Privacy Policy

Version 1.0 (pre-launch) · Effective date: [date] · Contact: sales@datumos.ai

This Privacy Policy explains how [COMPANY LEGAL NAME] (the "Provider", "we") processes personal data of visitors to datumos.ai, of people who contact us, of the customer representatives who contract for and administer DatumOS, and of people whose data is processed inside customer Instances. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR) and applicable national law.

1. Who we are and how to reach us

The controller for the processing described in sections 3 to 5 is [COMPANY LEGAL NAME], [REGISTERED ADDRESS], [REGISTRATION NUMBER]. You can reach us at sales@datumos.ai until a dedicated privacy address is published. [If appointed: Our data protection officer can be reached at [DPO CONTACT].]

2. Two roles: controller and processor

We act as controller for data about our website visitors, prospects, customers' contract and billing contacts and Organisation administrators (sections 3 to 5). We act as processor on behalf of our customers for personal data inside their DatumOS Instances: the cases, sessions, attachments and content the agent reads from the systems the customer connects (section 6). For that data the customer is the controller and the Data Processing Agreement applies. If you are an employee, customer or contact of one of our customers and have questions about data inside their Instance, please contact that organisation first; we will support them in answering you.

3. What we process as controller, and why

CategoryDataPurposeLegal basis (GDPR)Retention
Website visitorsIP address, user agent, requested pages, timestamps, referrer, in server and CDN access logsServing the site, security, abuse and fault diagnosisArt. 6(1)(f), legitimate interest in a secure, working websiteUp to 30 days in logs
EnquiriesName, e-mail address, organisation, role, the content of your message and our correspondenceAnswering your enquiry, preparing an offer, onboardingArt. 6(1)(b), steps prior to a contract at your request; Art. 6(1)(f) for follow-up on a business enquiryUntil the enquiry is closed and for 24 months afterwards, unless a contract follows
Customer contactsNames, business contact details and roles of the persons who sign, administer or receive invoices for a customer's contract; correspondence; support ticketsPerforming the contract, support, billing, notices about the ServiceArt. 6(1)(b); Art. 6(1)(c) for accounting records; Art. 6(1)(f) for service noticesFor the term of the contract and for the retention period required by tax and accounting law (typically 5 to 10 years for invoices)
Organisation administrators and usersIdentity attributes received from the customer's identity provider (name, e-mail address, group memberships used for roles), sign-in events, actions taken in the administration panelAuthenticating users, enforcing roles, audit trails, securityArt. 6(1)(b) towards the customer; Art. 6(1)(f), the customer's and our interest in secure, auditable operationFor the life of the Instance and the export window; audit logs up to 12 months after
Operational telemetryTechnical metrics about Instances (run counts, durations, error rates, feature usage) tied to the Instance, not to named usersOperating, securing and improving the Service; capacity planningArt. 6(1)(f), legitimate interest in running a reliable serviceAggregated after 13 months

We do not sell personal data and we do not use personal data for automated decisions that produce legal or similarly significant effects on you.

4. Cookies and similar technologies on datumos.ai

When you first visit datumos.ai a cookie banner asks for your choice. Cookies are grouped in three categories and only the first is used without consent:

You can change or withdraw your choice at any time under “Cookie settings” in the footer of every page; withdrawing consent removes the cookies of that category. Google Consent Mode signals are kept in line with your choice. Fonts may be loaded from Google Fonts, in which case Google receives your IP address and browser details when the font files are requested; see Google's privacy policy for its processing. Customer Instances set a session cookie needed for sign-in; its use is described to users inside the Instance.

5. Recipients of data we process as controller

We share personal data only with service providers that process it on our behalf under contract: Amazon Web Services (hosting, EU region), Microsoft (e-mail and productivity tools we use internally), Google Ireland Ltd. (Google Analytics 4, only for visitors who accepted analytics cookies), our payment processor where card payments are used, and our accounting and legal advisers where required. Public authorities receive data only where the law requires it.

6. Data inside customer Instances (we are the processor)

Each customer has its own DatumOS Instance with its own database, storage and encryption key, hosted on AWS in the EU unless the customer has chosen another AWS region. Inside the Instance the agent processes the content the customer gives it access to: cases, conversations in connected channels (for example Microsoft Teams, Outlook, GitHub, Jira, Salesforce), documents in knowledge bases and data from connected systems. This content frequently contains personal data of the customer's employees, customers and contacts.

We process that data only on the customer's documented instructions, as set out in the Data Processing Agreement. In particular: prompts and outputs are sent to the large-language-model provider the customer has selected and licensed (currently Anthropic or OpenAI), under the customer's own agreement with that provider; the customer decides per Space which providers may process its data; connector credentials are stored in an encrypted vault and made available to the agent only through pre-authorised tools; the agent runs in isolated execution environments; and we do not use Instance data to train models. When a contract ends, the customer can export its data during the export window, after which we destroy the Instance and its key.

7. Sub-processors

Our current sub-processors for customer Instances are listed in the Data Processing Agreement: Amazon Web Services EMEA SARL (hosting), Microsoft Ireland Operations Ltd. (Teams bot messaging relay where the customer uses the Teams channel), and, only where the customer uses model access issued through us rather than its own key, Anthropic and OpenAI. We notify customers of changes as described there.

8. International transfers

We host in the European Union. Where a recipient outside the EU/EEA is involved (for example a model provider established in the United States, or a support case handled by a provider's non-EU staff), we rely on an adequacy decision of the European Commission where one exists, including the EU-US Data Privacy Framework for certified recipients, or on the European Commission's Standard Contractual Clauses with supplementary measures. Copies of the relevant safeguards are available on request.

9. Security

We protect personal data with measures appropriate to the risk, including: one Instance per customer with no shared databases; encryption in transit (TLS) and at rest with a key per customer; access to production limited to named personnel with multi-factor authentication and logged; isolated execution environments for the agent; a credentials vault; regular backups; and monitoring for abuse and faults. Details for customers are in the Data Processing Agreement.

10. Your rights

Under the GDPR you have the right to access your personal data, to have it rectified or erased, to restrict or object to its processing, to receive it in a portable format where processing is based on contract or consent, and to withdraw consent at any time where processing is based on consent. To exercise these rights, write to sales@datumos.ai. We respond within one month, extendable by two months for complex requests, and may ask you to verify your identity. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your residence, workplace or the place of the alleged infringement; our lead authority is [SUPERVISORY AUTHORITY OF THE PROVIDER'S SEAT]. Where we act as processor, we will forward your request to the customer that controls the data.

11. Children

The Service is intended for business use by organisations and is not directed at children. We do not knowingly collect personal data of children under 16.

12. Changes to this policy

We update this policy when our processing or the law changes. The effective date at the top shows the current version. For material changes affecting customers we give notice by e-mail to Organisation administrators at least 30 days in advance. Earlier versions are available on request.