Legal
Data Processing Addendum
Version . This is the version in force. An acceptance recorded against your account names this document and this version.
1. What this document is
This Data Processing Addendum ("Addendum") forms part of the Terms of Service between you and Dija Limited ("Dija", "we", "us"), a company incorporated in Cyprus, registration number HE 483340, with its registered office at Inomenon Ethnon, 2 Anastasia Court, Floor 4, 6042 Larnaca, Cyprus. Accepting the Terms accepts this Addendum. There is no separate signature.
It applies whenever you use Dija Studio to hold or process personal data about other people: the prospects and contacts you research, the people you message, and anyone who replies to you. We call that Prospect Data. It is the contract that Article 28 of the GDPR requires between a controller and a processor, and it is written to satisfy the equivalent rules in the UK GDPR and comparable laws.
Personal data about you, our user, is covered by our Privacy Policy, where we are the controller.
Contact for anything in this Addendum: legal@dija.ai.
2. Who is who
You are the controller. You decide who is researched, what is recorded about them, what is sent to them, and when. Those are your decisions and nobody else makes them.
We are the processor. We hold and handle Prospect Data to run the Service for you, and for nothing else.
3. Your instructions
Your documented instructions are: the Terms, this Addendum, and your use of the Service. In practice that means the records you create and import, the agents and personas you configure, the playbooks you schedule, the messages you approve or allow to send unattended, and the accounts you connect.
We will not process Prospect Data for any other purpose. If we believe an instruction breaks data protection law, we will tell you.
We do not offer a separate instruction channel on this tier. If you need us to process your data in a way the Service does not support, we will decline.
4. What we promise
We will:
- process Prospect Data only on your documented instructions, including as regards transfers out of the EEA, unless the law requires otherwise, in which case we will tell you first unless the law forbids us to;
- keep it confidential, and make sure everyone we authorise to process it is under a duty of confidentiality;
- apply the security measures in Annex B, and not materially weaken them while you are a customer;
- use sub-processors only as set out in section 7;
- help you answer requests from the people whose data it is, as set out in section 9;
- help you with your own obligations on security, breach notification, data protection impact assessments and prior consultation, taking account of what we do and what information we have;
- delete or return Prospect Data when you stop using the Service, as set out in section 11;
- give you the information you need to show that we meet Article 28, and allow audits as set out in section 12.
5. What you promise
You confirm that:
- you have a lawful basis for every piece of Prospect Data you put into the Service or instruct it to collect;
- you have given the people concerned the information the law requires. This matters here: our agents find and record people you did not name, so the data was not collected from them, and Article 14 of the GDPR applies;
- you will not use the Service to process special-category data (such as health, religious belief, political opinion or trade union membership) or data about children. Nothing in the software prevents free text from picking such a thing up, so this is your responsibility, and you must remove it if it appears;
- you will honour objections, opt-outs and erasure requests from the people in your workspace;
- your instructions to us will be lawful.
6. Your own AI provider
Dija supplies no AI capacity. Agents run against your own account with an AI provider, using your key. When an agent runs, we build a prompt that can contain names, business email addresses, job titles, research notes and the full text of inbound replies, and send it to your provider.
Because that account is yours:
- your provider is not our sub-processor. They are your vendor, under your contract, and we are not a party to it;
- what they do with the content is governed by your contract and your account settings, including how long they keep it and whether they use it to train models. We do not set any no-retention or no-training option on the calls we make with your key. Check what your plan does;
- we transmit content to them only to carry out an instruction you gave the Service.
If you need a different arrangement, do not connect that provider.
7. Sub-processors
You give us general authorisation to use the sub-processors listed in Annex C, and to appoint others in accordance with this section.
Before a new sub-processor begins processing Prospect Data, we will notify the workspace owner by email. You may object on reasonable data protection grounds. If we cannot resolve your objection, you may stop using the Service and delete your data, and this Addendum ends with it.
We will place obligations on each sub-processor that are no less protective than those in this Addendum, and we remain responsible to you for what they do.
8. Where data is processed
Our production servers are in the European Union.
Where a sub-processor processes Prospect Data outside the European Economic Area and we are the exporter, we rely on the standard contractual protections recognised under EU data protection law.
Recipients that you connect, such as your AI provider, your mailbox provider, your CRM and your enrichment tools, receive data under your own arrangements with them, including where they are outside the EEA.
9. Requests from the people whose data it is
Taking account of the nature of the processing, we will help you meet requests from data subjects. What the Service can do today:
- Erasure. Deleting a person deletes their record and the messages, sequences, research notes and activity attached to them.
