DEV.co
Legal

Privacy Policy

Last updated: August 18, 2026 · Effective: August 18, 2026

This Privacy Policy explains how DEV.co (“DEV.co,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards personal information when you visit our websites, contact us, apply for a job with us, or engage us for services. It also explains the rights you have over your information and how to exercise them.

Please read it carefully. By accessing or using our sites and services, you agree to the practices described here. If you do not agree, please do not use our sites or services.

The short version

  • We collect what you send us through forms and what your browser reports automatically. We do not sell personal information.
  • We use analytics and, in some regions, advertising cookies. You can refuse non-essential cookies without losing core site functionality.
  • We do not use client project materials, source code, or confidential data to train AI models, and we do not permit our vendors to do so.
  • When we build software for a client, that client — not DEV.co — decides what happens to the end-user data in their system. We act on their instructions.
  • You can request access, correction, deletion, or a copy of your data at [email protected], wherever you live — not only where the law requires it.
  • We are based in the United States and store data there. Transfers out of the EEA/UK rely on Standard Contractual Clauses.

This summary is for orientation only. The full text below is what governs.

1. Scope & Affiliated Properties

This Privacy Policy applies to DEV.co and the affiliated web properties and services we operate, including:

  • DEV.co
  • LLM.co
  • Automatic.co
  • RMA.ai
  • SEARCH.co

References to “our sites” or “our services” include all of the properties listed above. Where a specific property publishes additional or different privacy terms, those terms are presented on that property and control to the extent of any conflict with this policy.

This policy does not apply to third-party websites, products, or services that we do not own or control, even where they link to or from our sites, and it does not apply to software we build and hand over to a client once that client operates it themselves.

2. Our Role: Controller vs. Processor

The role we play determines which obligations apply and who you should contact about your data. There are two distinct situations:

We are the controller
For personal information collected through our own websites, marketing, recruiting, sales inquiries, and business operations, DEV.co decides why and how the data is processed. This policy governs that activity, and you can exercise your rights directly with us.
We are the processor (or service provider)
When we build, host, or maintain software for a client, we process end-user data on that client’s instructions and for their purposes. The client is the controller. Our handling of that data is governed by our agreement and Data Processing Addendum with them — not by this policy. If you are an end user of a client’s product, direct your privacy request to that client; if you reach us instead, we will refer you to them and notify them of your request.

3. Key Terms

Personal information
Information that identifies, relates to, describes, or could reasonably be linked with a particular individual or household. Referred to as “personal data” under GDPR.
Sensitive personal information
A subset of personal information given heightened protection by law — for example government identifiers, precise geolocation, racial or ethnic origin, health data, biometric data, and the contents of private communications.
Processing
Any operation performed on personal information, including collection, storage, use, disclosure, and deletion.
Subprocessor
A third party we engage to process personal information on our behalf, such as a hosting or email-delivery provider.
Deidentified data
Data that cannot reasonably be used to infer information about, or otherwise be linked to, an identifiable individual. We maintain deidentified data in that condition and do not attempt to reidentify it.

4. Information We Collect

Information you provide to us

  • Contact and inquiry details — name, email address, phone number, company name, company website, and job title — submitted through our contact forms, project brief forms, cost calculator, email, or scheduling tools.
  • Project information you share when evaluating or performing services, including descriptions of your systems, requirements, budgets, and timelines.
  • Communications, including the contents of messages, support requests, chat sessions, call notes, and feedback.
  • Recruiting information if you apply for a role — CV/resume, work history, education, portfolio and code-sample links, work authorization status, and compensation expectations.
  • Billing and payment details for clients, such as billing contact, address, and tax identifiers. Card and bank details are handled by our payment processors; we do not store full payment card numbers.
  • Any other information you choose to provide.

Information collected automatically

  • Device and usage data — IP address, browser type and version, operating system, device type, screen size, referring and exit pages, pages viewed, links clicked, and timestamps.
  • Cookies, pixels, tags, and similar technologies (see the Cookies section below).
  • Approximate location — city or region level — derived from IP address. We do not collect precise GPS location from our websites.
  • Diagnostic and security data, including error logs, request logs, and records of suspected abuse or automated traffic.

Information from third parties

  • Analytics and measurement providers that report on how our sites perform.
  • Advertising and marketing partners, where applicable in your region.
  • Business contact and enrichment providers, publicly available sources, and professional networks.
  • Referrals and introductions from partners, clients, and other business contacts.

