Privacy Policy
Last Updated: August 22, 2026 Effective: August 22, 2026
This page outlines our policies with regard to the collection, use, and disclosure of Personal Information for visitors who have decided to use our Services.
If you choose to use our Services, then you agree to the collection and use of information in relation with this policy. The Personal Information that we collect is used for providing and improving the Service. We will not use or share your information with anyone except as described in this Privacy Policy.
The terms used in this Privacy Policy have the same meanings as in our Terms of Service, which is accessible at https://decka.dev/terms, unless otherwise defined in this Privacy Policy.
Information Collection and Use
For a better experience while using our Service, we may require you to provide us with certain personally identifiable information, including but not limited to your name, phone number, and postal address. The information that we collect will be used to contact or identify you.
Information you provide to us directly
We may ask for certain information when you register for the Services or interact with us (such as a username, your first and last names, birthdate, phone number, profession, postal/physical and e-mail address).
We also collect any messages you send us through the Services (such as user feedback, search queries and prompts), and may collect information you provide in User Content you post to the Service (such as text, images, and lottie files you upload to use in your slides). We use this information to operate, maintain, improve and provide the features and functionality of the Service to you, to correspond with you, and to address any issues you raise about the Service.
When you browse presentation templates, we derive preference signals from the tags on templates returned by your searches and from the templates you open. We store the interaction type, tag identifiers, and timestamp — not the raw template search text — to personalize the order in which templates appear. Opening a template contributes more to this ordering than a search.
If you don't provide your personal information to us, you may not be able to access or use our Service or your experience of using our Service may not be as enjoyable.
Information from third-party services
When you sign in to the Service using a third-party authentication provider, such as Google or Microsoft, we receive the information that you authorize the provider to share with us, including your name, email address, and profile image. When you connect the Service to a third-party application or integration, we receive the information that the integration provides in the course of its operation. When you make a payment through the Service, our payment processor collects your payment details and shares limited transaction information with us. We do not store full payment card information on our systems.
Browser extensions and presentation add-ins
Parts of the Service are delivered through browser extensions and presentation add-ins — currently the Decka for Google Slides Chrome extension and the Decka for PowerPoint add-in. These components extend the Service into a presentation tool you already use. When you install one of them and connect it to your Decka account, the following applies in addition to the rest of this Privacy Policy.
What the Google Slides extension reads. To attach an activity to the intended slide and keep the presenter overlay synchronized, the extension reads the active Google Slides page URL and tab title, the presentation identifier and title, the identifier of the currently selected slide, and whether the presentation is in editing or presentation mode. Through the Google Drive API it checks the current file's type and whether the connected account can edit it. Through the Google Slides API it also reads limited structural metadata: presentation page size, slide and page-element object identifiers, and page-element description fields used to find Decka-owned placeholders. It does not read the body text, speaker notes, existing image content, or other content of non-Decka slide elements. That is a property of what the extension is for, not a limit we happen to observe: to attach an activity and keep the overlay in place it only ever has to find Decka's own elements, so that is all it looks at. Importing a presentation is a different feature with a different and unavoidable need — see Importing a presentation you already have below. The PowerPoint add-in uses its host APIs for comparable Decka binding and placeholder behavior; its marketplace disclosure describes the permissions granted by that host.
What the extension or add-in writes. When you bind an activity to a slide, the extension or add-in inserts a Decka-owned activity placeholder onto that slide so the activity is visible in your presentation flow. Depending on the activity, this may include a shape, label, or QR-code image. When you unbind an activity or remove its placeholder, the integration identifies and removes only Decka-owned elements. It does not modify slide content unrelated to Decka activities.
Decka account authentication. The Chrome extension accesses cookies associated with Decka's production domain, decka.dev, to reuse, renew, and clear the Decka website session. Decka access and refresh credentials are kept in those Decka-domain cookies, not copied into Chrome extension storage. When a Decka access credential expires, the extension sends the refresh credential to Decka's authentication endpoint over HTTPS to obtain a replacement.
