1. Introduction
DAITA AI Inc. values your privacy and is committed to protecting your personal data.
Personal data refers to any information which can be used to identify you, such as your name, email addresses, phone number, or billing information (Personal Data). This Privacy Policy explains what Personal Data we process, why we process it, how we use it, with whom we share your Personal Data, and your rights regarding your Personal Data, when you access, register on, browse and use our Services.
This Privacy Policy must be read along with the Terms (available at: https://daitalabs.com/legal/terms-of-service) and the Agreement referenced thereunder. Capitalized terms not defined here shall have the same meaning as under the Terms.
Where we process Personal Data on a Client’s behalf in connection with the Services, such processing is governed by the Agreement between us and the relevant Client, including any applicable data processing agreement. In such circumstances, we process such Personal Data on the Client’s behalf and in accordance with the Client’s documented instructions, except where otherwise required by applicable Data Protection Laws. Personal Data processed on a Client’s behalf includes mailbox content accessed through the Client’s own email systems (including message content and attachments), messages exchanged through the Client’s messaging channels, supplier, purchase order and production-tracking records, and the outputs our AI features generate from that content.
Data Protection Laws means laws and regulations relating to the protection, privacy or security of Personal Data, including, where applicable, the Digital Personal Data Protection Act, 2023 and rules made thereunder, the EU General Data Protection Regulation (Regulation (EU) 2016/679), the UK General Data Protection Regulation and the UK Data Protection Act 2018, and the California Consumer Privacy Act of 2018, as amended (CCPA).
2. What data do we process and why?
We may process your Personal Data to provide you our Services, including to help you create an account, manage your subscription, and using our Services. In particular, we collect:
| Type of data | How we use it and why |
|---|---|
| Contact details and profile information, such as full name, personal/work email address. We also record the time you last signed in. | Providing you our Services Verifying your identity and administering your account Communicating with you, or informing you about updates to the Services, this Privacy Policy or the Terms |
| Feedback, suggestions, support tickets, error logs and related metadata, as well as information derived from such data, to the extent its use is permitted under the relevant Agreement and applicable law. | Providing technical support and troubleshooting Operating and improving our Services Analyzing user interactions with our Services to assess service quality, accuracy, and security For the avoidance of doubt, we do not use Client Data (as defined in the applicable Agreement), or Personal Data processed on a Client’s behalf, to train AI models, including models operated by our service providers, except where expressly permitted under the applicable Agreement. Where we improve our models, we do so using anonymized or aggregated data only. Under the terms on which we use their application programming interfaces, our AI service providers do not use inputs or outputs to train their models. Those providers may retain inputs and outputs for a limited period for abuse monitoring and service operation in accordance with their own terms. |
| Billing and transaction information including the invoice email address and billing cycle for your account, and billing records, payment status, invoice information, contractual pricing arrangements. We do not collect or process payment card numbers, bank account credentials or other sensitive Personal Data through the Services, except that where you choose to pay by card, card payment details are collected and processed by our payment provider. | Processing payments, maintaining billing records, and ensuring compliance with our contractual obligations Enforcing the Terms and/or the Agreement, for protecting our and if necessary, a third party’s, rights, property and safety Fulfilling our obligations under applicable laws |
| Technical usage, such as records of our communication with you, activity on the Services such as login records, feature/functionality usage, API calls, profile updates, uploaded materials, chat interactions, requests, logs and related metadata, and identifiers assigned by our self-hosted analytics tool. | Improving our services Ensuring security of the Services, monitoring for fraud, etc. Personalizing your experience and recommendations Providing technical support and troubleshooting |
3. Where we collect your Personal Data from?
We collect your Personal Data:
- Directly from you: This includes any Personal Data that you share or upload on the Services, such as account details, notes, responses to our queries, feedback, support requests and other information you choose to provide. Where you provide or upload Personal Data on behalf of a Client, we may process it in accordance with the Client’s instructions and the applicable Agreement between us and the Client.
- Automatically: When you use our Services, we use automated means such as cookies and similar technologies to automatically collect certain technical and behavioral data about you, including your Personal Data, that helps us in improving your experience.
- Third parties: We may also receive data, including Personal Data, about you from third-party service providers that support provision, security, analytics or functionality of the Services, from third-party integrations you choose to use, or where permitted by applicable laws, from public sources/platforms (such as public database).
4. Who do we share your Personal Data with?
We share your Personal Data with third parties in accordance with this Privacy Policy and as required by law.
