PRIVACY POLICY

Version 1.3 • Effective: 21 July 2026

DIKAI LTD — dikigoros.ai Service

1. At a glance

This short summary captures the essentials of the Policy. Please read the full text for the complete picture.

  • Controller: DIKAI LTD (HE 465697), Nicosia, Cyprus.

  • What we do with your data: we provide your account and the dikigoros.ai subscription service; we process your queries and documents through artificial intelligence; we bill your subscription through Stripe; we communicate with you about the Service.

  • Where it is hosted: on EU infrastructure (Frankfurt via Vercel; database on Neon in Frankfurt, Germany (eu-central-1)).

  • Third-party recipients: a small number of specialist providers (hosting, database, payments, AI), each bound by an Article 28 GDPR data processing agreement.

  • Your rights: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, complaint to the Commissioner for Personal Data Protection.

  • Privacy contact: info@dikigoros.ai (DPO: Nicolas Connor Georgiades).

2. About this Policy

This Privacy Policy explains how DIKAI LTD processes personal data in connection with the dikigoros.ai Service. It is the notice we owe you under Articles 13 and 14 of the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Cyprus Law on the Protection of Natural Persons with Regard to the Processing of Personal Data 125(I)/2018.

The Policy applies to visitors of the website, registered users (natural persons or representatives of legal persons), subscribers and persons who contact us. Where we process personal data of third parties through the Service (e.g., counterparties, clients or employees of a user), Section 15 also applies.

3. Data controller

The controller of your personal data is DIKAI LTD (Company Registration Number: HE 465697), a private company limited by shares, incorporated in the Republic of Cyprus.

Registered office: 3 Polyviou Dimitrakopoulou, 2nd Floor, Office 201, 1090 Nicosia, Cyprus.

Telephone: +357 22210075 • Email: info@dikigoros.ai

4. Data Protection Officer

We have appointed a Data Protection Officer (DPO):

Nicolas Connor Georgiades • Email: info@dikigoros.ai

You may contact the DPO on any matter relating to the processing of your personal data or the exercise of your rights.

We collect only the data we need to provide the Service, to support it legally and technically and to comply with our obligations. The table below describes the categories of data we process, the purpose, the legal basis under the GDPR, and how long we retain it.

Data categoryPurposeLegal basisRetention
Account data: name, email, hashed password, optionally job title / company name / role.Account creation and administration; sign-in authentication; communications about the Service.Art. 6(1)(b) GDPR — performance of the contract (the Terms of Use).For the duration of your account. After deletion, twelve (12) months for resolving any open matters and defending against claims.
Subscription and billing data: chosen plan, transaction history, Stripe payment identifier, billing address, VAT number. We do not receive or store the full card number.Payment processing, issue of invoices, accounting and tax compliance.Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(c) (compliance with legal obligation, in particular Cyprus tax and accounting law).Seven (7) years from the end of the relevant tax year, in line with the Cyprus VAT Law 95(I)/2000 and the Cyprus Companies Law Cap. 113.
Input Data: queries, conversation messages, documents and files you upload.Providing AI-generated responses and outputs; preserving your conversation history for your own re-use; technical support and improvement.Art. 6(1)(b) GDPR — performance of the contract.For as long as you keep them in your account. You may delete conversations or files at any time. After deletion, items remain in backups for up to thirty (30) days.
AI outputs: answers, summaries, drafts produced by the Service.Delivery to the user; conversation history; resolution of quality complaints.Art. 6(1)(b) GDPR — performance of the contract.Same duration as the linked Input Data.
Usage data and technical logs: IP address, session identifier, browser/device information, request timestamps, usage counters.Security, abuse detection, load balancing, diagnostics, operational statistics.Art. 6(1)(f) GDPR — legitimate interests (ensuring the secure and reliable operation of the Service).Up to twelve (12) months, unless involved in the investigation of a security incident.
Support communications: emails to support, in-platform messages, attachments.Handling support requests; documenting their resolution; service improvement.Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) (legitimate interest of the Company to monitor and improve).Three (3) years from the last contact.
Marketing communications (only if you consent): emails, newsletters, feature announcements.Informing you about new features, offers and announcements.Art. 6(1)(a) GDPR — consent. For existing customers, Art. 6(1)(f) (soft opt-in) may apply under the electronic communications regime.Until you withdraw your consent or object (an unsubscribe link is included in every communication).
Local storage and similar technologies (see Section 14).Operation of the website and retention of your login session.Art. 6(1)(f) GDPR — legitimate interest in operating the Service securely.See Cookies Policy.