Google authorization and local extension storage. The extension requests only Google's file-specific drive.file permission. When the current presentation has not previously been shared with Decka, the extension shows a permission card; Google account connection and authorization for that specific file begin only when you click it. Each additional presentation requires the same file-specific authorization, while previously authorized presentations remain available through the connected account. The Google OAuth access token, optional refresh token, granted scope, token expiry, and consent state are stored in Chrome's local extension storage. The extension sends the access token to Google over HTTPS when it calls the Google Drive or Google Slides APIs. It sends the OAuth authorization code, and later the refresh token when renewal is needed, to Decka's authenticated token-exchange endpoints; Decka performs the corresponding exchange with Google because the OAuth client secret cannot be included in the extension. Chrome extension storage also contains the configured Decka service URL, presentation/slide-to-activity bindings, references used to find Decka-owned placeholder and QR elements, and limited interface and keepalive state.
State synchronized with Decka. To make bindings available after the extension panel or browser restarts, the extension synchronizes presentation and activity metadata with Decka. This metadata may include the Google presentation identifier and derived presentation title, slide identifier, Decka activity identifier, activity title and type, selected background reference, and update time. Decka stores this server-side state under the authenticated account or workspace. The extension does not send the body content of unrelated Google Slides elements as part of this synchronization. Importing a presentation, described below, is a separate feature and is not part of it.
Activities, uploads, and the presenter overlay. Activity content created in the extension — such as titles, prompts, poll options, quiz questions and answers, Q&A descriptions, reaction settings, and other activity configuration — is sent to and stored by Decka. Custom background images selected in the extension are uploaded to Decka and may contain embedded file metadata as described in Files and media you upload below. When an activity is presented, the extension loads a sandboxed Decka presenter page in an iframe over the Google Slides page. The iframe runs under Decka's web origin and connects to Decka to receive the activity configuration and live participant data needed for presentation, including display names or anonymous labels, answers, open-text responses, Q&A questions, quiz results, reactions, drawings, join/leave state, and aggregate counts. The remote page does not receive access to Chrome extension APIs.
Network and usage data. Requests from the extension and presenter page provide the network and device information described in Log Data, including IP address and approximate location derived from it. If you explicitly accept Decka's optional analytics, we send product-usage events to PostHog, such as creating, deleting, starting, pausing, resetting, or ending an activity. Those events may include the Decka user and workspace identifiers, activity and presentation identifiers, request path and method, timestamps, participant or response counts, and operational exception messages and stack traces. The account's current analytics choice is applied to authenticated extension requests; a client-supplied analytics identifier cannot enable collection. The submitted extension package contains no PostHog or Sentry SDK, and the embedded presenter does not receive browser analytics or error-reporting SDK configuration.
Decka also uses Sentry for operational error diagnosis on its servers and on ordinary Decka web pages. Before an error report leaves our systems, we remove request query strings and bodies, recursively filter credential-bearing fields (including authorization, cookie, embed-token, and presenter-token values), and remove query strings and fragments from structured URL fields and URLs embedded in event text. We also suppress browser error reporting entirely on the extension's embedded presenter and on credential-bearing OAuth callback pages. Error reports may still contain the scrubbed exception message and stack trace, request path and method, browser or runtime information, and a timestamp. We use these records only to secure, diagnose, and maintain the Service. The extension is not used to collect a history of unrelated websites, raw pointer positions, navigation-keystroke contents, or console logs.
Chrome Web Store Limited Use. User data obtained through the Chrome extension is used only to provide and improve its disclosed single purpose: creating, binding, and presenting interactive Decka activities in Google Slides. We do not sell extension user data or use or transfer it for advertising, data brokerage, unrelated secondary purposes, creditworthiness, or lending. We transfer it only as needed to provide the user-requested features through our disclosed service providers, support user-directed sharing, maintain security and prevent abuse, or comply with law. Our handling of extension user data otherwise follows the Chrome Web Store User Data Policy's Limited Use requirements.
