1. Who we are and how to contact us
The controller responsible for this policy is Dialogis.ai s.r.o., ID No. 23985348, Sokolská 1883/8, Nové Město, 120 00 Prague 2, Czech Republic ("Dialogis", "we", "us").
Privacy contact: hello@dialogis.io (please use the subject "Privacy"). Postal address as above; Czech data box (datová schránka) w933rn4. We have not appointed a data protection officer because we are not required to; our privacy contact fulfils that role.
2. Who this policy is for
This policy covers three groups of people. Our role, and therefore who you should contact about your data, depends on which group you are in.
| You are… | What we process | Our role |
|---|---|---|
| A Customer or Authorised User who builds and runs AI Minds in the Dialogis admin platform | Account, workspace, billing, support and usage data | Controller |
| A Customer or Authorised User — for the Knowledge Sources you upload and the conversations your Minds have | Customer Content and Conversation Data | Processor on your behalf, under the Data Processing Agreement |
| An End User who talks to a Mind on a website, a hosted page, Telegram, WhatsApp or Instagram | Your messages, voice, contact details and related metadata | Processor on behalf of the Operator of the Mind, who is the controller. We are the controller only for the platform-level security, abuse-prevention and legal purposes described in Section 4 |
| A visitor of dialogislabs.com, dialogis.io or their subdomains, or someone who contacts us | Technical data, form submissions, emails | Controller |
Terms with a capital letter (Customer, Mind, Operator, End User, Knowledge Sources, Conversation Data and so on) have the meaning given in the Terms of Use.
If you are an End User, the Operator of the Mind decides why and how your conversation is processed. Their name appears in the chat or on the page or profile that hosts it. Direct requests about your conversation to them first; you can also contact us and we will pass the request on and help. Our User Data Deletion page explains the steps.
This policy does not cover the separate consumer mobile app published under the Dialogis name, which has its own notice, nor the websites of Operators that embed a Mind.
3. Personal data we process
3.1 If you are a Customer or Authorised User
- Account and identity data: name, email address, password hash or Google account identifier, language, role in the workspace, workspace and business name, VAT number and billing address for business plans, and acceptance records for the Terms (version and time).
- Workspace and usage data: the Minds you create, their configuration, publishing settings, connected Channels and integrations (stored credentials are encrypted), actions you take in the platform, audit records, usage against plan limits, and analytics about your Minds' conversations.
- Billing data: subscription and plan history, invoices, payment status and the last digits and brand of your payment card. Full card details are entered directly with our payment processor, Stripe, and never reach us.
- Support and communication data: emails and messages you exchange with us, and notices we send you.
- Technical data: IP address, browser and device information, timestamps, session identifiers, security and error logs.
- Voice Consent records if you request a Voice Clone: the signed consent and recording metadata for the person whose voice is cloned.
3.2 If you are an End User of a Mind
Depending on how the Operator configured the Mind:
- the content of your messages and the Mind's answers, and the conversation history;
- voice: audio you speak or send, its transcript, and synthetic voice answers;
- contact and request details you choose to give (name, email, phone, company, what you need), and the record of the notice you were shown and whether you agreed to be contacted;
- channel identifiers needed to deliver messages: a session identifier on the web, or your Telegram user ID and username, WhatsApp phone number and profile name, or Instagram account ID and username;
- attachments you send (images, documents, voice messages);
- technical data: IP address (web only), browser and device information, page URL where the widget is embedded, timestamps, diagnostics and security logs;
- human handoff data: the conversation and details passed to the Operator's staff when a person joins;
- consent records: the version of the terms you accepted and when.
3.3 If you visit our websites or contact us
- Technical data your browser sends (IP address, user agent, pages requested, referrer) recorded in server and content-delivery logs;
- your language preference, stored in your browser;
- what you send us through forms (for example a request to build or access a Mind: name, email and an optional link) or by email.
We do not use advertising or tracking cookies on our websites, and our website measurement sets no cookies and stores nothing on your device. See the Cookie & Storage Notice.
3.4 Data we receive from other sources
- Knowledge Sources uploaded by Customers may contain personal data about other people: the expert's own posts, talks and documents, and sometimes the names of clients, colleagues or people quoted. The Customer is responsible for having the right to use that material (Terms, Section 5.3). We process it only to build and run that Customer's Minds.