We may combine information from these sources with information we already hold about you.

5. Notice at Collection

The table below summarizes the categories of personal information we collect, why we collect them, where they come from, who we disclose them to, and how long we keep them. Category names follow the California Consumer Privacy Act so the disclosure maps cleanly onto that statute; the substance applies to all visitors.

Categories of personal information collected in the preceding 12 months.
CategoryExamplesSourcePurposeDisclosed toRetention
IdentifiersName, email, phone, company, IP address, cookie IDsYou; automatic collectionRespond to inquiries; operate and secure the sites; marketingHosting, email, analytics, CRM and scheduling providersUp to 7 years from last contact
Customer recordsBilling contact, billing address, tax identifiersYouContracting, invoicing, accountingPayment processor; accountants7 years (tax and accounting)
Commercial informationServices inquired about, proposals, engagement historyYou; our recordsProvide services; account managementHosting and CRM providers7 years from engagement end
Internet or network activityPages viewed, referring URLs, clicks, session dataAutomatic collectionAnalytics, performance, security, fraud preventionAnalytics providers14–26 months
Geolocation (approximate)City/region inferred from IPAutomatic collectionLocalization, analytics, securityAnalytics providers14–26 months
Professional or employment informationCV, work history, education, portfolio linksYou; recruiting platformsEvaluate applications; recruitingApplicant tracking and assessment providers2 years after a decision, unless you ask us to delete sooner
Audio/electronic informationContents of emails, form submissions, chat, call notesYouRespond to and document communicationsEmail, chat, and CRM providersUp to 7 years from last contact
InferencesLikely industry, project fit, content interestsDerived from the abovePersonalize content; prioritize outreachCRM providersUp to 3 years

We do not knowingly collect personal information from children, and we do not sell or share personal information as those terms are defined under US state privacy laws.

6. Sensitive Personal Information

We do not seek sensitive personal information through our websites, and we ask that you not send it to us in an inquiry. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit under applicable law, and we do not use it to infer characteristics about you.

Two narrow exceptions exist. Recruiting may involve work-authorization status, and where required by law we may collect diversity information on a voluntary, self-identified basis that is kept separate from hiring decisions. Client engagements may involve regulated data — for example health or financial records — in which case we handle it as a processor under the client’s instructions, a Data Processing Addendum, and any applicable Business Associate Agreement, not under this policy.

Please do not include passwords, API keys, production credentials, health records, financial account numbers, or government identifiers in a contact form or an unencrypted email. If an engagement requires that material, we will provide a secure channel for it.

7. How We Use Your Information

We use the information we collect to:

  • Respond to inquiries, prepare estimates and proposals, and communicate with you about our services.
  • Provide, operate, maintain, secure, and improve our sites and services.
  • Personalize content and understand how our sites are used, including which pages and topics are useful.
  • Send administrative and transactional messages such as confirmations, invoices, and service notices.
  • Send marketing communications where permitted, which you may opt out of at any time.
  • Evaluate job applications and manage recruiting.
  • Administer contracts, invoicing, collections, and accounting.
  • Detect, investigate, prevent, and address fraud, abuse, security incidents, and technical problems.
  • Create aggregated or deidentified statistics that do not identify you.
  • Comply with legal, tax, and regulatory obligations, establish or defend legal claims, and enforce our agreements.

If we intend to use your information for a materially different purpose than the one for which it was collected, we will provide notice and, where required, obtain your consent first.

8. Artificial Intelligence & Machine Learning

We build AI systems for clients and we use AI-assisted tooling internally. Because that raises reasonable questions about what happens to your data, we state our position plainly:

  • We do not use client project materials, source code, confidential business information, or the contents of your inquiries to train publicly available or third-party AI models.
  • Where we use AI-assisted development or productivity tools, we configure them, and contract with their providers, so that submitted content is not retained for model training.
  • We do not sell or license your personal information to AI developers as training data.
  • AI-assisted drafting may be used for internal summaries or first drafts of routine communications. A person reviews any output that affects you before it is sent or acted on.
  • Where a client engagement involves training a model, the training data, the model, and the resulting rights are governed by that engagement’s written agreement.

9. Automated Decision-Making & Profiling

We do not make decisions producing legal or similarly significant effects about you — such as credit, employment, housing, insurance, or access to essential services — based solely on automated processing without human involvement.

