Legal
Privacy Notice
What we collect on this website, why we collect it, how long we keep it, and how to make a request. Last updated August 10, 2026.
01Scope and controller
Dipp AI Technologies, Inc., One Manhattan West, 51st Floor, New York, NY, United States, is the controller of personal information described in this notice. It covers this website, account registration, research downloads, briefing requests, and correspondence with us.
It does not cover customer data processed inside a deployed Orcher tenant. For that data the customer is the controller and we act as processor under the data processing agreement in their contract.
02Information we collect
We collect only what we need to run the site and respond to you:
- Account details you provide: name, work email, organization, job title, and password credentials handled by our authentication provider.
- Correspondence: the content of briefing requests, research correspondence, and security disclosures you send us.
- Activity records: which research documents you download, and the date of the download, so we can honour licensing and follow up.
- Technical data: IP address, browser and device type, referring page, and pages viewed, collected in server and security logs.
We do not knowingly collect information from children, and we ask that you never send us special-category, patient, or client data through this website.
03How we use it
We use personal information to operate and secure the site, authenticate accounts, deliver requested research, respond to briefing and disclosure requests, tell you about new research when you have asked to hear from us, and meet legal or accounting obligations.
We do not sell personal information, and we do not share it with advertising networks or use it for cross-context behavioural advertising.
We do not use your correspondence or account details to train foundation models.
04Legal bases
Where the GDPR or UK GDPR applies, we rely on: contract, to give you an account and the materials you request; legitimate interests, to secure the site, understand which research is read, and contact professionals about relevant work; consent, for marketing email where consent is required; and legal obligation, for records we must keep.
Where we rely on legitimate interests, you may object at any time by writing to legal@dippai.com.
05Service providers
We keep the vendor list short and share only what each vendor needs. We currently use providers for cloud hosting and content delivery, managed database and authentication, transactional and announcement email, and product analytics and error monitoring.
Each provider is bound by contract to process personal information only on our instructions and to apply appropriate security measures. We will name our subprocessors on request to any customer or account holder.
06International transfers
We are based in the United States and process information there. When we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we use the European Commission's Standard Contractual Clauses together with additional safeguards where required.
07Retention schedule
We keep each category of information only as long as it has a purpose:
- Briefing, contact, and other correspondence: up to 36 months from the last exchange.
- Research and report access records: up to 24 months, so we can evidence licensing.
- Newsletter subscription and topics: until you unsubscribe, then 12 months of suppression data so we do not re-add you.
- Job applications and uploaded résumés: up to 12 months after a decision, unless you ask us to keep them on file.
- Account and profile records: while the account is active, then up to 24 months.
- Consent records: for the life of the related record plus 24 months, as proof that we had permission.
- Security and server logs: up to 12 months.
- Deletion requests: a minimal audit entry is kept indefinitely to evidence that we acted on the request; it holds no content we deleted.
We keep records longer only where law requires it.
08Consent records and versions
Every form on this site shows the same consent statement and records your answer against a version identifier — currently 2026-01-v1. We store the statement text you were shown, the purposes you agreed to, the time, and whether you accepted or declined.
When we change the wording, the version identifier changes with it, and consent captured under an earlier version is never silently carried over. You can ask us for a copy of your consent record at any time.
Declining consent is always an option: the form simply is not submitted, and no personal information is stored beyond the record of the decline itself.
09Deleting your data
You can start a deletion yourself at /privacy/delete-request. Enter the email address you used with us and we send a one-time confirmation link to that address — nothing is deleted until you follow it, so nobody can erase someone else's records.
Once confirmed, we remove briefing and contact requests, research access records, newsletter subscriptions, job applications and uploaded résumés, your account and profile, and the related consent records. We then email you a summary of exactly what was removed.
The link expires after 24 hours. Every step — requested, verified, executed — is written to an internal audit trail so we can evidence compliance without keeping the deleted content.
10Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the use of your personal information, to object to processing, to withdraw consent, and to be free from discrimination for exercising these rights.
Write to legal@dippai.com and we will respond within the period the applicable law requires — within forty-five days for California requests and within one month for GDPR requests. We may need to verify your identity before acting. EU and UK residents may also complain to their supervisory authority.
11Security
We use encryption in transit and at rest, role-based access control, least-privilege administrative access, row-level authorization on our databases, and logging of privileged actions. No system is perfectly secure, but we design for the same accountability we ask enterprises to expect of AI.
Suspected vulnerabilities can be reported to legal@dippai.com; we acknowledge every report and do not pursue good-faith researchers.
12Changes to this notice
We will update this notice as our practices change and will revise the date at the top of the page. Material changes will be announced on the site and, where we hold your address, by email.
Contact
Privacy requests, subprocessor lists, and data protection questions:
Dipp AI Technologies, Inc.One Manhattan West, 51st Floor
New York, NY, United States
legal@dippai.com
Ask us to delete your data.
Start a verified deletion request and we will confirm by email before anything is removed. Consent statement version 2026-01-v1.