Limited use of Google API data. Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, information received from Google APIs through the Services is used only to provide and improve user-facing features of the Services; is not transferred to third parties for advertising, machine learning, or any purpose unrelated to the user-facing features you signed up for; and is not used to train any general-purpose AI model, consistent with the broader commitment in How we use your information below. Google authorization data is processed locally by the extension, by your browser when you import a presentation, and by authenticated Decka and Google endpoints as needed to provide those features, and is transmitted over HTTPS. When you import a presentation from Google Drive, the short-lived access token authorising that one file is sent to Decka only so that Decka can request the export from Google; it is used for that request and discarded, and is never stored or logged. We do not permit human access to Google API data except where necessary for support or debugging at your request, to investigate suspected violations of our Terms of Use, or as required by law.
Disconnecting an extension or add-in. You can sign out of the extension or add-in at any time from its panel. Signing out ends the Decka session but does not by itself revoke Google authorization or delete server-side presentations, activities, participant submissions, uploads, or synchronized bindings. Choosing the extension's option to switch Google accounts removes the Google OAuth credentials stored by the extension before a new authorization begins. You can also revoke the Service's access to your Google account at https://myaccount.google.com/permissions or to your Microsoft account at https://account.microsoft.com/privacy. Uninstalling the Chrome extension removes its local extension storage; server-side information remains subject to the deletion and retention terms below. Importing a presentation leaves nothing to disconnect: that authorization covers only the single file you picked, Decka keeps no Google credential from it, and the imported deck is an ordinary Decka deck you can delete like any other.
Importing a presentation you already have
Separately from the extensions above, the Decka dashboard can import a presentation you already have — a PowerPoint .pptx file from your device, or a presentation from your Google Drive. You do not need the Chrome extension for this, and it is not part of it.
Why this reads more than the extension does. The Google Slides extension deliberately does not read your slide content, and that remains true of it. Importing is the opposite case: copying a presentation into Decka means reading the presentation, and there is no version of "import my deck" that does not involve reading the deck. So when you import one, we read the file in full — slide text, speaker notes, images, layout, fonts, colors, and shapes — and reproduce it as an editable Decka deck.
What happens to it. The imported presentation becomes your own Decka deck. It is stored and treated exactly like a deck you created in Decka, under Your content and Files and media you upload below, including their retention and deletion terms. Images embedded in the file are stored as deck assets and may carry embedded file metadata as described in Files and media you upload. We do not use imported content to train any general-purpose AI model.
Importing from Google Drive. When you choose to import from Google Slides, Google's own file picker opens and you select one presentation. That selection is the permission. Decka requests only Google's file-specific drive.file permission, which grants access to files you hand it through that picker and to nothing else — Decka cannot list, search, browse, or open anything in your Drive that you did not pick, and each presentation you import is authorized separately. Decka receives a short-lived Google access token, sends it to Google once to export that one presentation, and does not store, log, or reuse it. There is no long-lived refresh token in this flow, and Decka holds no standing access to your Google account. Your original presentation in Google Drive is not modified.
Importing a file from your device. A .pptx file you upload is transmitted to Decka over HTTPS and handled as described in Files and media you upload below.
Information about participants in sessions you didn't host
Some Decka features let people join an interactive session — a poll, a quiz, a word cloud, a Q&A, a drawing activity, an audience game — without first creating a Decka account. We refer to those people as "Participants." If you are a Participant joining a session that someone else created, this section describes the information we receive about you in that role.
