dAItagrid Privacy Policy
Effective date: 10-30-2025
Who we are: dAItagrid, Inc. (“dAItagrid”, “we”, “us”, “our”)
Contact: info@daitagrid.com • Attn: Privacy • 2609 Technology Drive, Suite 124, Plano, TX 74074.
This Privacy Policy explains how we collect, use, share, and protect information when you visit daitagrid.com, interact with our content and downloads, or use our products and services, including pilots and evaluations (together, the “Services”).
1) Scope & Roles
- Website Data (Controller): When you browse our site, download public-safe resources, subscribe, or contact us, we act as a data controller of your personal data.
- Customer Content & Service Data (Processor): When we host or process data on your behalf (e.g., pilot nodes, telemetry you enable, support artifacts), we act as a data processor to your organization (the Controller). Our processing is governed by a Data Processing Addendum (DPA) and, where applicable, Standard Contractual Clauses (SCCs).
2) Key Definitions
- Personal Data / Personal Information (PI): Any info that identifies or can reasonably identify a person.
- Customer Content: Data, files, configurations, metrics, or other content you or your org provide or generate through the Services.
- Service Data: Operational data about the Services (e.g., uptime, performance metrics, node health, security logs) that may occasionally include limited personal data (e.g., admin IDs).
- Website Data: Contact details, form submissions, cookie/analytics data, and marketing preferences collected on our site.
3) What We Collect
A) Data you provide
- Contact & account: name, email, phone, company, role, password(s) or SSO identifiers.
- Inquiries & support: messages, tickets, attachments, meeting recordings (if you consent).
- Events & downloads: registration details, interests, resource download history.
- Contracts: NDAs, DPAs, statements of work.
B) Data collected automatically (website & admin consoles)
- Device/usage: IP address, approximate location, device IDs, browser/OS, pages viewed, referring pages, timestamps.
- Cookies & similar tech: session cookies, preference cookies, and analytics (see Cookie Notice).
- Security logs: auth events, admin actions, anomaly alerts.
C) Service Data (deployments/pilots)
- Telemetry you enable: node health, performance, orchestration events, error logs.
- Configuration metadata: cluster/ node IDs, versions, policy states.
(You control whether personal data enters Service Data; default posture is to avoid personal data in telemetry.)
D) Data from third parties
- Identity providers (SSO), payment processors, event platforms, referral partners, and publicly available sources (e.g., business profiles).
4) How We Use Data (Purposes & Legal Bases)
- Provide & secure Services (contract; legitimate interests): account setup, authentication, support, fraud prevention, security monitoring, incident response.
- R&D & product improvement (legitimate interests): diagnostics, performance, feature development, de-identified analytics.
- Communications (contract; consent/opt-out): service notices, security alerts, onboarding, product updates.
- Marketing (consent/opt-out; legitimate interests): newsletters, event invites, public-safe content; you can unsubscribe anytime.
- Compliance & enforcement (legal obligation; legitimate interests): records, auditing, responding to lawful requests.
- With consent: where required (e.g., certain cookies, call recordings, testimonials).
For EEA/UK/Swiss users, we rely on the legal bases noted above; contact us to see our balancing tests for legitimate interests.
5) NDA, Confidential Resources & Gated Content
Some non-public materials (e.g., technical packets, detailed security architecture, performance numbers, pricing, partner information) are available only under NDA or gated terms. By requesting/receiving gated materials, you (and your organization) agree to:
- Use them solely to evaluate dAItagrid.
- Not disclose them to third parties without our prior written consent.
- Protect them with at least the same care you use for your own confidential information.
- Return or destroy them upon request or at the end of evaluation.
(These terms supplement, not replace, any separately signed NDA; the stricter terms will apply.)
Public downloads on our site are labeled “Public-Safe Version” and exclude sensitive details.
6) Sharing & Disclosures
We do not sell personal data and we do not share it for cross-context behavioral advertising.