Legitimate interests. Where we rely on legitimate interests, those interests typically consist in safeguarding the security and reliability of the Service, running the business properly and protecting against abuse. We have assessed that this processing is not overridden by your rights and freedoms. You can request a copy of the relevant legitimate interests assessment (LIA) at info@dikigoros.ai.

Special category data. We do not request, and do not wish to receive, special-category data (Art. 9 GDPR — health, ethnic origin, political opinions, religious beliefs, biometrics and the like). If such data is included in your Input Data, our legal basis for processing it as part of the Input Data is your explicit consent provided at the time of submission (Art. 9(2)(a) GDPR), unless another exemption applies.

6. How we use artificial intelligence with your data

Given the fully automated nature of the Service, the following transparency is provided.

Notice of AI use. In accordance with Article 50 of Regulation (EU) 2024/1689 (the EU AI Act), we expressly inform you that when you interact with the Service you are interacting with an artificial intelligence system, not with a lawyer or other natural person.

What we do with your Input Data. When you submit a query or upload a document, your data:

  • Is transmitted encrypted to our servers (Vercel, Frankfurt) and stored in our database (Neon, Frankfurt — eu-central-1);

  • Is sent to the AI systems we use as processors (see Section 8) to generate the response;

  • Is linked to your account so that the response can be returned to you and stored in your conversation history.

No model training without your consent. We do not use your Input Data to train AI models, whether our own or those of third parties. Under the commercial API terms of our AI providers, as currently in force, content submitted through their APIs is not used to train their models by default, and we have not opted in to any such use. Aggregated or de-identified usage information may be used to improve the Service, as described in this Policy. If at any point in the future we wish to request your consent for a limited use of your data for improvement purposes, we will do so by a separate, express and revocable request.

Nature of outputs. AI-generated outputs may contain errors or inaccuracies; they do not constitute legal advice. Details are set out in Section 12 of the Terms of Use. From a data-protection perspective this also means an output may misstate facts about you or about third parties; you are entitled to request rectification of your data (Section 12).

7. Sources of data

We collect your data as follows:

  • Directly from you — when you create an account, activate a subscription, enter queries or upload documents, contact support, or complete forms.

  • Automatically during use — through technical logs, cookies and similar technologies.

  • From third parties — limited and only where necessary: Stripe sends us information about the success or failure of a transaction; if you sign in through an identity provider (e.g., Google, Microsoft, Apple — if offered), we receive the profile information you authorise.

8. Who we share your data with

We do not sell your data and we do not share it for advertising purposes. We share data only with the following categories of recipients, applying the principles of necessity and data minimisation:

8.1 Processors (sub-processors)

The following providers process personal data on our behalf, under a contract that meets the requirements of Article 28 GDPR:

