Privacy Policy

Last Updated: June 1, 2026

Welcome to DevCompass! Your privacy is important to us. This Privacy Policy explains how DevCompass, a product of Germina Labs GmbH ("we", "us", or "our"), collects, uses, discloses, and safeguards your information when you visit and use our website and services (collectively, the "Platform"). Germina Labs GmbH is the legal entity operating DevCompass. Please read this policy carefully to understand our practices regarding your personal data.

1. Information We Collect

We may collect the following types of information:

1.1 Personal Information

When you register, sign in, or interact with our Platform, we may collect personal information such as:

  • Name and email address (via Google OAuth authentication)
  • Profile information from your Google account (if you grant permission)
  • User-generated content (comments, submissions, project work)
  • Communication data (emails, support tickets, feedback)
  • Payment information (processed securely by Stripe — we do not store card details)

1.2 Usage and Technical Information

We automatically collect certain information when you access our Platform, including:

  • IP address and device information
  • Browser type and version
  • Operating system
  • Pages visited, time spent, and navigation patterns
  • Referral sources and clickstream data
  • Cookies and similar tracking technologies (see §4)

1.3 Blockchain and Web3 Data

If you connect a Web3 wallet or interact with blockchain features:

  • Wallet addresses (public blockchain addresses)
  • Transaction data related to our Platform
  • NFT holdings or token balances (if relevant to our services)

Note: Blockchain data is publicly available and immutable. We do not control or have the ability to delete information recorded on public blockchains.

2. Legal Basis for Processing (GDPR Article 6)

If you are located in the European Economic Area (EEA), Switzerland, or the United Kingdom, we process your personal data under the following legal bases:

Processing PurposeLegal Basis
Account creation and authenticationContractual necessity (Art. 6(1)(b))
Providing and improving platform featuresContractual necessity (Art. 6(1)(b))
Processing paymentsContractual necessity (Art. 6(1)(b))
Security, fraud prevention, and legal complianceLegal obligation / Legitimate interests (Art. 6(1)(c)(f))
Platform analytics and performance monitoringLegitimate interests (Art. 6(1)(f))
Marketing communications and newslettersConsent (Art. 6(1)(a)) — you may opt out at any time
Non-essential analytics and marketing cookiesConsent (Art. 6(1)(a)) — via cookie banner

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object to such processing at any time (see §8).

3. How We Use Your Information

We use the collected information for the following purposes:

  • Service Delivery: To provide, maintain, and improve our educational content, campaigns, and community features
  • Authentication: To verify your identity and manage your account via Google OAuth
  • Personalization: To customize your learning experience and recommend relevant content
  • Communication: To send you updates, newsletters, campaign announcements, and respond to your inquiries
  • Analytics: To analyze usage patterns, improve Platform performance, and understand user behavior
  • Security: To detect, prevent, and address technical issues, fraud, and security threats
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes
  • Marketing: To promote our services, campaigns, and partnerships (you may opt out at any time)

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

4.1 Service Providers

We work with third-party service providers who assist us in operating our Platform, including:

  • Cloud hosting and infrastructure providers (Supabase, Vercel)
  • Authentication services (Google OAuth)
  • Analytics tools (e.g., Vercel Analytics)
  • Email service providers
  • Payment processors (Stripe)

These providers are contractually obligated to protect your data and use it only for the purposes we specify.

4.2 Legal Requirements

We may disclose your information if required by law, court order, or governmental request, or to protect our rights, property, or safety, or that of our users or the public.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change in ownership or control via email or prominent notice on the Platform.

4.4 With Your Consent

We may share your information with third parties when you explicitly consent to such sharing.

5. Cookies and Tracking Technologies

We use cookies, web beacons, and similar technologies to enhance your experience and analyze usage. Under GDPR and the ePrivacy Directive, non-essential cookies require your prior, explicit consent before being set.

Types of cookies we use:

  • Essential Cookies: Required for Platform functionality and authentication — no consent required
  • Analytics Cookies: Help us understand how users interact with our Platform — require your consent
  • Preference Cookies: Remember your settings and preferences — require your consent
  • Marketing Cookies: Track activity to deliver relevant content and advertisements — require your consent

You can manage or withdraw your cookie consent at any time through your browser settings or by contacting us. Withdrawing consent will not affect the lawfulness of processing based on consent before withdrawal.

