Privacy Policy
Last updated
How DAKAEi collects, uses, stores, and shares your information when you use the assistant, connect your apps, run agents, and talk to it by voice.
Who we are
DAKAEi Technologies Ltd is a company registered in England and Wales, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
We act as a controller for personal data about your account, your use of the service, billing, security, support, and our own service operations. For that data we decide why and how it is processed, and this policy describes what we do.
Where DAKAEi handles personal data inside content you supply or inside an application you connect, and it does so on behalf of an organisation that decides why that data is being processed, we act as a processor for that organisation. In that case the organisation's own privacy notice governs the data, our processing is limited to that organisation's instructions, and a data processing agreement sets the terms.
This policy covers the web app, the mobile app, the voice assistant, agents and automations, and anything else that links here.
DAKAEi is an assistant that works inside the apps you already use. That means the information it handles is often not ours and not even yours alone. It belongs to your inbox, your calendar, your team's workspace, and we treat it accordingly.
Information you give us
Account information. Your name, email address, password (stored only as a hash), and, if you sign in through another account, the basic profile that account shares with us.
What you send. Your messages, the files and images you upload, the instructions you save, the agents you create, and anything else you type or say into the product.
Data from apps you connect. When you connect an app, you authorise us to read and act on the data that app exposes for the permissions you granted. That can include email, calendar events, documents, messages, issues, and contacts. We request the narrowest permissions that make a feature work.
Voice. If you use the voice assistant, we process your microphone audio for the duration of the call in order to understand and answer you.
Payment information. If you subscribe, our payment processor collects and holds your card details. We never receive or store your full card number.
Information collected automatically
Usage. Which features you use, when, and how often, plus the model and tools a request used, so we can meter plans and understand what to improve.
Technical. IP address, browser and device type, operating system, language, and timestamps.
Diagnostics. Error reports and performance traces when something breaks. These can incidentally include fragments of a request that failed.
Cookies and similar technologies, as described in the Cookie Policy.
How we use information
To provide the service: answering you, running the tools you ask for, acting in the apps you connected, and keeping your history available across your devices.
To bill you and enforce plan limits.
To keep the service secure: detecting abuse, fraud, automated scraping of our own product, and attempts to break account isolation.
To support you when you contact us, which may involve looking at the specific conversation you are asking about.
To improve the product, in the limited way described under AI and product improvement below.
To send you service messages. Marketing email is separate and you can opt out of it at any time.
Legal bases for processing
Data protection law requires us to have a lawful basis for each purpose. Ours are as follows.
Creating and running your account, generating responses, carrying out actions in connected apps, processing voice, and taking payment: performance of our contract with you, or steps taken at your request before entering into it.
Keeping billing and tax records, and responding to lawful requests: compliance with a legal obligation.
Securing the service, preventing fraud and abuse, enforcing our terms, and establishing or defending legal claims: our legitimate interests in running a service that is safe and not misused. We balance those interests against your rights, and you can object as described under your rights.
Understanding how the product is used so we can improve it: our legitimate interests in developing the service, or your consent where the law requires consent for the technology involved.
Non-essential cookies and similar technologies, and marketing email where consent is required: your consent, which you can withdraw at any time.
Where we rely on legitimate interests, you can ask us for the assessment we carried out.
AI and product improvement
Your requests are processed by large language models in order to generate a response. Some of these models run on infrastructure operated by other companies on our behalf, under contracts that restrict what they may do with the data. We keep a current list of these providers, what each one is used for, and where it processes data. Ask us for it and we will send it.
We do not sell your data, and we do not use the content of your conversations, your files, or your connected app data to train foundation models.
We do use aggregated and de-identified information about feature usage, system performance, and errors to improve DAKAEi. That means counts, timings, and failure patterns, not the substance of what you asked or what came back.
Model output is generated text. It can be wrong, out of date, or confidently mistaken, and it should not be treated as professional advice. You remain responsible for checking anything you act on.
Some features send a request to an external provider to fetch live information on your behalf. We send only what that request needs in order to run. Because you compose the request, please avoid putting confidential details into a search you ask us to run externally.
Connected apps and other people's data
Connecting an app is explicit and per-app. Nothing is connected until you authorise it.
Access tokens for connected apps are held encrypted and are used only to carry out actions you or your agents ask for.
You can disconnect any app at any time from the product. Disconnecting revokes our ongoing access. It does not retroactively erase results already produced in your chat history, which you can delete separately.
Actions that write or send, such as sending an email, posting a message, or creating an event, are taken because you asked for them, directly or through an automation you configured.
