Privacy & Data Governance
This document details how we capture, process, and secure client information, design assets, codebases, and WebRTC telemetry. Complete transparency, zero compromise on trust.
1. Scope & Purpose
We design, develop, secure, and host digital products. This policy states how we safeguard the metadata, source files, credentials, and telemetry generated during our workflow.
Designcoffers ("we", "us", "our") is a premium service provider delivering flat-rate unlimited design, full-stack software development, server management, security auditing, and WebRTC streaming architectures. Your data protection is the bedrock of our operational integrity. This Privacy Policy governs our primary website, client portal, asset hosting repositories, and communication interfaces.
By registering an account, purchasing a subscription, or interacting with our development and design team, you confirm your understanding of this policy. If you are entering into this agreement on behalf of a corporate entity, your acceptance extends to all users under your organization's workspace.
2. Data We Collect
We collect account details, payment credentials (managed via Stripe), design brief materials, repository source code, and telemetry details essential for our engineering teams.
To deliver high-class, responsive, and uninterrupted services, we collect three distinct tiers of data:
A. Explicitly Provided Information
- Corporate Identity & Account Profile: Full name, authorized email addresses, company name, corporate tax identification numbers, physical office location, and billing details.
- Creative Assets & Project Briefs: Brand packages, custom Figma files, UI style sheets, server credentials, database connection strings (if required for migration), source code libraries, and direct product requirements.
- Direct Communications: Interactive text chats, email correspondences, tickets submitted to our support team, and records of scheduled consultation calls.
B. Automatically Logged Metrics
- Telemetry & Session Data: Access timestamps, interaction durations, mouse patterns, navigation sequences, page load performance indicators, and interface errors.
- Device & Infrastructure Data: Internet Protocol (IP) address, localized geographic region, browser version, operating system environment, hardware architecture, and screen viewport dimensions.
C. Telemetry from Live WebRTC & Deployment Features
During active code testing, video streaming integrations, or WebRTC signaling sessions, we collect temporary signaling headers, connection reliability data, network latency metrics, and STUN/TURN connection paths to resolve routing quality. We do not store media contents of WebRTC calls.
4. How We Process Data
Data is processed to allocate project resources, execute secure coding assignments, compile design assets, manage billing cycles, and secure site operations.
We process collected data exclusively to support our core operational tasks:
- Service Fulfillment: Assigning senior developers and designers to your tasks, reviewing project requests, and returning code repositories or design links.
- Operational Maintenance: Diagnosing errors on our hosted servers, testing WebRTC signaling connectivity, and maintaining high server performance.
- Financial Transactions: Processing subscriptions, verifying credit card integrity, drafting commercial invoices, and mitigating fraudulent chargeback attempts.
- Customer Assistance: Answering operational queries, troubleshooting development integrations, and notifying you about updates or service interruptions.
- Internal Auditing & Analytics: Reviewing structural performance logs to optimize our client dashboards and user experience flow.
5. GDPR Legal Bases
We process EU/UK data under four primary legal bases: contract execution, legitimate business interests, legal compliance, and explicit consent.
For clients residing in the European Economic Area (EEA) or the United Kingdom, we process personal information in strict compliance with the General Data Protection Regulation (GDPR) and UK GDPR, relying on the following legal frameworks:
1. Contractual Necessity
Required to establish workspaces, compile and deliver deliverables, and manage monthly subscription billing.
2. Legitimate Business Interests
Applied to system security hardening, bot detection, development server monitoring, and communication routing.
3. Legal Compliance
Processing data required to compile corporate tax returns, enforce audit log requirements, and satisfy statutory court orders.
4. Explicit Consent
When you explicitly opt-in to receive promotional bulletins or design updates. You can retract consent instantly at any time.
7. International Transfers
Data transferred from Europe is protected via EU Standard Contractual Clauses (SCCs) and robust security safeguards.
Designcoffers operates worldwide. To support collaboration across global timezones, personal data may be accessed by authorized, senior team members in countries outside the EEA or United Kingdom.
