Privacy Policy

Last update: 19/08/2026

1. Who Is the Data Controller?

ECO Impact Tech, S.L. (hereinafter "DEVERA" or "we"), with Tax ID B56263155 and registered address at Calle de la Travesía, S/N, Edificio La Terminal, ZIP Code 46024 Valencia (Spain), is the controller of your personal data.

DEVERA is the owner of the domain "devera.ai" as well as the website and platform (accessible at app.devera.ai), which is made available to its Clients and Users for automated Product Carbon Footprint (PCF) analysis services following the ISO 14067:2018 standard.

Contact: info@devera.ai


2. What Personal Data Do We Collect and Process?

2.1 Website Browsing Data

Aspect Details
Role of DEVERAData Controller
Data collectedBrowsing metrics, IP address, location (country, region, city), usage preferences, language, time spent on page, device data (operating system, browser)
Method of collectionThrough navigation within our website environment and cookies
Legal basisUser consent and our legitimate interest as data controllers
Retention periodMaximum of 18 months, unless the data subject withdraws consent
DisclosureData collected by technical cookies may be disclosed to our web hosting providers (Cloudflare)
International transfersNo transfers to third countries outside adequate safeguards are anticipated

2.2 User Account Data

When you create an account on our platform, we collect:

Aspect Details
Data collectedFull name, email address, password (encrypted), company name (optional), profile picture (optional)
Method of collectionDirectly from users during registration or via our OAuth provider (Google)
PurposeAccount creation, authentication, service provision, and communication
Legal basisPerformance of a contract and user consent
Retention periodFor the duration of the active account, plus any legally required retention period after deletion
DisclosureAuthentication provider (Google) if OAuth is used
International transfersOur OAuth provider may process data in the US under appropriate safeguards (EU-US Data Privacy Framework or Standard Contractual Clauses)

2.3 Payment and Billing Data

When you purchase credits:

Aspect Details
Data collectedBilling name, billing address, VAT number (if applicable), transaction history, credit balance
Payment card dataProcessed directly by Stripe; DEVERA does not store or have access to full card numbers
Method of collectionThrough Stripe's secure payment interface
PurposePayment processing, invoicing, and compliance with tax obligations
Legal basisPerformance of a contract and legal obligation
Retention periodTransaction records retained for 6 years as required by Spanish tax law
DisclosureStripe (payment processor)
International transfersStripe may process data in the US under appropriate safeguards

For more information, see Stripe's Privacy Policy.

2.4 Product and Analysis Data (PCF Tool)

When you use our Product Carbon Footprint analysis tool:

Aspect Details
Data collectedProduct information (name, description, ingredients/materials, weights, suppliers), manufacturing process data, transport information, packaging details, uploaded documents (Excel files, PDFs)
Method of collectionDirectly from users through the platform interface or file uploads
PurposeTo calculate Product Carbon Footprint following ISO 14067:2018 methodology
Legal basisPerformance of a contract
Retention periodFor the duration of the active account; deleted within 30 days of account closure
DisclosureSee Section 3 (AI Services)
International transfersSee Section 3 (AI Services)

Important: We understand that product data may contain sensitive business information (formulations, supplier details, proprietary processes). We treat all product data as confidential and implement appropriate security measures to protect it.

2.5 Generated Reports and Analysis Results

Aspect Details
Data collectedPCF analysis reports, emission calculations, phase breakdowns, AI-generated insights, report versions
Method of collectionGenerated by our platform based on user inputs
PurposeTo provide the contracted PCF analysis service
Legal basisPerformance of a contract
Retention periodFor the duration of the active account; users may delete individual reports at any time
DisclosureReports may be shared publicly if the user enables the sharing feature

2.6 Contact Form Data

Aspect Details
Data collectedName, email address, company name, message content, inquiry type
Method of collectionDirectly from users through contact forms
PurposeTo respond to inquiries and provide requested information
Legal basisUser consent and legitimate interest
Retention periodMaximum of 12 months after the inquiry is resolved
DisclosureMay be shared with our customer support tools

2.7 API Access Data

Aspect Details
Data collectedAPI key identifiers, usage logs, request metadata (endpoints, timestamps, IP addresses)
Method of collectionAutomatically when using the API
PurposeAuthentication, rate limiting, usage monitoring, and abuse prevention
Legal basisPerformance of a contract
Retention periodAPI keys retained while active; usage logs retained for 12 months
DisclosureNone

2.8 Guest Analysis Data

Aspect Details
Data collectedIP address, browser fingerprint, analysis timestamp
Method of collectionAutomatically during trial analysis
PurposeTo enforce the one-trial-per-user limit and prevent abuse
Legal basisLegitimate interest
Retention period12 months
DisclosureNone

3. Use of Artificial Intelligence Services

Our platform uses AI models (Anthropic Claude) to analyze product information and generate insights. For product analysis, these models run within our own AWS cloud infrastructure in the EU: Anthropic supplies the model, and AWS hosts and runs it inside EU data centers under our control, so your product data is not transmitted to the AI model provider's own infrastructure.

One optional feature is an exception: if you ask us to extract product information from a public URL or an uploaded document, that content is sent to Anthropic's API directly in order to perform a web search. This feature is optional, is not used when product data is submitted directly through the platform or our API, and can be disabled on request for business accounts. In either case, your data is never used to train AI models.

3.1 How AI Is Used

  • Product Analysis: AI assists in matching product ingredients/materials with emission factor databases.
  • Insights Generation: AI generates recommendations for reducing product carbon footprint.
  • Data Processing: Product information is processed by AI models running on Amazon Web Services (AWS) Bedrock, using an EU-only cross-region inference profile (requests enter in eu-west-3, Paris, and are processed within EU regions). Your product data does not leave the EU and does not reach the AI model provider's own infrastructure.