We do carry out limited profiling: we infer likely industry and project fit from what you tell us so we can route your inquiry and tailor follow-up, and we score marketing engagement to decide what to send. A person reviews any hiring decision, and automated screening is not the sole basis for rejecting an application.

Where applicable law grants you the right to opt out of profiling in furtherance of decisions producing legal or similarly significant effects, you may exercise it using the contact details below.

11. Cookies & Tracking Technologies

We use cookies and similar technologies — pixels, tags, local storage, and SDKs — to operate our sites, remember your preferences, measure performance, and understand usage. The categories we use are:

CategoryWhat it doesConsent requiredTypical lifespan
Strictly necessaryRouting, load balancing, security, fraud prevention, and remembering your cookie choicesNo — the site cannot function without theseSession to 12 months
Performance & analyticsCounts visits, measures page performance, and shows which content is usedYes, where required by lawUp to 26 months
FunctionalRemembers preferences such as form progress and scheduling widgetsYes, where required by lawSession to 12 months
Advertising & retargetingMeasures campaigns and shows relevant ads on other sitesYesUp to 13 months

You can control cookies through your browser settings and, where offered, through the cookie controls on our sites. Disabling strictly necessary cookies will break parts of the site; disabling the other categories will not. Where required by law, we obtain consent before setting non-essential cookies, and we make refusing as easy as accepting.

Most browsers let you delete existing cookies, block future ones, and receive a warning before one is set. Instructions differ by browser and are available in its help documentation.

12. Analytics & Advertising Partners

We use Google Analytics to understand aggregate site usage. Google processes this data under its own terms; you can prevent Google Analytics from collecting your activity by installing Google’s browser opt-out add-on.

We also use conversion measurement and, in some regions, retargeting so that our ads reach people who have shown interest in our services. These partners may set cookies and receive your IP address and pages viewed. We do not provide them with your name, email, or the contents of your project inquiries for their own independent marketing.

Some US state privacy laws define “sharing” broadly enough to include cross-context behavioral advertising. To the extent our advertising cookies constitute “sharing” under those laws, you may opt out using the mechanisms described in the next section.

13. Global Privacy Control & Do Not Track

We honor the Global Privacy Control (GPC) signal. Where your browser or extension transmits GPC, we treat it as a valid request to opt out of sale and sharing of personal information for the browser sending it, as required by California and several other state laws.

Separately, some browsers offer a “Do Not Track” setting. Because no common industry standard for interpreting that signal was ever adopted, our sites do not respond to it. Use GPC or our cookie controls instead — both produce an effect we can honor.

14. How We Share Information

We may share your information in the following circumstances:

  • Service providers and subprocessors that perform functions on our behalf, under contractual confidentiality and data-protection obligations.
  • Affiliated properties listed in this policy, where doing so is consistent with the purposes described here.
  • Professional advisers — lawyers, accountants, auditors, and insurers — where necessary and subject to professional duties of confidence.
  • Legal and safety reasons, including to comply with applicable law, respond to lawful requests from public authorities, enforce our agreements, or protect the rights, property, and safety of DEV.co, our clients, our users, and the public.
  • Business transfers, such as a merger, acquisition, financing, reorganization, or sale of assets, in which case information may be transferred as part of that transaction. We will give notice if your information becomes subject to a materially different privacy policy.
  • With your consent or at your direction.

We do not sell or rent your personal information to third parties for their own marketing purposes, and we have not done so in the preceding 12 months.

When we receive a government or law enforcement demand for data, we require valid legal process, evaluate whether the request is overbroad, disclose only the narrow set of data called for, and — where we are legally permitted — notify the affected person or client before responding.

15. Service Providers & Subprocessors

We engage a limited set of vendors to run our business. Each is bound by written terms requiring them to process personal information only on our instructions, protect it with appropriate security, and delete or return it at the end of the engagement.

Categories of subprocessors and what they handle.
CategoryPurposeData involvedLocation
Cloud hosting & CDNServing our websites and applicationsIP address, request logs, submitted form contentUnited States
Transactional emailDelivering form submissions, confirmations, and invoicesName, email, phone, message contentsUnited States
Analytics & measurementAggregate site usage and performanceIP address, device and usage data, cookie IDsUnited States, EU
CRM & marketing automationManaging inquiries and follow-upContact details, engagement history, inferencesUnited States
Scheduling & meetingsBooking and hosting callsName, email, meeting metadataUnited States
Chat & support widgetAnswering questions on the siteChat contents, contact details, page contextUnited States
Applicant trackingRecruiting and hiringCV, work history, contact detailsUnited States
Payments & accountingInvoicing, collections, bookkeepingBilling contact, invoice records, tax identifiersUnited States

A current list of named subprocessors is available to clients and prospective clients on request at [email protected]. Clients with a signed Data Processing Addendum receive advance notice of new subprocessors and may object as provided in that addendum.

