Legal
Privacy Policy
Version . This is the version in force.
1. Who we are
Dija Limited ("Dija", "we", "us") is a company incorporated in Cyprus, registration number HE 483340, with its registered office at Inomenon Ethnon, 2 Anastasia Court, Floor 4, 6042 Larnaca, Cyprus. We are the controller of the personal data described in this notice.
This is a notice, not a contract. It tells you what we do with personal data. It is not something you agree to, and nothing in it takes away a right you have under data protection law.
We have not appointed a Data Protection Officer. Privacy questions, requests and complaints all go to one address: legal@dija.ai.
2. What this notice covers
Two different kinds of personal data run through Dija Studio, and they are governed separately.
| Whose data | Our role | Where it is covered |
|---|---|---|
| Yours, as a user: your name, email, IP address, sign-in sessions, activity records | Controller | This notice |
| Visitors to dija.ai, including people who fill in a form, book a call, or apply for a job | Controller | This notice, section 11 |
| The people you research and message from your workspace: their names, business emails, job titles, your messages to them, their replies | Processor, acting on your instructions | The Data Processing Addendum |
If you are one of those third parties and you want to know why a Dija user holds data about you, the user is the controller and is the right person to ask. Write to us at legal@dija.ai and we will help you reach them.
3. What we collect about you
Your account. Your email address, your first and last name, an avatar image if you upload one, a hash of your password (never the password), your two-factor secret and backup codes if you enable them, verification and password-reset tokens, failed sign-in counts, and the time you last signed in.
Sign-in sessions. For each active session: your IP address, your browser's user agent, a device name, and when it was last used. We store a hash of the session token, never the token itself.
Your workspace. The workspace name, the company name you give us, the plan, your role, and the settings you choose.
Connections you make. When you connect a mailbox, an AI provider, a CRM, an enrichment tool or Telegram, we store the account address or identifier and the credentials for it. Credentials are encrypted before they are stored.
How you use Studio. Records of agent runs, including the prompts, the tool calls and the results; conversations with the in-product assistant; AI usage records with token counts and an estimated cost; and the content you create in your workspace.
Security and audit records. We keep an audit trail of security-relevant events, such as sign-ins, failed sign-ins, session and two-factor changes, workspace and membership changes, administrative actions, suspensions and deletions. Each record holds who did it, your IP address, your user agent, and what happened.
Acceptance records. When you accept our Terms of Service and Data Processing Addendum, we record which document, which version, when, your IP address, your user agent, and which screen captured it. That record is the evidence that an agreement exists.
Dija Marketplace. If you link a marketplace account, we hold your marketplace profile (display name, handle and email address) and a record of what you have installed.
4. Why we use it
| What for | On what basis |
|---|---|
| Creating and running your account and workspace | Performance of our contract with you |
| Signing you in, keeping sessions, and protecting your account | Contract, and our legitimate interest in security |
| Verifying your email address and resetting passwords | Contract |
| Preventing abuse, spam and fraud, including the sending limits and abuse checks in section 5 | Our legitimate interest, and the interest of the people your workspace sends mail to |
| Keeping a security audit trail | Our legitimate interest in accountability, and legal obligation for part of it |
| Sending you service and security messages | Contract |
| Understanding how the product is used, in aggregate, so we can improve it | Our legitimate interest |
| Meeting a legal obligation, or establishing or defending a legal claim | Legal obligation, or our legitimate interest |
Where we rely on a legitimate interest, you can object. See section 9.
We do not sell your personal data, and we do not use it for advertising. Section 10 explains separately what happens on our marketing website, which does use advertising technology with your consent.
5. Decisions made automatically
Workspace suspension. An automated check runs regularly over workspaces on the free tier. One signal, the rate at which your messages are rejected by recipients' mail servers, can suspend a workspace with no person involved. Suspension blocks writing and sending; read access to your own data continues. Other signals are recorded for a person to look at and never act on their own.
If your workspace is suspended you will see it in the product, with the reason. You can ask for a person to review it by writing to legal@dija.ai, and you can put your point of view to us.
6. Connected mailboxes, and Google's Limited Use rules
If you connect a Gmail mailbox, Dija asks for permission to send mail as you and to read your mailbox, so that it can detect and classify replies to the messages it sent. If you connect an Outlook mailbox, Dija asks for the equivalent Microsoft permissions. You can disconnect a mailbox at any time, in Studio and in your Google or Microsoft account.
Dija's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use mailbox content for advertising, we do not sell it, and we do not use it to train AI models. Mailbox content is sent to your own AI provider only where you have asked Studio to do something that requires it, such as classifying a reply or drafting an answer.
7. Who else sees your data
| Who | What they get | When |
|---|---|---|
| Hetzner Online GmbH (hosting) | Everything, because our servers and databases run on their infrastructure | Always |
| Resend (transactional email) | Your email address and the content of our own messages to you: verification, password reset, invitations and notifications | Always |
| Sentry (error monitoring) | Error reports and application diagnostics, pseudonymised before they leave us: your email address and public IP become one-way markers rather than the values themselves. Your internal user id and any free text that has no recognisable shape, such as a person's name, can still reach them | Only when error monitoring is switched on |
| Cloudflare (Turnstile) | Your IP address and a challenge token, at sign-up only, so that we can tell a person from a bot | Only on the sign-up page |
We do not use any other analytics, tracking or advertising service inside the product. The marketing website is different, and is described in section 10.
We may also disclose personal data where the law requires it, or to establish, exercise or defend a legal claim.
