Terms of Service
Version v1.0 · Effective September 29, 2026
View previous versionsHexifyer DevStudio Terms of Service
Effective date: 1 September 2026 · Last updated: 1 September 2026 · Version: 1.0
Operated by: Hexifyer FZ-LLC
These Terms of Service ("these Terms") form the agreement between your organisation and Hexifyer FZ-LLC for all of Hexifyer DevStudio: the marketing site, the AI estimator, the DevStudio platform and the software we build for you. You accept them when you create an account, and no signature is required. The Data Processing Agreement (Schedule 3), the AI Services Addendum (Schedule 2) and the Acceptable Use Policy (Schedule 1), set out below these Terms, form part of them.
Accepting these Terms is free of charge and does not commit you to any work. The commercial terms in Sections 12 to 15 apply only once a statement of work is agreed. The deletion, retention and turnaround figures in these Terms are the same as those in our Privacy Policy and the Data Processing Agreement. If you identify any difference, please tell us; the figure in the Privacy Policy is the one we will honour.
1. Who we are and how this agreement is formed
Hexifyer DevStudio is operated by Hexifyer FZ-LLC, a free zone company registered in Ras Al Khaimah, United Arab Emirates under licence number 47017173, at FOAM1588, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates. In these Terms, "DevStudio", "we" and "us" mean that company. "You" means the organisation on whose behalf the account is opened.
Formation. The agreement is formed when you create a DevStudio account or first use the service, whichever occurs first. No signature is required. We record the date, the time and the account against which these Terms were accepted, and that record is evidence of the agreement between us.
No order of work. Accepting these Terms does not order any work. An account carries no fee and no commitment to an engagement. Your payment obligations, the work we deliver and its price are set by a statement of work under Section 5. Until a statement of work exists, the commercial provisions of these Terms do not apply.
Statements of work. Where a statement of work differs from these Terms, the statement of work prevails for the engagement it covers. Section 3 sets out the full order of precedence.
2. Your account and your organisation
Account creation. You create your own account, using an email address and password or one of the third-party sign-in providers we support. We do not create accounts for you or sign anyone up on your behalf.
Third-party sign-in. Where you sign in through another provider, that provider authenticates you under its own terms and privacy policy, as an independent controller and not as our supplier. We receive only the information the provider sends us. If you lose access to that provider account, you lose that method of sign-in; contact support@hexifyer.com and we will help you re-establish access to your project.
The organisation is our counterparty. Signing up creates an organisation. The first person to sign up for a company creates the client organisation record, and these Terms are between us and that organisation, not the individual who signed up.
Authority to bind. The person who creates the organisation warrants that they are authorised to accept these Terms on its behalf. Acceptance binds the organisation. If you sign up and later find that you were not authorised to do so, tell us and we will resolve the matter without holding you to these Terms.
Colleagues. Other people from your organisation may join it and are given access to the projects they need. Their activity in DevStudio is attributable to your organisation. The statement of work names the people on your side who can approve a change and sign off a deliverable.
Credentials. You must keep credentials secure and are responsible for activity carried out through your personnel's accounts. Two-factor authentication is available and recommended. Notify us promptly if you believe an account has been compromised. Account holders cannot change their own account email address in the product; to change it, write to privacy@hexifyer.com.
Contactability. At least one contact in your organisation must be contactable at all times. We use these contacts to give the notices required by these Terms, including the notice before a project record is deleted under Section 27.
Age. Every DevStudio account holder must be at least 18 years old. The same minimum age applies under our Privacy Policy.
3. Order of precedence
Other documents apply alongside these Terms, and each governs its own subject matter. Where two documents address the same point, the following order applies, with the higher-ranked document prevailing:
- The statement of work. Scope, team, price, payment structure, milestones and other matters specific to one engagement. An agreed statement of work prevails over these Terms to the extent of any conflict, but only for the engagement it covers and only where it expressly says so.
- Schedule 3: Data Processing Agreement. Personal data we process on your behalf, being your own users' and staff data, referred to in our documentation as client payload. It forms part of these Terms and is in force without separate signature, and it prevails over these Terms on any matter concerning that data. It includes Standard Contractual Clauses and a security annex. A countersigned copy is available on request.
- Schedule 2: AI Services Addendum. The AI features in DevStudio and the use of AI in delivery work. It forms part of these Terms and governs AI matters where these Terms also address them.
- Schedule 1: Acceptable Use Policy. The limits on how DevStudio may be used. It forms part of these Terms and is maintained as a separate Schedule so that it can be updated without amending the rest of these Terms.
- Privacy Policy at https://devstudio.hexifyer.com/privacy. Our processing of personal data we control, which is most of the data DevStudio holds. Where the Privacy Policy and these Terms both state a figure, the Privacy Policy governs, and any difference is a drafting error.
Otherwise, these Terms prevail over any content on our website, in our documentation, in an estimate or in our marketing material. Your own purchase order or supplier terms do not apply, whatever they state, unless we have agreed to them in a statement of work.
4. The AI estimator
When you describe a project in plain language on our site, the estimator returns a recommended team composition, an hours breakdown by phase, a cost and a timeline. It runs through an automation that calls a model via the same named providers used for every other AI feature, under the same commitments: no training on what you submit, and provider retention of up to 30 days for trust and safety purposes only.
An estimate is not an offer. It does not bind either of us to a price, timeline or team, and it is not a quotation. Only the figures in an agreed statement of work are binding. The estimate assesses a project, not a person: it makes no assessment of the person who submitted it and is not used in any decision about any individual.
Email address. An email address is required, and the estimator cannot be used anonymously. If you prefer not to provide an email address, you may ask us to scope the work manually.
Data stored and retention. We store four fields: your email address, your project description, your expected budget and the estimate returned. No other data is stored and no cross-site tracking is attached. At 24 months from our last contact with you, your email address is deleted and the description, budget and estimate are retained without any identifier, to calibrate the estimator against actual project costs. On request, we delete the whole record instead. Sections 6 and 12 of our Privacy Policy contain further detail.
Communications. We reply to you about your project. We may also send occasional email about DevStudio, covering our work, our methods and trends in comparable projects. Where the law applicable to you requires consent for such messages, we request it on the form. Every message includes a one-click unsubscribe link. If you unsubscribe, we stop sending messages and delete your contact record within 30 days, retaining only the minimum record needed to ensure you are not emailed again.
Content of the description. The description is a free-text field. Do not include internal roadmaps, client names, credentials, commercial terms or any other information you would not want held in a record for two years.
5. How an engagement starts and who creates what
You create your account and your organisation. We create the project. DevStudio has no function for creating a new project, and none is planned. An account without a project is a normal state and may remain so indefinitely.
A project in DevStudio is a delivery engagement: an agreed scope, a team we assemble and manage, an agreed way of working and the commercial arrangement behind it. We create a project when there is an engagement to run. A project management platform for running your own work without our delivery is a different Hexifyer product, offered on different terms.
5.1 The sequence
- Estimate. You submit a description to the estimator and receive a structured estimate. This step is optional, and the estimate is non-binding under Section 4.
- Discovery call booking. You book a call from our site, with or without an estimate. Booking a call is free of charge and creates no commitment.
- Discovery. The call, followed by as many further meetings as are needed to agree what is being built. We review requirements, constraints, integrations and the systems we will need access to, and then propose the way of working for your project under Section 6. On larger engagements, discovery is paid work under its own statement of work, and the build is scoped afterwards on the basis of its findings. We will tell you which approach we propose before you commit to either.
- Statement of work. Agreed in writing by both of us before any work is built, either by signature or by confirmation from your named approver by email or in the product. It refers to and incorporates these Terms.
- Project creation. We create the project in DevStudio, assign the team and give your personnel access. No set-up is required on your side.
- Kick-off. We establish the backlog, the meeting cadence and the review schedule. From this point, the project record is the single source of truth for what was agreed, decided and done.
5.2 What a statement of work records
- the scope: what is being built and, where relevant, what is expressly excluded;
- the deliverables and the acceptance criteria for each of them under Section 11;
- the team composition, by role rather than by name, and the rate applying to each role;
- the payment structure under Section 12 and the schedule of invoices or milestones;
- the way of working under Section 6, the cadence of reviews and alignment meetings, the timeline, and any fixed dates;
- your dependencies under Section 7: the decisions, access, content and approvals we need from you, and when;
- the systems you will grant access to, which also constitutes the written instruction required by the Data Processing Agreement;
- whether AI assistance in delivery is permitted, under Section 20;
- any third-party licences, subscriptions or hosting costs the engagement depends on, under Section 15;
- the persons on each side who can approve a change and sign off a deliverable.
Start of work. Work starts when the statement of work is agreed and any first payment due under it has been received.
Team by role. The team is named by role and not by individual. We assemble the team from our network of vetted partners and manage it. Section 8 sets out our commitments regarding the team, including replacement of team members.
6. How we deliver
The delivery approach varies by project. It may be sprints with a backlog and a demo at the end of each sprint, phases with a review at the end of each phase, or, for smaller projects, a weekly checkpoint. The approach is agreed with you during discovery and recorded in the statement of work.
Whichever approach is used, we commit to:
- A visible plan in DevStudio before the work is carried out.
- Working software shown at regular intervals, through a sprint demo, phase review or checkpoint, according to the agreed rhythm.
- A current backlog, updated as work is done, discovered or reprioritised.
- Reports generated from the project data daily, weekly and monthly.
- Milestones tracked against the plan, with any change flagged when it occurs.
Alignment meetings. The meetings at which we agree what is being built and confirm what has been built are listed in the statement of work. You must attend them or send a representative with decision-making authority. If you cannot attend, tell us and we will record the meeting. A recording is not a decision, and work that requires a decision will wait for it.
Changing the way of working. If the agreed approach proves unsuitable, either of us may say so and we will agree a different approach. This is a change to how we work, not to what we build, and does not require a change request under Section 10 unless it affects a date or a cost, in which case it does.
Dates. A date in a statement of work is a commitment by both of us, and depends on the plan behind it and on dependencies being met. Where a date slips because of a matter on your side under Section 7, we will notify you in writing at the time and the timeline will be adjusted.
7. What we need from you
Each statement of work adds the dependencies specific to that engagement. In every engagement you are responsible for:
- A decision-maker. A person with authority to approve deliverables and changes, reachable within one working day, named in the statement of work. Tell us when this person changes.
- Timely decisions and approvals. Where work depends on a decision, we will identify it and state the date by which it is needed. Work that depends on a pending decision stops until it is made.
- Access. The systems, repositories, environments, accounts and credentials the work requires, provided to the people who need them. Section 23 and the Data Processing Agreement govern how we handle access to anything holding your users' data.
- Content and materials. Copy, brand assets, data, designs and any other materials you supply rather than purchase from us.
- Third-party cooperation. Where the work depends on your vendor, platform or contractor, securing their engagement is your responsibility.
- Attendance and review. Attending the alignment meetings under Section 6, reviewing deliverables within the window in Section 11, and identifying specifically what is wrong when something is.
Late dependencies. Where a dependency is late, we notify you in writing, record it in the project and continue with any other work we can. Where the delay prevents the team from working productively, we may reschedule them and the timeline moves accordingly. On an hourly engagement, waiting time is not billed. On a fixed-price or milestone engagement, a delay of more than 10 working days caused wholly by your side entitles us to re-price the remaining work or to treat the engagement as paused under Section 27.
Your users' data in the workspace. Do not enter your users' real data into the project workspace. Content created in DevStudio is sent for embedding when it is created, so a customer record pasted into a task description reaches an AI provider even though the source database would not. Use a redacted sample, and tell us if real data is entered so that we can remove it. Paragraph 5 of the AI Services Addendum (Schedule 2 to these Terms) sets out this restriction.
8. The team and our responsibility for it
We assemble and manage the team: developers, designers and project managers drawn from our vetted network, working as individual partners or through an agency. You do not hire or coordinate them and do not bear the risk associated with them.
Our personnel. For the purposes of these Terms, team members are our personnel. We are responsible for their work, their conduct and their compliance with these Terms, the Schedules and the confidentiality obligations in Section 22, as we would be for employees. Everyone assigned to your project is bound by written confidentiality terms before assignment. Clause 7 of the Data Processing Agreement (Schedule 3 to these Terms) reflects the same position for data protection: partners are our personnel and not sub-processors, so no notice period applies to an assignment and we are responsible for them.
Substitution. We may change the members of the team. Any replacement will have equivalent skills and experience for the role in the statement of work, and we bear the cost of the handover: you are not billed for a new team member becoming familiar with work already done. If you have a reasonable objection to an individual on your project, tell us and we will replace them.
Information visible to you. You can see a partner's name and profile photo. You cannot see their rate, CV, portfolio, skills profile, agency affiliations or other engagements. Section 9 of our Privacy Policy sets out this position. Where an engagement requires more information, we ask the partner first.
Rates and partner pay. The rates in your statement of work are our rates. The amount we pay a partner is a matter between us and the partner, is not disclosed to you, and is not a component of your price that is subject to audit or negotiation.
