Legal
Privacy Policy
Last updated: June 22, 2026
1. Who we are
Devino operates Notifly, a hosted platform that lets engineering teams send product notifications — email, SMS, push, in-app, and chat — through a single API. Questions about this policy or your data can be sent to [email protected].
Some data-protection laws (such as the EU GDPR) distinguish between a controller, who decides why and how personal data is processed, and a processor, who processes it on a controller's instructions. For our own websites and accounts we act as a controller. For the personal data your recipients generate when you route notifications through Notifly, we act as a processor on your behalf — see “Data we handle on your behalf” below.
2. Key terms
- Services — the Notifly websites (notifly.io), the managed cloud, and the hosted platform at app.notifly.io.
- Personal data — any information that identifies you directly or indirectly, including identifiers such as IP addresses or cookie IDs.
- You — a visitor to our sites or a user of our Services.
- Customer — an account holder who uses Notifly to send notifications.
- End recipient — a subscriber or contact of a Customer who receives notifications sent through Notifly.
3. Legal bases we rely on
Where the GDPR or similar laws apply, we only process personal data when we have a lawful basis to do so. Depending on the situation, that basis is one of: your consent; the performance of a contract with you; compliance with a legal obligation; or our legitimate interests in operating, securing, and improving the Services, where those interests are not overridden by your rights.
4. Data we handle on your behalf (as a processor)
When you use Notifly to deliver notifications, we process personal data about your end recipients strictly on your instructions and only to provide the Services. Depending on how you configure your workflows, this can include a recipient's name, email address, phone number, device or push tokens, locale, IP address, and the content and metadata of the messages you route to them.
For this data you are the controller and we are the processor — we do not use it for our own purposes. If you are an end recipient and want to exercise your rights, please contact the Customer that sent you the notification, since they control that data. Our handling of it is governed by our data processing terms.
5. Data we collect about you (as a controller)
When you interact with our own websites and accounts, we collect:
- Contact and newsletter details — if you message us through a form or subscribe to updates, we collect what you provide, such as your name, company, email, and the contents of your message.
- Account and registration data — to use the platform you create an account and provide at least your name and email. If you sign up through a third-party identity provider (for example GitHub or Google), we receive basic profile information from them, such as your email, name, username, and avatar.
- Billing information — for paid plans, payment is handled by our payment processor; we receive limited billing details (such as plan, status, and the last four digits of a card), not full card numbers.
- Usage and device data (cookies) — when you visit our sites or use the platform we automatically collect technical data such as your IP address, device and browser type, referring pages, and the actions you take. See “Cookies” below.
- Support communications — records of your correspondence with our support team.
6. How we use personal data
- Provide, operate, and maintain the Services, and authenticate your account.
- Process transactions and manage subscriptions.
- Respond to your requests and provide support.
- Monitor, secure, and improve the Services and develop new features, including by generating aggregate analytics.
- Detect, prevent, and address fraud, abuse, and security incidents.
- Send you service and administrative messages — these are not marketing, and you can't opt out of them while you hold an account.
- With your consent or as otherwise permitted, send you newsletters and product updates.
- Comply with legal obligations and enforce our agreements.
7. Marketing communications
We keep marketing to a reasonable level. You can stop marketing emails at any time using the “unsubscribe” link in any message, or by emailing [email protected]. Account, billing, and other service-related messages are part of the Services and will continue regardless of your marketing choices.
9. International data transfers
We and our service providers may process personal data in countries other than your own. Where we transfer personal data across borders — for example out of the EEA or the UK — we put appropriate safeguards in place, such as the European Commission's Standard Contractual Clauses or reliance on an adequacy decision, so that your data keeps an equivalent level of protection. Contact us for details of the safeguards we use.
10. Security
Protecting your data is a priority. We use technical and organizational measures — including encryption in transit, access controls, and monitoring — to guard against unauthorized access, loss, or misuse. No system can be guaranteed perfectly secure, and the safety of your account also depends on you keeping your credentials confidential.
11. Data retention
We keep personal data only as long as needed for the purposes described here, after which we delete or anonymize it. How long that is depends on the nature and sensitivity of the data, why we collected it, and our legal obligations. Subprocessors may retain data under their own policies. Email [email protected] for details on specific retention periods.
12. Your rights
Depending on where you live, you may have some or all of the rights below. We may need to verify your identity before acting on a request.
- Access — ask what personal data we hold about you.
- Correction — ask us to fix inaccurate or incomplete data.
- Deletion — ask us to erase your data (we may keep what we're legally required to).
- Restriction and objection — ask us to limit or stop certain processing.
- Portability — receive a copy of the data you provided in a portable format.
- Withdraw consent — where we rely on consent, withdraw it at any time without affecting prior processing.
- Complain — lodge a complaint with your local data-protection authority (we'd appreciate the chance to resolve it first).
To exercise any of these, email [email protected]. If the data is held on behalf of a Customer, please contact that Customer directly.
14. Third-party services
The Services may link to or integrate with third-party products. Your use of those is at your own risk and subject to their own terms and privacy policies — we're not responsible for how they operate.
15. Children
Notifly is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data without appropriate consent, contact us and we'll remove it.
16. Changes to this policy
We may update this policy to reflect changes in law or how we operate. We'll post the new version here and update the date above; significant changes may be highlighted. Please check back from time to time.
17. Contact us
Questions or requests about this policy or your personal data? Email [email protected] and we'll be glad to help.