Privacy Policy
Effective date: August 9, 2026 · Last updated: August 9, 2026
Dewacon is a software development and technology consulting company. We collect information that visitors, clients, and authorized users provide to request services, communicate with us, manage project work, access client portal features, and support billing or operational workflows.
This policy explains what we collect, why we collect it, who we share it with, and the choices you have. It uses "may" where a practice depends on the scope of a particular project or on whether you choose to use an optional feature.
Project-specific agreements may contain additional privacy, confidentiality, data processing, security, payment, or retention terms.
Who we are
- Dewacon LLC ("Dewacon", "we", "us") is a software development and technology consulting company based in the United States and operating from Wisconsin.
- We build and support websites, software, mobile applications, digital platforms, and related technology services for business clients.
- For privacy questions about this website, email info@dewacon.net.
Scope of this policy
- This policy covers the Dewacon corporate website at dewacon.net, its contact and service request forms, the public search feature, the Service Guide, the client project portal, and the internal workflows Dewacon uses to review requests, manage project status, and issue invoices.
- The client project portal also has its own portal privacy notice with more detail about how portal access works. Where the two describe the same thing, they are intended to agree; the portal notice is the more specific one.
- Separate applications, products, or services may have their own privacy notices, terms, and data practices, including products that Dewacon operates or builds.
- This policy does not replace any project-specific or service-specific agreement. Where a signed agreement covers the same subject, that agreement governs the project work it applies to.
Information we collect
We collect information in two ways: information you give us directly, and information that is recorded automatically when your browser requests a page.
- Information you provide directly: your name, company or organization name, email address, phone number, the service you are interested in, your project stage, an estimated budget range, and the message you write.
- Project and account information: the email address approved for client portal access, your organization name, and the project status content we record, including phase names, dates, and update notes.
- Billing contact information for a project that is invoiced, together with the invoice amount, currency, due date, and payment status.
- Business contact details for organizations we are in a sales or partnership conversation with, held in our internal records.
- Email correspondence between you and Dewacon.
- Account information for authorized Dewacon staff who use the administrative tools, including which actions they took and when.
- Recorded automatically: your IP address, browser and user-agent information, the page you requested, the page that referred you, and the date and time of the request. These appear in standard web server records.
- Recorded automatically: session and security information needed to keep you signed in where applicable, to protect forms against cross-site request forgery, to apply rate limits, and to detect abuse.
Information submitted through contact and service request forms
- The contact form asks for your name, email address, and a message. Company name, phone number, service interest, project stage, and budget range are optional.
- Submitting the form creates a service request record that Dewacon reviews. We store the review outcome, any reply we send you, whether the notification email was delivered, and the times those things happened.
- A submitted request does not create a contract, a client relationship, or an obligation for Dewacon to provide any service.
- We do not ask visitors to submit passwords, payment card numbers, government identification numbers, health records, or other sensitive information through public contact or service request forms.
- Please do not include confidential documents, production credentials, or anyone else's personal information in a public form. If a project requires sensitive information, we will agree an appropriate secure method with you first.
- We do not collect precise geolocation, biometric data, government identification numbers, financial account numbers, or health records through this website.
Client portal and project information
- If Dewacon accepts a request for planning, or if you are a contact on an existing project, we may invite you to the client project portal using an email address agreed for that project.
- The portal is read-only. It accepts no uploads, no messages, and no form submissions other than the email address used to request a sign-in link.
- Sign-in does not use a password. We email you a single-use link instead. We store only a cryptographic digest of each link's identifier, never the link itself, and the link identifies you by a keyed fingerprint rather than by placing your email address in it.
- Client portal access links are security-sensitive and should not be shared.
- Access is checked against the approved contact list each time a link is used, so removing a contact takes effect immediately.
- Portal pages are excluded from search engine indexing and are not reachable without a valid session.
Billing and payment information
- Dewacon issues invoices through an external invoicing and payment provider, such as Stripe or QuickBooks. Payment is made on a page hosted by that provider, not on a Dewacon page.