When you join a session, we may receive:
- A display name that you choose, or, where the session permits, an anonymous label;
- Your responses — the answers, votes, drawings, words, reactions, and other contributions you make in that session;
- Session timing data — when you joined, how long you stayed, and (for activities that depend on it) how quickly you responded to a prompt;
- Technical information sent by your browser to load and run the session, including your IP address, approximate geolocation derived from that IP address, browser type, and device identifiers — used for security, abuse prevention, and fault diagnosis;
- An email address, but only if you ask us to send you a copy of the results at the end of an activity. You can take part in a session without giving one, and nothing else in this section requires one. Because that address is handled differently from everything above, it has its own subsection below.
In most cases, the host of the session — the Decka account holder who created it, or the workspace they use Decka through — controls the personal information you provide as a Participant. We act on that host's instructions when we process Participant data and when we make it available to them through the Service. If you have questions about how a particular host uses the data they collect from you through Decka, please contact the host directly. Where we are processing Participant data on a host's behalf, we will pass your privacy-rights requests through to them.
We may use Participant data on our own behalf for limited operational purposes that apply to the Service as a whole — for example, to detect abuse, investigate security incidents, prevent fraud, and meet our legal obligations.
We retain Participant data only as long as needed for the host to use it through the Service, plus a short additional period to handle disputes or service issues. We do not enable persistent identification of Participants across sessions hosted by different organizers.
If you ask us to email you a copy of the results
At the end of an activity you took part in, Decka may offer to email you a copy of the results. If you accept, you type an email address. Alongside it we record which activity sessions in that meeting the copy should cover, and whether you ticked the box asking for additional communications from us. We do not ask for your name, and the address is not used to link what you did in one organizer's session to what you did in another's.
Decka is the controller for that address — the host is not. This is the one piece of Participant information in this section that does not belong to the person running the session. The host never sees it, cannot export it, and it does not appear in anything we make available to them, so a request about it goes to us at legal@decka.dev rather than to them. We use the address to send you one email with the results of the sessions you took part in, and to respond to you if that send fails or you contact us about it.
That email contains a link to a page showing the same results. There is no sign-in on that page, so the link itself is the whole key to it: treat it as private, and do not forward it to anyone you would not show your own answers to. The link stops working 90 days after you asked for the report.
How long we keep it. We erase the address 7 days after your report has been delivered. If the report is never delivered — the send fails permanently, or you asked for a copy of a session you then took no part in — the address is erased 30 days after you gave it to us, so a failed send cannot turn into indefinite storage. The address-free record behind the link (which sessions the copy covers, and the choice you made about additional communications) is kept for 90 days, the lifetime of the link itself, and is then deleted with it.
Additional communications are optional and separate. The box asking whether we may send you occasional additional communications from Decka starts unticked, and your copy of the results is sent whether or not you tick it. If you do tick it, we add your address to the Feature updates and marketing topic described under Email we send you, and how we measure it below; every message we then send carries a one-click unsubscribe link, and using it takes effect immediately and does not affect the results email you asked for. If your request reaches us from an IP address in Canada, we treat the box as declined whatever you ticked, because Canada's anti-spam law requires consent given expressly for that purpose.
Log Data
Whenever your browser requests the Service, our hosting and security infrastructure receives operational Log Data needed to deliver and protect that request. This may include your Internet Protocol ("IP") address, approximate location derived from it, browser or user-agent information, request path, and request timestamp. Route pageviews, page-leave events, and time spent are optional product analytics and are collected only while you have a current explicit Accept choice for analytics. We do not use the extension to collect a general history of unrelated websites.
Cookies
Cookies are small files or values that a website stores in your browser.
Our Services use strictly necessary cookies to persist authentication, protect authorization flows, provide billing, and remember your cookie choice. Optional analytics cookies are off by default and are used only after you click Accept. You can refuse optional cookies without losing core Service access. Blocking strictly necessary cookies in browser settings may prevent authentication, billing, or other requested features from working.
For more general information on cookies, please read "What Are Cookies".
Email we send you, and how we measure it
Decka sends two kinds of email, and they follow different rules.