ProviderRoleJurisdictionTransfer mechanism
Vercel Inc.Hosting of the application and serverless functions. Data is hosted in the Frankfurt region (eu-central-1).USA (provider entity); all hosting in the EU — Frankfurt (eu-central-1)EU-US Data Privacy Framework (DPF), with 2021 SCCs as fallback mechanism under Vercel’s DPA.
Neon Inc.Management of the Service database on a server in Frankfurt, Germany (eu-central-1).USA (provider entity); database in the EU — Frankfurt (eu-central-1)EU-US Data Privacy Framework (DPF), with 2021 SCCs as fallback mechanism under Neon’s DPA.
Voyage AI (part of MongoDB Inc. since February 2025)Provider of AI models (embeddings) for the operation of the Service.USAEU-US Data Privacy Framework (DPF) through MongoDB Inc., with 2021 SCCs as fallback mechanism.
Stripe Payments Europe Ltd / Stripe Inc.Processing of subscription payments. Receives payment details directly from you.Ireland (EU) and USAStripe Payments Europe Ltd acts from Ireland; any transfers to the USA are covered by the DPF and 2021 SCCs.
Anthropic, PBCProvider of large language model used to generate AI responses.USAEU-US Data Privacy Framework (DPF), with 2021 SCCs as fallback. Under Anthropic's commercial API terms as in force, our data is not used to train Anthropic's models by default, and we have not opted in to any such use.
Langfuse GmbHMonitoring and diagnostics of AI call performance (where enabled).Germany / EU-region infrastructure where availableProcessing within the EU where available; otherwise 2021 SCCs.
Resend, Inc.Delivery of transactional emails (account verification, password reset, account notifications).USAEU-US Data Privacy Framework (DPF), with 2021 SCCs as fallback.

An up-to-date list of processors, with a short description and jurisdiction, is set out in Section 8.1 of this Policy and, where published, at https://www.dikigoros.ai/sub-processors. We give notice of any new processor at least thirty (30) days before processing begins.

8.2 Other recipients

  • Legal and professional advisers (lawyers, auditors, IT consultants) bound by professional secrecy, where necessary for the conduct of the Company’s affairs.

  • Public authorities, where there is a legal obligation to disclose (e.g., tax authorities, supervisory authorities, court orders).

  • Successors or acquirers of the business, in the context of a corporate reorganisation, in compliance with the GDPR and with notice to you.

9. International data transfers

Although our hosting infrastructure and database are in the EU, some of our providers are established in the United States (see the table in Section 8.1). For the related transfers of personal data outside the EEA:

  • We primarily rely on the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795), where the relevant provider is self-certified.

  • Where the DPF is not available, or as a fallback mechanism, we rely on the Standard Contractual Clauses (Commission Decision (EU) 2021/914).

  • For each transfer we carry out a Transfer Impact Assessment in line with EDPB Recommendations 01/2020, to evaluate whether the laws of the destination country impair the protection.

You can request a copy of the applicable clauses and the transfer impact assessment at info@dikigoros.ai.

10. Retention

We retain your data for as long as is necessary for the purposes for which it was collected and as specifically set out in the table in Section 5. After expiry of the relevant periods, data is securely deleted or anonymised. In the event of a pending judicial, extrajudicial or regulatory matter, the relevant data is retained until its final resolution.

11. Security

We implement appropriate technical and organisational measures to protect your data from unauthorised access, alteration, disclosure or loss. By way of example:

  • Encryption of data in transit (HTTPS with TLS 1.2 or higher) and at rest on our infrastructure (AES-256, provided by our infrastructure providers);

  • Secure storage of passwords using the bcrypt algorithm; passwords are never stored in readable form;

  • Email address verification before any new account is activated;

  • Role-based access controls with the principles of least privilege and segregation of duties applied to our personnel;

  • Logging of critical authentication events in a dedicated audit log (auth audit log);

  • Rate limits on requests per account to protect against abuse and automated attacks;

  • Browser security headers (Content Security Policy, X-Frame-Options, X-Content-Type-Options);

  • Automated backups and point-in-time recovery through our infrastructure providers;

  • Selection of infrastructure providers with recognised security measures, contractually committed under Article 28 GDPR terms;

  • Security-incident response procedures and notification to the Commissioner for Personal Data Protection within 72 hours of becoming aware of a breach, in accordance with Articles 33 and 34 GDPR.