- For an invoiced project we record the billing contact email, the invoice title and description, the amount, the currency, the due date, the payment status, which provider issued it, and the link to that provider's hosted invoice page.
- We do not store card numbers, security codes, bank account details, or any payment credential. Our records contain no field that could hold one, because Dewacon does not process payments.
- Card handling is performed entirely by the invoicing provider. Dewacon makes no claim of PCI DSS compliance or certification.
- Dewacon never asks for card or bank details by email or telephone. If you receive a message that appears to do so, contact info@dewacon.net before acting on it.
- Internal billing notes are visible only to authorized Dewacon staff and are never shown in the client portal or included in an email to a client.
Public search and the Service Guide
- Public search searches approved public website content only. It does not search client portal records, admin records, billing records, service request records, or private project data.
- Search terms are read from the web address of the results page and are not stored in our records or used to build a profile of you. Like any requested address, a search page address may appear in standard web server records.
- The Service Guide is a fixed set of rules, not an AI system. It reads the choices you select, applies the same rules for everyone, and shows a suggestion.
- Using the Service Guide does not submit a request by itself. A request is submitted only when you choose to contact Dewacon or submit a form.
- If you continue from the Service Guide to the contact form, your selections may be carried across to prefill the form so you do not have to retype them. Nothing is sent to Dewacon until you submit the form.
Cookies, sessions, and security technologies
- We use a session cookie where a session is needed: to protect forms against cross-site request forgery, and to keep an authorized user signed in to the client portal or the administrative tools.
- The session cookie is restricted so that scripts on the page cannot read it, so that it is not sent with cross-site requests, and so that it is transmitted only over an encrypted connection in production.
- We use in-memory rate limiting keyed on IP address to limit repeated form submissions. This is used for abuse prevention and is not kept as a long-term record.
- We do not use advertising cookies, cross-site tracking cookies, or cookies that build a profile of your browsing across other websites.
reCAPTCHA and bot protection
- The contact form is protected by Google reCAPTCHA to reduce automated spam and abuse.
- To check a submission, reCAPTCHA runs in your browser and we send the resulting token and your IP address to Google for verification. Google processes that information under its own privacy terms.
- reCAPTCHA is the only third-party service that your browser contacts when you use the public website, and it loads only on the contact page.
- The contact form also uses a hidden field that ordinary visitors never see, as a simple check against automated submissions.
- If bot protection is unavailable, the form fails closed and declines the submission rather than accepting unverified traffic.
Analytics and advertising
- This website does not load any third-party analytics, advertising, tag management, session recording, or social media tracking script.
- The site records a small number of interaction events, such as which service was chosen in a dropdown, so that the page can respond to what you do. These events stay in your browser's memory for the life of the page and are not transmitted to Dewacon or to any third party.
- The site is built so that an analytics provider could be added later. If Dewacon ever enables one, this policy will be updated before or at the time that change goes live.
- We do not sell personal information, and we do not share personal information for cross-context behavioral advertising or targeted advertising.
How we use information
- To respond to an inquiry about websites, software, mobile applications, platforms, consulting, partnership, or general questions.
- To review a service request, decide whether we need more information, can accept it for planning, or should close it, and to tell you the outcome.
- To authorize and manage client portal access after a request is accepted, or for a contact on an existing project.
- To record and publish project status so a client can see where the work stands without having to ask.
- To issue invoices, record whether they have been settled, and keep accurate business and accounting records.
- To plan relevant service conversations and follow up on a possible project where there is a reasonable business context.
- To keep the website and portal secure, prevent abuse and spam, diagnose faults, and maintain reliability.
- To keep an internal audit record of administrative actions, so that a change to a project, invoice, or access record can be accounted for afterwards.
- To meet legal, tax, accounting, and record-keeping obligations, and to respond to lawful requests.
Third-party service providers
We use the following providers. Each processes information only to provide its function, and each has its own privacy terms that may apply to that processing.
- Render — application hosting and the persistent storage where our records are kept. Processes anything submitted to or served by the website, and standard server log information.
- Cloudflare — domain name service, network proxy, and edge security in front of the website. Processes connection information such as IP address and requested address.