9. Your access to DevStudio
Every engagement runs inside DevStudio. You have access to the same project the team works in, including tasks, sprints, logs, comments, meeting notes, documents, assets and generated reports, in real time.
Nature of the access. You receive a non-exclusive, non-transferable, non-sublicensable right to use DevStudio to participate in your own projects, for as long as an engagement is running or a project record of yours exists. It is not a licence to the platform, carries no separate fee, and ends as described in Section 27.
Restrictions. You must not: resell or share access outside your organisation; reverse engineer DevStudio or attempt to derive its source code, model configuration or prompts; use DevStudio, or anything learned from it, to build a competing product; scrape or bulk-extract data other than through the export in Section 27; circumvent a rate limit; or remove our notices and branding. The Acceptable Use Policy (Schedule 1 to these Terms) contains the full list and applies to everyone in your organisation.
Information not visible to you. The commercial terms between us and a partner, a partner's profile beyond name and photo, and any information belonging to another client. Work done under one agency is not visible to another. These rules also apply within the AI features: the assistant answers only from information the requesting person can already see.
Work in progress. Your access includes unfinished work, internal discussion, decisions under discussion and corrections. A task, draft or comment is not a commitment by us. Our commitments are set out in the statement of work.
10. Changes to scope
Raising a change. Either of us may raise a change, in the project in DevStudio, where it is recorded with the rest of the project history. Within 5 working days we respond with its impact on cost, on the timeline, and on anything already agreed that it displaces.
Written approval. No change takes effect until it is approved in writing by the person named in the statement of work. Approval in the project record constitutes writing; a remark in a demo does not. We will not start work on, or invoice for, an unapproved change.
Reprioritisation. Moving work within an agreed scope, or replacing one backlog item with another of comparable size, is ordinary planning and does not require a change request. A change request is required for work that adds to the scope, changes an agreed deliverable or acceptance criterion, or moves a date.
Refused changes. If either of us declines a change proposed by the other, the statement of work continues unchanged. Neither of us can impose a change on the other, and a refusal is not a breach.
11. Acceptance and defects
Acceptance criteria are set for each deliverable in the statement of work. They must be sufficiently objective for both of us to determine whether they are met.
Review window. When we deliver a milestone or deliverable for acceptance, you have 5 working days to review it and accept or reject it in writing, specifying which acceptance criterion is not met. If we receive no response within that window, the deliverable is accepted. The statement of work may set a longer window for a particular deliverable.
Specific rejection. A rejection must identify the acceptance criterion that is not met. A general statement of dissatisfaction is not a valid rejection. Where the requirement is not in the acceptance criteria, it is a change under Section 10 and not a defect, and we will identify it as such.
Valid rejection. We correct the deliverable at our own cost and re-deliver it, and a new review window starts. Where the same deliverable is validly rejected a third time for the same reason, you may treat that as a material breach under Section 27 and terminate the affected statement of work, paying for work properly delivered and accepted up to that point.
Acceptance by use. Putting a deliverable into production, or otherwise using it in your business, constitutes acceptance.
12. Fees and payment structures
The payment structure is agreed for each engagement, based on how well specified the work is and which party bears the risk of it being wrong. Any of the four structures below may be agreed, and we will recommend one and give our reasons.
- Lump sum. A fixed price for a defined scope, suited to stable, specified requirements. We bear the risk of the work taking longer than estimated; you bear the risk of changed requirements, which are handled under Section 10. Invoiced according to the schedule in the statement of work.
- Hourly. Billed per hour recorded against the work, at the role rates in the statement of work. Suited to exploratory work or an ongoing retainer. Section 12.1 describes how hours are recorded.
- Milestone. Payment on acceptance of defined milestones under Section 11, suited to staged delivery with go/no-go points. Each milestone has its own acceptance criteria and its own invoice.
- Hybrid. A combination of the above, typically a fixed-price discovery phase followed by milestone or hourly billing for the build.
12.1 How hours are recorded
Hours in DevStudio are entered by the person who did the work. There is no timer, screen capture, activity monitoring or automated measurement of anyone, whether our partners or your team. An estimate against a task is a plan; a logged hour is a self-report. The interface labels them accordingly, and Section 4 of our Privacy Policy records the absence of time tracking as a commitment.
Hourly billing is therefore based on self-reported hours, all of which are visible to you. Each logged hour appears in the project when it is recorded, attributed to the work it was recorded against. You may query any entry and we will review it with you. We do not offer billing based on automated tracking; if you require it, a lump-sum or milestone structure is the appropriate option.
12.2 Rates
Role rates are set in the statement of work and apply for 12 months from its start date, or for the duration of the engagement if shorter. After that, we may revise rates for work not yet performed on 30 days written notice. If you do not accept a revised rate, you may terminate the affected statement of work under Section 27 and pay for work done up to that point. Rates exclude the third-party costs in Section 15.
13. Invoicing, currency and tax
Invoicing. Invoicing is manual and takes place outside the platform. DevStudio has no payments module and holds no card on file. Invoices are issued by email to the billing contact named in your statement of work and are paid by bank transfer unless otherwise agreed. The contract and invoice records for your engagement are therefore held outside DevStudio, as described in Section 12 of our Privacy Policy.
Payment terms. Invoices are due 14 days from the date of issue unless the statement of work provides otherwise.
Currency. Fees are quoted and invoiced in US dollars unless the statement of work specifies another currency. Bank charges on a transfer to us are borne by you.
Tax. All prices exclude value added tax and any other sales, use or withholding tax. Where we are required to collect tax on a supply to you, it is added to the invoice. If you are registered for VAT, you must provide and keep accurate your registration number; where the law of your country applies a reverse charge to a supply from us, you are responsible for accounting for that tax. Payments to us are made without deduction or withholding. If a withholding is required by law, you will gross up the payment so that we receive the amount we would have received without it.
Retention of financial records. Contracts, invoices and tax records are retained for the statutory periods (7 years under UAE corporate tax law and 5 years under Egyptian VAT law), and are therefore kept after the deletion of other data under Section 27. They contain no client payload.
14. Late payment and suspension
If an invoice remains unpaid after its due date, we will follow up by email to your billing contact and to the project contacts. Where an invoice is 14 days overdue and we have given you written notice, we may suspend work and access until it is paid. We will notify you before suspending.
Interest on an overdue amount accrues at 1% per month from the due date, and we may recover reasonable costs of collection.
Suspension is not deletion. During suspension, work stops but your project record remains in place and exportable. We do not delete your content because an invoice is unpaid or a project is inactive. Nothing in this Section permits us to withhold a deliverable you have already paid for.
Restarting after suspension. Restarting may depend on the availability of the team, whose members may have been assigned elsewhere. We will give you a realistic restart date and do not commit to the original timeline.
15. Third-party costs
Most builds depend on third-party services, such as hosting, a database, a domain, an email service, a payment gateway, an app store account, a font licence, an SDK or a monitoring tool. These costs are yours and are separate from our fees.
Accounts in your name. Third-party accounts are opened in your name wherever possible, with access granted to us. Where an account must be held in our name for a period, the statement of work states this and specifies when the account transfers to you.
Approval before commitment. We will not commit you to a recurring cost without your written approval. Where we pay a cost on your behalf with your approval, we invoice it at cost. Travel and other exceptional costs are billed only where the statement of work provides for them or you approve them in writing in advance.
16. Ownership of deliverables
Ownership. You own the deliverables outright. This covers source code, wireframes, UI mockups, architecture diagrams, API specifications, product requirement documents, database schemas, configuration, documentation and every other deliverable produced for you under a statement of work, including the intellectual property rights in them. We assign those rights to you worldwide for their full duration, and we will sign any document a registry or future acquirer reasonably requires to evidence the assignment.
Timing of transfer. Ownership passes as each deliverable is paid for. Until then, you have a licence to use the deliverable for evaluation and acceptance, but not in production. On full payment for an engagement, you own everything produced under it, whether or not accepted and whether or not finished.
Work in progress. If an engagement ends early for any reason, including termination by us, you own what you have paid for in its current state, and Section 27 sets out how it is handed over.
No retained rights. We do not withhold your code and do not keep a copy for our own use. We retain no licence to reuse your deliverables, other than the background material and reusable components described in Section 17, which are identified separately.
Deliverables containing personal data. Ownership of a deliverable is governed by this Section. Separately, where a deliverable contains personal data (for example a requirements document naming your stakeholders or a test dataset copied from production), our handling of that data is governed by the Data Processing Agreement. Section 2 of our Privacy Policy reflects the same position and does not claim any control over your deliverables as property.
17. What remains ours
The following remain our property and are not deliverables.
Background material. Anything we owned or developed before, or independently of, the engagement, including internal tooling, frameworks, libraries, boilerplate, scaffolding, project templates, checklists and know-how. Section 16 does not transfer any of it.
Reusable components. Where a deliverable includes a generic component of ours (such as an authentication scaffold, a deployment pipeline or a utility library not specific to your product), we retain ownership of the component and grant you a perpetual, irrevocable, worldwide, royalty-free, sublicensable licence to use, modify and distribute it as part of your deliverable and anything you later build from it. You are not dependent on us to continue running or extending what we built. Each such component is identified in the statement of work or the project record before delivery.
DevStudio. The platform, its interfaces and documentation, the Hexifyer and DevStudio names and logos, and everything else we use to run the engagement. Section 9 grants a right of use only.
General skill and knowledge. The general knowledge, experience and technique our personnel gain in doing your work remain with them and may be applied for other clients, subject in every case to the confidentiality obligations in Section 22. We will not reuse anything specific to you, your product or your business.
Feedback. We may use any feedback on DevStudio freely, without obligation, payment or attribution, and feedback does not become your confidential information. A feature request is feedback; the project data described in making it is not.
18. Open source and third-party components
We use open-source and third-party components in our work, subject to the following commitments.
Disclosure. Before a deliverable is accepted, the project record identifies the third-party and open-source components it depends on and the licence applicable to each.
Protection of your ownership. We do not incorporate a component whose licence would require you to disclose or license your own source code (typically a strong copyleft licence in a distributed product) unless you have first agreed in writing. Where such a component is the appropriate technical choice, we will explain the trade-off and you will decide.
Third-party components are licensed to you by their own licensors on their own terms, not by us. We do not warrant them or indemnify you in respect of them. Section 24 sets out our warranties for the work we do with them.
19. Your content and the licence we need
Ownership of your content. All content you put into the project remains yours, including your materials, data, content, documents, and the tasks and comments written by your personnel. We claim no ownership of any of it.
Licence. You grant us a non-exclusive, worldwide, royalty-free licence to host, store, copy, transmit, display and process your content only to the extent needed to deliver, secure and support the engagement, including processing through the AI features on which DevStudio operates, and including the backups and disaster-recovery copies described in our Privacy Policy. The licence covers nothing else. It does not permit us to train models on your content, market to your personnel, build datasets, or show your content to anyone who does not already have access to it. It ends when your content is deleted, subject to the backup and audit windows in Section 27.
Your warranties. You warrant that you have the rights needed to grant this licence, that your content does not infringe any third party's rights or break any law, and that where it contains personal data you have a lawful basis for our processing of it. Where you act as an agency or intermediary, a third party's code, designs, briefs or credentials are usually subject to that party's contract with you, and the decision to provide them to us is your responsibility.
Hosting location. DevStudio is hosted in Germany, in AWS eu-central-1, for every client regardless of location. Personal data you put into a project is therefore transferred out of your country when it is created. For data we control, the transfer is our responsibility, as described in Sections 11 and 21 of our Privacy Policy. For your own users' data, clause 14 of the Data Processing Agreement (Schedule 3 to these Terms) records that you are the exporter and that obtaining any approvals your own law requires for the transfer is your responsibility. This is an acknowledgement of where responsibility lies and not a warranty to us: it is not covered by the indemnity in Section 26, and a gap in your local approvals is not a breach of these Terms.
20. AI in the product and in the work
The AI Services Addendum (Schedule 2 to these Terms) contains the detailed terms. The following commercial terms also apply.
No metering or charges for AI. AI usage is not metered or charged separately. There are no credits or allowances, and nothing to purchase. AI usage is included in the price of the engagement.
AI features cannot be disabled. The AI features cannot be switched off for a project or an account, and no such option is planned. Search, retrieval, the assistant, the classification that organises a project and the reports you receive operate as a single system. Project content is sent to the AI providers named in the sub-processor list in Section 24 of our Privacy Policy at https://devstudio.hexifyer.com/privacy, including when it is created and not only when a search is run. If this is not acceptable to your organisation, your own client or a regulator, you should not run the work in DevStudio, and you should raise this during discovery, before a statement of work is agreed. Paragraph 9 of the AI Services Addendum (Schedule 2 to these Terms) sets out our commitments in place of an opt-out, and paragraph 5 sets out the rule that your users' data never reaches an AI provider.
