Security and data handling

Last updated: 10 September 2026

What this page covers

This page covers two things: using this website, and engaging us for an AI Operations Assessment. If you are working through a supplier checklist before booking a call, the answers should be here. Anything missing, email us and we will answer it in writing.

The controller is InterNova Consulting Limited, trading as dploy.ai, registered in Ireland, company number 750353, at 175 Harold’s Cross Road, Harold’s Cross, Dublin 6W. Data protection questions go to hello@dploy.ai.

Where your data goes

Four services can hold personal data that reaches us through this website or through an assessment. That is the complete list.

ServiceWhat it doesWhere it processes
Vercel Inc.Hosts this website and runs the form that sends us your details.European Union
Brevo (Sendinblue SAS)Holds our mailing list and sends the emails we send you.European Union
Calendly LLCTakes bookings for the introductory call.United States
Microsoft Ireland Operations LimitedEmail and document storage for anything you send us.European Union

Hosting

The site is hosted by Vercel Inc. and served from an EU edge. The function that handles form submissions runs in an EU region, so the details you type into a form on this site are processed within the European Union.

Booking a call

Calendly LLC processes booking data in the United States. That transfer relies on Calendly’s self-certification under the EU-US Data Privacy Framework, with the European Commission’s Standard Contractual Clauses in place as a fallback. If you would rather your details were not processed outside the European Union, email hello@dploy.ai instead of using the booking link and we will arrange a time by email.

Email, marketing and storage

Brevo processes within the European Union under an EU data processing agreement. Email and documents you send us sit in Microsoft 365, held in the European Union. Both Vercel and Microsoft can reach data from outside the EEA when their support staff are working on a problem. Their standard terms cover that with Standard Contractual Clauses.

What an assessment touches

Your data stays in your environment. We review processes, we do not extract data.

In practice, an assessment gives us:

  • How your work actually gets done, described by the people who do it
  • The names of the systems involved, the volumes going through them, and how long each step takes
  • Whatever you choose to show us on screen during the discovery session
  • Business contact details for the people we speak to and correspond with

And it does not give us:

  • An export, a database copy, or a file dump of your records
  • A login to any of your systems
  • Anything installed on your machines or your network

Where a process cannot be explained without an example, we ask for one with the personal details taken out, or we look at it on your screen and take notes. The report and roadmap you receive name processes and systems, not individuals.

What we do not claim

We hold no security certification. We are not ISO 27001, SOC 2 or Cyber Essentials certified, and we will not tell you otherwise to get through a procurement form. What we do have is a short list of processors and the working practices below.

  • Multi-factor authentication on every account that holds personal data.
  • TLS on every connection to this site and to each service above.
  • Full-disk encryption on the machines we work on.
  • Credentials held in the deployment platform or in a local environment file, never in the code and never in a repository.
  • Access to each of the systems above limited to the account owner.

Cookies and tracking

This site sets no cookies. Nothing is stored on your device, nothing follows you to another website, and there is no consent banner because there is nothing to consent to. Fonts are served from this site rather than fetched from a third party, so loading a page tells nobody else that you were here.

No analytics run on this site today. We have built a cookieless option, Plausible, and left it switched off. On the day we switch it on, it will process within the European Union, store nothing on your device, and create no personal data, and this page and the privacy notice will say so in the same release.

Your rights

You can ask for a copy of what we hold about you, ask us to correct it or delete it, object to how we use it, ask for it in a portable format, or withdraw consent where you gave it. Email hello@dploy.ai. We reply within one month and there is no charge.

Retention periods, lawful bases and how to complain to the Data Protection Commission are all in the privacy notice.

Asking for a data processing agreement

Email hello@dploy.ai and we will send one. We will also complete a supplier security questionnaire if your procurement process needs it.

An assessment does not normally put us in the position of processing your customers’ personal data, because we review processes rather than take copies of records. If your own policy requires an agreement anyway, we will sign one.

Implementation engagements are governed by a separate agreement and a data protection addendum, available on request.

Ask us anything this page misses

A fifteen-minute call is usually faster than a form. Bring the checklist and we will work through it.