12. Your rights

As a data subject you have the following rights, subject to the conditions of the GDPR:

  • Access — to obtain confirmation and a copy of your data (Art. 15);

  • Rectification of inaccurate or incomplete data (Art. 16);

  • Erasure (the “right to be forgotten”) where the conditions of Art. 17 apply;

  • Restriction of processing (Art. 18);

  • Portability — to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller (Art. 20);

  • Objection to processing based on legitimate interests or for direct marketing purposes (Art. 21);

  • Withdrawal of consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3));

  • Not to be subject to a solely automated decision producing legal or similarly significant effects (Art. 22 — see Section 17);

  • Complaint to the supervisory authority (see Section 19).

13. How to exercise your rights

You can exercise your rights by emailing info@dikigoros.ai or by writing to the Company’s registered office. For your protection, we may ask you for reasonable information to verify your identity.

We will respond without undue delay and in any event within one (1) month of receiving the request. That period may be extended by a further two (2) months where necessary, taking account of the complexity and number of requests; we will inform you of any extension within the first month.

Exercising your rights is, in principle, free of charge. For manifestly unfounded or excessive requests we may charge a reasonable fee or refuse to act, explaining our reasons.

14. Cookies and similar technologies

The Service does not set any first-party cookies. To keep you signed in and to remember your language preference, we store a small amount of information in your browser's local storage. Our payment provider, Stripe, may set its own cookies on its hosted checkout pages. Full details are set out in the Cookies Policy at https://www.dikigoros.ai/cookies.

Because we set no cookies, and the local storage we use is either strictly necessary or stored at your explicit request, no consent banner is required. You can clear this storage and control or delete cookies at any time through your browser settings. If we introduce cookies that require consent, we will ask for it beforehand.

15. Third-party personal data within your Input Data

If you include personal data of third parties in your Input Data (e.g., counterparties, employees, clients or opponents of a user), you act as controller or processor for that data, while we act as processor on your behalf.

In that case you confirm that you have a lawful basis to transmit such data to us, that you have informed the third parties where required and that you will support us in responding to any requests to exercise rights relating to them. For professional users (lawyers, in-house legal teams), we can enter into a separate Data Processing Agreement (DPA) to govern this scenario. Please contact info@dikigoros.ai.

16. Children

The Service is not directed at minors under the age of 18. We do not knowingly collect personal data of minors. If we become aware that an account belongs to a minor, we will close the account and delete the related data.

17. Automated decision-making and profiling

The Service produces outputs through artificial intelligence, without human intervention. Those outputs are informational and, from our side, do not take decisions producing legal or similarly significant effects on you within the meaning of Article 22 GDPR. Under the Terms of Use, any action or decision you take on the basis of Service outputs is taken by you, at your own responsibility and after your own verification.

We do not create behavioural or personality profiles based on your data for advertising or similar purposes.

18. Changes to this Policy

We may update this Policy to reflect changes in our practices, in our processors or in legal requirements. Where the change is material we will notify you in good time by email or by a clearly visible notice within the Service. The date of last update is shown at the top of the document. Older versions are available on request at info@dikigoros.ai.

19. Complaints

If you believe that the processing of your data does not comply with the GDPR or Cyprus law, we encourage you to contact us first at info@dikigoros.ai so we can look into it.

In any case, you retain the right to lodge a complaint with the Cyprus supervisory authority:

Office of the Commissioner for Personal Data Protection

1 Iasonos Street, 1082 Nicosia, Cyprus

Telephone: +357 22818456 • Email: commissioner@dataprotection.gov.cy • Website: www.dataprotection.gov.cy

If you live in another EU Member State, you may alternatively lodge a complaint with the supervisory authority of your habitual residence.

20. Contact

For any question regarding this Policy or the processing of your data:

DIKAI LTD (HE 465697)

3 Polyviou Dimitrakopoulou, 2nd Floor, Office 201, 1090 Nicosia, Cyprus

Telephone: +357 22210075

Email: info@dikigoros.ai

DPO: Nicolas Connor Georgiades — info@dikigoros.ai