Your Personal Data may be processed and stored using infrastructure located in Mumbai, India. We also engage certain third-party service providers, including providers of artificial intelligence and related services, which may process Personal Data outside India. The location of processing may vary depending on the service provider and the functionality used.
| S. No. | Who we share the data with: | Why we share the data: |
|---|---|---|
| 1. | Service providers | We engage service providers to provide Third-Party Content such as cloud infrastructure, large language models, communication services for sending notifications via WhatsApp, SMS and email and for providing support, and subscription management, billing as well as payment processing services. These providers may process your Personal Data as necessary to provide their services to us, in accordance with their contractual terms and applicable law. Where required, we impose contractual restrictions on such providers from using Personal Data for any other purposes except as instructed by us or required by applicable laws. We currently engage service providers in the following categories: cloud hosting and storage; managed database services; communications and messaging services for WhatsApp, SMS and email; large language model and AI inference providers; document extraction providers; application performance monitoring; and customer support and customer success. A current list of our sub-processors, with a short description of what each one does and where it processes data, is published at https://daitalabs.com/legal/subprocessors, and we update that page when our sub-processors change. |
| 2. | Legal and regulatory purposes | We may disclose your data with third parties (such as governmental authorities, law enforcement agencies, etc.) if:
Where the disclosure relates to Personal Data we process on a Client’s behalf, we will, to the extent permitted by applicable Data Protection Laws, notify the relevant Client and reasonably cooperate with them in relation to such disclosure. |
| 3. | Corporate Transactions / Change in Control | If we are involved in a merger, acquisition, restructuring, or sale of assets, your Personal Data may be transferred as part of that transaction. |
| 4. | With your consent | If you give explicit consent or make a specific request, we may share your data with other parties for purposes not covered in this Privacy Policy. |
5. Hosting and cross-border transfer of Personal Data
We may host, transfer and process your Personal Data in India and other countries through DAITA and third-party service providers that we rely on to operate and manage the Services. Your Personal Data will be processed in accordance with this Privacy Policy and applicable Data Protection Laws.
Your Personal Data may be stored and processed using infrastructure located in India, including Amazon Web Services (AWS) and MongoDB Atlas infrastructure located in Mumbai. We also use third-party service providers, including providers of AI, communications, customer support, analytics and other services, that may process your Personal Data outside India. The location of processing may vary depending on the service provider and the functionality used.
Where your Personal Data is transferred to, or processed in, a country outside your country of residence, the laws of that country may differ from those applicable in your country of residence. Your Personal Data may therefore be subject to the laws and lawful disclosure requirements applicable in those countries, including requirements imposed by governmental or regulatory authorities or courts.
If you use the Services from outside India, your Personal Data may be transferred to, stored and processed in India and other countries in which DAITA or its service providers operate. Where required by Data Protection Laws, we will implement appropriate safeguards for such transfers, which may include contractual safeguards such as the Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum.
6. How long do we retain your Personal Data?
We retain Personal Data collected from you only for as long as reasonably necessary to make available our Services. We may further retain and use such Personal Data only as necessary to comply with legal obligations, maintain accurate accounting, financial and operational records, resolve disputes, and enforce agreements. Where we process Personal Data on behalf of a Client, retention and deletion of such Personal Data are also subject to our Agreement with the applicable Client. When Personal Data is no longer required for these purposes or other applicable obligations, we will securely delete or irreversibly anonymize it. Anonymized and aggregated information may be retained for analytics, research, service improvement, or other legitimate business uses, subject to applicable Data Protection Laws.
If you ask us to delete your account by writing to us at dsr@daitalabs.com, we will delete your Personal Data within 30 (thirty) days of your request, subject to any Personal Data we are required or permitted to retain under applicable Data Protection Laws. If your access to the Services through a Client comes to an end, your account is marked inactive, and deletion of that Client’s data is governed by our Agreement with that Client. While we work to accommodate the aforementioned deletion requirements, we may need to retain certain Personal Data for a while longer for the following reasons:
- to perform our contractual obligations to which you are subject or to respond to your questions or provide necessary service or support;
- to prevent fraud, resolve complaints, address inquiries, or exercise/defend legal claims, including providing evidence in legal proceedings;
- to comply with legal obligations, exercise our rights, resolve disputes, or for security and safety reasons, as permitted under the law (such as adhering to applicable statutes of limitations or regulatory investigations).
7. Your rights
You may have rights in relation to your Personal Data under applicable Data Protection Laws.
