Privacy Policy
Last Updated: 15 July 2026 | Effective: 15 July 2026
1. Who We Are (Controller Identity)
Diliga ("Diliga", "we", "us", "our") is the data controller for personal data processed through this website and service. For all data protection enquiries, contact us at: privacy@diliga.io. We are not required to appoint a Data Protection Officer (DPO) at this stage as we are an SME that does not conduct large-scale systematic monitoring; however we voluntarily handle all data subject requests via the contact above.
2. What Personal Data We Collect and Why
| Data Category | Purpose | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Account email, name | Account creation and authentication | Art. 6(1)(b) — Contract performance |
| Company name, VAT/registration number, country, responsible person name and email | Pre-filling compliance documents you request us to generate | Art. 6(1)(b) — Contract performance |
| AI system description, use-case metadata, risk trigger answers | Classification and document generation core service | Art. 6(1)(b) — Contract performance |
| Payment status, order ID (not card data) | Billing reconciliation and access gating | Art. 6(1)(b) — Contract performance |
| IP address, browser type (anonymised analytics) | Aggregate product analytics (PrivacyAnalytics, EU-hosted) | Art. 6(1)(a) — Consent (via cookie banner) |
| Support ticket content | Resolving customer support requests | Art. 6(1)(b) — Contract performance |
| Audit log entries (action, timestamp, resource ID) | Security, fraud prevention, legal compliance | Art. 6(1)(f) — Legitimate interests |
3. AI Processing and Zero Training Policy
Our compliance document generation pipeline utilizes enterprise-grade Commercial Cloud AI Infrastructure Providers. All third-party API calls are executed under strict enterprise commercial agreements that explicitly prohibit model training on customer inputs or data retention beyond request execution.
Your company data and AI system details leave our servers solely to generate compliance documentation and are never stored or retained by third-party AI providers.
4. Data Sub-processors
We use the following sub-processors who may handle your personal data:
| Sub-processor Category | Purpose | Location | Safeguard |
|---|---|---|---|
| CloudDB Vault Infrastructure | Database, authentication, encrypted file storage | EU (eu-central) | DPA executed, SCCs |
| Commercial Cloud AI Engine Providers | Document generation & risk synthesis APIs | USA / EU | Commercial DPA, SCCs, Zero Data Retention & Training |
| Polar Infrastructure | Payment processing (Merchant of Record) | USA / EU | DPA with SCCs |
| MailDispatch Services | Transactional email (receipts, notifications) | USA / EU | DPA with SCCs |
| PrivacyAnalytics Services | Product analytics (EU cloud instance) | EU (eu-cloud) | EU-hosted, consent-gated |
| EdgeCloud Hosting Platform | Web hosting and CDN (edge functions) | USA / EU | DPA with SCCs, EU deployment |
We will notify you of any material changes to this sub-processor list with at least 10 days notice via email before the new sub-processor begins processing your data.
5. Data Retention
- Account data and documents: Retained for the duration of your account plus 30 days after deletion request (to allow recovery if deletion was accidental).
- Audit logs: 365 days, then automatically purged.
- Analytics events: 30 days, then automatically purged.
- Payment records: 7 years (legal requirement for financial records under EU law).
- Support tickets: 2 years after resolution.
6. Your Rights Under GDPR (Articles 15–22)
You have the following rights. To exercise any of them, email privacy@diliga.io with "Data Subject Request" in the subject line. We will respond within 30 days.
- Right of access (Art. 15): Request a copy of all personal data we hold about you.
- Right to rectification (Art. 16): Ask us to correct inaccurate data.
- Right to erasure (Art. 17): Request deletion of your account and all associated data (subject to legal retention obligations above).
- Right to restriction (Art. 18): Request we limit processing while a dispute is resolved.
- Right to data portability (Art. 20): Request your data in a machine-readable format (JSON or CSV).
- Right to object (Art. 21): Object to processing based on legitimate interests (e.g., analytics).
- Right not to be subject to automated decisions (Art. 22): Diliga's risk classification engine produces advisory outputs only — no automated decisions with legal effects are made about you.
If you believe we have mishandled your data, you have the right to lodge a complaint with your national supervisory authority (e.g., ICO in the UK, CNIL in France, BfDI in Germany).
7. Payment Processing
All payments are processed by Polar acting as Merchant of Record. Diliga never receives, stores, or processes raw card numbers, CVV codes, or bank account details. Payment data is subject to Polar's own privacy policy and PCI DSS compliance.
8. Cookies and Analytics
We use:
- Strictly necessary cookies: CloudDB Vault session authentication (no consent required).
- Analytics cookies (PrivacyAnalytics): Only set after you accept cookies via our consent banner. You can withdraw consent at any time by clicking "Cookie Settings" in the footer.
9. International Data Transfers
Where personal data is transferred to processing regions outside the EEA/UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914) and commercial DPAs as the transfer mechanism. Copies of applicable SCCs are available on request.
10. Changes to This Policy
We will notify registered users by email at least 14 days before any material changes to this policy take effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.
11. Contact
Data protection enquiries: privacy@diliga.io
General: hello@diliga.io

