Privacy Policy
Last updated: July 6, 2026 · GDPR-compliant
DepthLevel is an international platform. This policy is written with GDPR as the primary framework — if you are based in the European Union, your rights under the GDPR apply in full. Users in other regions also benefit from equivalent protections under their local laws where applicable.
1. Who We Are
The data controller is [LEGAL_ENTITY], operating depthlevel.com ([REGISTERED_ADDRESS]). Contact: info@depthlevel.com.
2. Data We Collect
Account data: Email address and hashed password (via Supabase Auth). If you sign in with Google, we receive only your email and name from Google — no password.
Payment data: Your subscription status and billing dates. Card details are entered directly into Stripe’s PCI-DSS-certified environment — DepthLevel never sees or stores your card number, CVV, or expiry.
Usage data: Pages visited, features used, and session activity — used to operate and improve the Platform.
Technical data: IP address, browser type, device type, and referring URL — collected automatically by our hosting infrastructure.
3. How We Use Your Data & Legal Bases
- Contract performance (Art. 6(1)(b) GDPR): Creating and managing your account, processing your subscription, sending transactional emails (confirmations, password resets, billing).
- Legitimate interests (Art. 6(1)(f) GDPR): Platform security, fraud prevention, and aggregate analytics to understand how the Platform is used.
- Consent (Art. 6(1)(a) GDPR): Marketing emails, if you opt in. You may withdraw consent at any time.
For details on how immediate access to digital content affects your right of withdrawal, see our Terms of Service, Section 6.
4. Our Data Processors
We share data only with the following processors, each bound by data processing agreements:
- Supabase (Supabase Inc., USA) — Authentication and database storage. Infrastructure runs on AWS. EU data transfers are covered by Standard Contractual Clauses (SCCs).
- Vercel (Vercel Inc., USA) — Application hosting and global CDN. EU data transfers covered by SCCs.
- Stripe (Stripe Inc., USA) — Payment processing. PCI DSS Level 1 certified. EU data transfers covered by SCCs.
- Resend (Resend Inc., USA) — Transactional email delivery (account confirmations, password resets). EU data transfers covered by SCCs.
We do not sell your personal data to third parties.
5. International Data Transfers
All four processors above are US-based. Transfers of personal data from the European Economic Area (EEA) to the US are made under Standard Contractual Clauses (SCCs) as provided for under GDPR Article 46(2)(c). You may request a copy of the applicable SCCs by contacting us.
6. How Long We Keep Your Data
- Active accounts: For as long as your account remains active.
- After account deletion: We delete or anonymise personal data within 90 days, except where a longer retention period is required by law (e.g., tax and financial records, which may be kept for up to 10 years under Turkish commercial law).
- Server / access logs: Up to 90 days.
7. Your Rights Under GDPR
If you are in the EEA, you have the following rights. To exercise any of them, contact us at info@depthlevel.com:
- ACCESS Request a copy of your personal data.
- RECTIFY Correct inaccurate or incomplete data.
- ERASE Request deletion of your data (“right to be forgotten”).
- PORTABILITY Receive your data in a structured, machine-readable format.
- OBJECT Object to processing based on legitimate interests.
- RESTRICT Request that we limit how we process your data in certain circumstances.
- WITHDRAW Withdraw consent at any time (where processing is consent-based).
You also have the right to lodge a complaint with your local data protection authority. In Türkiye, the supervisory authority is the Kişisel Verileri Koruma Kurumu (KVKK).
8. Children’s Privacy
DepthLevel is not directed to persons under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, contact us immediately and we will delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to registered users by email. The “Last updated” date at the top of this page always reflects the most recent version.
10. Contact
Privacy questions or data requests: info@depthlevel.com
[LEGAL_ENTITY] · [REGISTERED_ADDRESS] · Tax ID: [TAX_ID]