We may share information with:
- Service providers/sub-processors: cloud hosting, security, analytics, communications, and support tooling—bound by contract to use data only on our instructions. A current list is available upon request.
- Affiliates & corporate transactions: in connection with mergers, acquisitions, financing, or sale of assets (commitments transfer accordingly).
- Professional advisors: lawyers, accountants, auditors under confidentiality.
- Legal & safety: to comply with law, enforce agreements, protect rights, security, users, or the public.
7) Data Retention
We keep Website Data and Service Data only as long as needed for the purposes above, to comply with legal obligations, or to resolve disputes. Customer Content is retained per your instructions and our DPA. When no longer needed, we delete or de-identify data.
8) Security (Overview)
We implement technical and organizational measures appropriate to risk, including:
- Zero-trust principles; hardware-backed identity and remote attestation for nodes.
- Encryption in transit and at rest, key management, signed updates, and SBOM hygiene.
- Segmentation/least privilege, audit logging, vulnerability management, and incident response.
A detailed Trust & Security Packet is available under NDA.
9) International Transfers
We operate globally. Where personal data is transferred internationally (e.g., to the US), we use appropriate safeguards such as SCCs for EEA/UK/Swiss data and enter DPAs with processors.
10) Your Rights & Choices
Depending on your location, you may have the right to access, correct, delete, port, or restrict/opt-out of certain processing.
- EEA/UK/Swiss: GDPR/UK GDPR rights + right to object to processing based on legitimate interests; right to lodge a complaint with your supervisory authority.
- US (CA/CO/CT/VA/UT/etc.): right to know/access, delete, correct, opt-out of targeted advertising and certain profiling; we do not sell or share PI under CPRA.
- How to exercise: email info@daitagrid.com. We may verify your request and, where allowed, act on your authorized agent’s request.
- Appeals (VA/CO/CT): If we deny your request, you may appeal by replying “Appeal” to our decision email.
Marketing: unsubscribe anytime via the link in emails or by emailing us.
Cookies: manage via our cookie banner or browser settings (see Cookie Notice).
11) Children’s Privacy
Our Services are not directed to children under 16 (or as otherwise defined by local law). We do not knowingly collect personal data from children.
12) Third-Party Links
Our site may link to third-party sites or services. Their privacy practices are governed by their own policies.
13) Changes to this Policy
We may update this Policy from time to time. We’ll post the updated version and revise the effective date. Material changes will be highlighted or notified where required.
14) Contact Us
Questions or requests: info@daitagrid.com
Security researchers: info@daitagrid.com (PGP available on request)
Appendix A – California (CPRA) Disclosures
Categories collected (may vary by user): identifiers (name, email, IP), commercial info (download history), internet activity (usage, analytics), geolocation (approximate), professional info (company/role), inferences (product interest).
Sensitive PI: we do not seek to collect sensitive PI on the website. If sensitive data is processed in Customer Content, it is under your direction as Controller.
Sale/Share: We do not sell or share personal information for cross-context behavioral advertising.
Retention: see Section 7.
Appendix B – Sub-Processors
We maintain an up-to-date list upon request or in your customer portal. Typical categories include: cloud infrastructure, logging/monitoring, email delivery, chat/support, analytics, and document signature.
Appendix C – Download Gate Terms
By downloading non-public resources you agree:
- The materials are Confidential Information of dAItagrid.
- You will use them solely to evaluate our Services; no reverse engineering or re-publication.
- You will not disclose them outside your organization without written consent and will apply reasonable safeguards.
- If you already have an NDA with us, it controls; otherwise these terms apply.
- We may revoke access and request deletion at any time.
Appendix D – Data Processing Addendum (Processor Terms)
For customers using the Services, our DPA includes:
- processing instructions & scope,
- confidentiality, security measures, and audits,
- international transfer mechanisms (e.g., SCCs),
- sub-processor commitments and notifications,
- assistance with data subject requests and incidents,
- deletion/return of Customer Content at termination.
To obtain our DPA/SCCs, contact info@daitagrid.com.