Data Protection

Privacy Policy

Last Updated: 15 July 2026 | Effective: 15 July 2026

1. Who We Are (Controller Identity)

Diliga ("Diliga", "we", "us", "our") is the data controller for personal data processed through this website and service. For all data protection enquiries, contact us at: privacy@diliga.io. We are not required to appoint a Data Protection Officer (DPO) at this stage as we are an SME that does not conduct large-scale systematic monitoring; however we voluntarily handle all data subject requests via the contact above.

2. What Personal Data We Collect and Why

Data CategoryPurposeLegal Basis (GDPR Art. 6)
Account email, nameAccount creation and authenticationArt. 6(1)(b) — Contract performance
Company name, VAT/registration number, country, responsible person name and emailPre-filling compliance documents you request us to generateArt. 6(1)(b) — Contract performance
AI system description, use-case metadata, risk trigger answersClassification and document generation core serviceArt. 6(1)(b) — Contract performance
Payment status, order ID (not card data)Billing reconciliation and access gatingArt. 6(1)(b) — Contract performance
IP address, browser type (anonymised analytics)Aggregate product analytics (PrivacyAnalytics, EU-hosted)Art. 6(1)(a) — Consent (via cookie banner)
Support ticket contentResolving customer support requestsArt. 6(1)(b) — Contract performance
Audit log entries (action, timestamp, resource ID)Security, fraud prevention, legal complianceArt. 6(1)(f) — Legitimate interests

3. AI Processing and Zero Training Policy

Zero Training Commitment: None of the company data, AI system descriptions, or personal data you submit to Diliga is used to train AI models by us or our AI providers. All third-party AI API calls are made under commercial data processing agreements (DPAs) that explicitly prohibit training on customer inputs.

Our compliance document generation pipeline utilizes enterprise-grade Commercial Cloud AI Infrastructure Providers. All third-party API calls are executed under strict enterprise commercial agreements that explicitly prohibit model training on customer inputs or data retention beyond request execution.

Your company data and AI system details leave our servers solely to generate compliance documentation and are never stored or retained by third-party AI providers.

4. Data Sub-processors

We use the following sub-processors who may handle your personal data:

Sub-processor CategoryPurposeLocationSafeguard
CloudDB Vault InfrastructureDatabase, authentication, encrypted file storageEU (eu-central)DPA executed, SCCs
Commercial Cloud AI Engine ProvidersDocument generation & risk synthesis APIsUSA / EUCommercial DPA, SCCs, Zero Data Retention & Training
Polar InfrastructurePayment processing (Merchant of Record)USA / EUDPA with SCCs
MailDispatch ServicesTransactional email (receipts, notifications)USA / EUDPA with SCCs
PrivacyAnalytics ServicesProduct analytics (EU cloud instance)EU (eu-cloud)EU-hosted, consent-gated
EdgeCloud Hosting PlatformWeb hosting and CDN (edge functions)USA / EUDPA with SCCs, EU deployment

We will notify you of any material changes to this sub-processor list with at least 10 days notice via email before the new sub-processor begins processing your data.

5. Data Retention

  • Account data and documents: Retained for the duration of your account plus 30 days after deletion request (to allow recovery if deletion was accidental).
  • Audit logs: 365 days, then automatically purged.
  • Analytics events: 30 days, then automatically purged.
  • Payment records: 7 years (legal requirement for financial records under EU law).
  • Support tickets: 2 years after resolution.

6. Your Rights Under GDPR (Articles 15–22)

You have the following rights. To exercise any of them, email privacy@diliga.io with "Data Subject Request" in the subject line. We will respond within 30 days.

  • Right of access (Art. 15): Request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16): Ask us to correct inaccurate data.
  • Right to erasure (Art. 17): Request deletion of your account and all associated data (subject to legal retention obligations above).
  • Right to restriction (Art. 18): Request we limit processing while a dispute is resolved.
  • Right to data portability (Art. 20): Request your data in a machine-readable format (JSON or CSV).
  • Right to object (Art. 21): Object to processing based on legitimate interests (e.g., analytics).
  • Right not to be subject to automated decisions (Art. 22): Diliga's risk classification engine produces advisory outputs only — no automated decisions with legal effects are made about you.

If you believe we have mishandled your data, you have the right to lodge a complaint with your national supervisory authority (e.g., ICO in the UK, CNIL in France, BfDI in Germany).

7. Payment Processing

All payments are processed by Polar acting as Merchant of Record. Diliga never receives, stores, or processes raw card numbers, CVV codes, or bank account details. Payment data is subject to Polar's own privacy policy and PCI DSS compliance.

8. Cookies and Analytics

We use:

  • Strictly necessary cookies: CloudDB Vault session authentication (no consent required).
  • Analytics cookies (PrivacyAnalytics): Only set after you accept cookies via our consent banner. You can withdraw consent at any time by clicking "Cookie Settings" in the footer.

9. International Data Transfers

Where personal data is transferred to processing regions outside the EEA/UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914) and commercial DPAs as the transfer mechanism. Copies of applicable SCCs are available on request.

10. Changes to This Policy

We will notify registered users by email at least 14 days before any material changes to this policy take effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.

11. Contact

Data protection enquiries: privacy@diliga.io
General: hello@diliga.io