Information about other people. An inbox, a calendar, or a shared workspace contains personal data about people who are not DAKAEi users and who did not choose us. We process that information only as far as needed to do what you asked, we do not use it to build profiles or to enrich our own records, and we do not use it to contact those people. Where you bring such data into DAKAEi, you are responsible for having a lawful basis to do so, and where you are acting for an organisation, that organisation is the controller of it.
Agents and automations
Agents are configurations you create: a name, instructions, and a set of apps and sources they are allowed to use. Automations are standing instructions that run when an event happens in a connected app, without you present.
An agent can only reach the apps and sources you attached to it, and only within the permissions you already granted to your account. Creating an agent does not grant new access.
An automation acts on your behalf and its actions can have effects outside DAKAEi, including messages sent to other people. Review what an automation is allowed to do before enabling it, and grant the narrowest set of apps that makes it work.
We keep a record of what an agent or automation did so you can see it and so we can support you.
You can disable or delete an agent or automation at any time, which stops it running from that point.
Agent output and agent actions are machine-generated and are not guaranteed to be correct. You remain responsible for what runs under your account.
When we share information
Service providers. We use other companies to host infrastructure, store files, send email, process payments, run models, and monitor errors. They act on our instructions, may only use the data to provide their service to us, and are bound by written terms covering confidentiality, security, use of their own subprocessors, assistance with your rights, and deletion or return of data.
Legal. We may disclose information where we are legally required to, or where it is necessary to investigate fraud or protect someone's safety.
Business transfer. If the business is acquired or merged, information may transfer as part of that transaction. You will be told before your information becomes subject to a materially different policy.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
International transfers
The service is operated from, and uses infrastructure in, more than one country. Your information may be processed outside the country where you live, including countries whose data protection laws differ from your own.
We are established in the United Kingdom, so UK data protection law applies to what we do with your information. Where a transfer takes personal data outside the United Kingdom or the European Economic Area, we rely on the safeguards those regimes recognise, including adequacy regulations and the standard contractual clauses and UK addendum agreed with the companies that process data for us.
If you are in the European Economic Area, you can raise any matter relating to our processing of your personal data with us directly at privacy@dakaei.com.
How long we keep it
Account information is kept while your account exists.
Conversations, files, and agents are kept until you delete them or delete your account.
When you delete content or your account, it is removed from the product immediately and irreversibly deleted from our systems and backups within 30 days.
Voice audio is processed to answer you and is not retained as a recording once the call ends. The transcript of the exchange is personal data, is kept in your history like any other conversation, and is deleted when you delete that conversation or your account.
Security and authentication logs are kept for 90 days.
Error reports and performance traces are kept for 90 days.
Aggregated usage analytics are kept for up to 24 months.
Billing and tax records are kept for 6 years, because company and tax law requires it.
Where we must keep something to establish or defend a legal claim, we keep it until that need ends.
Your rights
Subject to the conditions in the applicable law, you have the right to be told what we do with your personal data, which this policy sets out; to access a copy of it; to have inaccurate data corrected; to have data erased; to restrict how we process it; to object to processing carried out on the basis of legitimate interests, including profiling; to receive data you gave us in a portable, machine-readable form and have it transmitted to another controller where technically feasible; and to withdraw consent at any time where we rely on consent, without affecting processing carried out before you withdrew it.
We do not make decisions about you by solely automated means that produce legal effects concerning you or similarly significantly affect you. Agents and automations act on instructions you configure, on your behalf, rather than making decisions about you. If that ever changes we will say so here and explain the logic involved and your rights before it takes effect.
You can exercise most of these directly in the product: your conversations, agents, and connected apps can all be removed from your account settings.
For anything else, write to privacy@dakaei.com. We will respond within one month, and will tell you if we need longer because the request is complex. We do not charge for this unless a request is manifestly unfounded or excessive.
If your data reached us through an organisation using DAKAEi, and we act as its processor, we will point you to that organisation, which is the right place to bring the request.
If you are in the United Kingdom, you have the right to complain to the Information Commissioner's Office. If you are in the European Economic Area, you can complain to your local supervisory authority. We would prefer the chance to resolve it first.
Security
We encrypt data in transit and at rest, restrict internal access to what a role requires, and isolate each account's data. The Security Overview describes this in more detail.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify the Information Commissioner's Office within 72 hours where the law requires it, and tell you without undue delay where the breach is likely to result in a high risk to you.
Children
DAKAEi is not directed at children. We do not knowingly provide accounts to anyone under 16, or under the higher age set by the law where they live, without any parental or guardian authorisation that law requires.
If you believe a child has given us information, contact us and we will delete it.
Changes and contact
We may update this policy. If a change materially affects how we handle your information, we will tell you in the product or by email before it takes effect, and update the date at the top of this page.
Questions about this policy, or any request about your data: privacy@dakaei.com.