PRIVACY POLICY

Privacy Policy

Last updated 26 July 2026. This policy explains what we collect, why, and what you control. It is written to be read.

1. What we collect

Account data — name, work email, company, billing details. Workspace data — the documents, records, and messages you connect so Dutta can do its job. Usage data — feature usage, performance, and error telemetry.

2. Why we process it

To provide the service, to bill you, to keep the platform secure, and to support you when you ask. We process workspace data solely on your instruction, as your processor.

3. What we never do

We do not sell personal data. We do not use your workspace data to train shared or third-party models. We do not read your workspace content except when you explicitly ask support to investigate an issue.

4. Sub-processors

We use a short list of infrastructure and model providers, each under a data-processing agreement. The current list is published and version-controlled; customers on Company and Enterprise plans are notified before it changes.

5. Your rights

Access, correction, export, and deletion — on request, or self-serve in the workspace settings. EU/UK users have the full set of GDPR rights; contact privacy@dutta.io.

6. Retention

Workspace data is retained while your account is active and for 30 days after cancellation, then permanently deleted. Audit logs are retained per your configured policy.

7. Contact

Data controller: Dutta Technologies, DIFC, Dubai, UAE. Data protection enquiries: privacy@dutta.io.