سياسة الخصوصية

Last updated: 30 July 2026

Controller: DataDiwan, Y-tunnus 3641767-6, Pakkamestarinkatu 1 F 94, 00520 Helsinki, Finland

Contact: info@datadiwan.com · support@datadiwan.com

Supervisory Authority: Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), PL 800, 00531 Helsinki


1. Introduction

This Privacy Policy explains how DataDiwan ("DataDiwan", "we", "us") collects, processes, and protects personal data when you use the DataDiwan OS platform ("Service"), website, and related services. We act as the data controller for personal data relating to our customers, end-users, and website visitors.

This Policy is prepared in accordance with:

  • EU Regulation 2016/679 (General Data Protection Regulation, "GDPR")
  • Finnish Data Protection Act (Tietosuojalaki 1050/2018)
  • EU Regulation 2024/1689 (Artificial Intelligence Act, "AI Act")
  • Finnish Information Society Code (Laki sähköisen viestinnän palveluista 917/2014)

2. Data We Collect

2.1 Account & Business Data (provided by you)

  • Name, email address, phone number, job title
  • Company name, business ID (Y-tunnus), billing address
  • Company Memory content (services, ICP, value proposition)
  • Leads, prospects, project data, and client information you input

2.2 AI Interaction Data (generated through use)

  • Prompts, queries, and instructions given to AI Directors (Sami / Chief of Staff; Leena, Mikko, Noora, Aino, Olli)
  • AI-generated outputs (proposals, invoices, content drafts, research notes)
  • Approval/rejection decisions and edit history
  • Agent run logs and performance metrics

2.3 Technical & Usage Data (collected automatically)

  • IP address, browser type, operating system
  • Device identifiers, session cookies
  • Access logs, timestamps, pages visited, feature usage
  • Error logs and diagnostic data

2.4 Integration Data (when you connect your own accounts)

  • Gmail metadata: email addresses, thread subjects, send/receive timestamps
  • QuickBooks data: invoice records, payment status
  • Slack metadata: workspace ID, channel names (when Slack is connected)
  • WhatsApp data: phone numbers, message content, contact lists (when WhatsApp integration is enabled)
  • Calendar integrations (e.g. Google Calendar) are deferred until productized — this Policy will be updated before those integrations go live

Important: For these integrations, you retain control of your own accounts. We access this data only through OAuth authorization that you grant and can revoke at any time. We do not store full email bodies, calendar details, or Slack messages unless explicitly required for the AI function you request.

2.5 Payment Data

  • Payment card details (processed by Stripe; we do not store full card numbers)
  • Billing history, subscription tier, VAT identification number
  • Invoice and receipt data

2.6 Customer Support Communications

When you contact us by email at info@datadiwan.com, support@datadiwan.com, or through other support channels, we collect:

  • Your email address and name
  • The content of your message and any attachments
  • Metadata (timestamps, subject line, IP address if applicable)

This data is processed through our business email provider, Zoho Mail, and is used solely to respond to your inquiry and maintain a support history.


3. Legal Basis for Processing

PurposeLegal BasisGDPR Article
Providing the Service (account management, AI agent operation, storage)Contract performanceArt. 6(1)(b)
Billing and payment processingContract performanceArt. 6(1)(b)
Service improvement, debugging, securityLegitimate interestArt. 6(1)(f)
Marketing communications (newsletters, product updates)ConsentArt. 6(1)(a)
Legal compliance (accounting, tax, regulatory)Legal obligationArt. 6(1)(c)
AI model training and fine-tuning (anonymized/aggregated only)Legitimate interestArt. 6(1)(f)
Fraud prevention and platform securityLegitimate interestArt. 6(1)(f)
Customer support communicationContract performance / legitimate interestArt. 6(1)(b) and (f)

Note on AI Processing: AI-generated outputs are produced through automated processing. However, DataDiwan OS is designed as a decision-support tool: all customer-facing actions require your explicit approval. No AI agent sends emails, invoices, or publishes content without human review. This means DataDiwan OS does not make solely automated decisions with legal or similarly significant effects on you or your clients within the meaning of GDPR Article 22.


4. How We Use AI and Automated Processing

4.1 AI System Transparency (AI Act Compliance)

DataDiwan OS incorporates artificial intelligence systems ("AI Directors") that:

  • Analyze your Company Memory and business data to draft proposals, content, invoices, and research
  • Score leads and prospects against your Ideal Customer Profile
  • Monitor project health and flag at-risk deliverables

You are informed that you are interacting with an AI system. Every AI-generated output is clearly labeled and requires your explicit approval before any external action is taken.

4.2 Human Oversight

Our architecture enforces human-in-the-loop approval for all customer-facing actions. You retain full control over:

  • Whether to approve, edit, or reject any AI-generated proposal, invoice, or content
  • Whether to promote a prospect to a sales lead
  • Whether to schedule or publish any marketing content
  • Final decisions on all business operations

4.3 Training Data

We do not use your personal data or confidential business data to train third-party foundation models (e.g., Google Gemini, Anthropic Claude) without your explicit consent. Any model training we conduct uses anonymized, aggregated data only.