16. Third-Party Services & Links

Our sites may contain links to third-party websites, including client work, open-source projects, partner sites, and social platforms. We are not responsible for the privacy practices or content of those sites, and this policy does not apply to them. Review their policies before providing information.

Embedded third-party content — such as videos, maps, or scheduling widgets — may collect data directly from your browser even if you do not interact with it. That collection is governed by the provider’s own policy.

17. Client & Project Data

When we build, host, or maintain software for a client, we may have access to data held in that system — including the client’s own customer or employee data. That access is governed by our services agreement and Data Processing Addendum, not by this policy.

Our standing commitments on client data are:

  • We process it only on the client’s documented instructions and for the purposes of the engagement.
  • We use production data in development or testing only where the client instructs it; otherwise we work with synthetic or masked data.
  • Access is limited to personnel who need it for the engagement, under confidentiality obligations that survive the engagement.
  • We do not use it to train AI models, to build our own products, or for any purpose of our own.
  • On termination we return or delete it as the client directs, subject to retention required by law.
  • We support client compliance obligations, including responding to data-subject requests routed through the client and assisting with breach notification.

Where an engagement involves regulated data, we will enter into the applicable additional agreement — a Business Associate Agreement for protected health information, or equivalent terms for financial, educational, or government data.

18. Job Applicants & Recruiting

If you apply for a role with us, we collect the information in your application and any assessment materials, interview notes, and references you authorize us to contact. We use it to evaluate your application, communicate with you, and — where you consent — consider you for future openings.

We retain applicant records for two years after a hiring decision so we can respond to follow-up questions, defend against claims, and reconsider strong candidates for later roles. You can ask us to delete your application data sooner at [email protected].

Background or reference checks, where conducted, happen only after a conditional offer, with your authorization, and in compliance with applicable law. We do not ask for salary history where prohibited. Any voluntary diversity information is stored separately and is not visible to hiring managers.

19. Data Retention

We keep personal information only as long as necessary for the purposes described in this policy, then delete or deidentify it. Where a legal, tax, accounting, or dispute-resolution obligation requires a longer period, that period controls.

DataRetention periodWhy
Website analytics and usage data14–26 monthsYear-over-year trend analysis
Security and access logs12 monthsIncident investigation and abuse prevention
Inquiry and prospect recordsUp to 7 years from last contactBusiness continuity and dispute defense
Client engagement records and contracts7 years from engagement endTax, accounting, and limitation periods
Invoices and financial records7 yearsTax and accounting law
Marketing contactsUntil you unsubscribe, then a suppression record indefinitelyHonoring your opt-out
Job applications2 years after a decisionFuture roles and claim defense
Cookie consent records12–24 monthsDemonstrating valid consent
BackupsRolling, up to 90 daysDisaster recovery

Deletion requests are honored across active systems promptly and propagate out of backups as those backups age out on the rolling schedule above. We do not restore deleted data from backup except in a genuine disaster-recovery event.

20. Data Security

We implement administrative, technical, and physical safeguards designed to protect personal information, including:

  • Encryption in transit using current TLS, and encryption at rest for stored data and backups.
  • Role-based access control on a least-privilege basis, with access reviewed periodically and revoked promptly on role change or departure.
  • Multi-factor authentication on administrative accounts and code repositories.
  • Network protections including firewalling, rate limiting, and bot mitigation.
  • Secrets management, so credentials are not stored in source code.
  • Logging and monitoring of administrative and security-relevant events.
  • Security review in the development lifecycle, including dependency scanning and code review.
  • Vendor due diligence before engaging a subprocessor that will handle personal information.
  • Confidentiality obligations and security training for personnel and contractors.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping confidential any credentials you use with us and for the security of the systems from which you contact us.

21. Security Incidents & Breach Notification

We maintain an incident response process covering detection, containment, investigation, remediation, and notification.

