سياسة الخصوصية
Last updated: 30 July 2026
Controller: DataDiwan, Y-tunnus 3641767-6, Pakkamestarinkatu 1 F 94, 00520 Helsinki, Finland
Contact: info@datadiwan.com · support@datadiwan.com
Supervisory Authority: Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), PL 800, 00531 Helsinki
1. Introduction
This Privacy Policy explains how DataDiwan ("DataDiwan", "we", "us") collects, processes, and protects personal data when you use the DataDiwan OS platform ("Service"), website, and related services. We act as the data controller for personal data relating to our customers, end-users, and website visitors.
This Policy is prepared in accordance with:
- EU Regulation 2016/679 (General Data Protection Regulation, "GDPR")
- Finnish Data Protection Act (Tietosuojalaki 1050/2018)
- EU Regulation 2024/1689 (Artificial Intelligence Act, "AI Act")
- Finnish Information Society Code (Laki sähköisen viestinnän palveluista 917/2014)
2. Data We Collect
2.1 Account & Business Data (provided by you)
- Name, email address, phone number, job title
- Company name, business ID (Y-tunnus), billing address
- Company Memory content (services, ICP, value proposition)
- Leads, prospects, project data, and client information you input
2.2 AI Interaction Data (generated through use)
- Prompts, queries, and instructions given to AI Directors (Sami / Chief of Staff; Leena, Mikko, Noora, Aino, Olli)
- AI-generated outputs (proposals, invoices, content drafts, research notes)
- Approval/rejection decisions and edit history
- Agent run logs and performance metrics
2.3 Technical & Usage Data (collected automatically)
- IP address, browser type, operating system
- Device identifiers, session cookies
- Access logs, timestamps, pages visited, feature usage
- Error logs and diagnostic data
2.4 Integration Data (when you connect your own accounts)
- Gmail metadata: email addresses, thread subjects, send/receive timestamps
- QuickBooks data: invoice records, payment status
- Slack metadata: workspace ID, channel names (when Slack is connected)
- WhatsApp data: phone numbers, message content, contact lists (when WhatsApp integration is enabled)
- Calendar integrations (e.g. Google Calendar) are deferred until productized — this Policy will be updated before those integrations go live
Important: For these integrations, you retain control of your own accounts. We access this data only through OAuth authorization that you grant and can revoke at any time. We do not store full email bodies, calendar details, or Slack messages unless explicitly required for the AI function you request.
2.5 Payment Data
- Payment card details (processed by Stripe; we do not store full card numbers)
- Billing history, subscription tier, VAT identification number
- Invoice and receipt data
2.6 Customer Support Communications
When you contact us by email at info@datadiwan.com, support@datadiwan.com, or through other support channels, we collect:
- Your email address and name
- The content of your message and any attachments
- Metadata (timestamps, subject line, IP address if applicable)
This data is processed through our business email provider, Zoho Mail, and is used solely to respond to your inquiry and maintain a support history.
3. Legal Basis for Processing
| Purpose | Legal Basis | GDPR Article |
|---|---|---|
| Providing the Service (account management, AI agent operation, storage) | Contract performance | Art. 6(1)(b) |
| Billing and payment processing | Contract performance | Art. 6(1)(b) |
| Service improvement, debugging, security | Legitimate interest | Art. 6(1)(f) |
| Marketing communications (newsletters, product updates) | Consent | Art. 6(1)(a) |
| Legal compliance (accounting, tax, regulatory) | Legal obligation | Art. 6(1)(c) |
| AI model training and fine-tuning (anonymized/aggregated only) | Legitimate interest | Art. 6(1)(f) |
| Fraud prevention and platform security | Legitimate interest | Art. 6(1)(f) |
| Customer support communication | Contract performance / legitimate interest | Art. 6(1)(b) and (f) |
Note on AI Processing: AI-generated outputs are produced through automated processing. However, DataDiwan OS is designed as a decision-support tool: all customer-facing actions require your explicit approval. No AI agent sends emails, invoices, or publishes content without human review. This means DataDiwan OS does not make solely automated decisions with legal or similarly significant effects on you or your clients within the meaning of GDPR Article 22.
4. How We Use AI and Automated Processing
4.1 AI System Transparency (AI Act Compliance)
DataDiwan OS incorporates artificial intelligence systems ("AI Directors") that:
- Analyze your Company Memory and business data to draft proposals, content, invoices, and research
- Score leads and prospects against your Ideal Customer Profile
- Monitor project health and flag at-risk deliverables
You are informed that you are interacting with an AI system. Every AI-generated output is clearly labeled and requires your explicit approval before any external action is taken.
4.2 Human Oversight
Our architecture enforces human-in-the-loop approval for all customer-facing actions. You retain full control over:
- Whether to approve, edit, or reject any AI-generated proposal, invoice, or content
- Whether to promote a prospect to a sales lead
- Whether to schedule or publish any marketing content
- Final decisions on all business operations
4.3 Training Data
We do not use your personal data or confidential business data to train third-party foundation models (e.g., Google Gemini, Anthropic Claude) without your explicit consent. Any model training we conduct uses anonymized, aggregated data only.
