Privacy Policy
Last updated 22 September 2026
This policy explains what personal data Dripwork handles, why, and what you can ask us to do about it. The short version: this website collects nothing directly, sets no cookies and runs no analytics.
1. Who is responsible
Dripwork is a trading name of a sole trader established in Finland. Under the General Data Protection Regulation (GDPR), the data controller is:
Aqib Ilyas, trading as Dripwork
Ylioppilaantie 6
90130 Oulu, Finland
aqib@dripwork.dev
We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the GDPR. Privacy questions go to the address above.
2. What this policy covers
This policy covers the website at dripwork.dev and any correspondence you send us.
Each app we publish has its own privacy policy, shown on that app's marketplace listing and in the app itself. Apps handle different data in different systems, so where an app's own policy says something different about that app, the app's policy is the one that applies to it.
3. What this website collects
Nothing directly. There is no account to create, no form to submit, no newsletter sign-up and no tracking of any kind. The site is a set of static files.
Our hosting provider does process limited technical data in order to deliver the site and protect it from abuse. This typically includes your IP address, browser user agent, the page requested and a timestamp.
- Purpose: serving the website, and detecting and preventing attacks.
- Legal basis: our legitimate interests under Article 6(1)(f) of the GDPR in keeping the site available and secure.
- Retention: short-lived, and controlled by the hosting provider rather than by us.
4. Cookies
This website sets no cookies. It uses no analytics, no advertising pixels, no embedded social media widgets and no third-party fonts. It stores nothing in your browser for the purpose of identifying or tracking you.
That is why you do not see a cookie banner here. There is nothing to consent to.
5. If you contact us
When you email us, we receive whatever you put in the message: your email address, your name if you include it, and the content itself.
- Purpose: reading and answering your message, and keeping a record of support matters.
- Legal basis: our legitimate interests under Article 6(1)(f) in responding to people who contact us. Where your message concerns buying or using one of our apps, the basis is Article 6(1)(b), steps taken at your request before or under a contract.
Please do not send us special category data (such as health or biometric information) or passwords and API tokens. We do not need them and do not want to hold them.
6. Data in our apps
Our apps run inside the tool you install them into and follow the permissions that tool grants them. As a matter of design, our apps work on configuration, meaning settings and structure, rather than on the contents of your team's work items.
What each app reads, stores and for how long is set out in its own privacy policy on its marketplace listing. When you uninstall an app, we delete the data held for that account in line with that policy.
- Work Type Guardrails for Jira, which stores only work type IDs inside your own Jira site
- WhereUsed for monday.com, whose policy is published at whereused.app
- Lookahead: Read-only Gantt for Jira, which reads Jira data in the browser and stores only saved views and preferences inside Atlassian's own storage for your site
7. Who processes data for us
We keep the list of suppliers short. The ones that can touch personal data are:
| Provider | Role |
|---|---|
| Cloudflare, Inc. | Website hosting, content delivery and protection against abuse |
| Zoho Corporation (Zoho Workplace) | Email hosting for our dripwork.dev addresses, including receiving and storing correspondence |
These act as processors on our instructions. We do not sell personal data, and we do not share it for advertising.
8. International transfers
Cloudflare, Inc. is based in the United States. Zoho stores mailbox data in the data centre region selected for our account. Where personal data is transferred outside the European Economic Area, that transfer is covered by the European Commission's Standard Contractual Clauses, by an adequacy decision such as the EU-US Data Privacy Framework, or by another safeguard permitted under Chapter V of the GDPR.
9. How long we keep things
| What | How long |
|---|---|
| Website server logs | Short retention set by the hosting provider |
| General email correspondence | While the matter is open, then up to 12 months |
| Support correspondence | Up to 24 months, so we can follow up on recurring issues |
| Records we must keep by law, such as accounting records | For the period Finnish law requires |
10. Your rights
If you are in the EEA or the UK, the GDPR gives you the following rights over your personal data:
- Access. Ask whether we hold data about you, and get a copy.
- Rectification. Have inaccurate data corrected.
- Erasure. Ask us to delete data, where there is no overriding reason to keep it.
- Restriction. Ask us to pause processing while something is being resolved.
- Portability. Receive data you gave us in a structured, machine-readable format.
- Objection. Object to processing based on legitimate interests.
- Withdraw consent. Where we rely on consent, withdraw it at any time, without affecting processing already carried out.
To exercise any of these, email aqib@dripwork.dev. We answer within one month, as Article 12(3) requires, and we will tell you if we need longer for a complex request. Exercising these rights is free.
11. Complaints
If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to a supervisory authority.
Our lead supervisory authority is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) in Finland, at tietosuoja.fi. If you live in another EEA country, you may complain to your local authority instead.
12. Security
The site is served over HTTPS only, with a strict content security policy and no third-party scripts. The strongest protection we apply, though, is collecting very little in the first place. Data we never hold cannot leak.
13. Children
Our apps are business tools. This website and our apps are not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has sent us personal data, email us and we will delete it.
14. Changes to this policy
If we change how we handle personal data, we update this page and the date at the top. For significant changes affecting people who use our apps, we also note the change on the relevant marketplace listing.
Questions about anything on this page go to aqib@dripwork.dev. See also our Terms of Service.