- Rectification. You can edit any record.
- Objection to marketing. Every message carries one-click unsubscribe headers that nothing in the product can switch off. An opt-out stops every active sequence for that person immediately.
- Access and portability. You can export your workspace data as JSON and CSV from Settings.
- Restriction. The Service has no "keep but stop processing" switch. Write to legal@dija.ai and we will help by hand.
If a data subject contacts us directly about data in your workspace, we will not answer for you. We will tell them that you are the controller and pass the request to you.
10. Personal data breaches
We will tell you without undue delay after becoming aware of a personal data breach affecting Prospect Data we process for you, and give you the information you reasonably need for your own obligations, so far as it is available to us.
The notification will describe, so far as we can, what happened, the kinds and rough number of people and records affected, the likely consequences, and what we have done or propose to do.
11. Deletion and return
You can export your data at any time from Settings, and you should do so before you ask for deletion.
When you delete a workspace, or your account: the workspace is frozen immediately, so nothing more is processed; everyone in the workspace is emailed; you can cancel for 7 days; and after that the data is permanently deleted. A workspace we delete at your request is deleted in a single operation, so there is no half-deleted state.
Three things outlive that deletion, and each is deliberate:
- Backups hold a copy for up to 90 days. We do not use them to bring deleted data back into service, and if we ever restore from one, the deletion is applied again.
- Opt-out records survive as a one-way fingerprint of the address, which cannot be turned back into the address. We keep them so that a person who asked not to be mailed is not mailed again after a contact is deleted and re-imported. We rely on Article 17(3)(b) for this. They are scoped to your workspace, and they go when the workspace goes.
- Security audit records of a deleted workspace are detached from it and kept for 365 days, with the IP address and user agent removed 30 days after the event.
12. Audits
We will give you the information you need to show that we meet Article 28.
- Questionnaire. You may send us a reasonable written data protection questionnaire once in any 12 months, and we will answer it in a reasonable time.
- This Addendum and its annexes, which we keep current, are part of that answer. We hold no independent security certification and no third-party audit report to give you.
- Inspection. Where a supervisory authority requires it, or following a confirmed breach affecting your data, you or an auditor you appoint may inspect the relevant parts of our processing, on reasonable notice, during business hours, at your cost, under confidentiality, and no more than once in any 12 months.
Nothing in this section limits your rights under Article 28(3)(h) where the law does not allow them to be limited.
13. Liability
The liability provisions of the Terms apply to this Addendum. There is one aggregate cap of EUR 100 across both documents taken together, not one for each.
Nothing in either document excludes or limits liability for fraud, wilful misconduct, death or personal injury caused by negligence, or any liability the law does not allow to be excluded. In particular, an individual's right to compensation under Article 82 of the GDPR is not affected by anything agreed between us.
14. Precedence and versions
Where this Addendum and the Terms conflict about the processing of Prospect Data, this Addendum wins.
This Addendum carries its own version, shown at the top of this page. The Terms incorporate it, so a change here also moves the Terms version, and you will be asked to accept both again.
Annex A: what we process
Subject matter. Providing Dija Studio to you.
Duration. As long as your workspace exists, plus the periods in Annex D.
Nature and purpose. Storing, organising, enriching, analysing, generating content about, sending messages to, and recording the engagement of the people you are selling to.
Frequency. Continuous, including unattended runs on a schedule.
Categories of data subject. Prospects and contacts at the companies you target, whether you added them or an agent found them; anyone who replies to a message you send, or who writes into a thread the Service reads; colleagues of a prospect, where a relationship is recorded; and contacts imported from a CRM you connect.
Categories of personal data
- Identity and business contact details: name, job title, photograph, email address, phone number, LinkedIn profile, Telegram handle, time zone, employer.
- Research written by AI about the individual, including earlier versions of it.
- Message content, outbound and inbound, including the full text of replies, and the AI's assessment of them.
- Engagement: opens, clicks, bounces, replies and unsubscribes. The recipient's IP address and user agent are not stored.
- Scores, statuses, relationships, and pipeline records.
- Agent working data: prompts, tool calls, tool results and intermediate output.
- Whatever else you choose to put in a free-text or custom field.
Special categories. Not knowingly processed, and prohibited by section 5.
Annex B: security measures
These are the measures in place. We have written only what is true.
