D-DAO

Legal

Privacy Policy

This Policy explains what information D-DAO collects, why we use it, when we disclose it, and the choices available to you.

Effective: August 23, 2026

1. Scope and controller

This Privacy Policy explains how D-DAO Technology Inc. (“D-DAO,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information through our websites, inquiries, accounts, cloud services, and related business interactions. D-DAO Technology Inc. is a California corporation located in California, United States.

A customer may separately control personal information contained in workloads or Customer Content processed through our Services. In that context, the customer’s instructions and any applicable Data Processing Addendum govern our processing.

2. Information we collect

  • Contact and professional information, such as name, business email, company, country, role, and inquiry details.
  • Account information, such as verified email, display name, account identifiers, settings, and consent records.
  • Commercial information, such as orders, subscriptions, invoices, usage, payments, support history, and service communications.
  • Technical and security information, such as IP address, device and browser type, timestamps, logs, authentication events, diagnostics, and security signals.
  • Service content and configuration that customers submit or direct us to process in order to provide the Services.

3. How we collect information

We collect information directly from you, automatically when you use our websites or Services, from your organization or authorized users, from service providers supporting our operations, and from public or commercially available sources when appropriate for business verification, security, and compliance.

4. How we use information

  • Provide, operate, support, secure, and improve the Services.
  • Respond to inquiries, prepare proposals, manage customer relationships, and send requested communications.
  • Create and administer accounts, subscriptions, usage records, billing, and customer support.
  • Detect fraud, abuse, security incidents, prohibited activity, and violations of our agreements.
  • Comply with legal, tax, sanctions, export-control, and regulatory obligations and enforce our rights.
  • Send marketing communications only where permitted and consistent with your choices.

5. Website analytics

We use Vercel Web Analytics to understand page views, referral sources, general location, device, browser, and site interactions. Vercel Web Analytics is designed to provide aggregated analytics without cookies and uses a daily-resetting hash rather than a persistent cross-site identifier. We do not include contact-form fields, email addresses, or Customer Content in analytics events.

6. Contact inquiries

When you submit our contact form, we use your name, company, business email, country, area of interest, and project details to respond and manage the relationship. The submission is sent to HubSpot for customer relationship management, and Microsoft 365 is used to notify our team and send an acknowledgment to you.

7. How we disclose information

We do not sell personal information. We may disclose information to vendors and subprocessors that provide hosting, analytics, customer relationship management, communications, identity, payment, support, security, and professional services; to your organization and its authorized users; in a business transaction; or when required to comply with law, protect rights and safety, investigate abuse, or enforce agreements.

Service providers may process information only for contracted purposes and subject to appropriate obligations. We may disclose aggregated or de-identified information that cannot reasonably identify an individual.

8. Customer Content and model training

We process Customer Content to provide, maintain, secure, and support the Services and as instructed by the customer. We do not use Customer Content to train shared models without the customer’s explicit written consent. Customers are responsible for the legal basis and notices required for personal information they submit to the Services.

9. Retention

We generally retain ordinary sales inquiries for 24 months. If an inquiry develops into a customer or partner relationship, we may retain relevant information for the relationship and for a reasonable period afterward. Account, contract, billing, tax, security, and support records are retained as needed for operational, legal, audit, and dispute-resolution purposes.

After service termination, Customer Content is ordinarily available for export for 30 days and is then deleted or de-identified according to applicable agreements and backup cycles. We may retain information longer when required by law, a legal hold, security investigation, payment dispute, or other legitimate obligation.

10. Your choices and rights

Depending on your location, you may have rights to request access, correction, deletion, portability, restriction, or objection, and to appeal a decision about a privacy request. You may opt out of marketing email using the unsubscribe option or by contacting us. Transactional, security, inquiry-response, and service messages are not marketing subscriptions.

To submit a request, email privacy@d-dao.ai. We may verify your identity and authority before acting. Authorized agents may submit requests where permitted by law. We will not discriminate against you for exercising applicable privacy rights.

11. California disclosures

California residents may have rights under applicable California privacy laws. The categories of personal information we may collect are described in Section 2; the business purposes and disclosures are described in Sections 4 and 7. We do not sell personal information. If our practices change in a way that constitutes selling or sharing under applicable law, we will provide the required notice and choices.

California’s “Shine the Light” law may allow certain residents to request information about disclosures for third parties’ direct-marketing purposes. We do not disclose personal information to third parties for their own direct marketing in exchange for money.

12. International processing

D-DAO and its service providers may process and store information in the United States and other locations where they operate. Where required, we use appropriate transfer mechanisms and contractual protections for cross-border processing.

13. Security

We use administrative, technical, and physical safeguards designed to protect personal information. No system is completely secure, and we cannot guarantee absolute security. You are responsible for protecting credentials and promptly reporting suspected unauthorized access.

14. Children

The Services are not directed to individuals under 18, and we do not knowingly collect their personal information. If you believe a minor has provided personal information, contact privacy@d-dao.ai.

15. Changes to this Policy

We may update this Policy and will post the revised effective date. We will provide appropriate notice of material changes and request renewed consent where required.

16. Contact us

For privacy questions or requests, email privacy@d-dao.ai. For legal inquiries, email legal@d-dao.ai.