Our own staff. Our administration console shows workspace and account details, such as names, email addresses, plans and suspension state. It does not show the content of a workspace's CRM. A member of our staff can, however, be added to a workspace in order to support it, and would then see what any member sees. Doing that requires two-factor authentication, is recorded in the audit trail, and adds a visible member to the workspace.
Sub-processor changes. If we add or replace one of the providers above, we will tell workspace owners by email before the new provider starts processing.
8. Where your data is, and transfers out of the EEA
Our production servers are in the European Union.
Some of the providers in section 7 process data outside the European Economic Area, either because they are established elsewhere or because they operate a global network. Where we are the exporter and a transfer outside the EEA takes place, we rely on the standard contractual protections recognised under EU data protection law.
If your workspace connects an AI provider, an enrichment tool, or a CRM, that connection is yours. Data reaches that provider under your own contract with them, including where they are outside the EEA.
9. How long we keep it
| What | How long |
|---|---|
| Your account and workspace records | Until you delete them. Deletion takes effect after a 7-day grace period, described in section 13 of our Terms |
| Content in your workspace: contacts, companies, messages, research notes, agent runs and their event streams, assistant conversations | Until you delete it, or until the workspace is deleted. There is no automatic expiry |
| Sign-in sessions | Deleted when you sign out, change or reset your password, when we detect a stolen session token, or when your account is deleted. We do not delete them on a timer, so an unused session record can remain until one of those happens |
| IP address and user agent in the audit trail | Removed 30 days after the event. The rest of the record is kept |
| Audit records left behind by a deleted workspace | Deleted 365 days after the event |
| Our own platform security log (sign-ins, administrative actions) | Kept, with IP address and user agent removed at 30 days |
| Acceptance records for the Terms and the Addendum, including the IP address and user agent that evidence them | For the life of the account. They are deliberately outside the 30-day rule above, because they are the evidence that an agreement exists |
| Playbook trigger data | The stored copy is masked when it is written, and cleared 90 days after the run finishes |
| In-product notifications | 30 days |
| Data export files | 7 days, then the file is destroyed and only the record that you made an export is kept |
| Opt-out records | A one-way fingerprint of the address, for the life of the workspace. See section 10 |
| Backups | 90 days |
| Website analytics | 180 days |
| Job applications | The uploaded CV file is deleted after 365 days. The application record itself is kept until we delete it |
10. Your rights
Subject to the conditions in the law, you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to processing, to portability, and to withdraw consent where we rely on it. You can also complain to a data protection supervisory authority in the country you live or work in.
Two of these you can exercise yourself, without asking us:
- Export. Settings, then Data export. You can download your workspace data and your account data as a zip of JSON and CSV files. The archive lists what it deliberately leaves out, which is credentials, live tokens, and internal records.
- Deletion. Settings, then Delete. You can delete a workspace or your whole account. The workspace is frozen straight away, everyone in it is emailed, you can cancel for 7 days, and then the data is permanently deleted.
For anything else, write to legal@dija.ai. We will answer within one month.
Two honest limits on erasure.
Backups. Deleting data removes it from the live systems. Copies stay in our backups for up to 90 days. We do not use backups to bring deleted data back into service, and if we ever have to restore from one, the deletion is applied again.
Opt-outs. When someone tells a workspace to stop mailing them, we keep a one-way fingerprint of their address. It cannot be turned back into the address, and it is not a mailing list. We keep it so that the opt-out survives the contact being deleted and imported again, which is the only way to be sure the person is not mailed a second time. This is a legal obligation carve-out from erasure, and it is deliberate.
11. Our website
The marketing pages on dija.ai are separate from the product and use a small number of technologies.
- First-party analytics. We measure page performance without storing anything on your device. The server keeps a salted one-way hash of your IP address and browser for up to 180 days so that repeat visits can be counted. It cannot be turned back into your IP address.
- LinkedIn Insight Tag and Conversions API. On campaign pages, and only with your consent, we load LinkedIn's advertising tag and, on a form submission, send LinkedIn a hashed version of your email address rather than the address itself.
- Cal.com. If you book a call, the booking form is provided by Cal.com and loads only when you click.
- Consent. We ask for consent before loading advertising technology for visitors in the EEA, the United Kingdom, Switzerland, and anywhere we cannot determine the country. Accept and Reject are given equal prominence, and we honour the Global Privacy Control signal everywhere.
- Job applications. If you apply for a role, we hold what you send us, including your CV, in order to consider your application. Section 9 gives the retention periods.
In the product itself we set only the cookies needed to keep you signed in.
12. Security
We protect personal data with technical and organisational measures, including: encryption of stored credentials at the application layer; encrypted transport; role-based access control; tenant separation enforced in the application, including at the database access layer; optional two-factor authentication, which a workspace owner can make mandatory; mandatory two-factor authentication for our own administrative staff; rate limiting; and an audit trail. The security annex of our Data Processing Addendum describes these in more detail.
No system is perfectly secure. If a personal data breach affects your data, we will tell you where the law requires it, and we will notify the supervisory authority within the time the law allows.
13. Children
Dija Studio is for business use by adults. It is not intended for anyone under 18, and we do not knowingly collect data from children.
14. Changes to this notice
We may update this notice. Every version carries its date, and the version in force is shown at the top of this page. If we make a material change, we will tell you by email or in the product.
15. Contact
Dija Limited (HE 483340), Inomenon Ethnon, 2 Anastasia Court, Floor 4, 6042 Larnaca, Cyprus.