Legal
Privacy Notice
What we collect on this website, why we collect it, how long we keep it, and how to make a request. Last updated August 10, 2026.
01Scope and controller
Dipp AI Technologies, Inc., One Manhattan West, 51st Floor, New York, NY, United States, is the controller of personal information described in this notice. It covers this website, account registration, research downloads, briefing requests, and correspondence with us.
It does not cover customer data processed inside a deployed Orcher tenant. For that data the customer is the controller and we act as processor under the data processing agreement in their contract.
02Information we collect
We collect only what we need to run the site and respond to you:
- Account details you provide: name, work email, organization, job title, and password credentials handled by our authentication provider.
- Correspondence: the content of briefing requests, research correspondence, and security disclosures you send us.
- Activity records: which research documents you download, and the date of the download, so we can honour licensing and follow up.
- Technical data: IP address, browser and device type, referring page, and pages viewed, collected in server and security logs.
We do not knowingly collect information from children, and we ask that you never send us special-category, patient, or client data through this website.
03How we use it
We use personal information to operate and secure the site, authenticate accounts, deliver requested research, respond to briefing and disclosure requests, tell you about new research when you have asked to hear from us, and meet legal or accounting obligations.
We do not sell personal information, and we do not share it with advertising networks or use it for cross-context behavioural advertising.
We do not use your correspondence or account details to train foundation models.
04Legal bases
Where the GDPR or UK GDPR applies, we rely on: contract, to give you an account and the materials you request; legitimate interests, to secure the site, understand which research is read, and contact professionals about relevant work; consent, for marketing email where consent is required; and legal obligation, for records we must keep.
Where we rely on legitimate interests, you may object at any time by writing to legal@dippai.com.
05Service providers
We keep the vendor list short and share only what each vendor needs. We currently use providers for cloud hosting and content delivery, managed database and authentication, transactional and announcement email, and product analytics and error monitoring.
Each provider is bound by contract to process personal information only on our instructions and to apply appropriate security measures. We will name our subprocessors on request to any customer or account holder.
06International transfers
We are based in the United States and process information there. When we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we use the European Commission's Standard Contractual Clauses together with additional safeguards where required.
07Retention
Account and download records are kept while your account is active and for up to twenty-four months afterwards, so we can evidence research licensing. Correspondence is kept for up to thirty-six months. Security and server logs are kept for up to twelve months. We keep records longer only where law requires it.
08Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the use of your personal information, to object to processing, to withdraw consent, and to be free from discrimination for exercising these rights.
Write to legal@dippai.com and we will respond within the period the applicable law requires — within forty-five days for California requests and within one month for GDPR requests. We may need to verify your identity before acting. EU and UK residents may also complain to their supervisory authority.
09Security
We use encryption in transit and at rest, role-based access control, least-privilege administrative access, row-level authorization on our databases, and logging of privileged actions. No system is perfectly secure, but we design for the same accountability we ask enterprises to expect of AI.
Suspected vulnerabilities can be reported to legal@dippai.com; we acknowledge every report and do not pursue good-faith researchers.
10Changes to this notice
We will update this notice as our practices change and will revise the date at the top of the page. Material changes will be announced on the site and, where we hold your address, by email.
Contact
Privacy requests, subprocessor lists, and data protection questions:
Dipp AI Technologies, Inc.One Manhattan West, 51st Floor
New York, NY, United States
legal@dippai.com
Bring one workflow.
Briefings run against your directive, your role model, and your systems of record.
