Privacy Policy
Dataetic handles two very different kinds of data, and the distinction matters: the account data we hold about you as a customer, where we are the controller, and the data you connect to the platform, where you are the controller and we only process it on your instructions.
1Two roles, two kinds of data
This policy explains how Dataetic Private Limited, registered at No. 25, Iyyan Thiruvalluvar Street, Leelavathi Nagar 8th Street, Gerugambakam, Chennai 600122, Tamil Nadu, India (Dataetic, we, us), handles personal data. It covers our website at dataetic.com, our documentation site, and the Dataetic platform at app.dataetic.com.
Nearly every confusing question about a data platform's privacy policy comes from collapsing two separate things into one. We keep them apart:
| Kind of data | Our role | What it is |
|---|---|---|
| Account & website data | We are the controller | Who you are, how you signed up, how you use the product, what you email us. We decide why and how this is processed, and this policy governs it. |
| Connected data | We are your processor | The data the platform reads from your databases, warehouses, storage and SaaS applications. You decide why and how it is processed. We act only on your instructions — see clause 11. |
2What we collect
Data you give us
- Account data — name, work email, password (stored only as a salted hash), organisation name, job title where you provide it.
- Billing data — billing contact, billing address, tax identifiers, and the plan you are on. Card details go directly to our payment provider; we receive a token, the card type and the last four digits, never the full number.
- Configuration you create — connection settings, workflow definitions, dashboard layouts, agent instructions. These may contain personal data if you put it there.
- Communications — beta access requests, support emails, bug reports and anything else you send us, including attachments.
Data we collect automatically
- Usage and telemetry — pages and features used, actions taken, workflow and agent run metadata (start time, duration, row counts, success or failure), and error diagnostics. This is about how the platform ran, not about the content it moved.
- Device and connection data — IP address, browser and version, operating system, language, referring page, timestamps.
- Security and audit logs — sign-in attempts, session records, permission changes, and administrative actions in your workspace.
- Cookies and similar technologies — see our Cookie Policy.
Data from other sources
- If you sign in through an identity provider, that provider tells us your name, email address and the fact you authenticated.
- Our payment provider tells us whether a payment succeeded or failed.
- We may use publicly available business information — a company website or public registry — to understand who has requested beta access.
3Why we use it, and our legal basis
If you are in the UK, EU or another region with equivalent law, the table below is our record of purpose and legal basis. Where we rely on legitimate interests, we have assessed that our interest does not override your rights, and you may object.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and administer your account; authenticate you | Account data | Performance of a contract |
| Provide, operate and maintain the platform | Account, configuration, usage | Performance of a contract |
| Take payment and keep tax records | Billing data | Contract; legal obligation |
| Support you, and answer what you email us | Communications, account, usage | Contract; legitimate interests |
| Debug faults, monitor performance and capacity | Usage, telemetry, logs | Legitimate interests |
| Keep the platform secure; detect abuse and fraud | Device data, security logs | Legitimate interests; legal obligation |
| Improve the product and decide what to build | Aggregated usage, feedback | Legitimate interests |
| Tell you about changes that affect you, including to this policy | Account data | Contract; legal obligation |
| Send product news and marketing | Account data | Consent, or legitimate interests for existing customers with an opt-out in every message |
| Analytics on how the website and product are used | Cookie and usage data | Consent for non-essential cookies |
| Comply with the law; establish or defend legal claims | As needed | Legal obligation; legitimate interests |
What we do not do
- We do not sell personal data, and we do not share it for cross-context behavioural advertising.
- We do not make decisions about you by solely automated means that produce legal or similarly significant effects, and we do not profile you for advertising.
4Connection credentials
To connect a system, you give us a credential — a password, API key, service account key or OAuth token. This deserves its own clause because it is the most sensitive thing you hand us.
- Credentials are encrypted at rest using a managed key service, and encrypted in transit.
- They are used only to operate the connections you configured, and only by the parts of the platform that need them.
- They are not displayed back to you in full, not written to application logs, and not included in diagnostic bundles.
- When you delete a connection, we delete its stored credential. You should also revoke it in the source system — deleting our copy does not invalidate the credential itself.
5AI features and your data
The platform includes AI agents that answer questions over your connected data and help you build queries and workflows. Here is exactly what that means for your data.
- Your data is not used to train models. Not ours, not a third party's. We contract with our model providers on terms that prohibit training on data we send them, and we do not opt in on your behalf.
- What gets sent. To answer a question, an agent may send the model provider your prompt, relevant schema or metadata, and the specific rows needed to answer it. Only what the request requires, for the duration of the request.
- Retention at the provider. Providers may retain a request briefly for abuse monitoring, then delete it. They do not retain it for their own product development.
- Conversations. Agent conversations are stored in your workspace so you can return to them, and they are Customer Data under our Terms. You can delete them.
- You choose the exposure. Where the platform offers a self-hosted or in-region model option, using it keeps the data within that boundary. If a connection is never exposed to an agent, its data never reaches a model provider.