AI in delivery and your right to decline it. Our partners use AI coding assistants under the conditions in paragraph 6 of the AI Services Addendum (Schedule 2 to these Terms): configured not to train on your code, with a person accountable for every line, and with your production data never entered into them. If your own policy, your client's policy or your regulator prohibits AI assistance in delivery, tell us before the engagement starts and we will staff and contract accordingly. This is recorded in the statement of work under Section 5 and affects our estimate, and we will explain how.
Ownership of and responsibility for AI output. Ownership follows Section 16, regardless of whether a model was used: AI output that becomes part of your deliverable is part of your deliverable and belongs to you. Responsibility follows Section 24: generated code is reviewed, tested and owned by the person who submitted it in the same way as manually written code, and the use of a model is not a defence. We do not provide an intellectual property indemnity for generated code, as stated in Section 26.
Optional features. Two features are optional and are based on consent rather than contract: calendar sync, which reads or writes no data until you connect an account, and the AI meeting notetaker, which runs only when enabled for a particular meeting and then joins as a visible participant. Either may be declined at any time without affecting any other feature.
21. Acceptable use
The Acceptable Use Policy (Schedule 1 to these Terms) forms part of these Terms and applies to everyone in your organisation who uses DevStudio. It covers unlawful and infringing content, malware, attempts to gain unauthorised access, spam, excessive load, sharing or reselling access, and AI-specific restrictions: no prompt injection; no attempts to extract training data, model weights, system prompts or another project's content; no use of outputs to train or benchmark a competing model; and no entry of real production data into an AI feature.
The Acceptable Use Policy may be updated without amending the rest of these Terms. Material changes to it are subject to the same 30 days notice as a material change to these Terms. Where your organisation breaches it, we may act under Section 14, up to and including immediate suspension.
Removal of content. Where content breaches the Acceptable Use Policy, or the law requires us to take it down, we may remove or disable that specific content. This is the only circumstance in which we remove content you have put into a project (Section 14 on not deleting your work for non-payment or inactivity is unaffected). When we do so, we inform your contacts of what was removed and why.
22. Confidentiality and publicity
Each party agrees to use the other's confidential information only to perform these Terms, to protect it with at least the care it applies to its own, and to disclose it only to persons who need it and are bound by equivalent obligations. This includes the partners on your project, all of whom are bound in writing before assignment.
Scope. Your confidential information includes your project, which remains confidential after these Terms end, and your deliverables, materials, business plans and non-public information about your product. Our confidential information includes our rates, our partner arrangements and the internal workings of DevStudio. Information seen inside a project is confidential to the people on that project.
Exceptions. The obligation does not apply to information that is public through no fault of the recipient, was already known to it, or was independently developed, and does not prevent a disclosure required by law. Where we may lawfully do so, we will notify you before such a disclosure. Clause 15 of the Data Processing Agreement (Schedule 3 to these Terms) sets out how we handle a government or law-enforcement request.
Publicity. We will not use your name, logo or a description of your project in our marketing without your written consent. You may withdraw consent at any time, and we will then stop using them in new material. Case studies and references require separate written consent on each occasion, and you will see the text before publication.
23. Data protection
The roles in respect of personal data are as follows:
- The project record. Tasks, logs, comments, meetings, notes, assignments, reports and the account records of your personnel. We are the controller. We determine the purposes of processing, our Privacy Policy is the relevant disclosure, and requests about this data are made to us and not routed to you.
- Your users' and staff data. Personal data of your own users, customers or employees, accessed through production access you grant us or contained in a file you upload. You are the controller and we are the processor, and the Data Processing Agreement (Schedule 3 to these Terms) governs this data in full.
- Deliverables. Ownership is governed by Section 16, and we claim no regulatory control over deliverables. Where a deliverable contains personal data, the processor role above applies to that data.
Production access. Production access is granted by exception. Where the work requires access to a live system of yours, access is given to named individuals, at the narrowest permission required, recorded in an access register, and revoked at the end of the engagement or of the phase that required it, whichever is earlier. You may ask to see the register at any time, and you may revoke access yourself without notice to us; this is not a breach. Clauses 5 and 12 and Annex B of the Data Processing Agreement (Schedule 3 to these Terms) set out the detail.
Rights requests and exports. We respond to requests about personal data we control within 6 working days, free of charge, in every market, and we verify the requester against the account concerned without requiring identity documents. A project export is delivered within 5 working days of a request to privacy@hexifyer.com. Where a request concerns your users' data, we route it to you and inform the requester that we have done so, within the same 6 working days.
Security. Our measures include encryption in transit and at rest, password hashing, optional two-factor authentication, the visibility model in Section 9 enforced per project and per context, audit logging, and logging of staff access to project content, on a business-reason basis, beyond the delivery team. We do not currently hold any security certification, including SOC 2 or ISO 27001. We will complete a security questionnaire on request. The security measures we commit to are set out in Annex B of the Data Processing Agreement, which is contractually binding.
Breach notification. We notify the regulator within 72 hours of becoming aware of a personal data breach, or immediately on discovery where UAE law requires it, and where we are the processor we notify you without undue delay.
24. Warranties
We warrant that:
- we will perform the work with the reasonable skill and care of a competent professional software developer;
- the deliverables will conform materially to their acceptance criteria in the statement of work;
- the deliverables are our original work or properly licensed and, to the best of our knowledge, do not infringe any third party's intellectual property rights, subject to the position on generated code in Section 20 and on third-party components in Section 18;
- we have the right to assign the rights assigned under Section 16;
- we will not knowingly introduce malicious code into anything we deliver.
Defect warranty. For 60 days after acceptance of a deliverable, we will correct at our own cost any failure of that deliverable to conform materially to its acceptance criteria. Correction is your remedy for a breach of this warranty. The warranty does not cover a fault caused by a change made by another person, by your own environment or configuration, by a change in a third-party component or service, or by use outside the purpose for which the deliverable was built.
Disclaimer. Except for the warranties above, and to the fullest extent permitted by law, DevStudio and everything we provide are supplied as is. We disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose and non-infringement.
Matters not warranted. We do not warrant that software will be uninterrupted or error-free; that it will achieve any commercial objective, user number, conversion rate or revenue figure; that DevStudio will be available without interruption; or that any AI output or estimate is accurate. There is no uptime commitment and no service credits. AI output may be inaccurate. You must review it before relying on it, must not treat it as professional, legal, medical or financial advice, and must not allow AI output to be the sole basis of a decision with a legal or similarly significant effect on a person without human review.
Platform support. Support is provided by email at support@hexifyer.com. Our business hours are Sunday to Thursday, 09:00 to 18:00 Gulf Standard Time (UTC+4), and we aim to provide a first reply within 24 hours during those hours. This is a response target, not a resolution time or a service level, and no credit or refund is payable if it is missed. Support for software we built for you is a separate commercial matter, covered by the defect warranty above and, if you wish, a separate support or retainer arrangement.
25. Limitation of liability
Neither party is liable to the other for indirect, incidental, special or consequential loss, or for loss of profits, revenue, business, goodwill or data, or the cost of substitute services, even where the loss was foreseeable.
Cap. Each party's total liability arising out of or in connection with these Terms is limited to the greater of the fees paid or payable under the statement of work to which the claim relates in the 12 months before the claim arose, or USD 100. Where more than one statement of work is in force, each is capped separately by reference to its own fees. The cap applies to claims under the Data Processing Agreement and these Terms in aggregate and not separately, as clause 16 of the Data Processing Agreement (Schedule 3 to these Terms) provides.
Exclusions from the cap. The cap does not apply to: your obligation to pay fees properly invoiced; either party's indemnity obligations under Section 26; a breach of the confidentiality obligations in Section 22; a breach of the Acceptable Use Policy; either party's fraud or wilful misconduct; the rights a data subject has directly against either party under the Standard Contractual Clauses; or any liability that cannot lawfully be limited.
26. Indemnities
Your indemnity. You indemnify us against any third-party claim arising from your content or materials, from your use of DevStudio in breach of these Terms or the Acceptable Use Policy, or from a breach of your warranties in Section 19 about your rights in the materials you provide.
No intellectual property indemnity. We do not give an intellectual property indemnity. If a third party claims that a deliverable we produced infringes its rights, we will, at our option and our own cost, obtain the right for you to continue using the deliverable, modify or replace it so that the claim no longer applies, or refund the amount you paid for the affected deliverable. This is your sole remedy, in place of an indemnity.
This position also applies to AI-generated code. Section 20 and paragraph 10 of the AI Services Addendum (Schedule 2 to these Terms) state the same: a person is accountable for every line we submit, and no indemnity applies to generated output.
Conduct of claims. The indemnified party must notify the other promptly, allow it to control the defence, and cooperate reasonably. Neither party may settle a claim in a way that admits the other's liability without its consent.
27. Ending an engagement and closing your account
27.1 Term
These Terms apply for as long as you have a DevStudio account. Closing your account does not end a statement of work that is still running. Each statement of work continues until the work under it is complete or it is terminated, and these Terms continue to govern it until then.
27.2 Termination of an engagement
- For convenience. Either party may terminate a statement of work on 30 days written notice. You pay for work performed and accepted up to the end of the notice period, for work in progress at the point it stops, and for any non-cancellable third-party cost committed with your approval. No other amount is payable: there is no exit fee and no charge for the remaining scope.
- For material breach. Either party may terminate where the other is in material breach and has not remedied it within 30 days of written notice describing the breach.
- Immediately. We may terminate or suspend immediately for a breach of the Acceptable Use Policy, for non-payment after the notice in Section 14, where required by law, or where a party becomes insolvent or subject to sanctions.
- Third rejection. Section 11 gives you a right to terminate where the same deliverable is validly rejected three times.
27.3 Consequences of termination
Handover of work. Everything paid for belongs to you under Section 16 and is handed over in its current state and in usable form: repository access transferred or a full copy delivered, credentials and accounts transferred where held in our name, and existing documentation. We do not withhold a paid-for deliverable in respect of an unpaid invoice.
Access to your systems. Production access is revoked automatically, without any request from you. Any credential you issued to us is treated as compromised and discarded. You should also revoke access from your side, and we will remind you to do so.
Your users' data. Your users' data is returned or deleted, at your election, as set out in clause 13 of the Data Processing Agreement (Schedule 3 to these Terms). On request, we will certify the deletion in writing, free of charge, within 5 working days of its completion.
Project record. We retain your project record for the duration of the engagement and for 24 months afterwards, after which it is deleted, including tasks, sprints, logs, comments, meeting records, reports, files and assets. On request we will delete it earlier, unless a statutory retention requirement applies. We notify the project contacts 30 days before the deletion date.
Export. On request to privacy@hexifyer.com, we deliver an export within 5 working days. The export is a single archive containing a CSV file for each entity type, with each row carrying its own key and its parent's key so that the project structure is preserved, your files in their original formats with a manifest, and a README stating the export date, the entity types included and any exclusions.
27.4 Closing an account
Any account holder may ask us to delete their account at any time. A deletion request starts a 14-day grace period, during which it can be cancelled, after which erasure from our live systems completes within 72 hours. Deleted items remain in trash for 30 days beforehand and can be restored during that period. Copies persist in encrypted backups for up to 14 days after erasure and then expire; they are not restored to fulfil a request. If we restore a backup taken before a deletion, we re-apply the deletion to the restored data. We never delete an account for inactivity.
Scope of account deletion. The personal profile is deleted. Contributions to a project remain in the project record with authorship anonymised, as the project belongs to the organisation. We do not search project content for references to a departing person and do not provide a redaction service. This does not affect any person's legal right to erasure: we assess each request on its merits and do not refuse it outright.
Retained records. Contracts, invoices and tax records are retained for the statutory periods in Section 13, and audit records for 12 months to allow security incidents to be investigated. No other data is retained.
Notification emails. DevStudio notification emails contain the content of the item they relate to. Deleting an item in the project does not remove it from emails already delivered. Those copies are held in recipients' mail systems, outside our control, and cannot be recalled.
Survival. The following survive termination of these Terms: Sections 13 (as to amounts already due), 16, 17, 18, 19 (as to your warranties), 22, 23, 24 (for the remainder of the warranty period), 25, 26, 29 and 30, and any accrued payment obligation.
28. Non-solicitation
For the duration of an engagement and for 12 months after it ends, you agree not to solicit or engage any partner or employee who worked on your project, whether directly, through an agency or through another intermediary, without our prior agreement.
If you wish to hire someone who worked on your project, contact us. We will usually agree, in some cases for a fee reflecting the cost of finding and vetting that person. The restriction does not apply to a person who responds to a general job advertisement not directed at them, and nothing in this Section restricts a partner's own freedom to act.
29. Governing law, disputes and language
These Terms are governed by the laws of the Dubai International Financial Centre, and the DIFC Courts have exclusive jurisdiction over any dispute arising from them. Before starting proceedings, each party agrees to raise the issue in writing and to attempt in good faith for 30 days to resolve it.
Data protection law. The choice of law above governs this contract. It does not determine which data protection law applies to personal data, which depends on where you and the individuals concerned are located and is addressed in our Privacy Policy and the Data Processing Agreement. It also does not make the DIFC data protection regime applicable to us: Hexifyer FZ-LLC is registered in a Ras Al Khaimah free zone, so UAE Federal Decree-Law No. 45 of 2021 applies to us as a company, and the DIFC and ADGM regimes do not.
