GDPR Compliance
This Privacy Policy is designed to comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws. Customers in the European Union and European Economic Area (EEA) have specific rights regarding their personal data.
Table of Contents
- 1. Information We Collect
- 2. How We Use Your Information
- 3. Data Sharing and Disclosure
- 4. Data Security Measures
- 5. Cookies and Tracking Technologies
- 6. Data Retention and Deletion
- 7. Your Data Rights (GDPR)
- 8. International Data Transfers
- 9. Children's Privacy
- 10. Changes to This Policy
- 11. Contact Information
1. Information We Collect
We collect the following types of information to provide and improve our services:
Personal Information:
- Name and contact details (email, phone)
- Business information (company name, address)
- Payment information (processed securely via PayPal/Stripe)
- Account credentials and access tokens
Service Usage Data:
- API calls and usage statistics
- Deployment configurations and settings
- Error logs and system diagnostics
- Support ticket communications
Technical Data:
- IP address and device information
- Browser type and operating system
- Referral URLs and browsing behavior
2. How We Use Your Information
We use your information for the following purposes:
- Service Provision: Deploy, configure, and maintain AI agent services
- Account Management: Create and manage customer accounts and subscriptions
- Payment Processing: Process payments and manage billing
- Support Services: Provide technical support and customer service
- System Maintenance: Monitor performance, troubleshoot issues, and maintain infrastructure
- Security: Detect and prevent fraudulent activity and security threats
- Legal Compliance: Comply with legal obligations and regulatory requirements
- Improvement: Analyze usage patterns to improve our services
3. Data Sharing and Disclosure
We DO NOT sell your personal data to third parties.
We may share your information with the following parties:
- Service Providers: OVH (VPS hosting), PayPal/Stripe (payments), OpenAI/Kimi/Anthropic (AI models) — as necessary to provide services
- Legal Requirements: When required by law, court order, or government request
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- Affiliates: With our affiliates for the purposes described in this policy
AI Model Providers:
Customer data sent to AI model providers (OpenAI, Kimi, Anthropic) is processed according to their respective privacy policies. We do not use customer data to train or fine-tune AI models unless explicitly authorized.
4. Data Security Measures
We implement industry-standard security measures to protect your data:
- Encryption: Data encrypted at rest and in transit using AES-256 and TLS 1.3
- Access Controls: Multi-factor authentication, role-based access, least-privilege principles
- Network Security: Firewalls, intrusion detection, regular security audits
- Payment Security: PCI DSS compliance via PayPal and Stripe
- Regular Updates: Security patches and system updates applied promptly
- Breach Notification: Customers notified within 72 hours of any data breach (as required by GDPR)
However, no system is completely secure. While we take reasonable measures to protect your data, we cannot guarantee absolute security.
5. Cookies and Tracking Technologies
We use cookies and similar technologies for:
- Essential Cookies: Required for site functionality and authentication
- Analytics Cookies: To analyze site usage and improve performance
- Preference Cookies: To remember user preferences and settings
- Marketing Cookies: With consent, for targeted advertising
You can manage cookie preferences through your browser settings. Disabling cookies may affect site functionality.
6. Data Retention and Deletion
Active Customers: Data retained for the duration of the service relationship.
Terminated Accounts: Customer data deleted within 30 days of service termination, unless legal obligations require longer retention.
Logs and Analytics: Retained for up to 12 months for security and troubleshooting purposes.
Customers can request data deletion at any time. We will delete all personal data within 30 days of receipt of a deletion request, subject to legal retention requirements.
7. Your Data Rights (GDPR)
Under GDPR, you have the following rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Request limitation of data processing
- Right to Data Portability: Receive your data in a structured format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
- Right to Lodge a Complaint: File a complaint with a data protection authority
To exercise these rights, contact us at privacy@desmonddigital.com. We will respond to your request within 30 days.
8. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence, including:
- United States (primary server location)
- European Union (EU VPS instances)
- Other countries where our service providers operate
When transferring data internationally, we implement appropriate safeguards (such as EU Standard Contractual Clauses) to protect your data in accordance with GDPR requirements.
9. Children's Privacy
Our services are not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If we discover that we have collected such information, we will delete it immediately.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@desmonddigital.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified by:
- Email notification to customers
- Prominent notice on our website
- In-app notification for active users
Continued use of our services after changes constitutes acceptance of the updated policy. We encourage customers to review this policy regularly.
11. Contact Information
For questions about this Privacy Policy, data requests, or to exercise your GDPR rights, please contact:
privacy@desmonddigital.com
Desmond Digital
Data Protection Officer
Delaware, United States
Response Time: We will acknowledge your request within 3 business days and provide a full response within 30 days.