5. Data Sharing and Recipients

5.1 Service Providers (Processors)

We engage carefully selected subprocessors who process data on our behalf under GDPR Article 28 data processing agreements:

SubprocessorPurposeLocationSafeguards
Fly.io, Inc.Application hosting (API + Agent Worker)EU (Amsterdam)GDPR Art. 28 DPA, EU SCCs
Vercel, Inc.Web application hosting (Dashboard)EU (Frankfurt)GDPR Art. 28 DPA, EU SCCs
Supabase, Inc.PostgreSQL database, authentication, RLSEU (Frankfurt)GDPR Art. 28 DPA, EU SCCs
Upstash, Inc.Redis cache, message queue, rate limitingEU (Frankfurt)GDPR Art. 28 DPA, EU-based
Google Cloud / Vertex AIAI model inference (production)EU + USAGoogle Cloud DPA, EU SCCs, data minimization
Anthropic PBCAI model inference (development only)USAEU SCCs, development isolation
Stripe, Inc.Payment processing, billingUSAStripe DPA (incorporated), EU SCCs, PCI-DSS
Google LLCAuthentication (Google Sign-In)USAGoogle API DPA, EU SCCs
Meta Platforms, Inc.WhatsApp Cloud API messagingUSAMeta Business Tools DPA, EU SCCs
Langfuse GmbHLLM tracing, observabilityGermany (EU)GDPR Art. 28 DPA, EU-based
Zoho CorporationBusiness email and customer support communicationsEU (Ireland/Netherlands)Zoho DPA (see Section 5.4)

A current list of all subprocessors is available at https://app.datadiwan.com/en/subprocessors (or on request at support@datadiwan.com). Our Data Processing Agreement (DPA) governs processing of Customer Data on your behalf.

5.2 Legal Disclosures

We may disclose personal data if required by:

  • Finnish or EU law, court order, or regulatory request
  • Enforcement of our Terms of Service
  • Protection of our rights, property, or safety

5.3 Business Transfers

In the event of a merger, acquisition, or asset sale, personal data may be transferred subject to the same privacy commitments.


6. International Data Transfers

Your personal data is primarily stored and processed within the European Economic Area (EEA). Where we transfer data outside the EEA (e.g., to LLM providers, payment processors, or authentication services in the USA), we ensure appropriate safeguards are in place:

  • EU Commission Standard Contractual Clauses (SCCs) with additional technical and organizational measures
  • Transfers to countries with an EU adequacy decision
  • Data minimization for transfers (only necessary data is sent to LLM APIs)
  • EU-region hosting for core infrastructure (database, cache, application hosting)

7. Data Retention

Data CategoryRetention PeriodLegal Basis
Account dataUntil account deletion + 1 yearContract / legal hold
AI-generated outputs (proposals, content)Until account deletion, or as long as you maintain themContract
Billing and invoice data10 yearsFinnish Accounting Act (Kirjanpitolaki)
Server logs90 daysLegitimate interest (security)
Marketing consent recordsUntil consent is withdrawn + 2 yearsLegal obligation
Deleted account data30 days after deletion requestGDPR Art. 17
LLM tracing data (Langfuse)90 daysLegitimate interest (debugging)
Customer support emails2 years after resolutionLegitimate interest (support quality, dispute resolution)

Note on conflicting obligations: While GDPR grants you the right to erasure (Art. 17), Finnish accounting and tax laws require certain financial records to be retained for 10 years. In such cases, we will restrict processing (e.g., archive and isolate the data) rather than delete it, and erase the data immediately after the statutory retention period expires.


8. Your Rights Under GDPR

As a data subject, you have the following rights:

1. Right of access (Art. 15) — Request a copy of your personal data

2. Right to rectification (Art. 16) — Correct inaccurate or incomplete data

3. Right to erasure ("right to be forgotten", Art. 17) — Request deletion, subject to legal retention obligations

4. Right to restrict processing (Art. 18) — Limit how we use your data

5. Right to data portability (Art. 20) — Receive your data in a structured, machine-readable format

6. Right to object (Art. 21) — Object to processing based on legitimate interests or direct marketing

7. Right to withdraw consent — At any time, without affecting prior lawful processing

8. Right to lodge a complaint — With the Finnish Data Protection Ombudsman or your local supervisory authority

To exercise your rights, contact us at support@datadiwan.com. We respond within 30 days. We may need to verify your identity before processing your request.


9. Security Measures

We implement appropriate technical and organizational measures to protect your data:

  • Encryption at rest (AES-256) and in transit (TLS 1.3)
  • Row-level security (RLS) in PostgreSQL for tenant isolation
  • Role-based access controls and OAuth 2.0 authentication
  • Regular security assessments and dependency audits
  • Incident response plan with 72-hour breach notification capability (GDPR Art. 33)
  • Backups with geographic redundancy
  • Hash-chained audit logs (tamper-evident)

10. Cookies and Tracking Technologies

We use cookies and similar technologies. For detailed information, see our Cookie Policy.

You can manage cookie preferences through your browser settings.


11. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, contact us immediately for deletion.


12. Changes to This Policy

We may update this Privacy Policy to reflect changes in law, our practices, or the Service. Material changes will be notified via email or in-app notice at least 30 days before taking effect. The "Last updated" date at the top indicates the current version.


13. Contact Information

Data Controller:

DataDiwan

Pakkamestarinkatu 1 F 94

00520 Helsinki, Finland

Y-tunnus: 3641767-6

Email: support@datadiwan.com · info@datadiwan.com

We have not appointed a Data Protection Officer (DPO) as our processing activities do not meet the thresholds requiring one under GDPR Article 37.

Finnish Data Protection Ombudsman:

PL 800, 00531 Helsinki

Email: tietosuoja@om.fi

Phone: +358 29 56 66700

نظام داتاديوان