Mandatory local rights. Nothing in these Terms removes a right that the law of your location grants you and does not allow to be excluded by contract.
Language. These Terms are published in English and Arabic. If the two versions conflict, the English version governs.
Sanctions and export controls. Each party warrants that it is not subject to any applicable sanctions regime, is not located in a country subject to comprehensive sanctions, and will not make the work or the platform available to anyone who is. Either party may terminate immediately if this ceases to be true of the other.
30. Changes, notices and general terms
Changes. We may change these Terms. A material change (a new obligation on you, a reduction in any of our commitments, a change to fees outside the mechanism in Section 12, or a change to how termination or deletion works) is announced at least 30 days before it takes effect, by email to your contacts and by a notice in the product. Continued use of DevStudio after that date constitutes acceptance; if you do not accept the change, notify us before that date. A change does not alter a statement of work already agreed. Clarifications and corrections take effect on publication, with an updated last-updated date, and previous versions are kept in a public archive.
Designated material changes. Each of the following is a material change: introducing a payments module, introducing time tracking of any kind, and introducing partner scoring. We do not currently do any of these. Introducing time tracking would also change the basis on which hourly work is billed under Section 12.
Notices. We give notice by email to the contacts for your organisation or the project, or in the product. You are responsible for keeping at least one contact reachable, including for receipt of the notice in Section 27 before a project record is deleted. You give notice to us at support@hexifyer.com, or at privacy@hexifyer.com for matters concerning personal data.
Assignment. Neither party may assign these Terms without the other's consent, except that either party may assign them in whole to a successor in a merger, acquisition or sale of substantially all of its assets, on notice. Our use of partners and agencies to perform the work, as described in Section 8, is not an assignment.
Force majeure. Neither party is liable for a failure to perform caused by events outside its reasonable control, including infrastructure or network failure at a provider, natural disaster, war or government action. This does not excuse a payment obligation. Where such an event continues for more than 60 days, either party may terminate the affected statement of work, and you pay for work performed up to that point.
Independent contractors. Nothing in these Terms creates a partnership, joint venture, agency or employment relationship between us, or between you and any person we assign to your project.
General. If any provision is unenforceable, the remainder continues in effect and that provision is read down to the minimum extent necessary. A failure to enforce a right is not a waiver of it. These Terms, together with the documents listed in Section 3 and the statements of work agreed under them, constitute the entire agreement between us and supersede all prior statements.
Schedule 1: Acceptable Use Policy
This Schedule forms part of the Hexifyer DevStudio Terms of Service and, for partners and agencies, of the Partner Terms. It sets out the limits on how Hexifyer DevStudio and our site may be used, and a breach of it is a breach of the agreement of which it forms part.
1. Scope and application
This policy applies to everyone who uses DevStudio or our site: a client organisation and everyone in it, a partner working on a project, an agency and its administrators, and anyone using the marketing site or the AI estimator.
Where you are a client, this policy forms part of the Terms, which you accepted when an account was created for your organisation. Where you are a partner or an agency, it forms part of your Partner Terms. Where you are neither and you only use the site, it applies on its own.
Responsibility for others. A client organisation is responsible for everyone it invites into its projects, and an agency is responsible for the partners working under it. Where someone in your organisation breaches this policy, we deal with your organisation rather than with the individual.
Relationship with other documents. The AI Services Addendum (Schedule 2 to the Terms) governs the AI features, and paragraph 7 restates its restrictions without adding to them. Our Privacy Policy governs personal data. The Data Processing Agreement (Schedule 3 to the Terms) governs personal data we process on a client's behalf. Where a figure appears both in this policy and in the Privacy Policy, the Privacy Policy governs.
Age. You must be at least 18 years old to hold a DevStudio account.
2. Unlawful use
You must not use DevStudio to do anything unlawful, or to help anyone else do anything unlawful. This includes the law where you are, the law where we are, and the law where the people affected are.
In particular, you must not use DevStudio or anything we build for you to:
- infringe another person's intellectual property, or put content into a project that you do not have the right to put there;
- harass, threaten, defame or stalk anyone, or build something designed to do so;
- facilitate fraud, money laundering, sanctions evasion or any other financial crime;
- produce or distribute content that sexualises children, incites violence, or promotes terrorism or violent extremism;
- build surveillance capability aimed at people who have not consented to it, or anything whose evident purpose is to track, profile or monitor individuals covertly;
- breach an export control or a sanctions regime, or make the platform available to anyone subject to one.
These restrictions apply both to what you do in DevStudio and to what we are asked to build. If any of them may be relevant to your project, you must tell us during discovery. We may decline an engagement on that basis.
3. Prohibited project content
In addition to the unlawful content described in paragraph 2, the following must not be placed in tasks, comments, logs, meeting notes, files or anywhere else in DevStudio:
- Malware: viruses, worms, ransomware, or code whose purpose is to damage or gain unauthorised access to a system. Malware samples handled as part of legitimate security work are excepted, provided the exception is agreed with us in writing before anything is uploaded.
- Live credentials: production passwords, API keys, private keys or tokens. Use the credential route agreed for your engagement. If a credential is pasted into DevStudio, you must tell us and rotate it. Deleting the task is not sufficient, because notification emails carry item content and those copies are outside our control.
- Special category data (health records, biometric data, or data about a person's religion, politics, ethnicity, sex life or criminal record), unless it is necessary for the work and we have agreed in writing how it will be handled.
- Material you are not permitted to share with us, including a third party's code, designs, briefs or confidential material. Whether you may share such material is a matter for you under your own contract with that party.
4. Production data
You must not paste real production data into a task, a comment, a meeting note or a conversation with the assistant. Content created in DevStudio is sent for embedding at the moment it is created, not when it is searched, so a customer record pasted into a task description reaches an AI provider even though the database it came from does not. Use a redacted sample or synthetic data. If production data is entered, tell us at privacy@hexifyer.com and we will remove it.
Client payload. Data belonging to a client's own users is referred to as client payload. Client payload is not embedded, retrieved, classified or summarised by any AI provider where it reaches us through one of the two routes by which it normally arrives: access to a production system, or a file uploaded into a project. That commitment does not extend to text entered into a field, because the platform cannot identify a paragraph of text as a customer record. Paragraph 5 of the AI Services Addendum (Schedule 2 to the Terms) sets this out in full, and this paragraph accordingly places the obligation on you.
Intentional use of AI on your users' data. Applying AI to your users' data for a specific purpose (for example a migration, a classification job or an analysis) is available. It requires a separate written instruction under the Data Processing Agreement (Schedule 3 to the Terms), scoped to a named purpose and a named provider.
Production access. Where we are given access to a live system, that access is used for the work and for no other purpose. No one may copy production data out of it into a project, onto a personal device, or into any tool that is not part of the agreed environment.
5. Accounts, credentials and access
- One account per person. You must not share a login or allow another person to work under your account. Each person who needs access must have their own account.
- No external access. You must not give access to anyone outside the organisation to which the project belongs, and you must not resell, rent or sublicense access to DevStudio.
- No circumvention. You must not create multiple accounts or organisations to work around a limit, a restriction we have applied, or a suspension.
- No unauthorised access. You must not attempt to reach anything you have not been given access to, including another client's project, another partner's profile, another agency's work, an internal interface, or any part of our infrastructure. This applies whether access is attempted through an API or through the interface, and regardless of intent.
- No security testing. You must not probe, scan or test our systems for vulnerabilities without our written permission. A vulnerability found by accident should be reported as described in paragraph 10.
- No impersonation. You must not impersonate anyone, misrepresent who you are or who you work for, or use a name or address that is not yours.
You must keep your credentials secure, enable two-factor authentication, and tell us promptly if you believe an account has been compromised.
6. The platform
Reverse engineering. You must not reverse engineer or decompile DevStudio, or attempt to derive its source code, its model configuration or the prompts behind its AI features, except to the extent this restriction is unenforceable under the law that applies to you.
Competing products. You must not build a competing product from DevStudio, from its outputs, or from what you learn by using it. This does not restrict you from analysing your own project content for your own purposes.
Scraping. You must not scrape, crawl or bulk-extract the platform other than through an interface we provide for that purpose. Project data can be exported on request to privacy@hexifyer.com, and is provided as a structured archive within 5 working days.
Rate limits and load. We apply rate limits to the platform, in particular to the AI assistant and to any programmatic interface we make available. You must not work around them, or generate load that degrades the service for others, whether deliberately, through an automation left running, or through a malfunctioning script. Where we can, we will contact you before restricting anything.
Notices and branding. You must not remove or obscure our notices or branding, or misrepresent your relationship with us.
7. The AI features
The restrictions in this paragraph are those set out in paragraph 11 of the AI Services Addendum (Schedule 2 to the Terms). Where the two differ, the AI Services Addendum governs.
- No prompt injection: you must not attempt to manipulate the assistant, the writers, the reporting engine or the scheduled agent into behaving outside their intended purpose.
- No extraction attempts: you must not attempt to make a model reveal training data, model weights, system prompts, another project's content, or anything else you are not entitled to see. The assistant answers only from content you can already access, and an attempt to circumvent that is a breach whether or not it succeeds.
- No competing use of outputs: you must not use outputs to train, benchmark or build a competing model or product.
- No client payload or real production data in any AI feature, as set out in paragraph 4.
- No prohibited content: you must not generate content that paragraph 2 prohibits.
- No consequential decisions on AI output alone: no decision about a person concerning hiring, dismissal, pay, discipline, credit, insurance, housing or access to a service may be taken on an AI output without review by a person. This applies to your use of DevStudio and to anything you build with us.
Outputs are not verified. An AI output can be wrong. You must review an output before relying on it. You must not treat an output as professional, legal, medical or financial advice, or pass it to another person as though it had been verified.
Our commitments in relation to the AI features are set out in the AI Services Addendum: we do not train models on your content, providers retain a request for no more than 30 days and only for safety purposes, every request is pinned to a publicly named provider, and your users' data does not reach an AI provider.
8. Meetings, recordings and notes
DevStudio can record and transcribe a meeting and generate notes from it through the AI notetaker. The notetaker runs only when it is turned on for a particular meeting, and when it runs it joins as a visible participant. It does not record silently.
Consent. The person running the meeting is responsible for obtaining any consent the law requires from the participants, and for informing them that the meeting is being recorded. Recording laws differ between countries, and some require the agreement of every participant. We provide the visible participant. We do not obtain consent on your behalf.
Deletion on request. Any participant may request deletion of a recording. On request, the audio, the transcript, the notes derived from it and their embeddings are deleted. No reason is required and none is recorded. The fact that the meeting took place, and its attendance, remain in the project record.
Permitted use. A recording must not be used for any purpose other than the one for which it was made, including performance assessment or monitoring of any person, or outside the project to which it belongs.
9. Partners and agencies
This policy applies in full to partners and agencies. The following additional obligations apply.
Accurate profiles. Your profile (including your experience, skills, portfolio and CV) must be accurate. Clients are assigned teams on the basis of it. You must not apply on another person's behalf, present another person's work as your own, or allow another person to work under your account.
Personal performance. An assignment is made to you personally. You must not subcontract it, pass it to a person we have not approved, or bring another person into a project without telling us. If you need assistance, ask us and we will arrange staffing.
Project confidentiality. A client's code, designs, data and commercial information are confidential to the project. You must not take them elsewhere, reuse them on another engagement, or include them in your portfolio or a case study without the client's written agreement obtained through us.
Non-circumvention. You must not solicit a client you met through DevStudio to take work off the platform or to engage you directly outside your Partner Terms. If a client approaches you about working with them directly, you must tell us.
AI coding assistants. You may use AI coding assistants on the following conditions. Any assistant used on a client project must be on a plan and configuration under which the client's code and context are not used to train the vendor's models. If you cannot meet this condition, you must not use any assistant on that project. You are accountable for every line of code: generated code must be reviewed, tested and owned by you in the same way as code you wrote yourself, and the fact that a model generated it is not a defence. You must never enter a client's production data into an assistant.
Clients who decline AI assistance. Where a client has declined AI assistance for its engagement, this is recorded in the statement of work and applies absolutely to that project. No assistant may be used on any plan.
Agencies. An agency is responsible for the partners working under it, including for compliance with the two preceding obligations. An agency is a controller in its own right for the data it receives about its own partners, and its handling of that data is governed by its relationship with those partners rather than by our Privacy Policy. Work done under one agency is partitioned from work done under another agency or as a personal freelancer, and any attempt to access either is a breach of paragraph 5.
10. Reporting a problem
Abuse or content in breach of this policy. Report it to support@hexifyer.com, stating where the content is and what the problem is. We will review the report and respond.
Security vulnerabilities. Report them to the same address, marked as a security report. Provide enough information to reproduce the issue, and allow us a reasonable period to fix it before disclosing it to anyone else. You must not access, modify or retain anyone else's data while investigating, and you must stop as soon as you have established that a problem exists.