- Hostinger — domain and business email service used to send and receive Dewacon mail. Processes the content and addressing of email messages.
- Google reCAPTCHA — automated abuse protection on the contact form. Processes the reCAPTCHA token and your IP address.
- Stripe and QuickBooks (Intuit) — invoicing and payment pages for projects that are invoiced. Process the billing contact and payment details you enter on their own hosted pages. Dewacon receives confirmation that an invoice was settled and records that.
- We do not list vendors we do not use. If we add a provider that processes personal information, we will update this section.
Data retention
- We keep information for as long as needed for the purpose it was collected for, and then for a reasonable period afterwards for business records, security, and legal or accounting obligations.
- Contact and service request records are retained as long as reasonably needed to respond, to manage the relationship, to maintain business records, and to meet legal and operational obligations.
- Client and project records are retained for the duration of the project and for a reasonable business and legal retention period afterwards.
- Billing records are retained as required for accounting, tax, dispute, and legal purposes.
- Internal marketing records for prospects that are lost, inactive, or held for later follow-up, and the related activity history, are subject to a retention window that is set to 365 days by default and may be adjusted. Records connected to an active or won project are retained with the project record.
- Security and server log information is retained for a limited period for security, abuse prevention, debugging, and audit purposes.
- Archived records are hidden from day-to-day working views but are not deleted. Permanent deletion of a request record is restricted, is recorded in the internal audit history, and is refused where billing or other connected records must be preserved.
- A deletion request may be limited by legal, accounting, security, backup, dispute, or contractual obligations. Where we cannot delete something, we will tell you why.
Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the information we hold. Current measures include:
- Encrypted connections (HTTPS) for the website, portal, and administrative tools.
- Session cookies that scripts cannot read, are not sent cross-site, and in production are sent only over an encrypted connection.
- Cross-site request forgery protection on forms that change data.
- Automated abuse protection and rate limiting on public forms.
- Passwordless portal sign-in using short-lived, single-use emailed links, with only a cryptographic digest of each link identifier stored.
- Role-based access control, so authorized staff can reach only the functions their role allows.
- An internal audit record of administrative actions on requests, projects, access, and invoices.
- Restricted administrative routes that are excluded from search engine indexing and require authentication.
- Backup copies of our records, which means a deleted record may persist in a backup for a period before it ages out.
- No method of transmission or storage is completely secure. We cannot guarantee absolute security, and we do not claim any security certification or accreditation.
Your privacy choices and requests
- You can ask what personal information we hold about you, ask us to correct it, or ask us to delete it. Email info@dewacon.net.
- You can ask us to stop sending follow-up messages about a possible project at any time.
- You can ask us to remove your client portal access.
- You do not have to provide optional form fields such as phone number, company, project stage, or budget range. Name, email address, and a message are needed for us to reply.
- We may need to verify your identity before acting on a request, and we will only ask for what is necessary to do that.
- We aim to respond to a privacy request within a reasonable time. We will not treat you differently for making one.
- Where a request concerns data we handle on behalf of a client, we will refer it to that client, who controls that data.
U.S. state privacy disclosures
Some U.S. states give residents specific privacy rights. Whether a particular law applies to Dewacon depends on thresholds such as revenue and the number of consumers whose information is processed. This section describes our practices so that you can see them plainly, regardless of which law applies.
- Categories of information we collect: identifiers such as name and email address; contact details such as phone number; commercial and professional information such as company name, service interest, project stage, and budget range; the content of messages you send us; internet and network activity information such as IP address, browser information, and pages requested; and, for invoiced projects, billing contact and invoice status information.
- Purposes we use it for: responding to inquiries, reviewing and managing service requests, providing client portal access, recording project status, issuing and tracking invoices, business follow-up, security and abuse prevention, audit, and legal and accounting compliance.
- Categories of service providers we disclose to: hosting and infrastructure, domain and network security, email delivery, automated abuse protection, and invoicing and payment providers.
