Deployna is a personal, non-commercial project run in the Netherlands by Abdulhalim Alhossini. It is not a company or separate legal entity.
Privacy
Privacy policy
Last updated: 29 July 2026
We collect only what is needed to understand and answer your request and protect the service. We do not sell your data or use your files for marketing or advertising.
Controller and contact details
The data controller is Abdulhalim Alhossini, the individual operator of Deployna in the Netherlands. Deployna is a free personal project, not a company or registered trade name, and it currently has no KVK registration or VAT ID.
For privacy questions and rights requests, contact hello@deployna.com or +31 6 39104857.
Data we collect
When you submit the form, we store your name, email, optional phone number, language, request type, project description, desired outcome and project link or name. The system also creates a request number, follow-up status and a technical fingerprint to prevent duplicate submissions.
If you upload a ZIP, we store its name, size, SHA-256 fingerprint, storage path and deletion deadline. We also keep the delivery state of confirmation emails, without placing the project description or link in the operator notification.
If we create a private project page, we keep a limited copy of the name, email and language, page drafts and published revisions, messages and read state, and email-notification delivery state. The private-link token is stored encrypted with a verification hash. Message alerts contain neither the conversation text nor project details.
Web server and service logs may contain an IP address, browser type, requested path, request time and error or security messages. We do not use this data for advertising or profiling.
Purposes and legal bases
We use form data to understand and answer your request and assess whether limited technical help can be offered. This is based on our legitimate interest in operating the free project and handling the request you initiated under GDPR Article 6(1)(f). If you later ask for specific steps towards a separate agreement, Article 6(1)(b) may apply to those steps.
We use technical data and duplicate-prevention identifiers to secure the service, prevent abuse and diagnose faults on the basis of legitimate interests. We may process limited data to meet a legal obligation under Article 6(1)(c) when necessary.
The privacy checkbox confirms that you have read this notice; it is not marketing consent. We do not send marketing messages, make automated decisions or profile requesters.
Retention and deletion
The system schedules deletion of an uploaded ZIP and its stored file metadata after 7 days, and we may delete it sooner when it is no longer needed. A failed file deletion is retried daily and raises an operational failure until resolved.
The initial request and its email-delivery record are normally deleted after 90 days. If a private project page is activated, each meaningful publish or message extends the deletion date so follow-up remains possible. The page, revisions and messages are then deleted automatically 90 days after the last meaningful activity. An unpublished draft or revoked page is deleted after 30 days, and you may request earlier deletion.
If a safe linked file cannot be removed, a minimal technical cleanup marker without the name, email or brief remains until a retry succeeds. The same deletion deadlines are applied inside SQLite backups. Release backups are normally rotated after 30 days; the newest recovery copy may remain until a newer one exists, but expired data is scrubbed from it daily.
The application does not create a separate access log inside its database. Nginx and systemd logs are not used for advertising. The operator will record the live rotation period after inspecting the server and before indexing is enabled; indexing remains disabled until then. A specific incident record may be kept longer when necessary for an investigation or legal obligation.
There is currently no paid service. If paid work is agreed in the future under a separate contract, the data needed for it will be governed by that contract, an updated privacy notice and applicable legal and accounting obligations.
Processors and international transfers
Hetzner Online GmbH hosts the application, database and files, and Namecheap Private Email delivers request email. The operator will verify the hosting server's actual data-centre location before enabling indexing. The email service may process message data in the United States or outside the EEA.
Where Namecheap transfers email data outside the EEA, its data processing agreement identifies safeguards including Standard Contractual Clauses where applicable. Providers receive only the data needed for their service. We do not share request data for sale or advertising.
Your rights
You may request access, correction, deletion or restriction of your data, object to processing, and request portability where that right applies. We may ask for limited information to verify your identity before acting.
Email hello@deployna.com. We respond to rights requests without undue delay and normally within one month as required by the GDPR.
Complaints and cookies
If your concern is not resolved with us, you may complain to the Dutch Data Protection Authority, Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl.
Deployna uses no advertising cookies, tracking analytics or external marketing tools. Opening a private project link creates one essential session cookie protected with Secure, HttpOnly and SameSite=Strict; it expires automatically and is not used for tracking.