- Public web pages and social-media posts that a Customer asks us to import (for example the expert's own LinkedIn posts) are fetched through crawling services on the Customer's instruction.
- Channel providers (Telegram, Meta for WhatsApp and Instagram) send us the identifiers and message content described in Section 3.2 when you message a Mind.
- Google, if a Customer signs in with a Google account, sends us the name, email address and account identifier.
- Stripe sends us payment status, and, where you enter it, your billing address and VAT number.
We do not buy personal data from data brokers and do not enrich profiles from third-party sources.
4. Why we process personal data and on what legal basis
4.1 Where Dialogis is the controller
| Purpose | Examples | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the platform to Customers | creating workspaces, sign-in, building and publishing Minds, storing configuration, support | Performance of a contract (Art. 6(1)(b)) |
| Billing and accounting | subscriptions, invoices, tax records, fraud checks by Stripe | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax and accounting records |
| Security, abuse prevention and platform integrity | logs, rate limiting, detecting misuse of Minds, investigating incidents, enforcing the Acceptable Use Policy | Legitimate interests (Art. 6(1)(f)): keeping the platform and its users safe; legal obligation where the law requires it |
| Service communications | notices about changes to the service, terms or prices, security alerts, replies to your requests | Contract; legitimate interests in informing users |
| Product improvement and statistics | aggregated usage metrics, error analysis, evaluating answer quality of Minds under confidentiality | Legitimate interests: improving a service users pay for; we use aggregated or anonymised data wherever possible |
| Marketing to existing customers | occasional emails about new features and plans, always with an unsubscribe link | Legitimate interests, within the limits of Czech Act No. 480/2004 Coll. (existing-customer exception); consent where required |
| Responding to visitors and applicants | replying to form submissions and emails | Legitimate interests; steps at your request before a contract (Art. 6(1)(b)) |
| Legal claims and compliance | handling complaints, disputes, notices of illegal content, requests from authorities | Legitimate interests in establishing, exercising or defending legal claims; legal obligation |
| Voice Consent records | proving that a Voice Clone was authorised | Legal obligation and legitimate interests in demonstrating compliance; the person's explicit consent for the clone itself (Art. 9(2)(a), where applicable) |
Where we rely on legitimate interests we have balanced them against your interests and rights, and you may object at any time (Section 11).
4.2 Where the Operator is the controller
Operators typically process End-User conversations to answer questions, provide support, generate leads and improve their Mind. The Operator chooses the legal basis, usually performance of a contract or steps before one, legitimate interests, or consent (for example for passing your contact details to sales or for marketing). The Platform helps Operators comply by showing an AI disclosure and these documents before the first message, by recording consent for contact capture, and by supporting deletion requests. If you have questions about an Operator's purposes, ask the Operator.
5. AI processing
5.1 How a Mind answers
When you send a message, the Platform retrieves the most relevant passages from the Mind's Knowledge Sources, combines them with the Mind's persona instructions and recent conversation history, and sends that package to a third-party large language model, which generates the answer. For voice, a speech-to-text provider transcribes what you said and a text-to-speech provider reads the answer aloud. During ingestion, Knowledge Sources are transcribed (audio and video), read (web pages), OCR-processed (scanned documents), summarised and converted into vector embeddings so they can be searched.
5.2 Which providers see what
The providers currently used are listed with their location and role on our Sub-processor List. In summary: Google Cloud hosts everything in Frankfurt and provides embeddings and, where configured, Gemini models; OpenAI and Google provide the language models that generate answers; ElevenLabs provides speech-to-text, text-to-speech and voice clones; Mistral provides OCR; Apify and Jina fetch web pages and public posts on the Customer's instruction. Each provider receives only the data needed for its task.
5.3 No training on your data
We do not use Customer Content, conversations or Outputs to train or fine-tune general-purpose AI models. Our providers process your data only to return a result to us and are contractually prohibited from using it to train their models. Retention by providers is limited to what is needed for abuse monitoring under their terms; where a zero-retention option is available to us, we use it.
5.4 No automated decisions with legal effects
A Mind provides information and assistance. Neither we nor the Platform make decisions about you based solely on automated processing that produce legal or similarly significant effects (Article 22 GDPR). Operators are contractually prohibited from using Minds for such decisions without our written agreement and their own safeguards.