(a) If you are an Indian-resident
You have certain rights regarding your Personal Data, provided where we process your Personal Data on a Client’s behalf, you should direct your request to them, and we will assist the Client in addressing the same as per their instructions and applicable Data Protection Laws:
- Right to access information about your Personal Data: You can ask us for a summary of your Personal Data, the processing activity, and the recipients with whom we have shared your Personal Data, along with a description of the Personal Data shared.
- Right to seek correction and erasure of Personal Data: If you believe that the Personal Data we hold is inaccurate, incomplete or outdated, you can write to us. You may also request deletion of your data; however, in certain cases, we may need to retain it for legal or regulatory reasons (See the ‘How long do we retain your Personal Data?’ section above).
- Right to grievance redressal: If you wish to file a grievance, you may contact our Grievance Redressal Officer in accordance with this Privacy Policy. If your grievance remains unresolved, please be informed that you have the right to escalate it to the competent supervisory authority.
- Right to nominate: You can designate another individual to exercise your rights under this Privacy Policy on your behalf in the event of your death or incapacity.
To exercise any of these rights or seek further information, you can write to us at dsr@daitalabs.com. We reserve the right to verify your identity before processing your request, and not to respond to complaints that we believe are manifestly false, unfounded, or frivolous. Additionally, these rights may be limited in certain cases where we are legally required to process or retain your Personal Data.
(b) If you are a California state resident
You have the following rights to the extent, and in the manner, set out in the California Consumer Privacy Act (“CCPA”):
- The right to access your Personal Data;
- The right to know what Personal Data we intend to collect prior to collection;
- The right to opt out of the sale or sharing of your Personal Data, where applicable;
- The right to equal services without discrimination; and
- The right to request deletion of Personal Data.
The above rights, the manner in which you can exercise the same and the categories of Personal Data we collect and the manner in which we collect and use your Personal Data are detailed below.
For purposes of the CCPA, in collecting the information described above, we collect the categories of Personal Data listed below from you:
- Identifiers: We may collect your name, personal or work email address, phone number, account or other identifiers, and Internet Protocol (IP) address. We use identifiers as described in the ‘What data do we process and why?’ and ‘Who do we share your Personal Data with?’ sections of this Privacy Policy, including to provide and administer the Services, communicate with you, provide support, and maintain the security of the Services.
- Personal Data categories described in the California Customer Records statute: We may collect your name and contact information, including your email address and phone number, where provided in connection with your account or use of the Services. We use such Personal Data as described in the ‘What data do we process and why?’ and ‘Who do we share your Personal Data with?’ sections of this Privacy Policy.
- Commercial information: We may collect billing and transaction information, including billing records, payment status, invoice information and contractual pricing arrangements. We use such information to process payments, maintain billing records, administer our contractual relationship with you or the relevant Client, and comply with applicable laws.
- Internet or other electronic network activity information: We may collect technical usage information, including login records, feature and functionality usage, API calls, profile updates, uploaded materials, chat interactions, requests, logs and related metadata. We may also collect information through cookies and similar technologies, as described in the ‘Cookies and tracking technologies’ section of this Privacy Policy. We use such information to improve and secure the Services, monitor for fraud, personalize your experience and recommendations, and provide technical support and troubleshooting.
- Audio, electronic, visual or similar information: We may collect content and communications that you submit or upload through the Services, including uploaded materials, chat interactions, support requests and related content. We may also process recordings, transcripts and AI-generated summaries of calls in connection with the customer support and customer success functionality of the Services. We use such information for the purposes described in the ‘What data do we process and why?’ section of this Privacy Policy.
As described in this Privacy Policy, we have collected the categories of Personal Data listed below during the preceding 12 months:
- Identifiers
- Personal Data categories described in the California Customer Records statute
- Commercial information
- Internet or other electronic network activity information
- Audio, electronic, visual or similar information
Categories of sources: We have collected the Personal Data identified in this Privacy Policy from the following sources:
- Directly from you, including information you provide or upload through the Services;
- Automatically when you use the Services, including through cookies and similar technologies; and
- From third parties, including service providers, third-party integrations and, where permitted by applicable law, public sources or platforms.
We use the Personal Data collected from these sources for the purposes described in the ‘What data do we process and why?’ section of this Privacy Policy, including to:
- Provide and administer the Services;
- Create and manage accounts and subscriptions;
- Provide technical support and troubleshooting;
- Communicate with you;
- Improve and personalize the Services;
- Ensure the security of the Services and monitor for fraud;
- Process payments and maintain billing records; and
- Comply with applicable laws and enforce our agreements.
