Privacy Policy
1. Who We Are and What This Policy Covers
DesignVerse S.R.L. ("the Company," "we," "us," or "our") (Strada Ion Campineanu 11, Bucharest 010101, Romania) is the data controller for personal data processed through deisgnverse.com. The Company operates the DesignVerse platform, which turns product teams' design systems into working components, prototypes, and front-end code by ingesting design tokens, Figma variables, and Tokens Studio or Style Dictionary configurations. This Privacy Policy explains what personal data we collect from visitors, registered users, and team members, why we collect it, and what rights you have over it.
For any data-protection matter, including to exercise the rights described below, please contact us at [email protected].
2. Personal Data We Process
We process the following categories of personal data depending on how you interact with the Service:
- Identity and contact data you submit when registering or contacting us: name, work email address, employer name, and role.
- Account and subscription data: plan tier (Starter, Pro, or Team), billing contact details, and payment transaction references (payment card numbers are handled directly by our payment processor and are not stored by the Company).
- Design system content you upload: token files (Figma variable exports, Tokens Studio JSON, Style Dictionary configurations), component specifications, and generated output files. This content may incidentally contain personal data (for example, if a token name or comment references a person). We process this data solely to provide the generation and preview functions of the Service.
- Communications content: messages submitted via the contact form or sent to support, including any information you choose to include.
- Technical data collected automatically: IP address, browser type and version, operating system, pages and features accessed, session timestamps, and referring URL.
- Usage and analytics data, collected only where you have given consent via our cookie banner: feature interaction events, component generation counts, export format selections.
3. Purposes and Legal Bases (Article 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the DesignVerse platform and processing uploaded design tokens to generate component output | Performance of a contract (Art. 6(1)(b)) |
| Responding to support and contact form enquiries | Pre-contractual steps or legitimate interest (Art. 6(1)(b)/(f)) |
| Operating, securing, and improving the Service | Legitimate interest (Art. 6(1)(f)) |
| Billing and subscription management | Performance of a contract and legal obligation (Art. 6(1)(b)/(c)) |
| Compliance with legal and regulatory obligations | Legal obligation (Art. 6(1)(c)) |
| Usage analytics and measuring product adoption | Consent (ePrivacy Directive + Art. 6(1)(a)) |
We do not use your design system content or generated component output to train machine learning models, and we do not sell your data to third parties.
4. Recipients and International Transfers
Personal data is shared only with processors acting on our behalf under Article 28 GDPR data-processing agreements. Our current processor categories include cloud infrastructure (token files and generated output are stored in the EU, currently in Frankfurt), email delivery, and payment processing. We do not currently transfer personal data outside the EU/EEA in a way that requires a transfer mechanism. Should any such transfer become necessary, we would rely on Standard Contractual Clauses (Article 46 GDPR) and conduct a Transfer Impact Assessment consistent with the Schrems II ruling.
5. Retention
We retain personal data only for as long as necessary for the purposes described in this policy:
- Account and subscription data: retained for the duration of the account and for five years after closure, for statutory accounting and tax obligations.
- Uploaded design token files and generated output: retained for the duration of the active subscription. Files are deleted within 30 days after account closure or on your explicit deletion request.
- Contact and support communications: retained for 24 months after last contact.
- Server access logs: retained for 90 days.
- Cookie consent records: retained for 12 months.
6. Your GDPR Rights
Because the Company is established in Romania, an EU member state, the General Data Protection Regulation (EU) 2016/679 applies in full. You have the following rights with respect to personal data we hold about you:
- Right of access (Art. 15) - confirm whether we process your personal data and obtain a copy of it;
- Right to rectification (Art. 16) - have inaccurate or incomplete data corrected;
- Right to erasure / "right to be forgotten" (Art. 17), subject to limited exceptions under applicable law;
- Right to restriction of processing (Art. 18) - ask us to pause processing in specified circumstances;
- Right to data portability (Art. 20) - receive data you provided to us in a structured, commonly used, machine-readable format;
- Right to object (Art. 21), including to direct marketing at any time without further conditions;
- Right not to be subject to solely automated decision-making (Art. 22) - we do not engage in automated decision-making that produces legal or similarly significant effects.
To exercise any of these rights, email [email protected] with a clear description of your request and sufficient information to identify your account. We will respond within one calendar month. For complex or numerous requests, we may extend this period by a further two months and will inform you of the extension within the first month.
7. Right to Lodge a Complaint
You have the right to lodge a complaint with the Romanian data protection supervisory authority:
Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)
Bulevardul General Gheorghe Magheru 28-30, Sector 1, Bucharest 010336, Romania
Website: dataprotection.ro
You may also lodge a complaint with the supervisory authority of your country of residence. A directory of EU/EEA supervisory authorities is available at edpb.europa.eu.
8. Cookies
We use cookies and similar technologies on deisgnverse.com. Please see our Cookie Policy for full details. Non-essential cookies (analytics) are not set without your prior consent, consistent with the requirements of the ePrivacy Directive.
9. Security
We implement technical and organisational measures appropriate to the risk associated with the personal data we process. These include TLS encryption in transit, encrypted storage, role-based access controls limiting internal access to personal data, and periodic security reviews. Design token files uploaded to the Service are stored in an isolated, access-controlled environment and are not accessible to other customers.
10. Children
The Service is directed to professionals and is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, contact us at [email protected] and we will delete it promptly.
11. Changes to This Policy
If we make material changes to this Privacy Policy, we will update the "Last updated" date at the top of this page. Where required by law or where the changes affect rights or obligations in a material way, we will notify registered users by email and, where necessary, request renewed consent before the changes take effect.
12. Contact
DesignVerse S.R.L.Strada Ion Campineanu 11
Bucharest 010101, Romania
Email: [email protected]
Phone: +40 21 316 0730