Privacy Policy
Last updated 2026-07-30
1. Controller
The controller responsible for processing your personal data within the meaning of Art. 4(7) GDPR is:
TODO: street and house number
TODO TODO: city
Germany
Represented by: David Gorges
Email: legal@dekkode.com
LayoutMark is a design-review tool: a browser extension and a web application that let you and your team comment on live web pages, capture screenshots of them, and route the resulting feedback to the people and tools that fix it.
2. Data we process
Account data. First and last name, email address, a hashed password, your workspace memberships and roles, your language and notification preferences, the date you confirmed this privacy notice, and - if you sign in through your employer's identity provider - the identifiers that provider sends us. Legal basis: Art. 6(1)(b) GDPR (performance of the contract).
Review content you create. Comments, replies, status changes, the URL of the page you annotated, the technical description of the element you marked (selector, position, size, computed styles), your browser and viewport details, screenshots of the page section you captured, and files you upload. Screenshots may incidentally contain personal data visible on the page you are reviewing - you decide what to capture. Legal basis: Art. 6(1)(b) GDPR.
Usage and log data. IP address, date and time of the request, requested URL, referrer, user agent, and error diagnostics. Server logs are kept for a short period to operate the service securely and to investigate faults. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in a secure, working service).
Anti-abuse data. When you register we submit a captcha token and your IP address to Cloudflare Turnstile, and we count signup attempts per IP address to stop automated abuse. Legal basis: Art. 6(1)(f) GDPR.
Cookies. We set a session cookie required to keep you signed in, an optional “remember me” cookie if you ask us to, and a CSRF token cookie that protects forms. These are strictly necessary for the service you requested; we do not use advertising or cross-site tracking cookies.
3. Why we process it
- To create and administer your account and workspaces
- To store, display and synchronise your review content across the extension, the web app and our API
- To notify you - by email, in-app or push - about activity that concerns you
- To deliver feedback to the third-party tools you connect yourself
- To keep the service secure, prevent abuse and diagnose faults
- To comply with our legal obligations
4. Sharing and processors
We do not sell your personal data. We share it only with service providers acting as processors on our instructions under Art. 28 GDPR, and only as far as the service requires:
- Hosting and storage providers in the EU, which run our servers, database and file storage.
- Email delivery, to send account, verification and notification messages.
- Cloudflare, for the signup captcha (Turnstile).
- AI model providers - only when you use an AI-assisted feature. In that case the content you submit to the assistant, and the review content it needs to answer, are transmitted to the model provider for processing. We do not permit providers to train their models on this content. If you would rather not have content leave our systems, do not use the AI features.
- Tools you connect yourself - for example an issue tracker or a chat service. When you enable an integration, the feedback items you send are transmitted to that provider under their privacy policy, at your instruction.
Other members of your workspace can see the content you create in it, together with your name, email address and activity. Workspace administrators can additionally manage your membership and access.
5. Transfers outside the EU/EEA
We prefer providers inside the EU. Where a provider processes data in a third country, we rely on an adequacy decision of the European Commission or on the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR. You can request a copy of the safeguards in place from the address in section 1.
6. Retention
Account data is kept while your account exists. Review content is kept until you or your workspace administrators delete it, or until the workspace is deleted. Server and security logs are kept for up to 90 days. Where statutory retention periods apply, we restrict processing to those obligations instead of deleting the data.
7. Your rights
Under the GDPR you have the right to:
- Access your personal data (Art. 15)
- Have inaccurate data corrected (Art. 16)
- Have your data erased (Art. 17)
- Restrict processing (Art. 18)
- Receive your data in a portable format (Art. 20)
- Object to processing based on our legitimate interests (Art. 21)
- Withdraw a consent you gave, at any time and with effect for the future (Art. 7(3))
To exercise any of these, write to legal@dekkode.com. You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR) - in Germany, the data protection authority of your state of residence.
8. Automated decision-making
We do not use your personal data for automated decision-making or profiling that has legal effect for you within the meaning of Art. 22 GDPR.
9. Security
We use transport encryption, hashed passwords, role-based access control and per-workspace data isolation, and we keep our dependencies patched. No system is perfectly secure, but we take appropriate technical and organisational measures under Art. 32 GDPR.
10. Changes to this policy
We may update this policy as the service changes. The current version is always published on this page with its revision date. If a change materially affects you, we will inform you in the app or by email before it takes effect.