Ryan Jarvis trading as DPPLogic · Nanny Cay, Tortola, British Virgin Islands · support@dpplogic.com
Versions: tos-2026-09-17-v1 · privacy-2026-09-22-v2 · dpa-2026-09-17-v1. Not a BVI company, not VAT registered, no company number, no licensing claim.
Privacy Notice.
This notice describes production processing for DPPLogic. It is not a claim of certified compliance with the BVI Data Protection Act, 2021, UK GDPR, EU GDPR or PECR.
Who we are
The controller for account administration, billing records, support correspondence, security logs and DPPLogic marketing-site visitor data is Ryan Jarvis trading as DPPLogic, an individual trading as DPPLogic.
Business and privacy contact: support@dpplogic.com (monitored, handled manually). Business correspondence address: Nanny Cay, Tortola, British Virgin Islands. That address is a correspondence location only. It is not a company-registration address, residential address or licensed premises. No Data Protection Officer has been appointed.
DPPLogic is not VAT registered and has no VAT number. That does not mean taxes never apply.
UK/EU privacy duties that apply to personal data of people in those places are not removed because the contract is governed by BVI law. BVI Data Protection Act, 2021 duties that apply to processing in or from the Virgin Islands are likewise not removed by customer location.
Controller and processor roles
Customer workspace content (products, evidence, findings, tasks, passport drafts) and customer-supplied supplier-collection content: DPPLogic acts on the customer’s documented instructions (processor-style service role).
Supplier contacts entered by a customer: processed on the customer’s instruction. The customer is responsible for having a basis to share those contacts.
Supplier login, grant and security or access records: DPPLogic may process limited login and security information for its own service-security purposes, separately from the collection content processed on the customer’s instruction.
Account administration, billing metadata, support correspondence and security logs: DPPLogic as controller.
Public passport publication: the customer decides to publish intended public fields. DPPLogic hosts those fields on instruction. Anyone can read published fields. DPPLogic does not certify that publication is lawful.
Personal data we may process
Account email and organisation or membership identifiers.
Session and authentication tokens, challenge proofs and related security events.
Organisation and member role information.
Product records. These are not automatically personal data.
Documents and evidence uploaded by a customer or supplier, if a file identifies a living individual.
Supplier contacts and supplier submissions, including uploaded evidence and submission history.
Audit events. Plan audit-retention days are entitlements, not a proven personal-data purge.
Billing metadata and Stripe identifiers. Card numbers are not stored by DPPLogic.
Support correspondence sent to support@dpplogic.com.
Usage and technical or security logs.
Public passport fields the customer chooses to publish.
Local OCR output, when available, is a processing aid and is not evidence verification. OCR, when present, is a processing aid and is not verification. Production OCR, when present, uses local Poppler and Tesseract only. OCR is a processing aid, not verification.
AI-derived suggestions only if a production AI feature is separately activated after a legal and subprocessor review. Production Evidence AI is OFF. Customer data is not sent to OpenAI.
Purposes
Create and authenticate accounts and authorised users.
Provide the workspace, supplier-collection, document, review and passport-draft features the customer requests.
Process subscription billing if Stripe live mode is separately activated. Customer charging remains off until a separate billing-gate approval.
Provide monitored support via support@dpplogic.com. No contractual SLA unless separately agreed.
Protect the service, investigate abuse and maintain audit events.
Host public passport fields the customer chooses to publish.
Meet accounting, tax and legal obligations that apply to DPPLogic.
Lawful bases
For DPPLogic-controlled processing, the working mapping is:
Service and account administration: contract, or steps necessary to provide the requested B2B service.
Billing and accounting: contract, plus legal obligations where they apply.
Support: contract / service administration.
Security and fraud prevention: legitimate interests. A concise LIA is recorded internally. Individuals may object where that right applies.
Customer-instruction workspace and collection content: the customer is responsible for its lawful basis. DPPLogic does not use its own basis for that processor-style processing.
Supplier login and security records processed for DPPLogic’s own security: legitimate interests (same LIA family as security/fraud).
Direct marketing: NONE. No marketing processing is activated.