5.5 Transparency under the AI Act
Every Mind discloses that it is an AI at the start of a conversation and labels synthetic voice. Our AI Transparency Notice describes the system, its limitations, the models used and human oversight.
6. Voice data and voice clones
- Speech recognition: audio you speak is sent to the speech-to-text provider to be transcribed. On the web, audio is streamed and not retained by us beyond the transcript; voice messages sent on messaging channels are stored with the conversation together with their transcript.
- Synthetic voice: answers may be read out by a stock synthetic voice or, where the Operator has a Voice Clone, by a voice modelled on the expert. It is always disclosed as AI-generated.
- Voice Clones: we create a Voice Clone only on a Customer's request and only with the explicit, written consent of the person whose voice is recorded. The recordings and the resulting voice model are stored with our voice provider and used only for that Customer's Minds. The person may withdraw consent at any time by contacting the Customer or us; we delete the clone within 30 days of withdrawal, of the Customer's request, or of the end of the Customer's contract.
- No identification by voice: we do not create voiceprints to identify or authenticate people, and voice data is never used to recognise who is speaking.
7. Who we share personal data with
- Sub-processors that host and operate the Platform on our behalf under written data-processing terms: cloud hosting, identity provider, AI model, speech and OCR providers, web-fetching services, email delivery and payment processing. The current list, with locations and safeguards, is at dialogislabs.com/legal/subprocessors. We notify Customers at least 30 days before adding a sub-processor.
- Operators: if you are an End User, the Operator of the Mind and its team receive your conversation, contact details and consent records.
- Channel providers: Telegram, and Meta for WhatsApp and Instagram, transport your messages under their own terms and privacy policies, which apply independently of ours.
- Integrations chosen by the Operator: CRM systems and webhooks the Operator connects (for example HubSpot, Pipedrive, Raynet, Flowii, GramCRM or AutoCRM). Data is sent there only as the Operator configures and with the notice or consent described in Section 4.2.
- Payment processor: Stripe, which also acts as an independent controller for its own regulatory obligations.
- Professional advisers and authorities: lawyers, accountants and auditors under confidentiality; courts and authorities where the law requires or allows it, including under Section 19 of the Terms of Use.
- Business transfers: if we merge with, are acquired by, or transfer our assets to another company, personal data may be transferred to the successor, who will be bound by this policy.
We do not sell personal data and do not share it with advertisers.
8. International transfers
The Platform is hosted in the European Union (Google Cloud, europe-west3, Frankfurt, Germany), and our identity and email providers run in the EU (Amazon Web Services, Stockholm and Ireland). Some providers process data in the United States: OpenAI (language models), ElevenLabs (speech and voice), Google LLC (Gemini API), Stripe (payments) and Amazon Web Services (for support access to EU-hosted services). For those transfers we rely on:
- the EU-U.S. Data Privacy Framework where the provider is certified under it (Commission adequacy decision of 10 July 2023); and
- the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), supplemented where necessary by additional measures such as encryption and data minimisation.
The mechanism used for each provider is stated in the Sub-processor List. You can request a copy of the relevant safeguards at hello@dialogis.io. Messaging channels (Telegram, WhatsApp, Instagram) transfer data under their own terms.
9. How long we keep personal data
| Data | Retention |
|---|---|
| Customer account and workspace data | For the life of the account, then deleted within 30 days after the account is closed and the 30-day export period has ended |
| Knowledge Sources, embeddings, Mind configuration | Until the Customer deletes them or the account is closed (then as above) |
| Conversations, voice messages and transcripts, leads, consent records of End Users | Until the Operator deletes them, a valid deletion request is fulfilled (within 30 days), or the Operator's account is closed |
| Voice Clone recordings and models | Until consent is withdrawn, the Customer requests deletion, or the contract ends; deleted within 30 days |
| Voice Consent records | For as long as the clone exists and 3 years afterwards, to demonstrate compliance |
| Streamed web voice audio | Not stored; only the transcript is kept with the conversation |
| Billing records, invoices and tax documents | 10 years after the end of the tax year, as required by Czech tax and accounting law |
| Support emails and correspondence | 3 years after the last contact |
| Security, access and error logs | 30 days, unless needed longer for an ongoing security investigation |
| Sign-in sessions | Up to 30 days (24 hours of inactivity ends a web session) |
| Automated build runs for hosted pages | 30 days |
| Website form submissions (for example requests to access a Mind) | 12 months |
| Backups | Rolling backups are kept for 14 days and then overwritten; deleted data therefore disappears from backups within 14 days |
| Aggregated or anonymised statistics | Indefinitely; they do not identify anyone |
When a retention period ends, we delete or anonymise the data, unless we must keep it to establish, exercise or defend legal claims, in which case it is isolated and kept only for that purpose.