When executing international data movements, we enforce Standard Contractual Clauses (SCCs) approved by the European Commission. This ensures that regardless of destination, your personal information benefits from the identical structural protections guaranteed inside Europe.
8. Retention & Disposal
Active account files are stored indefinitely. Suspended project files are archived after 180 days, and account deletions trigger complete data purge within 30 days.
We preserve personal data only as long as necessary to complete your creative design and coding requests, handle operational disputes, or comply with financial rules:
- Active Client Workspace: Maintained for the lifespan of your active subscription.
- Workspace Archival Policy: If a subscription is suspended or paused, project briefs and designs are placed in a cold archive for up to 180 days to allow quick reactivation. After 180 days, assets may be permanently purged from active systems.
- Account Deletion Protocol: Upon receiving a formal deletion demand, all account records are destroyed within 30 calendar days. Cold backups of databases are overwritten on standard 90-day cycles.
- Statutory Retention Requirements: Billing details, commercial invoices, and tax registers are stored for 7 years to satisfy regulatory audits.
9. Security Architecture
Zero-trust access, SSL/TLS 1.3 transit encryption, AES-256 storage encryption, and a committed 72-hour breach alert guarantee.
Our infrastructure operates under a zero-trust model. We implement rigorous security controls, including:
- Transit Encryption: All information exchanged with our websites or portals is protected in transit using TLS 1.3 cryptographic suites.
- Storage Encryption: All persistent database disks, object storage buckets, and file caches are encrypted at rest using AES-256.
- Fine-Grained Role Access: Team members can only access files or resources required to complete their immediate task (Principle of Least Privilege).
- Continuous Security Reviews: Our codebase, dependencies, and hosted servers undergo routine automated audits to detect vulnerabilities.
Breach Notifications: While no architecture is entirely secure, we maintain an active Incident Response plan. In the event of a confirmed breach compromising your personal data, we will notify you and relevant regulatory authorities within 72 hours of verification.
10. GDPR & CCPA Rights
You possess full rights to view, modify, transfer, or delete your personal details. California residents can opt-out of data sale or sharing under CCPA.
We respect your rights regarding how your personal information is stored and processed. You can exercise these rights at any time by contacting our security team.
For Users in the EU / UK (GDPR Rights):
- Right of Access & Portability: Obtain a structured, machine-readable export of all your stored data.
- Right to Rectification: Request correction of inaccurate profile or company metrics.
- Right to Erasure (To Be Forgotten): Request deletion of your personal account files.
- Right to Restriction & Objection: Object to specific automated analytical audits or processing tasks.
For Users in California (CCPA / CPRA Rights):
- Right to Know: Discover details regarding the categories of personal data collected and shared over the prior 12 months.
- Right to Deletion: Direct us to erase collected personal data.
- Right to Opt-Out of Sale or Sharing: Designcoffers does not sell or share data as defined under CCPA. If this changes, we will supply a clear "Do Not Sell or Share My Info" link.
- Right to Non-Discrimination: Exercising your privacy rights will never result in degraded performance, subscription limits, or increased fees.
To invoke any of these rights, email us at privacy@designcoffers.com. We will verify your identity before processing the request.
11. Children's Protection
Our services are restricted to individuals aged 16 and older. We do not collect minor telemetry.
Designcoffers' creative subscriptions, development servers, and software portals are targeted exclusively at adults, businesses, and corporate teams. We do not structure services for children under 16 years of age.
We do not knowingly collect personal data from minors. If you believe a child under 16 has submitted profile data, contact us immediately. We will take proactive steps to delete the information from our databases.
12. Revisions & Updates
Material updates will be notified to subscribers via email and recorded in our online change log.
We may modify this policy as our platform features and legal demands evolve. The active revision date at the top of this document indicates when changes were last deployed.
For minor cosmetic adjustments, updates are posted directly to this page. In the event of material processing changes (e.g., introducing a new subprocessor handling client files), we will provide 15 days' notice by emailing all active account administrators.
13. DPO & Contact Info
Have questions about our data safety?
Our Data Protection Officer and compliance team respond to queries within 10 business days.