Legal

Privacy Policy

Last updated: 24 August 2026

1. Who we are

[Company Legal Name] of [Registered Address], operating the Digital Asset Intelligence platform ("DAI", "we", "us"), is the data controller for personal data processed through daiintelligence.com and related services. Paddle acts as an independent controller and Merchant of Record for transaction data, as set out in section 4.

2. Personal data we collect

  • Account data — name, work email address, authentication credentials or OAuth identifier, organisation and role where you provide them, subscription tier, and team membership.
  • Payment-related data — subscription status, plan, renewal date, and a Paddle customer/subscription identifier. We do not collect or store card numbers, bank details, or billing addresses; these are handled by Paddle.
  • Product usage data — the jurisdictions in your footprint, topic and jurisdiction alert preferences, saved items, folders, private notes you write, search queries, exports generated, and contributions or suggested edits you submit.
  • Communications data — messages sent through the contact form, newsletter and alert subscription records, and email delivery/engagement events (sent, delivered, bounced, unsubscribed).
  • Technical and analytics data — IP address, browser and device type, pages viewed, referrer, approximate location derived from IP, and error logs.

3. How we use data, and the legal basis

  • Provide the service — authenticate you, render the live feed, operate saved items, notes, search, and export. Legal basis: performance of a contract.
  • Personalise your jurisdiction dashboard — surface items matching your selected jurisdictions and topics, and count what is new since your last visit. Legal basis: performance of a contract.
  • Send alerts and briefings — deliver the regulatory digests you have subscribed to and apply frequency throttling. Legal basis: performance of a contract; consent for the public newsletter.
  • Administer subscriptions — reconcile Paddle subscription events with your tier and entitlements. Legal basis: performance of a contract.
  • Support — respond to enquiries submitted through the contact form. Legal basis: performance of a contract; legitimate interests.
  • Improve coverage and product quality — analyse aggregated usage of jurisdictions, filters, and search to prioritise sources and features. Legal basis: legitimate interests in improving the service.
  • Security, abuse prevention, and service integrity — detect credential sharing, scraping, and fraudulent transactions. Legal basis: legitimate interests.
  • Legal, tax, and accounting compliance. Legal basis: legal obligation.

We do not sell personal data, and we do not use your private notes, saved items, or search queries to build advertising profiles or to train third-party models on your identifiable content.

4. Paddle as payment processor and Merchant of Record

All payments are processed by Paddle.com Market Limited, which acts as the Merchant of Record for our sales. When you subscribe, Paddle collects and processes your payment method, billing address, tax identifiers, and transaction history in order to take payment, calculate and remit sales tax/VAT/GST, issue invoices, and handle chargebacks and refunds. Paddle is an independent controller for that data and processes it under its own privacy policy. We receive from Paddle only the subscription status, plan, renewal dates, and customer identifier needed to grant and maintain your access.

5. Who else we share data with

  • Cloud hosting and database providers — application hosting, authentication, and data storage.
  • Email delivery provider — transactional email, alerts, and briefings sent from notify.daiintelligence.com.
  • AI processing providers — used to summarise and classify public regulatory source material and to generate impact analysis. Account identifiers are not required for, and are not sent as part of, this processing.
  • Analytics and error monitoring — aggregated usage measurement and diagnostics.
  • Professional advisers — legal, accounting, and audit advisers under confidentiality obligations.
  • Authorities — where required by law or to establish or defend legal claims.

These providers act as processors under written data-processing terms, except Paddle as noted above.

6. International transfers

Our providers may process data outside the UK and EEA, including in the United States. Where that happens we rely on UK/EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision.

7. Retention

  • Account data — kept while your account is open, and for 12 months after cancellation so you can reactivate without losing your workspace.
  • Saved items, folders, and private notes — retained for 30 days after account deletion is requested, then permanently deleted; deleted immediately on explicit request.
  • Usage and analytics data — retained in identifiable form for 14 months, then aggregated or deleted.
  • Alert and email delivery logs — 24 months, for deliverability and suppression management.
  • Support and contact form messages — 24 months from last correspondence.
  • Transaction and tax records — retained by Paddle and by us for the period required by tax law, typically 6–7 years.

8. Your rights (UK/EU GDPR)

You have the right to:

  • access the personal data we hold about you;
  • have inaccurate or incomplete data corrected;
  • have your data erased where it is no longer needed or where processing relies on consent;
  • restrict or object to processing based on legitimate interests;
  • receive your data in a portable, machine-readable format — saved items and notes can also be exported directly from the platform;
  • withdraw consent to marketing at any time, including via the unsubscribe link in every email;
  • lodge a complaint with your supervisory authority.

To exercise any of these rights, email privacy@daiintelligence.com from the address on your account. We verify requests and respond within one month, which may be extended by two further months for complex requests.

9. California residents (CCPA/CPRA)

If you are a California resident, you may request disclosure of the categories and specific pieces of personal information we have collected, request deletion or correction, and are entitled not to be discriminated against for exercising those rights. We do not sell personal information and do not share it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA. Submit requests to privacy@daiintelligence.com; an authorised agent may act on your behalf with written proof of authorisation.

10. Cookies

We use strictly necessary cookies for authentication, session persistence, and security — these cannot be disabled without breaking sign-in. We use analytics cookies and equivalent local storage to measure page and feature usage in aggregate. We do not use advertising or cross-site tracking cookies. You can clear or block cookies in your browser settings; blocking necessary cookies will prevent you from signing in.

11. Security

Data is encrypted in transit, access to production systems is restricted on a least-privilege basis, and row-level access controls scope each account's saved items, notes, and preferences to that account. No system is perfectly secure; report suspected vulnerabilities to privacy@daiintelligence.com.

12. Contact

Privacy enquiries: privacy@daiintelligence.com or [Registered Address]. General enquiries go through our contact form.

See also our Terms of Service and Refund Policy.