic logs. Up to 12 months.
Ask for earlier deletion at any time and we will comply unless we have to keep something for a legal reason, in which case we will tell you what and why.
12. Security
- Traffic is encrypted in transit with TLS.
- Sign-in is passwordless, so there is no password of yours for us to lose.
- Stored credentials are encrypted at rest with AES-256-GCM under a key held outside the database.
- Files sit in private storage and are reachable only through short-lived signed URLs issued after an ownership check.
- Access to production data is limited to team members who need it for the work.
- Card data never reaches our servers. Stripe handles it.
No system is immune to every attack. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours where required, and notify you without undue delay where the risk is high.
13. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you and receive a copy.
- Have inaccurate data corrected and incomplete data completed.
- Have your data erased where there is no continuing lawful basis to hold it.
- Restrict processing while a dispute about accuracy or legitimate interests is resolved.
- Receive your data in a portable, machine-readable format, or have it sent directly to another controller where technically feasible.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent, where consent is the basis, without affecting processing that already happened.
- Complain to a supervisory authority.
Exercise any of these by writing to operations@daservices.services. We respond within one month and may ask you to confirm your identity first. There is no charge unless a request is manifestly unfounded or excessive.
Our lead supervisory authority is the Commission for Personal Data Protection (Комисия за защита на личните данни), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria, https://www.cpdp.bg. You may also complain to the authority in your own country of residence or workplace.
14. Notice for United States residents
If you live in California or another US state with comprehensive privacy legislation, you have the right to know what personal information we collect and why, to request a copy, to request correction or deletion, and not to be discriminated against for exercising those rights.
We collect the categories described in Section 3: identifiers, commercial information about your subscription, internet activity in the form of technical and diagnostic logs, and the content you upload to your board. We do not sell personal information and we do not share it for cross-context behavioural advertising, under any definition of those terms. Use the same contact address in Section 13 to make a request.
15. Children
The Services are for businesses and people aged 18 or over. We do not knowingly collect data from children. If you believe a child has given us personal data, write to us and we will delete it.
16. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not profile you for that purpose.
17. Changes to this policy
We update this policy when our practices or the law change. The current version is always on this page with its "Last updated" date. For changes that affect your rights we give notice by email or in the dashboard before they take effect.
18. Contact
Privacy questions and requests go to operations@daservices.services, or by post to 137 Web Design LLC, Lovech, Bulgaria.
Questions about this document
Write to operations@daservices.services and a person will answer. If a clause reads badly for your situation, say so before you subscribe and we will tell you whether we can vary it in writing.
See also: Terms of Service and Privacy Policy.