Personal Data sold: We have not sold any categories of Personal Data during the preceding 12 months.
Personal Data disclosed for a business purpose: We have disclosed for a business purpose the categories of Personal Data listed below during the preceding 12 months:
- Identifiers
- Personal Data categories described in the California Customer Records statute
- Commercial information
- Internet or other electronic network activity information
- Audio, electronic, visual or similar information
We have disclosed these categories of Personal Data to categories of third parties including (1) service providers that support cloud hosting, databases, communications, customer support, analytics, monitoring, AI functionality, subscription management, billing and payment processing; and (2) professional advisors.
The CCPA gives consumers the right to request that we (1) disclose what Personal Data we collect, use, disclose, and sell, and (2) delete certain Personal Data that we have collected or maintained. You may submit these requests to us as described below, and we honour these rights where they apply.
If a request is submitted in a manner that is not one of the designated methods for submission, or if the request is deficient in some manner unrelated to our verification process, we will either (i) treat the request as if it had been submitted in accordance with the designated manner, or (ii) provide you with specific directions on how to submit the request or remedy any deficiencies with the request, as applicable.
- Request to know: As a California resident, you have the right to request: (1) the specific pieces of Personal Data we have collected about you; (2) the categories of Personal Data we have collected about you; (3) the categories of sources from which the Personal Data is collected; (4) the categories of Personal Data about you that we have sold and the categories of third parties to whom the Personal Data was sold; (5) the categories of Personal Data about you that we disclosed for a business purpose and the categories of third parties to whom the Personal Data was disclosed for a business purpose; (6) the business or commercial purpose for collecting, disclosing, or selling Personal Data; and (7) the categories of third parties with whom we share Personal Data. Our response will cover the 12-month period preceding our receipt of a verifiable request.
- Request to delete: As a California resident, you have the right to request the deletion of certain Personal Data collected or maintained by us. As described herein, we will delete your Personal Data from our records and direct applicable service providers to delete your Personal Data from their records. However, we are not required to honour a deletion request if an exemption applies under applicable Data Protection Laws.
- Submitting a request: You may submit a request to know or to delete by email to the address provided in the ‘Contact us’ section of this Privacy Policy. Regarding requests to delete, we may present you with the choice to delete select portions of your Personal Data, subject to applicable Data Protection Laws and our contractual or legal obligations.
Verification Process: We are required by law to verify the identities of those who submit requests to know or to delete. To determine whether the individual making a request is the consumer about whom we have collected Personal Data, we will verify your identity by matching the identifying information provided by you in the request to the Personal Data that we already maintain about you. As part of this process, we may require you to provide your name and email address, and mobile number, if voluntarily provided by you in connection with your use of the Services. We will inform you if we cannot verify your identity.
- If we cannot verify the identity of the person making a request for categories of Personal Data, we may deny the request. If the request is denied in whole or in part for this reason, we will provide an explanation of the basis for the denial.
- If we cannot verify the identity of the person making the request for specific pieces of Personal Data, we may deny the request for specific pieces of Personal Data. Where appropriate, we may instead evaluate the request as one seeking disclosure of categories of Personal Data.
- If we cannot verify the identity of the person making a request to delete, we may deny the request. If there is no reasonable method by which we can verify the identity of the requestor to the degree of certainty required, we will state this in our response and explain why we have no reasonable method by which we can verify the identity of the requestor.
- Authorized Agents: Authorized agents may submit requests via the methods identified in this Privacy Policy. If you use an authorized agent to submit a request to know or a request to delete, we may require you to: (1) provide the authorized agent with written permission to do so; (2) verify your identity directly with us; and (3) directly confirm with us that you provided the authorized agent permission to submit the request. We may also require the authorized agent to provide evidence of their authority to act on your behalf, as permitted by applicable Data Protection Laws.
- Excessive Requests: If requests from a user are manifestly unfounded or excessive, in particular because of their repetitive character, we may either (1) charge a reasonable fee, where permitted by applicable law, or (2) refuse to act on the request and notify the user of the reason for refusing the request. If we charge a fee, the amount will be based upon the administrative costs of providing the information or communication or taking the action requested.
CCPA Non-Discrimination: You have the right not to receive discriminatory treatment by us due to your exercise of the rights provided by the CCPA. We do not offer financial incentives or price or service differences in connection with the exercise of CCPA rights, and we do not discriminate against consumers for exercising their rights under the CCPA.