No bug bounty. We do not operate a bug bounty programme and do not pay for reports. We will not pursue anyone who reports a genuine issue to us in good faith, stays within the limits in this paragraph, and gives us an opportunity to fix it.
Personal data. Matters concerning personal data (including a report that someone's data is somewhere it should not be, or a rights request) must be sent to privacy@hexifyer.com. Response times are set out in our Privacy Policy.
11. Enforcement
Our response to a breach of this policy is proportionate to the breach. The measures available to us are:
- Request to stop. This is the ordinary first step. Most breaches are accidental (for example a pasted credential, an automation left running, or production data in a task) and are resolved by a message.
- Removal or disabling of specific content. This applies where content breaches this policy or the law requires its removal. This is the only circumstance in which we remove content you have placed in a project, and when we do so we inform your contacts of what was removed and why.
- Restriction of a feature or application of a limit. This applies where the problem is load, automated access or misuse of a particular capability, and a restriction is sufficient.
- Suspension of an account. This applies where an individual is responsible and the breach is serious or repeated.
- Suspension or termination of an engagement. This applies where the breach is the organisation's rather than an individual's. The termination provisions of these Terms apply, including their provisions on your work and your data.
Immediate action. We may act immediately, without prior notice, where there is a risk of harm to any person, an active threat to the security or stability of the platform, or where the law requires it. We will tell you the reason as soon as we have acted, and we will restore access once the cause is resolved.
Effect of suspension. A suspension does not delete your content. Your project record remains in place and exportable, and nothing in this policy permits us to withhold a deliverable you have already paid for. These Terms make the same provision in the case of non-payment.
Breach by a partner. Where a partner is responsible, the consequences are a matter between us and that partner and are not borne by the client. Where the breach affects a client's project, we will inform the client and replace the partner.
12. Review of enforcement decisions
To challenge a decision, reply to the notice we sent you or write to support@hexifyer.com, stating your reasons. The review is carried out by a person, not by a model or by the automated check that raised the issue. We aim to respond within 5 working days, and sooner where an account or an engagement is suspended.
If the decision was wrong, we reverse it and restore anything removed, where that remains possible. If the decision was correct, we tell you what we found and what must change before access is restored.
13. Changes to this policy
We may update this policy as new forms of abuse arise. A material change (a new restriction on you, or a change to the measures we take when this policy is breached) is announced at least 30 days before it takes effect, by email to client contacts, agency administrators and partners, and by a notice in the product. The same notice period applies under these Terms, our Privacy Policy and the AI Services Addendum.
Clarifications and corrections take effect on publication, and the last-updated date is changed. Previous versions are kept in a public archive, showing the content of this policy on any date.
Schedule 2: AI Services Addendum
This Schedule forms part of the Hexifyer DevStudio Terms of Service and, for partners and agencies, of the Partner Terms, each of which incorporates it by reference. It governs the AI features in Hexifyer DevStudio and the use of AI in the work we deliver, and applies whenever anyone working on a DevStudio project uses an AI feature.
Where this Schedule and those agreements both address a point concerning AI, this Schedule governs. Where this Schedule and our Privacy Policy both state a figure, the Privacy Policy governs.
1. The AI features
The AI features are the parts of DevStudio that use a language model to read or generate text on your behalf: the assistant, which answers questions about a project; the writers, which draft task descriptions, log entries and summaries; the reporting engine, which compiles daily, weekly and monthly reports from project data; the meeting notetaker; the scheduled agent, which organises and classifies project content on a timer; and the AI estimator on our marketing site.
No metering. The AI features are not metered. DevStudio has no AI credits, no usage allowance and no AI purchases. AI usage is part of the service and is priced into the engagement.
2. Our commitments
No training on your content. Neither we nor the providers behind the AI features use your project content (tasks, comments, logs, meeting notes, files, deliverables or assistant conversations) to train, fine-tune or improve any model, whether ours or theirs, and whether individually or in aggregate.
Retention of no more than 30 days, for safety only. A provider processing one of your requests may retain it for up to 30 days for trust, safety and abuse monitoring, after which it is deleted. This retention is for the provider's investigation of misuse of its own service and is not used for any other purpose.
These commitments are made by Hexifyer. We hold our providers to them by contract and through configuration, and we publish the providers we use. The commitments do not change if a provider amends its own terms.
3. Where requests are sent
The sub-processor list in Section 24 of our Privacy Policy names every AI provider we use, what each one does, and the country in which it processes data. All of them currently process in the United States. That list is authoritative and is updated independently of this Schedule. You can subscribe to changes and object to a new sub-processor as described in our Privacy Policy.
Requests are sent only to providers in that list. Our routing is pinned to those providers and automatic fallback to any other provider is not permitted. A new provider is added to the sub-processor list, with notice, before it receives any request.
The location of your data (including the region, the data stores and the backups) is set out in our Privacy Policy and is the same whether or not a feature uses AI.
4. Your content in the AI features
Using an AI feature involves sending project content to a provider for processing. Only the content required for the action is sent (for example the task you asked about, the meeting you asked to summarise, or the surrounding context the assistant needs to answer).
In addition, project content is sent for embedding when it is created, not only when it is searched. Embedding is required for project search and for the assistant. Content therefore reaches our embedding provider whether or not anyone on the project uses the assistant, and, as set out in paragraph 9, no setting prevents this.
Permissions. The assistant answers only from content the person asking can already see. A partner asking about a project they are not assigned to receives nothing, a client cannot reach another client's project through the assistant, and an agency administrator cannot use it to see work a partner did under a different engagement. The visibility model in Section 9 of our Privacy Policy applies within the AI features in the same way as elsewhere in DevStudio.
The licence you grant under these Terms covers this processing and nothing further. It permits us to process your content to deliver the service, including through AI. It does not permit us to use your content for training, to build datasets, or to disclose it to anyone who does not already have access to it.
5. Client payload
In building software we may hold personal data belonging to a client's own users, such as a production database our developers are given access to, or a file of customer records uploaded into a task. Our Privacy Policy refers to this as client payload. We act as processor, not controller, of client payload.
Client payload received by file upload or through access to a production system is not sent to any AI provider. An uploaded file is stored and not embedded, the assistant does not read it, and the scheduled agent does not classify it. A live production system we are given access to is worked in directly and is not connected to any AI feature. Application of AI to a client's users' data (for example a migration, a classification job or an analysis) requires a separate instruction, agreed in writing under the Data Processing Agreement (Schedule 3 to the Terms), scoped to a named purpose and a named provider.
Text typed or pasted into a task, a comment, a sprint note or an assistant conversation is project content, whatever it contains. Project content is embedded when it is saved, so a customer record pasted into a task description reaches a provider even though the database it came from does not. We cannot distinguish such text from any other content, and no setting prevents its embedding. You are responsible for instructing your own personnel not to enter your users' data into free-text fields, as provided in clause 8 of the Data Processing Agreement (Schedule 3 to the Terms). Use a redacted sample, and tell us if such data is entered so that we can remove it.
6. AI in delivery work
This paragraph governs the use of AI by the people building your software, as distinct from the AI features within DevStudio.
Our partners use AI coding assistants, subject to the following conditions:
- Configured not to train. Any assistant used on your project must be on a plan and configuration under which your code and context are not used to train the vendor's models. A partner who cannot meet this condition uses no assistant on your project.
- Human accountability. Generated code is reviewed, tested and owned by the partner who submitted it in the same way as code they wrote themselves. The fact that a model generated it is not a defence and does not change responsibility under these Terms.
- No production data in coding assistants. Your production data is never entered into a coding assistant. This applies paragraph 5 to development tooling, and partners are briefed on it before they are assigned.
- Opt-out. If your policy, your client's policy or your regulator prohibits AI assistance in delivery, you must tell us before the engagement starts, and we will staff and contract accordingly. This may affect our estimate, and we will tell you how.
- No IP indemnity. We do not provide an intellectual property indemnity for generated code. Paragraph 10 sets out how responsibility for outputs is allocated, and generated code falls within it.
We will not use a general-purpose AI service in a way that exposes one client's codebase to another, or provide your repository to a tool we have not disclosed to you.
7. Partner data and AI
A partner's profile is commercial information about that partner, including their rate, availability, CV, portfolio and work history. It is handled under our Privacy Policy, subject to the following AI-specific commitments:
- No automated scoring. No model ranks partners, rates suitability, predicts performance or shortlists candidates. Assignment decisions and application decisions are made by people, as set out in Section 8 of our Privacy Policy.
- No client search of partner profiles. The assistant answers only from content the person asking can already see. A client can see a partner's name and photo, and the assistant cannot be used to obtain a partner's rate, CV or other engagements, whatever it is asked.
8. The AI estimator
The estimator on our marketing site converts a plain-language project description into a team composition, an hours breakdown, a cost and a timeline. It runs through an automation on n8n Cloud, which calls a model through the same gateway and the same named providers as the other AI features, subject to the no-training and 30-day retention commitments in paragraph 2.
- An estimate is not an offer. An estimate is a starting point for discovery. It does not bind either party to a price, a timeline or a team. Only an agreed statement of work is binding.
- It estimates a project, not a person. The estimator makes no assessment of the person who submitted the description and does not inform any decision about anyone.
- Submissions. What we store, for how long, and the uses we do not make of a submission are set out in Section 6 of our Privacy Policy.
9. AI features cannot be disabled
The AI features in DevStudio cannot be disabled for a project or for an account. No setting in the product and no request enables this, and none is planned.
Project content is sent to the AI providers named in our sub-processor list, including at the moment it is created and not only when it is searched, and no configuration prevents this. If this is not acceptable to your organisation, to your own client or to a regulator to which you are accountable, the work should not be run in DevStudio, and you should raise this during discovery, before the engagement starts.
The following commitments apply to every project: no training on your content; no provider retention beyond 30 days; every request pinned to a publicly named provider, with automatic fallback disabled; 30 days' notice and a right to object before a new provider is added; and the commitment in paragraph 5 that client payload does not reach an AI provider.
Optional features. Two features are optional, and for both the lawful basis is consent rather than contract: calendar sync, which reads or writes nothing until you connect an account, and the AI meeting notetaker, which runs only when turned on for a particular meeting and joins as a visible participant. Either may be declined at any time without affecting anything else.
Deletion. Deleting content deletes the data derived from it. An embedding is removed in the same transaction as the item from which it was derived, and assistant chat history is deleted when the conversation or the project record is deleted. Both follow the standard periods in Section 12 of our Privacy Policy: 72 hours from live systems and 14 days for backups. Deletion of derived data cannot be triggered in bulk by disabling a feature.
10. Outputs: ownership and responsibility
Ownership. Ownership of outputs is governed by these Terms, not by this Schedule. Deliverables (including wireframes, architecture, specifications and code) belong to you, whether or not a model contributed to them. An AI output that becomes part of a deliverable is part of that deliverable. An AI output that is internal working material (for example a drafted task description or a generated status report) forms part of the project record on the same terms as the rest of it. We claim no separate ownership of any model output and assert no licence over it beyond what is needed to operate the service.
Outputs may not be unique. Models produce similar outputs for similar prompts. Another customer may receive a materially similar output, and we give no assurance of exclusivity or originality in an AI-assisted output.
Outputs are provided as is. To the fullest extent permitted by law, we disclaim all warranties in respect of the outputs of the AI features, including as to accuracy, completeness, currency, reliability, fitness for a particular purpose and non-infringement. An AI output can be wrong. You must review an output before relying on it, and must not treat it as professional, legal, medical or financial advice.
Warranties for delivered work. The disclaimer above applies to the AI features themselves, such as an answer from the assistant, a generated summary or an estimate. It does not affect the warranties, acceptance criteria and remedies under these Terms that apply to the software we deliver. A defect in a deliverable is not excused because a model contributed to it.
Decisions about people. An AI output must not be the basis of a decision with a legal or similarly significant effect on a person (including hiring, dismissal, pay, discipline, credit, insurance, housing or access to a service) without review by a person. This applies to anything you build with us as well as to your use of DevStudio.
11. Restrictions
The restrictions on use of the AI features are set out in the Acceptable Use Policy (Schedule 1 to the Terms), which forms part of the same agreement. They prohibit: prompt injection; attempts to extract training data, model weights, system prompts or another project's content; use of outputs to train, benchmark or build a competing model or product; generation of content prohibited by that policy; entry of client payload or real production data into an AI feature; and use of an output for a consequential decision about a person without human review.
A breach of those restrictions is a breach of these Terms or of the Partner Terms, as applicable, and the suspension provisions of those agreements apply.
12. Changes to this Schedule
A material change to this Schedule (including a weakening of a commitment in paragraph 2, a new restriction, a change to the position on delivery tooling in paragraph 6, or any narrowing of paragraph 5) is announced at least 30 days before it takes effect, by email to client contacts, agency administrators and partners, and by a notice in the product. Clarifications and corrections take effect on publication, and the last-updated date is changed. Previous versions are kept in a public archive.
The addition or replacement of an AI provider is a change to our sub-processor list, not to this Schedule, and follows the notice and objection process described in Section 10 of our Privacy Policy.