If a security incident affects your personal information, we will notify you and any applicable regulator as required by law. For clients, where we act as processor, we notify the client without undue delay after becoming aware of a personal-data breach affecting their data, and provide the information they need to meet their own notification obligations — including what happened, the categories and approximate volume of data involved, likely consequences, and the steps we have taken.

To report a suspected vulnerability or security issue, email [email protected]. We do not pursue legal action against good-faith security research that respects user privacy, avoids service disruption and data destruction, and gives us reasonable time to remediate before disclosure.

22. Your Privacy Rights

Depending on where you live, you may have some or all of the rights below. As a matter of practice we extend the core rights — access, correction, deletion, and portability — to everyone who asks, regardless of location.

  • Access / know — obtain confirmation that we process your data and a copy of it, along with details of purposes, categories, recipients, and retention.
  • Correction — have inaccurate or incomplete information rectified.
  • Deletion / erasure — have your personal information deleted, subject to legal exceptions.
  • Portability — receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time.
  • Restriction — request that we limit processing while a dispute about accuracy or lawfulness is resolved.
  • Opt out of sale, sharing, or targeted advertising — we do not sell personal information; you can opt out of advertising cookies at any time.
  • Limit use of sensitive personal information — we do not use it beyond permitted purposes.
  • Opt out of profiling in furtherance of decisions producing legal or similarly significant effects.
  • Withdraw consent — where processing is based on consent, without affecting prior processing.
  • Non-discrimination — we will not deny service, charge a different price, or provide a lesser quality of service because you exercised a privacy right.

23. How to Exercise Your Rights

Email [email protected] with the request and enough detail for us to identify your records. You may also write to us at the address on our contact page.

Verification

To protect your information we verify requests before acting. For most requests we confirm control of the email address on file and ask you to confirm details we already hold. For requests involving sensitive information or deletion of a substantial record, we may ask for additional verification. We use information provided for verification only for that purpose.

Authorized agents

You may use an authorized agent to submit a request. We will ask for written authorization signed by you and may still ask you to verify your identity directly, except where the agent provides a valid power of attorney.

Timing

We acknowledge requests within 10 business days and respond substantively within 45 days, extendable by an additional 45 days where reasonably necessary, with notice to you. Under GDPR/UK GDPR we respond within one month, extendable by two further months for complex requests. There is no fee unless a request is manifestly unfounded or excessive, in which case we will tell you before proceeding.

Appeals

If we decline your request, our response will explain why and how to appeal. To appeal, reply to our decision with “Privacy Appeal” in the subject line; a reviewer not involved in the original decision will respond within 45 days. If we deny the appeal, we will tell you how to contact your state attorney general or supervisory authority.

24. California Privacy Rights

California residents have rights under the California Consumer Privacy Act as amended by the CPRA. The categories of personal information we collect, our purposes, sources, and recipients are set out in the Notice at Collection table above.

  • Right to know the categories and specific pieces of personal information collected, the sources, the business purpose, and the categories of third parties to whom it was disclosed.
  • Right to delete personal information we collected from you, subject to statutory exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of the sale or sharing of personal information. We do not sell personal information. To the extent advertising cookies constitute “sharing,” you may opt out through our cookie controls or by transmitting a Global Privacy Control signal.
  • Right to limit use and disclosure of sensitive personal information. We do not use sensitive personal information for purposes that trigger this right.
  • Right to non-discrimination for exercising any of these rights.

We disclosed the categories of personal information described in the Notice at Collection table to service providers for business purposes in the preceding 12 months. We did not sell personal information and did not knowingly sell or share the personal information of consumers under 16.

Shine the Light: California Civil Code § 1798.83 permits residents to request information about disclosure of personal information to third parties for their direct marketing purposes. We do not make such disclosures, but you may confirm this by writing to [email protected].

25. Other U.S. State Privacy Rights

Comprehensive privacy laws in a growing number of states provide broadly similar rights. If you are a resident of one of these states, you may exercise the rights below using the process in Section 23. We honor these requests regardless of whether we meet a given state’s applicability thresholds.