(c) If you are a resident of the United Kingdom (UK), a European Union (EU) country, or European Economic Area (EEA)
- Right to access your Personal Data: You have the right to receive confirmation as to whether or not Personal Data concerning you is being processed and, where that is the case, to request access to such Personal Data.
- Right to rectification: You have the right to request that inaccurate or incomplete Personal Data concerning you be corrected.
- Right to erasure: In some cases, you have a legal right to request that we erase your Personal Data.
- Right to object to processing: You have the right to object to our processing of your Personal Data under certain conditions.
- Right to restrict processing: You have the right to request that we restrict the processing of your Personal Data under certain conditions.
- Right to data portability: You have the right, under certain conditions, to receive the Personal Data you have provided to us in a structured, commonly used and machine-readable format and to request that we transmit such Personal Data to another organization, where technically feasible.
- Right to make a complaint to a supervisory authority: If you believe we have not processed your Personal Data in accordance with applicable Data Protection Laws, we encourage you to contact us using the contact information provided in the ‘Contact us’ section. You also have the right to lodge a complaint with the relevant supervisory authority or seek a remedy through the courts. To exercise any of these rights, please write to us at dsr@daitalabs.com.
- Right not to be subject to automated decision-making, including profiling: You have the right, under certain conditions, not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you.
We collect and process Personal Data about you only where we have a legal basis to do so. The legal basis relied upon will depend on the type of Personal Data collected and the context in which it is processed, including the Services involved. If you are located elsewhere, you may have rights in relation to your Personal Data under the law applicable to you, and you can write to us at dsr@daitalabs.com.
8. How do we protect your Personal Data?
We implement and maintain technical and organizational measures designed to protect Personal Data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit at the edge, encryption of stored files and of secrets, row-level access separation between tenants, role-based access controls, token-based authentication, and restricting access to personnel who need such access to provide the Services.
Our employees, agents, contractors, and third parties, who have access to your Personal Data for performance of business functions, are required to process your Personal Data in accordance with their respective contractual obligations, applicable law, and our information security and data protection requirements, as applicable.
While we make every effort to protect your Personal Data, we understand that no system can guarantee complete security. If you have any concerns, require assistance, or suspect that your interaction with us is no longer secure, please contact us immediately using details in the ‘Contact us’ section below.
9. Third-party websites and links
Our Services may contain external links, and accordingly you are advised to verify the privacy practices of such other websites. We are not responsible for the manner of use or misuse of information made available by you at such other websites. We encourage you not to provide personal information, without assuring yourselves of the privacy policies of third-party links. Accessing such third-party content is done at your own discretion, and we highly recommend reviewing their privacy policies to understand how they treat your data. This section does not apply to the service providers engaged by DAITA to process Personal Data in connection with the Services, which are addressed in the ‘Who do we share your Personal Data with?’ section above.
10. Cookies and tracking technologies
When you utilize our Services, we may place a number of cookies on your browser. For example, we use cookies to understand visitor and user preferences, improve their experience, and track and analyze usage and other statistical information. Additionally, cookies allow us to remember your preferences and support functionality of the Services. You can control the use of cookies at the individual browser level. If you elect not to activate the cookie or to later disable cookies, you may still utilize our Services, but your ability to use some features or areas thereof may be limited. We may use any of the following categories of cookies:
- Essential Cookies: we use two essential cookies. A refresh token cookie (HttpOnly), retained for seven days, keeps you signed in; and a device-trust cookie helps us recognize a device you have used before. Without these the Services will not work.
- Analytics Cookies: we use Rybbit, which we host ourselves at analytics.daitalabs.com, to understand how visitors and users interact with the Services. Rybbit identifies individual users.
11. Contact us
Grievance officer:
Name: Jérôme Schmidt
Email: privacy@daitalabs.com
We aim to resolve privacy concerns promptly and effectively. Please write to privacy@daitalabs.com with questions about this Privacy Policy or to raise a grievance, and to dsr@daitalabs.com to exercise your rights in relation to your Personal Data. If you are not satisfied with our response, and do not think we are handling your Personal Data adequately, you may lodge a complaint with the relevant regulatory authority, as per applicable Data Protection Laws.
12. Updates to this Privacy Policy
We reserve the right to modify, add, or remove portions of this Privacy Policy, at our sole discretion. We will make reasonable efforts to notify you of any material changes via notifications, or email. Once the revised Privacy Policy is published on our website, the changes will take effect immediately unless stated otherwise. Your continued use of our website after such updates constitutes consent to the updated policy, to the extent permitted by law. Please take the time to periodically review this Privacy Policy for the latest information on our privacy practices.