Transactional email is email you receive because of something you or someone else did in the Service: a sign-in code, a password reset, a workspace invitation, a receipt, a report for an activity you presented, and the copy of the results a Participant asked us for. We send it whether or not you have opted in to anything, because it is the thing that was asked for.
Marketing email — product announcements, tips, offers, and other promotional updates — goes only to addresses that have opted in to the Feature updates and marketing topic. Every checkbox that offers that topic starts unticked, and we do not subscribe you as a side effect of creating an account or signing in through Google or Microsoft. Every marketing message carries our physical mailing address and a one-click unsubscribe link, and if you have an account you can change the topic at any time under Settings → Email preferences. Requests reaching us from an IP address in Canada are treated as opted out regardless of the checkbox, in line with the express-consent standard in Canada's anti-spam law.
How we measure our own email. For the lifecycle messages we send as part of a campaign, we record whether the message was opened and whether its links were clicked. An open is measured by a single-pixel image loaded from our own servers when your mail client displays the message; a click is measured by sending the link through our own redirect before it takes you where it says it goes. Both carry an identifier for the message, not for you — your address never appears in those URLs, they are served by Decka rather than by an advertising network, they are not used to build a profile of you, and none of it is shared with any presenting workspace. If you would rather not be measured this way, most mail clients can be set not to load remote images, and unsubscribing stops the messages altogether. A click also sets the short-lived first-party cookie described in our Cookie Policy, which exists to connect a visit to the message that prompted it.
We also keep day-bucketed totals — how many messages went out, how many were opened, how many clicks came back, and how many visits followed — which carry no email address and no account identifier.
How we use your information
We use the information we collect for the following purposes:
- to provide, operate, maintain, and improve the Service;
- to authenticate users and protect the security of accounts;
- to process payments and send transactional communications;
- to send the email you asked us for, to send marketing email where you have opted in to it, and to measure whether our own messages and pages work;
- to respond to your inquiries and provide customer support;
- to personalize your experience and remember your preferences;
- to analyze usage trends so that we can improve the Service;
- to detect, investigate, and prevent fraudulent or unauthorized activity; and
- to comply with our legal obligations and to enforce our Terms of Service.
We do not use your User Content to train general-purpose AI models, whether our own or those of third parties.
Service Providers
We may employ third-party companies and individuals due to the following reasons:
- To facilitate our Services;
- To provide the Services on our behalf;
- To perform Services-related services; or
- To assist us in analyzing how our Service is used.
These third parties may have access to your Personal Information to be able to perform the tasks assigned to them on our behalf. They are obligated not to disclose or use the information for any other purpose.
Sharing your content
Several features in our Services exist so that you can share your work with other people. When you choose to share, the form of sharing you choose determines who can access the content and what they can do with it. This section explains what happens to information when you exercise those sharing features, and how that information moves between you, other users, and, in some cases, third parties.
Content you publish via join codes, public links, or embeds
Some features such as, but not limited to, interactive activities, participant-joinable sessions, shareable view-only links, and embeds, are designed so that any person who holds the code, link, or embed can access the associated content without an account or invitation from you.
When you generate a join code or enable a public link, you should assume that the content behind it may be viewed by anyone the code or link is forwarded to, indexed by tools that scrape public URLs, or captured by recipients (for example, via screenshots, recordings, downloads, or browser caches). Once you have made content accessible in this way, we cannot retract it from places where it has already been viewed, captured, or redistributed.
Content you share with specific recipients
Where the Service supports sharing with named individuals (for example, by inviting collaborators by email, granting workspace access, or adding co-editors to a presentation), those recipients may view, edit, comment on, copy, duplicate, or export the shared item according to the role you grant them, and will see your full name as the inviter. When you invite a recipient by email, that address becomes associated with the shared item for the purpose of access control. Recipients you invite may further share the item with others if the role you grant them permits it. Removing a recipient or revoking a link prevents further access through our Services, but does not affect copies, exports, or derivatives the recipient may already hold.
