Privacy
Privacy Notice
1. Who is responsible
DEVIS by Nathan Office, Switzerland, is responsible for personal data handled through this site and through DEVIS engagements. Contact: contact@devisos.com.
2. What this Privacy Notice covers
This Privacy Notice explains how DEVIS handles personal data through:
- this website;
- enquiry, booking, and communication channels;
- client onboarding;
- scoping conversations;
- DEVIS engagements and sprint work;
- client administration, security, record-keeping, and service operation.
3. What we collect
Through this site, we may collect limited information such as: name; contact details; company or organisation; role or professional context; enquiry details; scheduling information; technical and security data; and privacy-respecting analytics.
In an engagement, we may process information provided by the client and information obtained from open, public, registry, commercially obtainable, and lawfully accessible sources about companies, individuals, counterparties, transactions, ownership structures, management teams, commercial relationships, disputes, insolvency records, sanctions, regulatory records, litigation, media, and related subjects within the agreed scope.
4. Why we process personal data
We process personal data to:
- respond to enquiries;
- assess whether an engagement is appropriate;
- conduct onboarding and administration;
- scope, perform, deliver, and manage DEVIS engagements;
- identify, structure, qualify, and map exposure signals;
- produce evidence-qualified deliverables;
- operate, secure, maintain, and improve the service;
- maintain records for legal, contractual, business, auditability, security, and dispute-protection purposes;
- comply with legal obligations;
- protect the legitimate interests, rights, and security of DEVIS, clients, and relevant third parties.
5. Legal basis and justification
Depending on the context, DEVIS processes personal data on the basis of contract performance, pre-contractual steps, consent where applicable, legal obligations, and legitimate interests in operating a professional exposure-intelligence service, protecting business and legal interests, maintaining security, and carrying out client-authorised engagements.
Where applicable law requires a separate justification, DEVIS processes personal data only where the processing is lawful, proportionate, purpose-limited, and consistent with the agreed engagement purpose.
6. Information about third parties
Exposure intelligence may involve information about individuals connected to a company, transaction, counterparty, ownership structure, management team, commercial relationship, legal record, regulatory record, or public source.
DEVIS processes such information for the specific professional purpose of the engagement, subject to applicable law, proportionality, confidentiality, source limitations, and evidence qualification. Material findings are qualified by verification status: confirmed, unverified, contradictory, or unresolved.
7. Sensitive information
DEVIS does not seek special-category or highly sensitive personal data unless it is lawful, proportionate, directly relevant to the engagement purpose, and reasonably necessary in context.
If such information appears in lawful source material, DEVIS limits its use to what is material, proportionate, and relevant to the professional decision being assessed.
8. Who we share personal data with
DEVIS does not sell personal data. We may share personal data with:
- hosting, infrastructure, email, security, and operational service providers; Calendly (appointment scheduling, on the booking page) and Microsoft Clarity (privacy-respecting website analytics on selected pages, loaded only where you have given analytics consent);
- professional advisers;
- authorised client recipients within the agreed engagement scope;
- regulators, courts, authorities, or other parties where required by law or necessary to protect legal rights.
Service providers are used under appropriate confidentiality, security, and contractual obligations. Client confidential engagement material is not provided to other clients.
9. International handling
DEVIS is based in Switzerland. Where personal data is processed, stored, accessed, or transferred outside Switzerland, DEVIS uses appropriate safeguards consistent with applicable Swiss data protection law, GDPR requirements where applicable, contractual protections, and security controls.
10. Retention
DEVIS retains personal data and engagement material only for as long as necessary for the purpose collected, the engagement terms, client access, legal and business record obligations, auditability, security, dispute protection, and legitimate administration.
Retention periods may differ depending on the type of data, the engagement, legal obligations, operational requirements, and the need to preserve an accurate record of work performed. Where appropriate, information may be deleted, anonymised, restricted, or archived after the relevant retention period.
11. Security
DEVIS applies organisational and technical measures designed to protect personal data and engagement material against unauthorised access, disclosure, alteration, loss, misuse, or destruction. Access is limited on a need-to-know basis. Engagement material is handled according to scope, confidentiality requirements, and operational controls.
No system can be guaranteed completely secure. DEVIS maintains security controls proportionate to the sensitivity of the work and the risks involved.
12. Your rights
Subject to applicable law, you may have rights to:
- request access to personal data held about you;
- request correction of inaccurate personal data;
- request deletion or restriction of personal data;
- object to certain processing;
- withdraw consent where processing is based on consent;
- request data portability where applicable;
- complain to a competent data protection authority.
To make a request, contact contact@devisos.com. DEVIS may need to verify your identity before responding. Rights may be limited where necessary to protect confidentiality, legal privilege, trade secrets, the rights of others, legal claims, regulatory obligations, or the integrity of an engagement.
13. Automated decision-making
DEVIS does not use website data to make solely automated decisions with legal or similarly significant effects.
DEVIS deliverables support professional decision-making by clients. They do not make the client’s decision and do not replace the client’s independent judgement.
14. Changes
DEVIS may update this Privacy Notice from time to time. The current version will be published on this page.