Privacy Policy
Effective date: 1 June 2026 · Version 2026-06-01
This Privacy Policy describes how Dalea ApS (“Dalea”, “we”, “us”, or “our”), a company incorporated in Denmark, collects, uses, and protects your personal data when you use the Dalea platform (“Service”). This policy is provided in accordance with the EU General Data Protection Regulation (GDPR) and the Danish Data Protection Act (Databeskyttelsesloven).
1. Data Controller
Dalea ApS is the data controller for personal data processed through the Service.
Dalea ApS
Copenhagen, Denmark
Email: contact@dalea.tech
2. Personal Data We Collect
2.1 Account Data
When you register and use the Service, we collect:
- Full name
- Email address
- Password (stored as a salted hash, never in plaintext)
- Profile image (if provided)
- Organization and workspace membership
2.2 Authentication Data
To secure your account, we process:
- Session tokens and cookies
- Two-factor authentication secrets (encrypted)
- Passkey/WebAuthn credential identifiers
- OAuth tokens from connected providers (Google, Microsoft)
2.3 Usage and Technical Data
When you use the Service, we automatically collect:
- IP address
- Browser type and version (user agent)
- Actions performed within the Service (audit log)
- Timestamps of access and activity
- Device information
2.4 Customer Data
You and your Authorized Users may upload or create content within the Service, including documents, data tables, inventory records, files, and other materials. While this data may contain personal data, Dalea processes it only as a data processor on your behalf. See Section 8.
2.5 Payment Data
For paid subscriptions, payment processing is handled by our payment provider (Polar). We do not store credit card numbers or full payment details. We receive only a billing customer identifier and subscription status.
3. Purposes and Legal Bases
We process your personal data for the following purposes and legal bases under GDPR Article 6(1):
| Purpose | Legal Basis |
|---|---|
| Providing and operating the Service | Performance of contract (Art. 6(1)(b)) |
| Account creation and authentication | Performance of contract (Art. 6(1)(b)) |
| Sending transactional emails (verification, password reset) | Performance of contract (Art. 6(1)(b)) |
| Security monitoring and audit logging | Legitimate interest (Art. 6(1)(f)) |
| Abuse prevention and fraud detection (CAPTCHA) | Legitimate interest (Art. 6(1)(f)) |
| Billing and subscription management | Performance of contract (Art. 6(1)(b)) |
| Legal compliance (e.g., tax records, breach notification) | Legal obligation (Art. 6(1)(c)) |
| Recording consent for Terms of Service and Privacy Policy | Legitimate interest (Art. 6(1)(f)) |
4. Data Storage and Sovereignty
Core Customer Data is stored within the European Union on Dalea-managed application infrastructure supplied by Scaleway in France. Where AI features are enabled, selected prompts, context, content chunks and outputs are processed by Scaleway Generative APIs in Paris, France. The primary database and stored files remain in the core environment.
Some limited-purpose providers and optional features may process limited data outside the EU/EEA, as described below. Where required, international transfers are subject to a lawful GDPR Chapter V transfer mechanism. Customer-selected external connections may also cause data selected by you or your authorised users to be sent to the selected recipient.
5. Data Retention
- Account data: Retained for the duration of your account. Deleted within 30 days of account closure, except where retention is required by law.
- Audit logs: Retained for up to 2 years for security and compliance purposes.
- Session data: Automatically deleted upon expiration.
- Consent records: Retained for the duration of your account and up to 5 years after account closure to demonstrate compliance.
- Customer Data: Deleted within 30 days of account termination, unless you export it beforehand.
- Payment records: Retained as required by Danish tax law (typically 5 years).
6. Providers and Sub-processors
We use the following sub-processors to provide the core Service and enabled features:
| Sub-processor | Purpose | Location |
|---|---|---|
| Scaleway S.A.S. | Cloud infrastructure and, where enabled, Generative APIs for AI inference and embeddings | France (EU) |
| Plus Five Five, Inc. (Resend) | Transactional and notification email delivery | USA, subject to an applicable GDPR Chapter V transfer mechanism |
| Brave Software, Inc. (optional) | External web-search queries when that AI feature is enabled or invoked | USA; enabled for personal data only where a valid GDPR Chapter V transfer basis applies |
Optional sign-in, security, billing and customer-directed connection providers may process limited account, browser-security or customer-selected data. They do not receive stored research or laboratory Customer Data merely because they are configured:
| Provider | Limited purpose |
|---|---|
| Google OAuth | Optional federated sign-in selected by the user |
| Microsoft OAuth / Entra ID | Optional federated sign-in selected by the user |
| Cloudflare Turnstile | Optional bot and abuse protection on authentication pages |
| Polar Software, Inc. | Optional subscription checkout and billing as merchant of record |
| Customer-selected external providers | Optional BYOK AI providers, external MCP clients, import sources and URL retrieval selected or instructed by the customer |
We will notify you of any changes to our sub-processor list at least 30 days in advance.
7. Your Rights Under GDPR
As a data subject, you have the following rights under the GDPR:
- Right of access (Art. 15): You can request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): You can request correction of inaccurate personal data.
- Right to erasure (Art. 17): You can request deletion of your personal data, subject to legal retention requirements.
- Right to restriction (Art. 18): You can request restriction of processing in certain circumstances.
- Right to data portability (Art. 20): You can request your data in a structured, machine-readable format. The Service provides built-in export functionality.
- Right to object (Art. 21): You can object to processing based on legitimate interest.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at contact@dalea.tech. We will respond within 30 days.
8. Customer Data Processing
When you use the Service to store and process data that may contain personal data of third parties (e.g., research participant identifiers, patient codes), you act as the data controller for that data, and Dalea acts as the data processor. In such cases:
- We process Customer Data only according to your instructions and for the purpose of providing the Service.
- We do not access Customer Data except as necessary to operate the Service, provide support (with your consent), or comply with legal obligations.
- A Data Processing Agreement (DPA) governing our obligations as processor is available upon request.
9. Cookies and Tracking
The Service uses the following cookies:
- Session cookies (strictly necessary): Required for authentication and session management. These cannot be disabled as they are essential for the Service to function.
- CAPTCHA cookies (strictly necessary): Used by Cloudflare Turnstile for bot protection during registration and login.
We do not use analytics cookies, advertising cookies, or third-party tracking pixels. We do not share data with advertising networks.
10. Security Measures
We implement appropriate technical and organizational measures to protect personal data, including:
- Encryption in transit and protection of sensitive credentials where applicable
- Role-based access controls with row-level security
- Password hashing with modern algorithms
- Two-factor authentication and passkey support
- Audit logging of security-relevant events
- Monitoring and logging of security-relevant events
11. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the Danish Data Protection Authority (Datatilsynet) without undue delay and, where feasible, within 72 hours of becoming aware of the breach where required by GDPR Article 33.
- Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34).
12. Children’s Privacy
The Service is not intended for use by individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us and we will delete it promptly.
13. Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with:
Datatilsynet (Danish Data Protection Authority)
Carl Jacobsens Vej 35
2500 Valby, Denmark
Website: www.datatilsynet.dk
You may also lodge a complaint with the supervisory authority in your EU/EEA country of residence.
14. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days’ notice via email and in-app notification. The effective date at the top of this page indicates when the policy was last updated.
Contact
For questions about this Privacy Policy or to exercise your data rights, contact us at:
Dalea ApS
Copenhagen, Denmark
Email: contact@dalea.tech
See also our Terms of Service.