Last updated: August 13, 2026
1. Data Controller Identification & Business Registration
The LookADev software platform and engineering services (7-day Web Sprints, custom web systems, WhatsApp AI automations, and technical code audits) are owned and operated under the legal business entity and sole proprietorship Lucas Martins do Carmo Borges (trading as LookADev, "we", "our", "us"), acting as the Data Controller under applicable international data protection regulations (UK/EU GDPR and LGPD).
2. International Multi-Jurisdictional Framework
Because LookADev serves clients across the United Kingdom, United States, Brazil, and the European Union, our data architecture is engineered to uphold the highest global data privacy benchmarks simultaneously:
- United Kingdom (UK GDPR & DPA 2018): UK General Data Protection Regulation and the Data Protection Act 2018, aligned with Information Commissioner's Office (ICO) guidelines.
- European Union (EU GDPR): General Data Protection Regulation (Regulation EU 2016/679).
- United States (CCPA / CPRA & FTC): California Consumer Privacy Act as amended by the California Privacy Rights Act, and Federal Trade Commission fair information practices.
- Brazil (LGPD): General Data Protection Law (Federal Law No. 13,709/2018).
3. Categories of Data Collected and Processing Purpose
We enforce the principle of data minimization (collecting only the minimum data essential for technical execution and client communication):
| Category | Data Elements | Specific Technical Purpose |
|---|---|---|
| Inquiries & Quotes | Name, email address, WhatsApp / phone number, company name. | Preparing project proposals, sprint kickoff, and ongoing project communications. |
| Code Audits (VibeCoders) | Git repository access (GitHub/GitLab), environment configs, database schemas. | Executing automated and manual vulnerability scans, security hardening, and refactoring. |
| WhatsApp Automations | Message IDs, customer contact numbers, authorized webhook events. | Routing 24/7 client conversational flows through the official WhatsApp Business API. |
| Job Board & Community | Job titles, vacancy descriptions, developer public profiles & portfolio links. | Displaying public developer profiles and matching contractors with opportunities. |
| Telemetry & Security | Anonymized IP address, user-agent, request timestamps. | Infrastructure defense, anti-DDoS perimeter protection, and API rate-limiting. |
4. Absolute Source Code Confidentiality (VibeCoder Protocol)
For clients engaging our Code Audit and 7-Day Sprint services for AI-generated applications (Cursor, v0, Bolt, Windsurf, Lovable), we guarantee Strict Intellectual Property Protection:
Zero AI Model Training
Your proprietary codebase, business logic, and database schemas are NEVER used to train any public or private artificial intelligence models.
Ephemeral Sandboxes
Cloned repositories are analyzed within encrypted, sandboxed environments and securely wiped immediately after sprint handover.
API Secret Sanitation
Active auditing for leaked API credentials (OpenAI, Stripe, database keys) with immediate guidance on secure key rotation.
5. Data Flows in WhatsApp AI Automations
In our intelligent WhatsApp Business API chatbot solutions:
- In-Transit Encryption: All webhook transmissions are secured via HTTPS/TLS 1.3 with cryptographic payload signature validation (HMAC SHA-256).
- No Data Brokering: We never sell, lease, or monetize customer contact lists or conversation records to any third party.
- Restricted Retention: Transit conversation logs are stored only for the technical duration required to synchronize data with your external CRM or database.
6. Lawful Bases for Data Processing
Under Article 6 of the UK/EU GDPR and Article 7 of the LGPD, we process personal information on the following legal grounds:
- Performance of Contract (Art. 6(1)(b) GDPR): Delivering agreed software engineering, sprint deliverables, and quoting requests.
- Legal Obligation (Art. 6(1)(c) GDPR): Complying with financial reporting, invoicing, and tax statutes.
- Legitimate Interests (Art. 6(1)(f) GDPR): Protecting web application security, mitigating malicious traffic, and ensuring server uptime.
- Consent (Art. 6(1)(a) GDPR): For published client case studies, testimonials, and non-essential cookie preferences.
8. Your Individual Rights (GDPR, LGPD & CCPA)
You retain full sovereign control over your personal data. Upon contacting our DPO, you may exercise:
Request formal confirmation and a copy of all personal data held about you.
Demand prompt correction of inaccurate or incomplete records.
Request deletion of your data when no overriding statutory retention grounds apply.
Receive your data in a structured, machine-readable format (JSON/CSV).
LookADev explicitly does not sell or share personal information for commercial consideration.
Withdraw previously granted consents at any time without adverse consequences.
9. Technical Security Architecture & Encryption
We apply modern technical and organizational defense controls aligned with ISO/IEC 27001 and OWASP Top 10 recommendations:
- End-to-end in-transit encryption with TLS 1.3 and modern elliptic curves.
- Hardened HTTP security headers: Content Security Policy (CSP), HSTS, X-Frame-Options: DENY, and X-Content-Type-Options: nosniff.
- Mandatory Multi-Factor Authentication (MFA) across all code repositories, cloud control planes, and administrative consoles.
- Zero persistent storage of client production database credentials on local developer workstations.
10. Contacting Our Data Protection Officer (DPO)
To exercise any privacy rights, report security observations, or request data deletion:
Email: dpo@lookadev.com / lucas@lookadev.com
Direct WhatsApp: +44 7356 026050
Response SLA: Within 15 business days (or within GDPR 30-day requirement).