7International transfers
We and our processors operate in more than one country, so personal data may be
transferred outside the country where you are based, including to
the United States (Google Cloud region us-central1).
Where we transfer personal data out of the UK or EEA to a country without an adequacy decision, we rely on an appropriate safeguard — usually the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum — and we assess whether additional measures such as encryption are needed. You can ask us for a copy of the safeguard we rely on for a particular transfer.
If your organisation needs its data to stay in a specific region, tell us before you connect anything — data residency is a core concern of this product and we would rather configure it correctly at the start.
8How long we keep it
We keep personal data only as long as we need it for the purpose we collected it for, or as long as the law requires.
| Data | Retention |
|---|---|
| Account data | While your account is open, then deleted within 30 days of closure |
| Connected data (Customer Data) | Under your control; on account closure, exportable for 30 days, deleted from active systems within 30 days and from backups within 90 days |
| Connection credentials | Deleted when you delete the connection or close the account |
| Billing and tax records | 8 years, as tax law requires |
| Security and audit logs | Up to 12 months |
| Application and error logs | Up to 90 days |
| Support correspondence | Up to 24 months after the matter is closed |
| Aggregated, de-identified statistics | Indefinitely — these no longer identify anyone |
| Marketing contact record | Until you unsubscribe, plus a suppression record so we do not contact you again |
Backups are held on a rolling schedule, so deleted data may persist in a backup for a short period after deletion from active systems before it is overwritten.
9How we protect it
We take security seriously because the whole premise of the product is that your data stays under your control. Our measures include:
- encryption in transit (TLS) and at rest;
- connection credentials encrypted with a managed key service, separate from application data;
- role-based access control internally, on a least-privilege and need-to-know basis, with access reviewed periodically;
- multi-factor authentication on administrative access to production systems;
- network isolation between components, and separation of production from development environments;
- audit logging of administrative and security-relevant events;
- encrypted backups and tested restore procedures;
- secure development practices, dependency scanning, and code review before release;
- an incident response process, including assessment, containment and notification.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data, we will notify the relevant supervisory authority within 72 hours where the law requires it, and tell you without undue delay where the breach is likely to result in a high risk to you.
To report a vulnerability, email hello@dataetic.com. Please report privately and give us a reasonable chance to fix it — never in a public issue.
10Your rights
Depending on where you live, you have some or all of the following rights over the personal data for which we are the controller:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have data deleted where we no longer have a valid reason to keep it.
- Restriction — have us pause processing while a dispute about it is resolved.
- Portability — receive data you gave us in a structured, machine-readable format, or have it sent to another provider.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent — where we rely on consent, withdraw it, without affecting processing already carried out.
- No automated decisions — not be subject to a solely automated decision with legal or similarly significant effects. We do not make such decisions.
- Non-discrimination — for California residents, not receive worse service for exercising your rights.
How to exercise them
Email hello@dataetic.com. We will respond within one month (45 days for California residents), and will tell you if we need longer because the request is complex. There is no charge unless a request is manifestly unfounded or excessive. We may need to verify your identity first, and we will only ask for what is necessary to do so. An authorised agent may act for you with written proof of authority.
If you are not satisfied
Please raise it with us first — we would rather fix it. You also have the right to complain to your data protection authority: in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, the authority in your country of residence or workplace. We have no establishment in the UK or the EEA, so no single lead supervisory authority applies to us — a complaint goes to the authority where you live or work.
11When we act as your processor
For connected data, you are the controller and we are your processor. In that role we commit to:
- process it only on your documented instructions, and tell you if we believe an instruction breaks the law;
- apply the security measures in clause 9;
- bind our sub-processors to equivalent obligations, and remain responsible for their performance;
- ensure our personnel are subject to confidentiality obligations;
- help you respond to data subject requests and, where needed, to a data protection impact assessment or a regulator;
- notify you without undue delay of a personal data breach affecting your data;
- delete or return your data at the end of the service, per clause 12 of the Terms;
- make available the information you reasonably need to demonstrate our compliance.
If you need these commitments in a signed data processing agreement, including Standard Contractual Clauses, request one at hello@dataetic.com.
12Children's data
The platform is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact hello@dataetic.com and we will delete it. You must not connect data about children to the platform without a lawful basis and appropriate safeguards of your own.
13Changes to this policy
We will update this policy as the product develops. When we do, we change the effective date at the top of this page. For a change that materially affects how we handle your personal data, we will give you notice by email or in the application before it takes effect — and where the law requires consent for the change, we will ask for it rather than assume it.
14How to contact us
- Privacy and data subject requests — hello@dataetic.com
- Security reports — hello@dataetic.com
- General enquiries — hello@dataetic.com
- Data controller — Dataetic Private Limited, No. 25, Iyyan Thiruvalluvar Street, Leelavathi Nagar 8th Street, Gerugambakam, Chennai 600122, Tamil Nadu, India
- Data protection officer or representative — none appointed. We have no establishment in the UK or the EEA. Should we begin offering the service to individuals there, a representative under UK/EU GDPR Article 27 may become necessary and this page will be updated.