Schedule 3: Data Processing Agreement
This Data Processing Agreement (the DPA) forms part of the Hexifyer DevStudio Terms of Service at https://devstudio.hexifyer.com/terms (the Terms), which incorporate it by reference. It is in force from the moment the Terms take effect and does not require signature.
This DPA governs personal data that Hexifyer DevStudio processes on your organisation's behalf. Hexifyer is the controller of the project record for each engagement, and our Privacy Policy is the disclosure for it. The personal data we hold on your instructions is personal data belonging to your own users, customers or staff, and that is the subject of this DPA. Where this DPA and the Privacy Policy both state a figure, the Privacy Policy governs.
1. Formation and parties
Hexifyer DevStudio is operated by Hexifyer FZ-LLC, a free zone company registered in Ras Al Khaimah, United Arab Emirates under licence number 47017173, at FOAM1588, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates. In this DPA, "Hexifyer", "we" and "us" mean that company. "You" means the client organisation that accepted the Terms.
Formation. This DPA takes effect when the Terms do and applies for as long as we process personal data on your behalf. Obligations that by their nature must outlive it (confidentiality, deletion, and the transfer safeguards in Annex D) survive its termination.
Signature. The Standard Contractual Clauses and the other transfer instruments described in Annex D are incorporated into this DPA and take effect with it. By accepting the Terms, each party is deemed to have signed them as of the date the Terms began. If your procurement process requires a countersigned copy, contact privacy@hexifyer.com and we will provide one with the same content.
Instructions. Instructions under this DPA are given by a client contact your organisation has authorised on the engagement, and an instruction from any such contact binds you. Where an instruction would change what we do with your users' data (a new purpose, a new destination, a longer retention), we will ask for it in writing at the address above before acting on it.
2. Scope
This DPA covers one category of personal data: personal data belonging to your own users, customers, employees or other people whose data your organisation controls, which you make available to us in the course of an engagement. Our Privacy Policy refers to it as client payload. Annex A describes it in full. It reaches us in two ways:
- Production access. You grant our developers access to a live system of yours that holds real personal data, such as a database, an admin console or a third-party account.
- Upload. Someone on your side puts a file containing real personal data into a DevStudio task, comment or asset folder, such as a customer export, an employee list, a support archive or a dataset for testing.
Data outside the scope of this DPA. All other data in DevStudio is data for which Hexifyer is the controller. It is not governed by this DPA because you do not instruct us in respect of it:
| Not covered by this DPA | Basis of our role | Covered by |
|---|---|---|
| Project content: tasks, sprints, logs, comments, meetings and notes, reports, assignments, files and deliverables | We run the delivery and determine what is logged, who is assigned, the sprint plan and the record of the work. We are the controller. | Sections 2, 4 and 12 of our Privacy Policy |
| Partner and agency records: profiles, rates, CVs, applications, assignments | These concern our relationship with our suppliers. What you can see is set out in Section 9 of our Privacy Policy. | Sections 4, 9 and 12 of our Privacy Policy |
| Your account and billing records, and your correspondence with us | We collect these and determine the purposes. | Sections 4 and 5 of our Privacy Policy |
For the data in the table above, Hexifyer is the controller and carries the lawful basis, transparency, retention, data subject rights and liability obligations directly to the people concerned. The Privacy Policy sets out those obligations and is enforceable against us by anyone it covers. Accordingly, a request from one of your users comes through you under clause 9. A request from a member of your staff who uses DevStudio, or from a partner, comes to us and we answer it directly.
Order of precedence:
- This DPA prevails over the other provisions of the Terms on anything concerning personal data we process on your behalf.
- Our Privacy Policy governs any figure, including a retention period, a deadline or a turnaround. If a figure in this DPA differs from the one in the Privacy Policy, we will honour the Privacy Policy figure and correct this DPA.
- The Standard Contractual Clauses and the other instruments in Annex D prevail over the rest of this DPA to the extent of any conflict, for the transfers they cover.
- Where a signed order form or statement of work exists between us, it prevails over this DPA to the extent it expressly says so.
3. Roles of the parties
The allocation of roles is the same as in Section 2 of our Privacy Policy.
| Data | Your role | Our role |
|---|---|---|
| Client payload: personal data belonging to your users, customers or staff, reached through production access or uploaded into a project | Controller | Processor. We process it on your documented instructions and for no purpose of our own. This DPA governs it. |
| Project content, partner and agency records, account and billing data: tasks, sprints, logs, comments, meetings, reports, assignments, files, partner profiles and applications, your account record | Not applicable: you do not instruct us in respect of this data | Controller. Our Privacy Policy is the disclosure, and the obligations are ours directly. |
| Deliverables as commercial property: wireframes, architecture, specifications, source code | Owner, under the Terms | Neither controller nor processor of them as property. Ownership is governed by the Terms, not by this DPA. |
Personal data in deliverables. A deliverable can contain personal data, for example a specification naming your stakeholders, a test dataset copied from production, or a screenshot showing a real customer's email address. Where it does, the personal data in it is client payload and is governed by the first row, even though the deliverable itself is a commercial asset owned by you.
Where you are a processor. If the personal data you make available to us belongs to your own client, you may be a processor rather than a controller for it. In that case we act as your sub-processor, you confirm that your controller has authorised the engagement, and Module Three of the Standard Contractual Clauses applies to the transfers instead of Module Two.
4. Instructions and limits on processing
We process client payload only on your documented instructions, including with regard to transfers, unless a law to which we are subject requires otherwise. In that case we will inform you before processing, unless that law prohibits us from doing so.
Your instructions consist of: this DPA and the Terms; the scope of work agreed for the engagement, including the systems you grant access to and the purpose that access serves; and any further written instruction you send to privacy@hexifyer.com. We will inform you if we consider that an instruction breaches data protection law, and we may decline to follow it until the matter is resolved.
Restrictions. In respect of client payload:
- We do not sell it, and we do not share it for advertising by anyone.
- We do not use it to train, fine-tune or improve any model, whether ours or a provider's.
- We do not send it to an AI provider where it reaches us by upload or through production access. Text pasted into a task, comment or note is project content and is processed by the AI features like any other project content. Clause 8 sets out where this line falls.
- We do not copy it out of your systems, to a local machine or elsewhere, except where the engagement requires it and you have requested it in writing.
- We do not use it as test data, seed data or demonstration data. Where an engagement needs realistic data, we ask you for a redacted or synthetic set rather than using production data.
- We do not access it except to carry out the engagement, to secure the service, or where the law requires it. Access requires a business reason and is logged.
- We do not disclose it to anyone other than the people working on your engagement, the sub-processors in Annex C, and the recipients of a legal request handled under clause 15.
Minimising production data. Where you can provide a redacted extract, a synthetic dataset or a staging environment instead of production data, you should do so. Where production data is necessary (for example for a migration, a defect that reproduces only on real records, or a report that must be checked against live figures), this DPA governs it.
De-identified and aggregated data. We generate de-identified and aggregated data from the operation of the service and use it for internal telemetry and to improve and secure DevStudio, and for no other purpose. We do not publish, share or sell it, or use it in marketing or benchmarking. It is not reversible, and we do not attempt re-identification. Client payload is never used as input. Telemetry is derived from how the product is used (events, volumes, timings, errors), not from the contents of your systems.
5. Personnel
Everyone who can access client payload is bound by a confidentiality obligation in their employment or engagement contract, which continues after their employment or engagement with us ends. This includes partners, who are contractors rather than employees and who are bound before they are assigned to an engagement.
Access is limited to the people who need it to carry out the engagement, requires a business reason and is logged. Our staff and partners work from Cairo and elsewhere. Where they access a system of yours, that is remote access to a system that remains where it is hosted.
Production access is granted only by exception. It is granted to named individuals rather than to a team, scoped to the narrowest permission the task needs, and revoked at the end of the engagement or the end of the phase that required it, whichever is sooner. You may revoke it yourself at any time without prior notice to us, and doing so is not a breach of the Terms. We keep a record of who held which access and when it ended, which you may request under clause 12.
6. Security
We implement and maintain the technical and organisational measures set out in Annex B, taking account of the state of the art, the cost of implementation, the nature, scope, context and purposes of the processing, and the risk to the individuals concerned.
Annex B describes measures currently in place. Planned measures are not included. We may change a measure as the product and the threat environment change, but we will not reduce the overall level of protection, and a material reduction is a change under clause 17.
We do not currently hold SOC 2 or ISO 27001 certification. In its place we make available Annex B, the sub-processor list, a completed security questionnaire under clause 12, and this DPA. If certification is a requirement of your procurement process, contact us and we will inform you of our current position.
7. Sub-processors
You give us a general written authorisation to engage sub-processors to help deliver the service. All sub-processors we use are named in the sub-processor list in Section 24 of our Privacy Policy, which is the authoritative list and is kept current. Annex C identifies which of them can receive client payload.
Sub-processors are engaged under standard written vendor agreements (which may include the vendor's standard data processing addendum) that impose data protection obligations appropriate to the service they provide. We remain fully liable to you for the acts and omissions of our sub-processors as if they were our own.
Notice of changes. We post a new sub-processor in the sub-processor list, and notify by email everyone subscribed to changes there, at least 30 calendar days before it begins processing. You may object in writing within 30 calendar days of that notice, on reasonable grounds relating to data protection, to privacy@hexifyer.com. We will work with you to resolve the objection, normally by explaining the safeguards in place or by making a change to the service available where possible. If we cannot resolve it within a reasonable period, you may terminate the affected engagement without penalty.
A new sub-processor does not begin processing until the notice period has expired. Removal of a sub-processor requires no notice. The sub-processor list and our configuration are updated in the same release.
Partners are not sub-processors. A freelance developer, designer or project manager working on your engagement acts under our direction and within our systems and controls, and is treated as our personnel for the purposes of this DPA rather than as a separate processor. Partners are bound by the confidentiality and access terms in clause 5, and we are liable for them as for our own staff. An agency that receives data about its own partners is a separate controller of that data, as described in Section 10 of our Privacy Policy. No client payload reaches it.
Propagation of rights requests. Where you exercise a right that must be passed on (an erasure or a correction affecting data held by a sub-processor), we propagate it to every affected sub-processor within 30 days, using the route each vendor provides.
8. AI providers
DevStudio uses AI throughout, and AI processing cannot be switched off. The assistant, the writers, search, the reporting engine and a scheduled agent all send project content to model providers outside our infrastructure, and project content is sent for embedding when it is created. Paragraph 9 of the AI Services Addendum (Schedule 2 to the Terms) explains why no such setting is offered and what is offered instead.
Client payload is never sent to an AI provider, provided it is submitted via secure file upload or accessed via direct production database connections. Any text, including client payload, manually typed or pasted by your users or partners into open text fields (such as task descriptions, sprint notes or comments) is classified as Project Content and will be processed by our AI features. You are solely responsible for instructing your personnel not to paste sensitive client payload into project text fields.
The line is determined by the route the data takes, not by how it is labelled. An uploaded file is stored and not embedded. A production system you grant us access to is worked on directly and is not connected to any AI feature. Text typed into a task is project content from the moment it is saved and is embedded at that moment, and no setting prevents this. Clauses 4 and 13 accordingly advise against entering your users' data in project text fields.
AI processing of client payload on instruction. Applying AI to your users' data (for example a classification job, a migration or an analysis) requires a separate written instruction under clause 4, scoped to a named purpose and a named provider and agreed before any data is sent. This is available on request and is never the default.
The following commitments apply to every AI provider we use:
- No training. Neither we nor any provider uses content from DevStudio to train, fine-tune or improve any model.
- Provider retention of no more than 30 days, for trust, safety and abuse monitoring only, after which the content is deleted. This is the same figure published in our Privacy Policy, our sub-processor list and the AI Services Addendum.
- Requests go only to named providers. Every AI request passes through a single gateway and is pinned to a named provider. Automatic fallback to a provider not in the sub-processor list is disabled, so a request cannot be served by a model that has not been disclosed to you.
The AI Services Addendum (Schedule 2 to the Terms) governs all other aspects of the AI features, including the use of AI coding assistants in the delivery work. Where the AI Services Addendum and this DPA both cover the handling of personal data, this DPA governs.
9. Data subject requests
Your users have rights over their personal data: access, correction, erasure, restriction, objection, portability and withdrawal of consent. For client payload those rights are exercised against you, as the controller.
Requests received by us. If one of your users contacts us directly about their data, we will not act on the request ourselves. We acknowledge it, inform the individual that it has been routed to you, and pass it to you within 6 working days. This is the deadline our Privacy Policy publishes for every rights request.
Assistance. Where the data is held in your own production system, you may satisfy the request directly. Where it is held in material you uploaded into a project, we will locate, extract, correct or delete it on your instruction, free of charge.
Requests for which we are controller. A person at your organisation who uses DevStudio is also our data subject: their account, their profile and their activity in the project are data we control. A request concerning that data comes to us and we answer it directly under Section 13 of our Privacy Policy, on the deadlines stated there. Clause 2 determines the allocation: a request concerning a person's use of DevStudio is ours to answer; a request concerning a person in your systems or your uploaded files is yours, and we support you.