WordPress.com public-site visitor data: assessment security, necessary browser recovery, and limited first-party event receipts. The public Privacy and Cookies pages describe this processing separately from authenticated workspace data.
Sources
The individual, when they create an account, sign in, contact support or use the supplier portal.
The customer organisation, when it invites members or suppliers or uploads workspace content.
Payment-provider events after Stripe live activation.
Automated security and application logs.
Recipients
Fly.io — production application hosting. Production hosting is Fly.io London. A London machine does not mean all Fly account data stays in the UK.
Stripe — deferred payment processor; no live checkout or customer charging is available. Status: Stripe is deferred; billing is OFF and paid pricing is not published.
Resend — authentication challenge email. Requested signup and login challenges are sent by DPPLogic <notifications@mail.dpplogic.com> through Resend. Automatic supplier, member-invitation, billing and marketing email remain OFF.
Google Workspace — operational mailbox for support@dpplogic.com.
WordPress.com / Automattic — public marketing site visitors only.
OpenAI is not an active customer-data processor.
Authorised users of the customer organisation, and suppliers the customer invites.
Regulators, courts or professional advisers where legally required.
International transfers
Restricted transfers may occur. BVI contract law does not replace UK/EU transfer rules that apply to personal data of people in those places.
Provider-published mechanisms, which this notice does not invent and which DPPLogic has not independently certified as executed for production: Fly.io publishes a DPA and states UK-extension DPF participation, and states that information it collects is stored and processed in the United States unless it says otherwise. Stripe publishes a DPA and Data Transfers Addendum (DPF, then UK Addendum / SCCs). Resend publishes a DPA with SCCs and UK Addendum and states stored account, message and log data remain in the United States even if mail is sent from Ireland. Google documents Workspace transfer terms including the UK Extension for certain US transfers.
DPPLogic does not attach its own SCC or IDTA schedules. Live charging remains deferred. Authentication email is limited to the existing qualified Resend sender when enabled.
Retention
Active account: operational customer data is retained while the service is active. This is not a promise of indefinite retention.
Cancelled account: data is not automatically deleted. The customer may read and export according to current product policy.
Account self-delete clears account email, sessions and memberships and retains shared organisation records and audit history. A last owner must transfer ownership first.
Organisation deletion is not fully self-service. Email support@dpplogic.com. Requests are handled manually.
Document deletion removes the stored original and associated metadata according to the implemented product action. Backup copies may remain until backup rotation.
Billing and accounting records are retained for the period reasonably required for accounting, tax, dispute and legal obligations. No invented statutory year-count is stated.
Security logs are retained only as reasonably necessary for security, fraud prevention, incident investigation and operation.
Support correspondence is retained as reasonably required to support the relationship and legal obligations.
Plan audit-retention days (Free 30, Professional 90, Business 365, Enterprise contractual) are plan entitlements, not automatic personal-data deletion jobs.
Your rights
Depending on the BVI Data Protection Act, 2021 and, where they apply, UK GDPR or EU GDPR, individuals may have rights of access, rectification, erasure, restriction, objection and portability, and the right to complain to the BVI Office of the Information Commissioner, the ICO or another competent authority.
Send requests to support@dpplogic.com. We handle them manually. There is no automated rights portal. Requests about customer workspace or collection content may be referred to the customer organisation.
Security
Implemented controls include tenant isolation, server-side role checks, private document storage separate from public passport drafts, hashed authentication tokens, and signed billing-webhook validation. This is not a claim of ISO 27001, SOC 2, PCI certification by DPPLogic, guaranteed security, zero data loss or contractual uptime.
Public passport behaviour
Publication is customer-controlled. Only intended public fields are exposed. Private documents and internal evidence are not automatically public. Published fields may be read by anyone. DPPLogic does not certify publication.
Business use
The service is offered to businesses and organisations, not consumers. Signup and paid checkout require: “I am purchasing/using DPPLogic for business or professional purposes.” The service is not directed at children.
Changes
Material changes to this notice will be posted on this page, with 30 days’ notice where reasonably practicable. Minor technical, legal-compliance or security corrections may be made without that full period.