- We do not sell personal information, and we do not share it for cross-context behavioral advertising or targeted advertising. We therefore do not offer an opt-out of sale or sharing, because we do neither.
- We do not use personal information for automated decision-making that produces a legal or similarly significant effect, and we do not profile you for advertising.
- We do not knowingly collect or process sensitive categories such as government identification numbers, financial account numbers, health information, precise geolocation, or biometric data through this website.
- To exercise a right, or to ask which rights are available to you, email info@dewacon.net. You may use an authorized agent where the applicable law allows it.
Email communications
- When you submit the contact form we send an acknowledgement to the address you provided, and we send the inquiry to a Dewacon address so that someone can act on it.
- The acknowledgement deliberately does not quote the message you wrote back to you. The recipient address is whatever was typed into the form, so quoting the message would let the form be used to send content to someone else.
- We send transactional email about a request or project: the review outcome, a portal invitation, a sign-in link, a project update, or an invoice notice. These are part of the service rather than marketing, so they are not sent on a marketing subscription basis.
- We may send a reasonable business follow-up about a possible project. Ask us to stop and we will.
- We do not run advertising email campaigns from this website, and we do not add addresses collected here to a bulk marketing list.
Children's privacy
- Dewacon provides services to businesses and organizations. This website is not directed to children, and we do not knowingly collect personal information from children.
- Please do not submit a child's personal information through a public form on this website.
- If we learn that we have received a child's personal information without an appropriate basis, we will delete it. Contact info@dewacon.net to report it.
International users
- Dewacon is based in the United States, and the systems that run this website and store its records are operated in the United States.
- If you access this website from outside the United States, your information may be transferred to and processed in the United States, where privacy laws may differ from those in your location.
- This website is intended for business visitors and is not directed at individuals in the European Economic Area or the United Kingdom.
- If Dewacon later offers services to individuals in the European Economic Area or the United Kingdom, or processes their personal data on behalf of a client, additional terms may apply, including a data processing agreement and appropriate transfer terms. Dewacon does not claim to be certified or approved under any international privacy framework.
Data processing for clients
- Dewacon has two different roles, and which one applies depends on whose data is involved.
- For the Dewacon website, its forms, the client portal, our billing records, and our own business communications, Dewacon decides how the information is handled, and this policy describes that.
- For systems Dewacon builds, supports, or manages for a client, the client generally controls the data in those systems. Dewacon may process it as a service provider or processor, only as needed to deliver the agreed work, and under the project agreement.
- Clients are responsible for providing their own privacy notices to their own users, and for having a lawful basis for the data they ask Dewacon to process.
- Where Dewacon processes personal data on a client's behalf, a data processing agreement may be required, and the client should raise it before that processing begins.
- Project-specific agreements may contain additional privacy, confidentiality, data processing, security, payment, or retention terms, and those terms control the project work they apply to.
Data breach and incident notice
- If we become aware of a security incident affecting personal information we hold, we will investigate it, take steps to contain it, and assess what notice is required.
- Where notice to affected individuals is required by applicable law, we will provide it within the time that law allows, using the contact details we hold or another method reasonably expected to reach you.
- Where an incident affects data we process on behalf of a client, we will notify that client so they can meet their own obligations, in accordance with the project agreement.
- Suspected security problems can be reported to info@dewacon.net. Please include what you observed and when, and do not include credentials or other sensitive information in the report.
Changes to this policy
- We may update this policy as our services, features, or providers change.
- When we do, we will change the last updated date at the top of this page.
- If a change materially affects how we handle information already collected, we will take reasonable steps to bring it to your attention rather than relying on the updated date alone.
- Continuing to use the website after an update means the updated policy applies to that use.
Contact us
- Email info@dewacon.net for any privacy question, to ask what we hold about you, to request correction or deletion, to withdraw from business follow-up, or to ask whether a project-specific notice applies instead of this one.
- You can also use the contact page on this website. Please do not include sensitive information in your message.
- Dewacon LLC, United States. This policy applies to dewacon.net.
Email info@dewacon.net or use the contact page for privacy questions about the Dewacon corporate website. See also the Terms of Use.