Privacy Policy
Last updated
This is a GDPR-oriented privacy policy draft prepared for launch readiness. It must be reviewed and finalized by qualified legal/data-protection counsel before DARA is offered commercially.
This Privacy Policy explains how INBESO Consulting GmbH (“INBESO,” “we”) processes personal data in connection with the DARA platform, in accordance with the EU General Data Protection Regulation (GDPR/DSGVO).
1. Data controller
For data processed to operate the DARA platform on behalf of a customer organization, that organization is typically the data controller and INBESO is the data processor, governed by a Data Processing Agreement. For data collected directly by INBESO (e.g. via the contact form or marketing site), INBESO is the controller. See the Imprint for contact details.
2. What we process
- Account and identity data (name, work email, tenant membership, role).
- Customer Data you upload or connect (documents, spreadsheets, connected sources).
- Usage data (queries, token counts, feature usage) for metering and product improvement.
- Contact-form submissions (name, email, company, message) when you reach out to us.
3. Legal basis
Processing is based on contractual necessity (operating the service you subscribed to), legitimate interest (security monitoring, product improvement), and consent where required (e.g. optional cookies, marketing communications).
4. Data residency and international transfers
Customer Data is stored and processed on EU-region infrastructure. We do not route inference or storage through non-EU infrastructure for the core product. Where a sub-processor requires a transfer outside the EU/EEA, we rely on the European Commission’s Standard Contractual Clauses or an equivalent safeguard.
5. Retention
Customer Data is retained for the duration of the subscription and deleted or returned within a reasonable period after termination, per the retention terms in the applicable order form. Audit logs are retained on an append-only basis for the period required by our security and compliance obligations.
6. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request erasure (“right to be forgotten”).
- Export your data in a portable format.
- Object to or restrict certain processing.
Enterprise customers can exercise export and erasure rights directly from the product’s data & privacy settings; individual requests can be sent via our contact page.
7. No training on your data
Customer Data is never used to train foundation models, for INBESO’s benefit or any third party’s. This is an architectural and contractual commitment, not an opt-out setting.
8. Sub-processors
We use a deliberately short list of sub-processors, primarily Microsoft Azure (EU regions) for infrastructure and Microsoft Entra ID for identity. See our Security & Trust Center for detail.
9. Contact
Data protection questions can be sent via our contact page. You also have the right to lodge a complaint with your local data protection authority.