10. Security
We protect personal data with technical and organisational measures that include: hosting in certified EU data centres; encryption in transit (TLS) and at rest; encrypted storage of integration credentials and tokens; role-based access control and least-privilege access for our staff; separate production, staging and development environments; logging and monitoring of security events; automated backups; regular dependency updates; and confidentiality obligations for everyone who works with us. Annex 2 of the Data Processing Agreement describes the measures in more detail.
If a personal-data breach affects you, we will notify the competent supervisory authority within 72 hours where required and inform you without undue delay where the breach is likely to result in a high risk to you. Where we act as a processor, we notify the Operator within 48 hours of becoming aware so that they can meet their own obligations.
No online service is completely secure. Please do not share passwords, payment card numbers or other sensitive information in a chat, and keep your own sign-in credentials safe.
11. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten") where there is no overriding reason to keep it;
- restrict processing in the situations set out in Article 18 GDPR;
- data portability: receive data you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent at any time where processing is based on consent, without affecting processing before withdrawal;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
How to exercise them. Email hello@dialogis.io with the subject "Privacy", or write to our postal address. Customers can also manage much of their data directly in the platform (edit the workspace, delete Minds, Knowledge Sources and conversations, disconnect channels). The User Data Deletion page gives step-by-step instructions. We may ask you to confirm your identity, for example by writing from the email address linked to the account or the channel you used. We respond within one month; for complex or numerous requests we may extend by two further months and will tell you why. Requests are free unless they are manifestly unfounded or excessive.
If we are a processor. Where your request concerns a conversation with a Mind, the Operator is the controller. We will forward your request to the Operator, inform you that we have done so, and act on the Operator's instruction or, where the Operator cannot be reached, delete the data ourselves within 30 days as the Terms of Use allow.
Complaints. You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State where you live or work or where the alleged infringement occurred. Our lead authority is the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, www.uoou.gov.cz. We would appreciate the chance to address your concern first.
12. Children
The Dialogis platform is for adults. Minds must not be directed at children under 16 (under 15 in the Czech Republic) unless the Operator has told us and implemented the protections the law requires. If you believe a child has provided personal data through a Mind, contact the Operator or us and we will delete it.
13. Cookies and browser storage
Our websites, the admin platform, the chat widget and hosted pages use only strictly necessary cookies and browser storage (sign-in sessions, security tokens, your language choice, and the chat session so a conversation can continue). We use no advertising or social-media tracking technologies. We measure how our public websites and the admin platform are used with analytics software we host ourselves, which sets no cookies, stores nothing on your device, keeps no IP addresses and cannot recognise a visitor across days; it links a visit to our website with a sign-up in the admin platform only within the same day. Details are in the Cookie & Storage Notice.
14. Marketing communications
We may send existing customers occasional emails about new features, plans and events, relying on the existing-customer exception in Czech Act No. 480/2004 Coll. and Article 13 of the ePrivacy Directive. Every such email includes an unsubscribe link, and you can also opt out by emailing us. We do not send marketing to End Users of Minds; any marketing by an Operator is the Operator's responsibility and requires the opt-in the law demands.
15. Changes to this policy
We will update this policy when the service, our providers or the law change. The version and effective date appear at the top of the page, and previous versions are listed at dialogislabs.com/legal. For material changes we will notify Customers by email and in the platform at least 30 days in advance where the change affects them adversely.
16. Contact
Dialogis.ai s.r.o. · Sokolská 1883/8, Nové Město, 120 00 Prague 2, Czech Republic · ID No. 23985348 · Data box w933rn4 Privacy requests: hello@dialogis.io (subject "Privacy") Deletion instructions: dialogislabs.com/privacy/data-deletion WhatsApp-specific notice for Operators' chatbots: dialogislabs.com/privacy/whatsapp