6. Data Security

We implement industry-standard security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction. These include:

  • Encryption of data in transit (HTTPS/SSL)
  • Secure authentication via OAuth 2.0
  • Regular security audits and vulnerability assessments
  • Access controls and authentication mechanisms
  • Secure database storage with Supabase

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.

7. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer period is required by law. Specific retention periods are as follows:

  • Account Data: Retained for the duration of your account, plus 2 years after account closure for legal and operational purposes
  • Payment Records: Retained for 7 years to meet financial and tax obligations
  • Analytics Data: Retained for up to 26 months, then anonymized or deleted
  • Marketing Consent Records: Retained for 3 years after you last interacted with our communications
  • Support Correspondence: Retained for 3 years from the date of last communication
  • Blockchain Data: Permanently recorded on public blockchains and cannot be deleted by us

When your data is no longer needed, we will securely delete or anonymize it.

8. Your Rights and Choices

If you are located in the EEA, Switzerland, or the UK, you have the following rights under GDPR:

  • Access (Art. 15): Request a copy of the personal information we hold about you
  • Correction (Art. 16): Request correction of inaccurate or incomplete information
  • Deletion (Art. 17): Request deletion of your personal information (subject to legal obligations)
  • Portability (Art. 20): Request transfer of your data in a machine-readable format to another service
  • Restriction (Art. 18): Request that we restrict processing of your data in certain circumstances
  • Objection (Art. 21): Object to processing based on legitimate interests, including for marketing purposes
  • Withdrawal of Consent (Art. 7): Withdraw consent at any time where consent is the legal basis — this does not affect the lawfulness of prior processing

How to exercise your rights: Email us at thedevcompass@gmail.com with the subject line "Data Rights Request". We will respond within 30 days as required by GDPR. To opt out of marketing emails, use the unsubscribe link in any email we send you.

Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority at any time. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch. EU residents may contact their national data protection authority.

9. International Data Transfers

DevCompass is operated by Germina Labs GmbH, based in Switzerland. Your data may be processed by our service providers in countries outside Switzerland and the EEA, including the United States. Where such transfers occur, we ensure that appropriate safeguards are in place in accordance with GDPR Chapter V, including:

  • Standard Contractual Clauses (SCCs): Our processors (including Supabase, Vercel, Google, and Stripe) rely on EU Standard Contractual Clauses approved by the European Commission to ensure adequate protection of your data
  • Adequacy Decisions: Switzerland benefits from an adequacy decision for certain data flows

You may request a copy of the applicable transfer safeguards by contacting us at thedevcompass@gmail.com.

10. Third-Party Links

Our Platform may contain links to third-party websites, services, or resources. We are not responsible for the privacy practices or content of these external sites. We encourage you to review the privacy policies of any third-party services you access.

11. Children's Privacy

DevCompass is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have inadvertently collected such information, we will take steps to delete it promptly. If you believe we have collected information from a child under 16, please contact us immediately.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. For material changes that affect how we process your personal data, we will notify you by email or via a prominent notice on the Platform at least 30 days before the changes take effect, and we will obtain your consent where required by law. Non-material changes will be posted on this page with an updated "Last Updated" date.

13. Data Controller & Contact

The data controller responsible for your personal information is:

DevCompass (operated by Germina Labs GmbH)

Herman-Greulich-Strasse 60

Zürich, 8004

Zürich, Switzerland

Email: thedevcompass@gmail.com

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at the address above.

14. Governing Law

This Privacy Policy shall be governed by and construed in accordance with the laws of Switzerland, including the Swiss Federal Act on Data Protection (FADP). Any disputes arising from or related to this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of Zürich, Switzerland, without prejudice to your rights under applicable local consumer protection or data protection laws.

By using DevCompass, you acknowledge that you have read and understood this Privacy Policy. Your continued use of the Platform constitutes acceptance of non-material changes. Material changes will be subject to separate notification and, where required, your explicit consent.