10. Assessments and regulators
We provide the information you reasonably need to meet your own obligations regarding security of processing, breach notification, data protection impact assessments and prior consultation with a supervisory authority, taking account of the nature of the processing and the information available to us.
This comprises this DPA, Annex B, the sub-processor list, our published policies and a completed security questionnaire under clause 12, all free of charge. Where you require something bespoke (an assessment specific to your organisation, an unusual questionnaire, or engineering time to produce information we do not already hold), we will tell you what it involves and agree the cost with you in writing before we start. No charge will be made that you have not agreed.
Where your impact assessment concerns AI processing of material in your project, the relevant inputs are clause 8 and the AI Services Addendum (Schedule 2 to the Terms), including the fact that AI processing cannot be switched off.
11. Personal data breaches
If we become aware of a personal data breach affecting client payload, we will notify you without undue delay and in any event within 72 hours of becoming aware of it. The same period applies to our notifications to regulators.
The notification will state the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences, the measures taken or proposed, and a contact point. Where not all of this information is available at once, we will provide what we have and follow up with the remainder, and will not delay notification until it is complete.
Where a breach originates in a system of yours to which we had access, we notify you in the same way and within the same period, and provide our access records for the relevant period without waiting for a request.
We assist you in meeting your own notification obligations to regulators and affected individuals. We document every breach we identify, including those that do not meet a notification threshold and the reasons for that conclusion. Notification is not an admission of fault by either party.
12. Audits and information
You are entitled to verify our compliance with this DPA as follows.
12.1 Information on request, once every 12 months
- Annex B, our Privacy Policy, our sub-processor list and any third-party audit report or certification we hold at the time (at the date of this DPA, none).
- A written security questionnaire, answered in writing within 30 days of receipt. Standard industry questionnaires are preferred, and we will inform you if a questionnaire is unusually long.
- The production access record for your engagement, showing who held access to which of your systems, under what permission, and when access was granted and revoked.
- Any further information reasonably necessary to demonstrate compliance with this DPA, including with the Standard Contractual Clauses.
12.2 Inspection
If our written answers do not provide what you reasonably need, or following a personal data breach on our systems, you or an auditor you appoint may inspect our processing, subject to the following conditions:
- 21 days' written notice, with a proposed scope agreed in advance;
- during business hours, without unreasonable interference with our operations;
- the auditor is not a competitor of Hexifyer and is bound by confidentiality obligations at least as protective as those between us;
- the scope is limited to data and systems relevant to your processing, and the auditor is given no access to information about another client, or about a partner beyond what your engagement involves;
- no more than once every 12 months, except that after a breach affecting your data you may inspect within a reasonable period of it regardless of when you last did so;
- at your cost, including our reasonable time in facilitating it, agreed with you in advance.
If an audit or inspection identifies a material issue, we will remedy it and inform you of the action taken. Findings and any information obtained in the process are confidential to both parties.
13. Return and deletion
When we cease processing for you, because the engagement or this DPA ends, we will return or delete client payload at your election.
13.1 Return
For uploaded material, return means the project export. On request to privacy@hexifyer.com we deliver it within 5 working days as a single archive containing: a CSV file per entity type, each row carrying its own key and its parent's key so that the structure is preserved; your files in their original formats with a manifest; and a README stating the export date, the entity types included and anything excluded.
For production access there is nothing to return, as the data has not left your systems. Instead we provide the access record described in clause 12, showing what was accessible and when access ended.
13.2 Deletion
Deletion follows the figures in Annex E, which are the same figures published in Section 12 of our Privacy Policy. Deleted items remain in trash for 30 days. Erasure from our live systems is completed within 72 hours of a verified request. Copies in encrypted backups expire within 14 days after that and are not restored to serve a request. If we restore a backup taken before a deletion, we re-apply the deletion to the restored data.
At the end of an engagement, without the need for a request, production access is revoked and any credential you issued to us is treated as compromised and discarded rather than retained. You should also revoke access from your side, and we will remind you to do so.
Retained records. Invoices and tax records that the law requires us to keep (7 years under UAE corporate tax law, 5 years under Egyptian VAT law), and audit records for 12 months, retained so that a security incident can be investigated against records predating it. Neither contains client payload. No other data is retained.
The project record. Deletion of client payload does not delete the project record, which we hold as controller and retain for the duration of the engagement plus 24 months under Section 12 of our Privacy Policy. You may ask us to delete it sooner and we will do so, unless a statutory retention obligation requires otherwise. An instruction to delete under this DPA applies to your users' data, not to the record of the work.
Certification. On request and free of charge, we will certify in writing that deletion has been carried out, within 5 working days of its completion. We keep a record of each certification issued.
Notification emails. DevStudio notification emails contain the content of the item they concern, so deleting an item does not remove it from emails already delivered to recipients' mailboxes. Those copies are held in recipients' mail systems, outside our control, and cannot be recalled. Sections 12 and 19 of our Privacy Policy state the same. For this reason too, your users' data should not be entered into a task.
14. Data location and international transfers
All DevStudio project content, files and account records are stored in Frankfurt, Germany, in the AWS eu-central-1 region. This applies to every client and every partner regardless of location, and backups of both stores are held in the same region. Supabase holds authentication and stored files; Render holds the primary database, the AI database and the application services; AWS provides the underlying infrastructure for both.
Narrower categories of data reach our platform and AI sub-processors and are processed in those providers' own regions (currently Germany and the United States), as stated for each entry in the sub-processor list. Client payload reaching us by upload or through production access is not among them: an uploaded file is stored by the infrastructure providers in Frankfurt and reaches no other recipient. Client data typed into a task or comment is project content and is treated as project content, as clause 8 sets out.
Production access involves no transfer by us. Where our personnel access a system of yours, the data remains on your infrastructure in the country where you host it. This is remote access, not a transfer of your users' data to Germany or elsewhere, and Annex D treats it as such.
14.1 You are the data exporter for client payload
Where you upload personal data into a project, it leaves your country because you have placed it in a service hosted in Germany. As between you and us, you are the exporter of that data and we are the importer. The rights, consents and approvals a transfer requires attach to your relationship with the individuals concerned, with whom we have no relationship.
You therefore acknowledge that the following are your responsibility: the rights, the lawful basis, any consent, any notice to the individuals concerned, and any authorisation, registration or approval that a regulator in your country requires of you before personal data can be sent to a service hosted in Germany. This remains your responsibility for the duration of the engagement.
This is an acknowledgement, not a warranty. It records where responsibility sits, so that each party can answer a regulator accurately about its own obligations. It is not a promise to us, it is not subject to the indemnity in the Terms, and a gap in your local approvals is not a breach of this DPA. If you identify such a gap, we will assist you in documenting what we do with your data.
Our obligations. We inform you of exactly what happens to your data, and Annexes A to E are drafted so that you can describe it accurately to a regulator. We do not obtain local licences, permits or approvals on your behalf, we do not act as your representative before any authority, and we do not adopt country-specific processing templates. Our obligations to you are those in this DPA, and they are the same for every client in every market.
Data for which we are exporter. All data listed in the table in clause 2 (project content, partner and agency records, and your account and billing data) is data we control, so we are the exporter of it and the responsibility is ours, not yours. Sections 11 and 21 of our Privacy Policy are the disclosure for that data, and the basis we rely on is set out in Annex D.5.
Our staff and partners work from Cairo and elsewhere and access data that remains in Frankfurt. That is remote access to data already held abroad, not a further transfer of it to Egypt, and Annex D treats it as such.
15. Government and law-enforcement requests
If we receive a request from a government body, a law enforcement agency or a court for personal data we process on your behalf:
- We will inform the requester that we hold the data on your behalf and direct them to you, so that you can respond as the controller.
- Where we cannot redirect the request, we will notify you before disclosing anything, unless we are legally prohibited from doing so, in which case we will notify you as soon as the prohibition allows.
- We will challenge a request that appears unlawful, overbroad or not to follow proper legal process, and we will inform the authority that you have not authorised us to disclose your data.
- If we are required to disclose, we disclose the minimum the request legally requires and nothing more.
- We keep a record of every such request and the action taken.
We have not built, and will not build, any means of bulk or direct government access to client data.
16. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, and the cap in the Terms applies to claims under this DPA and the Terms in aggregate rather than separately.
This does not limit the rights a data subject has directly against either party under the third-party beneficiary provisions of the Standard Contractual Clauses, or any liability that cannot be limited under the data protection law that applies to you.
17. Changes to this DPA
We may update this DPA to reflect a change in the law, a change in the transfer instruments in Annex D, or a change to how the service works. A material change, meaning one that weakens a commitment made in this DPA, takes effect at least 30 days after we announce it by email to your client contacts and by a notice in the product. This is the same notice period used in Section 22 of our Privacy Policy and paragraph 12 of the AI Services Addendum (Schedule 2 to the Terms). Clarifications and corrections take effect on publication, and the last-updated date is changed. Previous versions are kept in a public archive.
Narrowing the commitment in clause 8 that client payload never reaches an AI provider is a material change.
Changes to the sub-processor list are not changes to this DPA and follow clause 7. Where a transfer instrument in Annex D is replaced by the body that issued it, the replacement applies from the date that body requires, and we will complete whatever it requires without the need for a further agreement from you.
18. Signed copies and notices
This DPA is in force without signature. If your procurement process requires a countersigned copy, write to privacy@hexifyer.com and we will send one for signature with the annexes completed for your organisation.
Written instructions, sub-processor objections, security questionnaires, export requests, deletion certification requests and anything else this DPA requires to be in writing are sent to the same address. Notices to you are sent to the client contacts on the engagement, and the Terms require you to keep at least one of them contactable.
Annex A: Details of the processing
This annex also serves as Annex I.A and I.B to the Standard Contractual Clauses. It describes client payload only. The data for which Hexifyer is controller is described in Sections 4 and 5 of our Privacy Policy.
- Data exporter: You, the client organisation that accepted the Terms, acting as controller (or as processor for your own client, in which case Module Three applies). You are the exporter of the personal data you make available to us, on the basis set out in clause 14. Contact details are those held on your account. Activities relevant to the transfer: engaging Hexifyer to build software.
- Data importer: Hexifyer FZ-LLC, FOAM1588, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates. Contact: privacy@hexifyer.com. Activities relevant to the transfer: delivering the engagement. Role: processor.
- Categories of data subject: Individuals appearing in the systems and files you make available to us. Typically: your users and customers; your employees and contractors; your own clients and their contacts; and anyone whose record is held in a database we are given access to or a file uploaded into a project. We have no relationship with any of them and, in most cases, no means of identifying them before seeing the data.
- Categories of personal data: Determined by you, being whatever your systems and files contain. Ordinarily: identity and contact data, account records, transaction and order history, support history, usage records, and any free-text field in your systems. Where a production database is accessed, the category is the whole schema unless the access granted is narrower.
- Special categories: DevStudio is not designed for special categories of personal data, and we do not request them. They may nonetheless reach us through production access, since a production system contains whatever data it holds: a health platform's database holds health data, a lender's holds financial data, and an HR system holds employment records and sometimes records of religion, disability or trade union membership. Granting access to such a system grants access to that data. Where you know an engagement will involve special-category data, inform us before it starts so that we can scope the access, limit who holds it and record the additional conditions that apply. You are responsible for establishing the lawful basis and meeting the additional conditions that apply to special-category data under the law that governs you, and for deciding whether an engagement should involve it at all. We do not obtain consent from your users, and nothing in the product obtains it on your behalf.
- Nature and purpose: Accessing, reading, querying and, where the engagement requires it, modifying, migrating or correcting personal data in your systems, for the purpose of building, testing, fixing or migrating the software you engaged us to deliver. Storing and securing files you upload into a project. No other processing, and in particular no analysis of the data, no derivation of insight from it, and no transmission of it to any AI provider.
- Frequency: Intermittent and task-driven rather than continuous. Access is exercised when a task requires it, by the people assigned to that task, and lapses when the phase ends.
- Duration: For the engagement, or the phase of it that required the access, whichever is shorter, and then the periods in Annex E. Sub-processors process for no longer than we do.
- Transfers to sub-processors: Uploaded files reach the infrastructure sub-processors only, processing in Germany. Production access reaches no sub-processor of ours. Neither route reaches a platform or AI sub-processor. Personal data typed into a project field is project content rather than client payload and is treated as project content. Annex C sets this out for each group.
- Competent supervisory authority: Where the Standard Contractual Clauses apply, the supervisory authority of the EEA member state in which you are established or, where you are not established in the EEA but the GDPR applies to you, the authority of the member state in which your EU representative is established. Annex D.4 names the FDPIC for Swiss transfers and Annex D.5 names the Egyptian Personal Data Protection Centre.
Annex B: Technical and organisational measures
This annex also serves as Annex II to the Standard Contractual Clauses. It describes the measures currently in place.
