Introduction

Privacy policy for personal data and AI services

Duale AI's privacy policy describes how the company collects, uses, and protects personal data across its website, SaaS platform, and communications.

Privacy policy covering data collection, retention, security, and GDPR rights for Duale AI's website, SaaS platform, and communications.

  • Data is hosted on Hetzner in Germany with Cloudflare for website and network protection.
  • Retention ranges from 93 days for technical logs to 10 years for invoices.
  • Customers processing third-party data are data controllers; Duale AI acts as processor.
  • Duale AI encrypts data in transit and applies application-level encryption at rest for Library documents.
  • Global Privacy Control and Do Not Track signals are honoured as refusal of optional cookies.

Summaries were generated by AI. Generative AI is experimental.

Introduction

This policy describes how Duale AI collects, uses, and protects personal data.

It applies to the website, the SaaS platform, and communications.

See also the Terms of use for AI agent orchestration and the Terms of sale for the prepaid credit platform.

Language. This policy exists in French and English. If the two diverge, the French version prevails.

Data controller

DUALE AI SAS; share capital €10,000; Paris Trade Registry 994 521 128; 60 rue François 1er, 75008 Paris, France

DPO: contact+dpo@mail.duale.ai

Data collected

Data you provide: name, email, company information, payment details, support messages.

Automatic collection: IP address, device information, pages visited, logs.

AI Services: prompts, documents, generated outputs, configurations.

Internal models: Duale AI uses open-source models hosted on European infrastructure for document indexing and search result ranking. This processing stays on Duale AI’s infrastructure.

If you submit third-party personal data to AI Agents, you are the data controller (Duale AI acts as data processor).

Purposes of processing

PurposeLegal basis
Account, billing, AI servicesContract
Security, improvement, statisticsLegitimate interest
MarketingYour consent
Legal obligationsLegal requirement
  • Purpose
    Account, billing, AI services
    Legal basis
    Contract
  • Purpose
    Security, improvement, statistics
    Legal basis
    Legitimate interest
  • Purpose
    Marketing
    Legal basis
    Your consent
  • Purpose
    Legal obligations
    Legal basis
    Legal requirement

Data recipients

Internal: only authorized employees, following least-privilege principle.

Subprocessors: Subprocessors and data transfer safeguards. Duale AI notifies any addition or replacement 30 days before if the subprocessor is in the European Economic Area, or 90 days before if outside the European Economic Area. Objections: contact+legal@mail.duale.ai

Others: competent authorities upon legal request, professional advisors (lawyers, auditors), acquirer in case of sale (prior notification).

Data location

Hetzner hosts the application data in Germany. The website and network protection run through Cloudflare.

Transfers outside the European Economic Area: Data Privacy Framework where it applies, or 2021 standard contractual clauses with supplementary measures where required.

Details: Subprocessors and data transfer safeguards

Retention periods

DataDuration
Active accountDuration of contract
Closed account+ 5 years
Connection logs12 months
Audit log of configuration, access, Tool dispatch, and task lifecycle events12 months
Usage analytics12 months
Invoices10 years (legal requirement)
AI contentContract + 30 days
Technical traces, which can contain prompts and outputs12 months
Technical logs and metrics93 days
Website and interface usage events6 months
Cookies consent6 months

Technical traces support diagnosis and service operation. They can contain the content of a prompt, a generated output, a tool argument, and a tool result. Access is limited to authorized Duale AI staff who need the traces for those purposes. They are not exposed in the web interface or through the API.

A closed account is kept 5 years under the civil limitation period (Article 2224 French Civil Code), invoices 10 years under Article L123-22 of the French Commercial Code.

Duale AI further keeps, for twelve months from each message, the selected model, the timestamp, and the task identifier. These logs contain no message content and outlive the contract, to establish and defend legal rights. The detail is in the Terms of sale for the prepaid credit platform, section Evidence and cooperation.

After: deletion or anonymization.

Security

Duale AI encrypts data in transit. It applies application-level encryption at rest to Library documents and derived search data, database backups, and reporting copies. Page access can cache eligible tenant-scoped resources from public pages for about seven days without application-level encryption at rest. Requests that contain cookies or authorization credentials bypass that cache. Duale AI requires multi-factor authentication for sensitive account changes, separates data per Customer, controls access by role, and records configuration, access, Tool dispatch, and task lifecycle events. The binding list is in the Terms of sale for the prepaid credit platform, section Data processing agreement (Article 28 GDPR).

In case of breach. For the data Duale AI controls (account, billing, and security), Duale AI notifies the supervisory authority without undue delay and, where feasible, within 72 hours (GDPR Art. 33(1)).

For the Content you submit, Duale AI acts as processor: it notifies you without undue delay (Art. 33(2)), and you must notify your supervisory authority if the breach warrants it.

When an incident requires notification under applicable law, Duale AI alerts you within 24 hours and delivers a final report within one month. Outside those cases, Duale AI informs you as soon as it can.

Contact: contact+security@mail.duale.ai

Your rights

Under GDPR (Art. 15-21), you have these rights:

  • Access your data (Art. 15)
  • Rectify inaccurate information (Art. 16)
  • Erase your data (Art. 17)
  • Restrict processing (Art. 18)
  • Port your data in structured format (Art. 20)
  • Object to processing (Art. 21)
  • Withdraw consent at any time without affecting prior processing (Art. 7.3)

Contact: contact+privacy@mail.duale.ai. Duale AI responds within one month. It can extend this period by two months for complex requests.

Recourse: complaint to your supervisory authority (for France: CNIL, https://www.cnil.fr (opens in a new tab))

Duale AI does not sell personal data, under any definition.

Cookies

Essential (no consent required): functionality, authentication.

Optional (your choice): audience measurement, marketing. Your consent is valid for 6 months (CNIL recommendation).

Cookie banner on first visit. Modify or withdraw consent in page footer.

Third parties: Crisp (support), Cloudflare (website and network protection). Duale AI operates authentication internally.

Browser signals

Duale AI honours Global Privacy Control and Do Not Track signals. When your browser sends one, Duale AI treats it as a refusal of optional cookies and switches off the matching tracking. You do not need to do anything else.

These signals do not affect the cookies essential to functionality and authentication, which do not rely on your consent.

Minors

B2B platform, reserved for professionals. Access is limited to Users whom a Customer authorizes and who are at least 18 years old. Duale AI does not knowingly collect data from minors. Report concerns: contact+privacy@mail.duale.ai

Automated decisions and artificial intelligence

Duale AI does not use your data for automated decisions producing legal effects concerning you (GDPR Art. 22).

AI transparency (EU AI Act 2024/1689): Platform AI Agents are artificial intelligence systems. The Customer’s code calls the Platform through the SDK and the API: it exposes no conversational interface to natural persons. If a Customer re-exposes outputs to natural persons, that Customer must tell them that they are interacting with an AI. See the Terms of use for AI agent orchestration, section Transparency: Who informs whom.

AI Agents configured by Customers can process third-party data. In this case:

  • The Customer is data controller (Duale AI = processor)
  • The Customer is responsible for GDPR Art. 22 compliance if Agents make automated decisions affecting third parties

Processing on behalf of Customers

When the Customer uses the Platform to process third-party personal data, the Customer is data controller and Duale AI acts as data processor (GDPR Art. 28). The data processing agreement forms a section of the Terms of sale for the prepaid credit platform and sets out Duale AI’s commitments.

Contact: contact+legal@mail.duale.ai

Modifications

Duale AI notifies substantial changes by email 30 days before they take effect.

Contact