Content visible within a workspace or organization
If you use the Services as part of a workspace, team, or organization, the administrator of that workspace may have access to the content, files, and activity created within it, including content created by you, regardless of whether you marked it as private. Workspace administrators may also be able to manage, transfer, export, or delete that content, suspend or reassign accounts, and apply retention or audit policies. We act on the instructions of the administrator with respect to workspace content. If you are unsure whether your account is part of a workspace, please contact your administrator before sharing anything personal through it.
Automatic and default sharing within your workspace
Some workspaces, teams, or organizations may configure the Service so that presentations, activities, or other items you create are automatically shared with a defined group, such as members of your team or workspace, at the moment of creation, without a separate action on your part. These settings may be controlled by you, by your workspace administrator, or by both. When automatic sharing is in effect, items you create may be visible to other members of the configured group as soon as they are saved, including drafts and works in progress. Changing the default later applies only to items created after the change and does not retroactively unshare items that were already shared. Before relying on a workspace, please review the automatic sharing settings that apply to your account.
Files and media you upload
When you upload images, animations (including Lottie files), fonts, audio, video, documents, or other media to the Service, those files are stored so that the slides, activities, or presentations containing them can be rendered. If the slide, activity, or presentation containing a file is shared, the underlying file is shared with it, including any metadata embedded in the file by the device or application that created it (such as EXIF location data, original filenames, or author tags). We do not strip embedded metadata from uploaded files. If a file contains information you do not wish to disclose, please remove that information before uploading.
Participant identity, reactions, and contributions
Features that allow people to join a presentation, react in real time, answer prompts, leave feedback, or otherwise contribute will display the contributor's chosen display name (or, where applicable, anonymous label), their reactions, and their responses to the host and to other participants of the same session, in accordance with the configuration of that session. Aggregate counts (for example, totals of a given reaction) and timing information (for example, when a participant joined or left) may be visible to the session's host or organizer. If you join a session as a participant, you should treat any name, response, or reaction you provide as visible to the host and, depending on the session, to other participants.
Exported and downloaded content
When you, or someone with whom you have shared content, export a presentation to formats such as .pptx, image, PDF, or video, or when you download embedded media, the resulting file is no longer governed by our Services. Once exported, the file may be stored, edited, redistributed, or uploaded elsewhere by the holder, and our access controls and revocation tools cannot reach it.
The practical limits of revocation
Across all of the sharing flows above, once a piece of your content has been viewed, copied, exported, screenshotted, recorded, downloaded, indexed, or otherwise captured by another person or system, we cannot guarantee its removal from those locations. Deleting content from your account, revoking a link, removing a collaborator, disconnecting an integration, or closing a session prevents further access through our Services going forward; it does not undo access that has already occurred. Please choose what you publish, and who you invite, with that limit in mind.
Information processed by AI-assisted features
If you use AI-assisted features of the Service (for example, generation, summarization, suggestions, or translation), the prompts you submit and the content you provide as context, including text, files, and uploaded media, are processed by the model serving that feature in order to return a result. We may retain prompts and outputs to operate, debug, monitor for abuse, and improve the feature. Where we use third-party model providers to deliver these features, prompts and content are transmitted to those providers under contractual restrictions; we do not authorize them to train their general-purpose models on your content. If you do not wish to submit a piece of information to an AI-assisted feature, do not include it in a prompt or attach it to one.
Data retention
We retain your personal information for as long as your account remains active and for as long as is necessary to provide the Services to you. The specifics depend on the category of data.
What we keep until you delete it. Presentations, activities you have opened or edited, templates, drafts you have interacted with, uploaded images, fonts, audio, video, and drawings are retained until you (or your workspace administrator) delete them. We do not run an automatic sweep that removes work you've created.
What ages out automatically. A small number of categories are removed on a scheduled basis:
- Abandoned drafts — presentations or activities you created but never opened or edited — are cleaned up after 90 days from creation.