5. Data Sharing and Recipients
5.1 Service Providers (Processors)
We engage carefully selected subprocessors who process data on our behalf under GDPR Article 28 data processing agreements:
| Subprocessor | Purpose | Location | Safeguards |
|---|---|---|---|
| Fly.io, Inc. | Application hosting (API + Agent Worker) | EU (Amsterdam) | GDPR Art. 28 DPA, EU SCCs |
| Vercel, Inc. | Web application hosting (Dashboard) | EU (Frankfurt) | GDPR Art. 28 DPA, EU SCCs |
| Supabase, Inc. | PostgreSQL database, authentication, RLS | EU (Frankfurt) | GDPR Art. 28 DPA, EU SCCs |
| Upstash, Inc. | Redis cache, message queue, rate limiting | EU (Frankfurt) | GDPR Art. 28 DPA, EU-based |
| Google Cloud / Vertex AI | AI model inference (production) | EU + USA | Google Cloud DPA, EU SCCs, data minimization |
| Anthropic PBC | AI model inference (development only) | USA | EU SCCs, development isolation |
| Stripe, Inc. | Payment processing, billing | USA | Stripe DPA (incorporated), EU SCCs, PCI-DSS |
| Google LLC | Authentication (Google Sign-In) | USA | Google API DPA, EU SCCs |
| Meta Platforms, Inc. | WhatsApp Cloud API messaging | USA | Meta Business Tools DPA, EU SCCs |
| Langfuse GmbH | LLM tracing, observability | Germany (EU) | GDPR Art. 28 DPA, EU-based |
| Zoho Corporation | Business email and customer support communications | EU (Ireland/Netherlands) | Zoho DPA (see Section 5.4) |
A current list of all subprocessors is available at https://app.datadiwan.com/en/subprocessors (or on request at support@datadiwan.com). Our Data Processing Agreement (DPA) governs processing of Customer Data on your behalf.
5.2 Legal Disclosures
We may disclose personal data if required by:
- Finnish or EU law, court order, or regulatory request
- Enforcement of our Terms of Service
- Protection of our rights, property, or safety
5.3 Business Transfers
In the event of a merger, acquisition, or asset sale, personal data may be transferred subject to the same privacy commitments.
6. International Data Transfers
Your personal data is primarily stored and processed within the European Economic Area (EEA). Where we transfer data outside the EEA (e.g., to LLM providers, payment processors, or authentication services in the USA), we ensure appropriate safeguards are in place:
- EU Commission Standard Contractual Clauses (SCCs) with additional technical and organizational measures
- Transfers to countries with an EU adequacy decision
- Data minimization for transfers (only necessary data is sent to LLM APIs)
- EU-region hosting for core infrastructure (database, cache, application hosting)
7. Data Retention
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Account data | Until account deletion + 1 year | Contract / legal hold |
| AI-generated outputs (proposals, content) | Until account deletion, or as long as you maintain them | Contract |
| Billing and invoice data | 10 years | Finnish Accounting Act (Kirjanpitolaki) |
| Server logs | 90 days | Legitimate interest (security) |
| Marketing consent records | Until consent is withdrawn + 2 years | Legal obligation |
| Deleted account data | 30 days after deletion request | GDPR Art. 17 |
| LLM tracing data (Langfuse) | 90 days | Legitimate interest (debugging) |
| Customer support emails | 2 years after resolution | Legitimate interest (support quality, dispute resolution) |
Note on conflicting obligations: While GDPR grants you the right to erasure (Art. 17), Finnish accounting and tax laws require certain financial records to be retained for 10 years. In such cases, we will restrict processing (e.g., archive and isolate the data) rather than delete it, and erase the data immediately after the statutory retention period expires.
8. Your Rights Under GDPR
As a data subject, you have the following rights:
1. Right of access (Art. 15) — Request a copy of your personal data
2. Right to rectification (Art. 16) — Correct inaccurate or incomplete data
3. Right to erasure ("right to be forgotten", Art. 17) — Request deletion, subject to legal retention obligations
4. Right to restrict processing (Art. 18) — Limit how we use your data
5. Right to data portability (Art. 20) — Receive your data in a structured, machine-readable format
6. Right to object (Art. 21) — Object to processing based on legitimate interests or direct marketing
7. Right to withdraw consent — At any time, without affecting prior lawful processing
8. Right to lodge a complaint — With the Finnish Data Protection Ombudsman or your local supervisory authority
To exercise your rights, contact us at support@datadiwan.com. We respond within 30 days. We may need to verify your identity before processing your request.
9. Security Measures
We implement appropriate technical and organizational measures to protect your data:
- Encryption at rest (AES-256) and in transit (TLS 1.3)
- Row-level security (RLS) in PostgreSQL for tenant isolation
- Role-based access controls and OAuth 2.0 authentication
- Regular security assessments and dependency audits
- Incident response plan with 72-hour breach notification capability (GDPR Art. 33)
- Backups with geographic redundancy
- Hash-chained audit logs (tamper-evident)
10. Cookies and Tracking Technologies
We use cookies and similar technologies. For detailed information, see our Cookie Policy.
You can manage cookie preferences through your browser settings.
11. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, contact us immediately for deletion.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in law, our practices, or the Service. Material changes will be notified via email or in-app notice at least 30 days before taking effect. The "Last updated" date at the top indicates the current version.
13. Contact Information
Data Controller:
DataDiwan
Pakkamestarinkatu 1 F 94
00520 Helsinki, Finland
Y-tunnus: 3641767-6
Email: support@datadiwan.com · info@datadiwan.com
We have not appointed a Data Protection Officer (DPO) as our processing activities do not meet the thresholds requiring one under GDPR Article 37.
Finnish Data Protection Ombudsman:
PL 800, 00531 Helsinki
Email: tietosuoja@om.fi
Phone: +358 29 56 66700