- Encryption: Data is encrypted in transit over TLS, and at rest in every store described in clause 14: Supabase Auth, Supabase Storage, the Render primary database and the Render AI database, and their backups.
- Production access control: Granted to named individuals rather than to a team; scoped to the narrowest permission the task needs; revoked at the end of the engagement or the phase requiring it, whichever is sooner; and recorded, so that who held what access and when can be evidenced. Credentials are not shared between people and are discarded rather than retained at the end.
- Separation of production from project material: Client payload is not copied out of your systems into DevStudio except where you have requested it in writing, and is not used as test, seed or demonstration data. Where realistic data is needed, we request a redacted or synthetic set.
- AI exclusion: Client payload that reaches us by upload or through production access is excluded from every AI feature: it is not embedded, not retrieved by the assistant, not classified by the scheduled agent and not summarised into a report. The control operates on the route, not on the content: text typed into a project field is project content and is processed as such, as stated in clause 8.
- Pseudonymisation: Where a person deletes their DevStudio account but their contributions remain in a project, their profile is anonymised and the content is retained without being attributed to them.
- Authentication: Password hashing; optional two-factor authentication; federated sign-in with Google, Apple, Microsoft, LinkedIn and GitHub. Account email changes are handled by us on request rather than self-serve.
- Access control within the product: The role model in Section 9 of our Privacy Policy, enforced per project and per agency context: a client sees their own projects and a partner's name and photo; a partner sees the projects they are assigned to; an agency admin sees only work done under that agency. The assistant answers only from what the person asking can already see.
- Access control for our personnel: Limited to people who need it to deliver or support the engagement; requires a business reason; logged. Remote access only: data stored with us remains in Frankfurt, and data in your systems remains with you.
- Confidentiality of personnel: Contractual confidentiality obligations that survive the end of employment or engagement, binding staff and partners alike, and entered into before a partner is assigned to a project.
- Logging and monitoring: Sign-ins, permission changes and content changes are recorded in an audit log, retained for 12 months so that an incident can be investigated against records predating it.
- Availability and resilience: Managed infrastructure with the redundancy operated by the platform providers; encrypted backups of both stores, held in the same region.
- Restoring availability after an incident: Restoration from backup. Where a restored backup predates a deletion, the deletion is re-applied to the restored data so that deleted content is not reinstated.
- Security of transfer: Encryption in transit to every sub-processor. AI requests pass through a single gateway pinned to named providers, with automatic fallback disabled.
- Physical security: Provided by AWS in eu-central-1 and inherited through Supabase and Render. Hexifyer holds no client data on its own premises, and as a matter of course none on staff or partner devices.
- Data minimisation and retention: The retention periods in Annex E, one per category, applied on a fixed schedule rather than at discretion.
- Data quality and rectification: Content is corrected directly in the product; account email changes are handled by us; clause 9 is the route for anything the product does not support.
- Portability and erasure: Project export as specified in clause 13; deletion on the Annex E figures; deletion certification on request; access revocation at the end of an engagement.
- Sub-processor governance: Sub-processors are bound by standard vendor data processing agreements requiring the protection and confidentiality of data. Vendor compliance is periodically reviewed.
- Incident management: A documented breach process meeting the 72-hour notification in clause 11, with documentation of every incident, including those below the notification threshold.
- Certifications: None. Hexifyer DevStudio does not currently hold a SOC 2 report or ISO 27001 certification. Clause 12 sets out the information available instead.
Annex C: Sub-processors
The current list of sub-processors, with the purpose of each, the data it receives and the country in which it processes, is published in Section 24 of our Privacy Policy. That list forms part of this annex and is the authoritative list. You can subscribe there to receive email notice of changes.
For client payload specifically, the position is narrower than the list as a whole:
- Infrastructure (Supabase, Render, Amazon Web Services; all processing in Germany, eu-central-1): Only where you upload a file containing client payload. That file is stored by Supabase Storage on AWS in Frankfurt. No other provider in this group receives client payload.
- Platform (transactional email, mobile push, meeting transcription, product analytics, and the automation behind the AI estimator): Not by either route described in clause 2. These providers receive notification content, calendar and meeting data, analytics events and estimator submissions. If someone pastes your users' data into a task, that text is project content and a notification email about the task would contain it, which is among the reasons clauses 4 and 8 advise against doing so.
- AI (the gateway and the model providers it routes to; all processing in the United States): Not for payload reaching us by upload or through production access. This is a contractual commitment, and narrowing it is a material change under clause 17. Text typed into a project field is project content and does reach these providers, including when it is saved. Clause 8 sets out where the line falls.
- Production systems (your own infrastructure, wherever hosted): No sub-processor of ours is involved. Our personnel access your system directly and the data does not pass through our systems.
Sign-in providers are not sub-processors. When someone signs in with Google, Apple, Microsoft, LinkedIn or GitHub, that provider authenticates them under its own terms and provides us with the profile fields they approve. We do not instruct it to process anything on our behalf.
Partners are not sub-processors, for the reason given in clause 7: they work under our direction, within our systems and controls, and we are liable for them as for our own staff.
Annex D: Transfer mechanisms by region
Hexifyer stores all DevStudio data in Frankfurt and applies one baseline to every client in every market. That baseline rests on the two bodies of law that govern DevStudio: the GDPR, which binds the infrastructure holding the data in Germany, and UAE Federal Decree-Law No. 45 of 2021, which governs Hexifyer as a company.
The baseline does not vary by country. Where the law that applies to you requires something beyond it (a local licence, a national standard contract, or an approval from a regulator), obtaining it is your responsibility, on the basis set out in clause 14. We will provide the information you need to obtain it, but we will not obtain it on your behalf.
D.1 United Arab Emirates
Hexifyer FZ-LLC is established in a Ras Al Khaimah free zone, which has no data protection legislation of its own, so Federal Decree-Law No. 45 of 2021 applies to us rather than the DIFC or ADGM regimes. Its Executive Regulations have not been issued. We apply the standard in this DPA to UAE-governed data and will adopt whatever the Executive Regulations require when they are issued, under clause 17.
D.2 European Economic Area
Where the GDPR applies to your processing and personal data is transferred to us, or onward to a sub-processor outside the EEA, the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914 apply and are incorporated into this DPA, with the following selections:
- Module Two (controller to processor) applies where you are a controller and we are your processor.
- Module Three (processor to processor) applies where you are a processor and we are your sub-processor.
- Clause 7 (docking clause) applies.
- Clause 9: Option 2, general written authorisation. The period for prior notice of sub-processor changes is that in clause 7 of this DPA: 30 calendar days.
- Clause 11: the optional independent dispute resolution language does not apply.
- Clause 17: Option 1. The clauses are governed by the law of Ireland.
- Clause 18(b): disputes are resolved before the courts of Ireland.
- Annex I.A and I.B are Annex A of this DPA; Annex II is Annex B; Annex III is the sub-processor list referenced in Annex C.
By accepting the Terms, each party is deemed to have signed these clauses.
D.3 United Kingdom
Where the UK GDPR applies, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018 applies, in the version current at the time of the transfer. Its Mandatory Clauses are incorporated by reference. Tables 1 to 3 are completed by Annexes A, B and C of this DPA. In Table 4, the exporter may end the Addendum as set out in section 19 of its Mandatory Clauses. Each party is deemed to have signed it.
D.4 Switzerland
Where the Swiss Federal Act on Data Protection applies, the clauses in D.2 apply with the following adaptations: references to the GDPR are read as references to the FADP; the Federal Data Protection and Information Commissioner is the competent supervisory authority for transfers governed by the FADP; the clauses protect the data of legal entities to the extent the FADP does; and data subjects habitually resident in Switzerland may bring proceedings in Switzerland.
D.5 Egypt
Where Egypt's Personal Data Protection Law No. 151 of 2020 applies, personal data leaves Egypt at the moment it is created, because it is written to Frankfurt at that moment and continuously thereafter. The transfer is structural and continuous rather than occasional. It is governed by Articles 14 to 16 of that Law, which permit a transfer where the destination affords a level of protection not lower than that provided by the Law, and which provide for licences and permits issued by the Personal Data Protection Centre.
Our position has two parts, reflecting our different roles. In DevStudio the second part covers the larger share of data:
- Client payload: you are the controller and we are your processor. This DPA is the instrument governing the transfer. It binds us by contract to the obligations in clauses 4 to 16 and to the measures in Annex B, and clause 7 flows those obligations down to every sub-processor that receives the data. Where client payload is accessed through production access rather than uploaded, no transfer out of Egypt occurs if your system is hosted in Egypt.
- Project content, partner records and account data: we are the controller. We rely on the level of protection available at the destination, which is Germany, a member state of the European Union.
| Requirement under Articles 14 to 16 | Position at the destination |
|---|---|
| A general data protection law binding on the recipient | Regulation (EU) 2016/679, the General Data Protection Regulation, applies directly in Germany alongside the Bundesdatenschutzgesetz. Both bind the infrastructure sub-processors holding the data there. |
| Rights for the individual, enforceable in practice | Access, rectification, erasure, restriction, objection and portability under Articles 15 to 21, with the right to complain to a supervisory authority and to a judicial remedy under Articles 77 to 79. Section 13 of our Privacy Policy sets out how they are exercised against us. |
| An independent supervisory authority with effective powers | The data protection authority of Hesse, the state in which Frankfurt is located, together with the federal and other state authorities, exercising the corrective and fining powers in Articles 58 and 83. |
| Security of processing and breach notification | Articles 32 to 34: security appropriate to the risk, notification to the authority within 72 hours, and notification to affected individuals where the risk is high. Clause 11 and Annex B apply the same standard and the same period to us. |
| Limits on onward transfer | Chapter V of the GDPR. Onward transfers from Germany to our platform and AI sub-processors are governed by the instruments in D.2 and by the flow-down and objection process in clause 7. Client payload reaching us by upload or through production access is not included in those onward transfers. |
| Purpose limitation and limits on retention | Article 5. Our own limits are in clause 4 and the retention periods are in Annex E. Both apply to every client, not only to those in one region. |
Licences and permits. Egypt has published no standard contractual clauses, no approved transfer instrument and no list of countries deemed to offer adequate protection, so there is no national template for us to adopt and nothing for us to sign on your behalf. Where the Personal Data Protection Centre requires a licence or permit for a transfer of client payload, obtaining it is your responsibility as the exporter, under clause 14. We provide the information needed to apply: the table above, Annex A (what is processed and about whom), Annex B (the measures protecting it) and Annex C (every recipient and the country in which it processes).
Consent. We do not ask individual users to consent to the transfer. Consent is not relied on as the basis for the transfer, because it may be withdrawn and the service operates from a single region, and because we cannot collect a data subject's consent for data we hold as processor rather than as controller. Nothing in this section reduces a right the Law gives you or the individuals whose data is concerned.
Transfer register. This transfer is entered in our internal cross-border transfer register, which records what is transferred, to which recipient and country, the mechanism relied on and the safeguards applied. The register is the evidence for this section, and you may request what it records about you under clause 12.
Annex E: Retention, deletion and response figures
This annex consolidates every figure in this DPA. They are the same figures published in our Privacy Policy, which governs.
| Item | Period |
|---|---|
| Deleted items in trash | 30 days, fixed, then purged |
| Grace period after an account deletion is started | 14 days, cancellable throughout |
| Erasure from live systems, after the grace period or a verified request | Within 72 hours |
| Last copy removed from encrypted backups | Within 14 days of erasure from live systems |
| Client payload you uploaded | Returned or deleted at the end of the engagement, at your election; earlier on written instruction |
| Production access granted to us | Revoked at the end of the engagement or the phase that required it, whichever is sooner; credentials discarded, not retained |
| Project record (held by us as controller, not client payload) | Duration of the engagement, then 24 months, then deleted; earlier on request |
| Meeting recordings, transcripts and notes | Same as the project record; any participant can have a specific recording deleted earlier |
| Embeddings and other AI-derived data | Deleted in the same transaction as the content they were derived from. Uploaded files and production data are not embedded, so none exists for them; text typed into a project field is embedded like any other project content |
| Audit and security logs | 12 months from the event |
| Retention by an AI provider | Up to 30 days, trust and safety only, then deleted; never used for training; client payload never reaches one |
| Invoices and tax records (statutory, survives deletion) | 7 years (UAE corporate tax); 5 years (Egypt VAT) |
| Project export delivered | 5 working days from request |
| Deletion certification issued, on request | 5 working days from completion of deletion |
| Routing one of your users' rights requests to you | 6 working days |
| Answering a rights request for which we are controller | 6 working days |
| Breach notification to you | Without undue delay, in any event within 72 hours |
| Propagating an erasure or correction to sub-processors | Within 30 days |
| Advance notice before a new sub-processor starts processing | 30 calendar days |
| Objection to a new sub-processor | 30 calendar days from notice |
| Answering a security questionnaire | 30 days, once every 12 months |
| Notice before an on-site inspection | 21 days |
| Notice of a material change to this DPA | 30 days |
DevStudio does not delete data for inactivity. There is no dormancy process and no reserved right to introduce one.