- Participant submissions on completed sessions (poll responses, reactions, word-cloud entries, drawings, Q&A submissions, quiz answers) are retained for 3 years from the end of the session.
- Template-personalization signals derived from template searches and opens are scheduled for automatic deletion after 90 days from the interaction. Raw template search text is not stored in this dataset.
- A participant's report address — an address someone gave us so we would email them a copy of a session's results — is erased 7 days after that report is delivered, or 30 days from the moment it was given if the report is never delivered; the address-free record behind the report link is kept for 90 days, the lifetime of the link, and is then deleted. Decka is the controller for this data and the presenting workspace never receives it.
- Marketing send records — which campaign message reached which address, and how that send settled — are kept for 24 months, the same window as our security audit logs, because that record is the compliance trail for the message itself. We delete them sooner when you delete your account or ask us to erase your data.
- First-party email and landing counters — day-bucketed totals carrying no address and no account identifier — are kept for 3 years.
- Security audit logs are retained for 24 months.
- Backups roll off after 30 days.
What we keep after account closure. When you close your account, your sign-in identity and any data we are not specifically required to keep are deleted. We retain a small set of records as required to comply with our legal obligations, defend against legal claims, satisfy tax and accounting requirements, and enforce our agreements — most notably, the consent records that show which version of these terms you agreed to, and our billing records.
While an account-deletion request is pending reconciliation, the underlying template-personalization pins and interaction records may remain temporarily, and new personalization writes are blocked. Once deletion is finalized, those records are deleted. The only template-personalization deletion marker that remains is a domain-separated pseudonymous hash used as a tombstone to reject delayed authenticated writes. It is retained for a short access-token safety window of at least 24 hours and then purged by the next scheduled retention sweep.
You may request deletion of your information at any time by deleting your account from your dashboard settings or by contacting us at legal@decka.dev.
International transfers
We may transfer, store, and process your information in countries other than the country in which you reside, including the United States and the European Union. Where the law of the jurisdiction from which the information originates requires specific safeguards for international transfers, we rely on lawful transfer mechanisms recognized by that jurisdiction. These mechanisms may include the Standard Contractual Clauses approved by the European Commission. By using the Service, you acknowledge that your information may be processed in this manner.
Your rights and choices
Depending on where you reside, you may have certain rights with respect to your personal information. These may include:
- the right to access the personal information we hold about you;
- the right to request correction of inaccurate or incomplete information;
- the right to request deletion of your information;
- the right to receive a portable copy of your information in a machine-readable format;
- the right to object to or restrict certain types of processing;
- the right to withdraw consent where we rely on consent to process your information; and
- the right to lodge a complaint with the data protection authority of your jurisdiction.
To exercise any of these rights, please contact us at legal@decka.dev. We may need to verify your identity before responding to your request, and we will respond within the time required by applicable law.
Security
We value your trust in providing us your Personal Information, thus we are striving to use commercially acceptable means of protecting it. But remember that no method of transmission over the internet, or method of electronic storage is 100% secure and reliable, and we cannot guarantee its absolute security.
Links to Other Sites
Our Service may contain links to other sites. If you click on a third-party link, you will be directed to that site. Note that these external sites are not operated by us. Therefore, we strongly advise you to review the Privacy Policy of these services or sites. We have no control over, and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
Underage Privacy
Our Services do not address anyone under the age of 18. We do not knowingly collect personal identifiable information from children under 18. In the case we discover that a child or underaged person (under 18) has provided us with personal information, we immediately delete this from our servers. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us on legal@decka.dev so that we will be able to do necessary actions.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. Thus, we advise you to review this page periodically for any changes. We will notify you of any changes by posting the new Privacy Policy on this page. These changes are effective immediately, after they are posted on this page.
Contact Us
If you have any questions or suggestions about our Privacy Policy, please contact us at legal@decka.dev.