Encryption. Credentials are encrypted before they are stored, using AES-256-GCM with a per-record key and additional data binding the ciphertext to the row and column it belongs to, so a stolen value cannot be replayed elsewhere. This covers AI provider keys, mailbox OAuth tokens, SMTP and IMAP passwords, Telegram session data, CRM credentials, webhook secrets and two-factor secrets. Traffic to and from the Service is encrypted in transit. The content you store, such as message bodies and research notes, is not separately encrypted inside the database.
Tenant separation. Every request is scoped to one workspace at the route layer, and again at the database access layer, where an automatic constraint limits every read and every change to the workspace acting, and refuses any write that names a different one. That mechanism is unconditional: there is no setting that weakens it. It is enforced in the application rather than by the database itself.
Access control and authentication. Four workspace roles against a deny-by-default permission matrix, with integration credentials restricted to the workspace owner. Passwords are hashed with bcrypt. Access tokens are short-lived; refresh tokens are stored only as a hash, are single use, and a replayed token revokes every session for that user. Repeated failed sign-ins lock an account temporarily. TOTP two-factor authentication is available to every user, and a workspace owner can make it mandatory for the whole workspace. It is mandatory, with no exception, for our own administrative staff.
Audit trail. Security-relevant events are recorded with the actor, the IP address and the user agent. For privileged actions, a failed audit write aborts the action.
Application hardening. Input is validated at every route boundary. Outbound fetches of user-supplied addresses are checked on every redirect and refused for private network ranges. Uploaded images are re-encoded rather than trusted. Inbound webhooks are signature-verified.
Error monitoring. Diagnostics sent to our error-monitoring provider are pseudonymised first: email addresses and public IP addresses become one-way markers. This is pseudonymisation, not anonymisation, and text with no recognisable shape, such as a person's name, can still pass through.
Data minimisation for recipients. Open and click tracking does not store the recipient's IP address or user agent.
Abuse controls that protect data subjects. Platform-level sending caps beneath your own per-mailbox limits, rate limiting, automated abuse detection, one-click unsubscribe headers that cannot be switched off, and durable suppression of opt-outs and hard bounces.
Availability. Daily backups with 90-day retention, health checks, graceful shutdown, and resource limits so a runaway agent run cannot take the Service down. We run a single production environment with no failover, and we make no availability commitment.
What we do not have. We hold no SOC 2 report, no ISO 27001 certification, and no independent penetration test report. If any of those is a requirement for you, this tier is not suitable.
Annex C: sub-processors
| Sub-processor | What they do | What they receive |
|---|---|---|
| Hetzner Online GmbH | Hosting of the application, the database and the backups | All Prospect Data, at rest and in transit |
| Resend | Our own transactional email: verification, password reset, invitations, notifications | Your email address and the content of those messages. No Prospect Data |
| Sentry | Error monitoring | Error reports and diagnostics, pseudonymised before they leave us. Used only when error monitoring is switched on |
| Cloudflare | Anti-bot challenge on the sign-up page | The signing-up person's IP address and a challenge token. No Prospect Data |
Recipients you connect are not our sub-processors. They receive data because you connected them, under your own credentials and your own contract: your AI provider, your Gmail, Outlook, SMTP or IMAP mailbox, your Telegram account, your enrichment tools, and any CRM you import from.
We use no object storage, no content delivery network, no payment processor, no product analytics, and no session recording inside the product.
Annex D: how long we keep it
| What | How long |
|---|---|
| The contents of your workspace: contacts, companies, opportunities, deals, messages and their full bodies both ways, research notes including superseded versions, agent runs and their event streams, assistant conversations, and engagement records | Until you delete them, or until the workspace is deleted. No automatic expiry |
| Audit records belonging to a live workspace | Kept, with IP address and user agent removed 30 days after the event |
| Audit records left behind by a deleted workspace | Deleted 365 days after the event |
| Playbook trigger data | Masked when stored, and cleared 90 days after the run finishes |
| Agent memory | Deleted when it expires |
| In-product notifications | 30 days |
| Data export files | 7 days, then destroyed |
| Opt-out fingerprints | Life of the workspace. They survive deletion and re-import of the contact |
| Backups | 90 days |
| Deleting a person | Immediate, cascading to their messages, sequences, research notes and activity. The opt-out fingerprint is deliberately left in place |
| Deleting a company | The company goes; the people stay, without a company |
| Deleting a workspace | Frozen at once, permanently deleted after 7 days, cancellable throughout |
Where the table says there is no automatic expiry, that is the honest position. You decide how long to keep the contents of your workspace, and deleting the workspace deletes all of it.