Last updated: 2025-01-15
Controller: Deviant Group S.R.L. (Romania)
Data protection contact: privacy@thedeviantgroup.com
General contact: contact@thedeviantgroup.com
Operating from Bucharest. This notice applies to data we control. Client work is governed by contract.
This policy explains how we process personal data when you use our website, contact us, or work with us. In client engagements we may act as independent controller (for our methods/outputs) or processor (on the client's documented instructions). The applicable role is defined in the contract / DPA.
Directly from you; your employer; public sources; service providers (hosting, analytics, comms, security); and other lawful third parties.
Where we rely on consent, you may withdraw it at any time; prior processing remains lawful.
We share personal data with:
A list of material subprocessors is available on request: privacy@thedeviantgroup.com.
Where data leaves the EEA/UK, we use approved safeguards (e.g., EU Standard Contractual Clauses and supplementary measures) and conduct transfer risk assessments where required.
We keep data only as long as needed for the purposes above and legal/accounting requirements. Typical ranges:
Specific retention details available on request.
Technical and organizational measures include: encryption in transit/at rest, role-based access, least-privilege, logging/monitoring, vulnerability management, and incident response. We maintain SOC 2-aligned practices; not SOC 2 certified at this time.
You can request access, rectification, erasure, restriction, portability, and object to processing (including B2B marketing). Where we rely on consent, you can withdraw consent.
To exercise rights, email privacy@thedeviantgroup.com. We may request reasonable verification and will respond within statutory timelines.
You can lodge a complaint with your local authority or with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP). We encourage contacting us first.
Our services are not directed to children under 16. We do not knowingly process their data.
See Cookie Policy for details and choices. Non-essential cookies/analytics run only with consent where required. Preferences can be updated via the consent banner.
We do not make automated decisions producing legal or similarly significant effects on individuals via the public website. Any risk scoring within client engagements is governed by contract and includes human oversight.
We will update this notice as needed and revise the "Last updated" date. For material changes we may post a notice on the Site or contact you by email where appropriate.
Contact: privacy@thedeviantgroup.com