3.2 Data Protection with AI Services

Aspect Details
Data processed by AIProduct descriptions, ingredient lists, and other product-related information necessary for analysis
Data NOT processed by AIUser credentials, payment information, personal contact details
Data reaches AI provider?No for product analysis. AI models run within our AWS infrastructure, so your data is not transmitted to the model provider (Anthropic). The one exception is the optional URL/document extraction feature described above, which sends the submitted content to Anthropic's API directly and can be disabled on request
Training prohibitionYour data is NOT used to train AI models. Contractually prohibited
Processing locationAI models run on AWS Bedrock using an EU-only cross-region inference profile (entry region eu-west-3, Paris). Product data submitted through the platform or API does not leave the European Union

4. Data Security Measures

We implement appropriate technical and organizational measures:

  • Encryption in transit: All data encrypted using TLS/SSL protocols
  • Encryption at rest: Personal data and product information encrypted
  • Access controls: Strict role-based access controls
  • Secure infrastructure: AWS in EU with industry-standard security certifications
  • Password security: Hashed using bcrypt, never stored in plain text
  • Regular security reviews

4.1 Infrastructure Location

  • Primary servers: Amazon Web Services (AWS) Europe (Spain) region, eu-south-2, including the application, database and backups
  • Database: Hosted within EU, encrypted at rest using AES-256
  • CDN: Cloudflare with EU data processing options enabled
  • Backups: Daily automated backups stored in AWS S3 (EU region) with 30-day retention

4.2 Data Residency

All User Data, Generated Reports, and AI processing for product analysis are performed exclusively within EU data centers. Our application, database and backups are hosted in AWS Europe (Spain), eu-south-2, and our AI infrastructure runs on AWS Bedrock with an EU-only cross-region inference profile, so product data submitted through the platform or our API does not leave the European Union at any stage of the analysis pipeline.

Two limited exceptions are disclosed for transparency: the optional URL/document extraction feature described in Section 3, and internal service notifications that may contain a product name and the requesting user's email address. Both are described in Section 8 and can be disabled or suppressed on request for business accounts.

4.3 Certifications and Compliance

  • AWS infrastructure operates under SOC 1, SOC 2, and ISO 27001
  • GDPR-compliant data processing
  • Data Processing Agreement (DPA) available upon request for enterprise customers

5. Data Retention Summary

Data Category Retention Period
Account dataDuration of active account + legally required period
Product/analysis dataDuration of active account; deleted within 30 days of account closure
Payment records6 years (Spanish tax law requirement)
Browsing dataMaximum 18 months
Contact inquiriesMaximum 12 months after resolution
Generated reportsUntil user deletes them or closes account

6. Where Do Your Data Come From?

  • Directly from you: Through registration, contact forms, platform usage, and file uploads
  • From our OAuth provider: If you sign in with Google
  • Automatically collected: Browsing data via cookies and similar technologies

7. Data Disclosure to Third Parties

Recipient Purpose Data Shared
StripePayment processingBilling information, transaction data
Anthropic (via AWS Bedrock EU)AI-powered analysis (processed within EU)Product information (anonymized where possible)
AWSCloud hostingAll platform data (encrypted)
CloudflareCDN and securityBrowsing data, IP addresses
GoogleOAuth authenticationOnly if you choose OAuth login
Slack (Salesforce)Internal service notifications to our team (monitoring and support)Limited metadata only: a product name and the requesting user's email address. Never the underlying product data. Can be suppressed on request for business accounts
Anthropic (direct API)Optional URL/document extraction feature only (see Section 3)Only the content you submit for extraction. Not used when product data is submitted directly. Can be disabled on request
Email service (AWS SES)Transactional emailsEmail address, name

We do NOT sell your personal data to third parties.


8. International Data Transfers

Our core data processing infrastructure, including AI analysis of product data, is located entirely within the European Union (AWS Europe (Spain), eu-south-2, with AI inference on an EU-only Bedrock cross-region profile). Product data submitted through the platform or our API remains within the EU.

For specific third-party services that operate globally, transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the recipient is certified, and otherwise on EU-approved Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914).

Countries where limited data may be processed: United States, in the following cases only:

  • Stripe, for payment processing.
  • Google, for OAuth authentication, if you choose to sign in that way.
  • Slack (Salesforce group), for internal service notifications containing limited metadata such as a product name and the requesting user's email address. This can be suppressed on request for business accounts.
  • Anthropic, only if you use the optional URL/document extraction feature described in Section 3. This can be disabled on request.

9. Your Rights

Under the GDPR, you have the following rights:

Right Description
AccessRequest a copy of your personal data
RectificationRequest correction of inaccurate data
ErasureRequest deletion ("right to be forgotten")
RestrictionRequest limitation of processing
ObjectionObject to processing based on legitimate interest
PortabilityRequest data in a portable format
Withdraw consentWithdraw at any time

How to Exercise Your Rights

  • Email: info@devera.ai
  • Account settings: Access, modify, and delete certain data directly
  • Report deletion: Delete individual reports from your dashboard
  • Account deletion: Request full deletion by contacting us

We will respond within one month as required by GDPR.


10. Cookies

Our website uses cookies. For full details, see our Cookie Policy.

Types of cookies used: Essential, Analytics, and Preference cookies.


11. Changes to This Policy

We will update the "Last updated" date and notify registered users via email if changes materially affect how we process their data.


12. Complaints

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD):

  • Address: Calle Jorge Juan, 6, 28001 Madrid, Spain
  • Phone: +34 901 100 099 / +34 91 266 35 17
  • Website: https://www.aepd.es

13. Contact Us

ECO Impact Tech, S.L.

Email: info@devera.ai

Address: Calle de la Travesía, S/N, Edificio La Terminal, 46024 Valencia, Spain