01
Who we are
Laver is operated by Developyn Ltd, registered in England and Wales at 42 Kittiwake Drive, Brierley Hill, DY5 2QJ. For the personal data described here, Developyn Ltd is the data controller. You can reach us at support@developyn.com.
Where you use Laver for an organisation, that organisation decides what work content goes into its workspaces and who may see it. For that content, the organisation is the controller and we act on its instructions.
02
What we collect
Your account. Your first and last name, email address, and a hash of your password — the password itself is never stored, and the hash cannot be reversed. Optionally a phone number and a profile picture, if you add them. If you turn on two-factor authentication, a secret for your authenticator app and hashes of your backup codes.
Your work. Everything you put into Laver: workspaces, boards, tickets and their comments, subtasks, labels, sprints, wiki pages and their version history, and any files you attach. We treat this as yours. We do not read it except when you ask us to look at something, or where we must to keep the service running, safe or lawful.
Billing. Your plan, billing interval, seat count and the identifiers Stripe gives us for your customer and subscription records. Card details never reach our servers — they go directly to Stripe.
Security and audit records. Sign-ins, password and email changes, session revocations, and similar account events, so that you and we can see what happened to an account.
Technical logs. Our servers log requests, including IP address and browser user-agent, to run and secure the service.
03
Website analytics, without following you
We count visits to our public pages. Each page view records the path, the host of the referring site (never the full referring URL, which can carry the words somebody typed into a search box), a campaign source if a link carried one, and a visitor hash.
That hash is a SHA-256 of the current date, a server-side secret, your IP address and your user-agent, truncated. It lets us recognise two page views on the same day as one browser. It rotates at midnight, so views on different days cannot be joined together at all, and it cannot be turned back into an IP address. Your IP address itself is not stored in the analytics table.
There is no cookie, no third-party analytics service, and no advertising or profiling. That is why Laver has no cookie banner: there is nothing to consent to.
05
Why we are allowed to hold it
Most of what we hold, we hold to perform our contract with you: your account, your workspaces and their content, and the billing records that go with a paid plan.
Security records, technical logs and the aggregate analytics above rest on our legitimate interests in keeping the service available, keeping accounts safe from people who should not be in them, and understanding which of our pages are useful. We have weighed those interests against your privacy; the analytics design above is the result.
Where we must keep records to satisfy tax or accounting rules, we rely on our legal obligations. We do not rely on consent for anything described here, and we do not sell personal data or use it for advertising.
07
How long we keep it
Your account and its content stay while your account is open. If you delete your account, it is closed immediately and scrubbed 30 days later: your name is replaced, and your email, phone number, profile picture, verification codes, reset codes and two-factor secrets are removed.
A stub of the account row survives that scrub on purpose, because tickets, comments and wiki history point at it — removing it entirely would tear holes in a shared workspace's history that other people are relying on. What is left carries no personal data.
Content in a workspace belongs to that workspace, so leaving one does not remove what you wrote in it. Billing records are kept as long as tax and accounting rules require.
08
Your rights
Under UK and EU data protection law you can ask for a copy of your personal data, ask us to correct it, ask us to delete it, ask us to restrict or object to how we use it, and ask for it in a portable form.
Two of those are buttons rather than requests. Export in your profile downloads a JSON file of your account and your content — the workspaces you belong to, your tickets, your assignments and your comments. Delete account starts the process described above. For anything else, write to support@developyn.com and we will answer within one month.
If you think we have handled your data badly, please tell us first — but you can complain to the Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EEA.
09
How we protect it
Passwords are hashed with Argon2. Two-factor authentication is available with an authenticator app and single-use backup codes. Changing your password revokes every existing session, because a password change is the one moment we know the old credential may be in someone else's hands. Sessions have a maximum age they cannot be renewed past.
Traffic is encrypted in transit. Uploaded files are scanned for malware before they are stored. Sensitive endpoints are rate limited, and every request is checked against the workspace it claims to belong to.
No service can promise perfect security. If a breach affects your personal data and is likely to be a risk to you, we will tell you and the regulator within the time the law allows.
10
Children
Laver is for people aged 18 and over and is not directed at children. If you believe a child has given us personal data, tell us and we will remove it.
11
Changes, and how to reach us
If we change this policy we will update the effective date above, and for anything significant we will tell account holders by email before it takes effect.
Write to Developyn Ltd, 42 Kittiwake Drive, Brierley Hill, DY5 2QJ, or email support@developyn.com.