StateLawRights available
CaliforniaCCPA / CPRAKnow, delete, correct, opt out of sale/sharing, limit sensitive data, non-discrimination
VirginiaVCDPAAccess, correct, delete, portability, opt out of targeted advertising and profiling, appeal
ColoradoCPAAccess, correct, delete, portability, opt out incl. universal opt-out signals, appeal
ConnecticutCTDPAAccess, correct, delete, portability, opt out, appeal
UtahUCPAAccess, delete, portability, opt out of targeted advertising and sale
TexasTDPSAAccess, correct, delete, portability, opt out, appeal
OregonOCPAAccess incl. list of third parties, correct, delete, portability, opt out, appeal
MontanaMCDPAAccess, correct, delete, portability, opt out, appeal
Delaware, Iowa, Nebraska, New Hampshire, New JerseyState consumer privacy actsAccess, correct (except Iowa), delete, portability, opt out, appeal
Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode IslandState consumer privacy actsAccess, correct, delete, portability, opt out, appeal

Nevada: residents may direct us not to sell certain covered information. We do not sell covered information, but you may submit a verified request to [email protected].

Washington and Nevada health data laws: we do not collect consumer health data as defined by the My Health My Data Act or Nevada SB 370 through our websites.

26. EEA, UK & Swiss Rights

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the rights listed in Section 22 under the GDPR, UK GDPR, or the Swiss FADP, including the rights to access, rectification, erasure, restriction, portability, and objection, and the right not to be subject to solely automated decisions with legal or similarly significant effects.

You also have the right to lodge a complaint with your local supervisory authority. In the UK that is the Information Commissioner’s Office; in Switzerland, the Federal Data Protection and Information Commissioner; in the EEA, the authority for your country of residence, place of work, or the place of the alleged infringement. We would appreciate the chance to address your concern first at [email protected].

We do not currently maintain an establishment in the EEA or UK. Where Article 27 requires it, we will designate a representative and publish the contact details here.

27. Canada & Other Jurisdictions

Canada: we handle personal information consistently with PIPEDA’s principles, including accountability, limiting collection and use, accuracy, safeguards, openness, and individual access. Canadian residents may request access or correction, and may complain to the Office of the Privacy Commissioner of Canada.

Other jurisdictions: where local law grants you privacy rights not described here, we will honor them to the extent they apply to our processing. Contact [email protected] and tell us where you are located.

28. International Data Transfers

We are based in the United States, and the information we collect is processed and stored in the United States and in other countries where our subprocessors operate. Privacy laws in those countries may differ from those in your country of residence.

Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards, which may include:

  • The European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies.
  • An adequacy decision covering the destination country, where one exists.
  • Supplementary technical and organizational measures — including encryption in transit and at rest, access controls, and a policy of requiring valid legal process before disclosing data to authorities.

You may request a copy of the relevant transfer mechanism, with commercially sensitive terms redacted, at [email protected].

29. Children's Privacy

Our sites and services are intended for businesses and for individuals aged 18 and over. They are not directed to children, and we do not knowingly collect personal information from anyone under 13 — or under the higher minimum age set by your jurisdiction, such as 16 in parts of the EEA.

If you believe a child has provided us with personal information, contact [email protected] and we will delete it promptly. Parents and guardians may request access to, or deletion of, a child’s information using the same address.

30. Marketing & Communications Preferences

Transactional and service messages — responses to your inquiry, proposals, invoices, and security or service notices — are part of doing business with us and are not marketing. You cannot opt out of these while an engagement is active, though you can ask us to change how we reach you.

Marketing email includes an unsubscribe link in every message, which we honor promptly. You may also email [email protected] to be removed. When you unsubscribe we keep a minimal suppression record so that we do not email you again — this is the one record we retain specifically to honor your choice.

If you provide a phone number and consent to calls or text messages, message and data rates may apply and frequency varies. Reply STOP to any message to opt out and HELP for assistance. We do not send marketing text messages without prior express consent.

31. Accessibility of This Notice

We aim to make this notice usable with assistive technology, including screen readers. If you have a disability and need this policy in an alternative format, or need help submitting a privacy request, contact [email protected] or use the contact page and we will provide a reasonable accommodation.

32. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we do, we will revise the “Last updated” date above.

For material changes — for example, a new purpose for using your information or a new category of recipient — we will provide additional notice before the change takes effect, by email or a prominent site notice, and obtain consent where the law requires it. Your continued use of our sites and services after an update takes effect constitutes acceptance of the revised policy.

Prior versions are available on request at [email protected].

33. Contact Us & Complaints

For questions about this policy, to exercise a privacy right, or to raise a concern:

We take complaints seriously and will investigate and respond. If you are not satisfied with our response, you may contact your state attorney general or, in the EEA, UK, or Switzerland, your supervisory authority as described in Section 26.

This Privacy Policy is provided for general informational purposes and does not constitute legal advice.