Privacy Notice
What personal data Dataflag collects, why, and what you can do about it.
Effective date: August 16, 2026
1. Overview
Dataflag provides a vendor data-governance rating service. We collect and process personal information to provide, secure, support, bill for, and improve the Service as described in this Notice.
Dataflag does not sell personal information and does not use Customer Content to train, fine-tune, improve, or develop AI/ML models by default.
2. Roles
For account, website, billing, and business-contact information, Dataflag generally acts as a controller or business. For personal information contained in Customer Content that a customer submits to the Service, Dataflag generally acts as a processor or service provider under the customer's instructions, as described in the Data Processing Addendum.
3. Personal Information We Collect
We may collect the following categories of personal information:
- Account data, such as name, email, workspace, role, password hash, verification status, and authentication records.
- Customer workspace data, such as vendor records, internal notes, notification recipients, rating preferences, and alert settings.
- Customer Content, such as uploaded files, vendor legal documents, prompts, source URLs, document text, generated chunks, ratings, evidence artifacts, outputs, and reports.
- AI-processing data, such as prompts sent to model providers and model responses used to produce ratings and audit artifacts.
- Billing data, such as plan, subscription status, billing contact, billing address, tax information, Stripe customer and subscription identifiers, invoice data, and payment-method references.
- Communications data, such as support messages, transactional email metadata, and alert-recipient information.
- Security and usage data, such as IP address, user agent, session records, CSRF/authentication events, audit logs, and service logs.
- Necessary cookies used for sign-in, session security, CSRF protection, and billing workflow continuity.
Dataflag uses third-party services only as described in this Notice and on the Subprocessors page. Public pages may load fonts from third-party font providers unless Dataflag self-hosts those assets.
4. How We Use Personal Information
We use personal information to:
- create and administer accounts and workspaces;
- provide vendor intake, document processing, DGAIR scoring, reports, alerts, monitoring, and exports;
- route Customer Content to subprocessors needed to provide the Service, including AI/model providers for inference;
- secure the Service, detect abuse, troubleshoot errors, and maintain audit records;
- process subscriptions, invoices, tax calculations, and payment workflows;
- send transactional emails, account notices, security notices, billing notices, and customer-configured alerts;
- respond to support requests and legal requests; and
- improve the Service in non-training, non-commercializing ways.
We do not use Customer Content, prompts, uploads, files, outputs, or customer-specific reports to train, fine-tune, improve, or develop AI/ML models by default.
5. AI and Model Providers
Dataflag uses AI/model providers to process Customer Content for inference and rating generation.
Dataflag does not authorize AI/model providers to train on, reuse, sell, or retain Customer Content except as needed to provide the Service and comply with law.
6. How We Share Personal Information
We share personal information only:
- with subprocessors and service providers under contract and purpose limitation;
- with payment processors to process subscriptions and payment workflows;
- with transactional email providers to send account, billing, and alert emails;
- with AI/model providers to generate ratings and outputs requested through the Service;
- with professional advisors, auditors, or authorities where legally required or necessary to protect rights and security;
- in connection with a merger, acquisition, financing, or corporate transaction, subject to continuity of confidentiality and privacy obligations; or
- with Customer's instruction or consent.
Dataflag does not sell personal information and does not share personal information for cross-context behavioral advertising or targeted advertising.
7. Retention
| Data category | Retention period |
|---|---|
| Account and workspace profile data | Active account term plus 30 days after deletion or termination, unless longer retention is required by law or legitimate dispute/security needs. |
| Customer Content, uploaded files, prompts, source text, outputs, rating artifacts, and customer-specific reports | Active subscription term plus 30 days after deletion request or termination; backups overwritten within 90 days. |
| LLM request/response audit artifacts | Active subscription term plus 30 days, unless retained longer for legal hold, security investigation, dispute resolution, or financial recordkeeping obligations. |
| Authentication sessions | Access sessions expire after approximately 15 minutes; refresh sessions expire after approximately 14 days unless revoked earlier. |
| Security, audit, and access logs | 12 months, unless needed for security investigation, legal hold, or compliance. |
| Billing, tax, invoice, and payment records | 7 years or the period required for tax, accounting, and legal obligations. |
| Transactional email logs and support communications | 24 months, unless a longer period is required for legal, security, billing, or support continuity reasons. |
8. Deletion and Export
Customers may request export, return, deletion, or correction of Customer Content by contacting hello@dataflag.io. We will complete verified deletion requests within 30 days for active production systems and within 90 days for backups, subject to legal holds, security investigations, dispute resolution, and billing/tax record obligations.
9. Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing of personal information, and to opt out of sale, sharing, targeted advertising, or certain profiling. We do not sell personal information or share it for targeted advertising. You may exercise rights by contacting hello@dataflag.io. We may need to verify your identity and authority before fulfilling a request.
10. International Transfers
Dataflag and its subprocessors may process personal information in the United States and other countries where they operate. Where required, Dataflag uses appropriate transfer mechanisms such as standard contractual clauses or other lawful safeguards.
11. Changes
We will provide notice of material changes to this Notice. If a change materially expands our rights to use Customer Content for AI training, sale, sharing, or commercialization, we will not apply that change to Customer Content collected before the change without affirmative consent where required by this Notice or applicable law.