Legal

Privacy Notice

What we collect on this website, why we collect it, how long we keep it, and how to make a request. Last updated August 10, 2026.

01Scope and controller

Dipp AI Technologies, Inc., One Manhattan West, 51st Floor, New York, NY, United States, is the controller of personal information described in this notice. It covers this website, account registration, research downloads, briefing requests, and correspondence with us.

It does not cover customer data processed inside a deployed Orcher tenant. For that data the customer is the controller and we act as processor under the data processing agreement in their contract.

02Information we collect

We collect only what we need to run the site and respond to you:

  • Account details you provide: name, work email, organization, job title, and password credentials handled by our authentication provider.
  • Correspondence: the content of briefing requests, research correspondence, and security disclosures you send us.
  • Activity records: which research documents you download, and the date of the download, so we can honour licensing and follow up.
  • Technical data: IP address, browser and device type, referring page, and pages viewed, collected in server and security logs.

We do not knowingly collect information from children, and we ask that you never send us special-category, patient, or client data through this website.

03How we use it

We use personal information to operate and secure the site, authenticate accounts, deliver requested research, respond to briefing and disclosure requests, tell you about new research when you have asked to hear from us, and meet legal or accounting obligations.

We do not sell personal information, and we do not share it with advertising networks or use it for cross-context behavioural advertising.

We do not use your correspondence or account details to train foundation models.

05Service providers

We keep the vendor list short and share only what each vendor needs. We currently use providers for cloud hosting and content delivery, managed database and authentication, transactional and announcement email, and product analytics and error monitoring.

Each provider is bound by contract to process personal information only on our instructions and to apply appropriate security measures. We will name our subprocessors on request to any customer or account holder.

06International transfers

We are based in the United States and process information there. When we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we use the European Commission's Standard Contractual Clauses together with additional safeguards where required.

07Retention schedule

We keep each category of information only as long as it has a purpose:

  • Briefing, contact, and other correspondence: up to 36 months from the last exchange.
  • Research and report access records: up to 24 months, so we can evidence licensing.
  • Newsletter subscription and topics: until you unsubscribe, then 12 months of suppression data so we do not re-add you.
  • Job applications and uploaded résumés: up to 12 months after a decision, unless you ask us to keep them on file.
  • Account and profile records: while the account is active, then up to 24 months.
  • Consent records: for the life of the related record plus 24 months, as proof that we had permission.
  • Security and server logs: up to 12 months.
  • Deletion requests: a minimal audit entry is kept indefinitely to evidence that we acted on the request; it holds no content we deleted.

We keep records longer only where law requires it.

09Deleting your data

You can start a deletion yourself at /privacy/delete-request. Enter the email address you used with us and we send a one-time confirmation link to that address — nothing is deleted until you follow it, so nobody can erase someone else's records.

Once confirmed, we remove briefing and contact requests, research access records, newsletter subscriptions, job applications and uploaded résumés, your account and profile, and the related consent records. We then email you a summary of exactly what was removed.

The link expires after 24 hours. Every step — requested, verified, executed — is written to an internal audit trail so we can evidence compliance without keeping the deleted content.

10Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict the use of your personal information, to object to processing, to withdraw consent, and to be free from discrimination for exercising these rights.

Write to legal@dippai.com and we will respond within the period the applicable law requires — within forty-five days for California requests and within one month for GDPR requests. We may need to verify your identity before acting. EU and UK residents may also complain to their supervisory authority.

11Security

We use encryption in transit and at rest, role-based access control, least-privilege administrative access, row-level authorization on our databases, and logging of privileged actions. No system is perfectly secure, but we design for the same accountability we ask enterprises to expect of AI.

Suspected vulnerabilities can be reported to legal@dippai.com; we acknowledge every report and do not pursue good-faith researchers.

12Changes to this notice

We will update this notice as our practices change and will revise the date at the top of the page. Material changes will be announced on the site and, where we hold your address, by email.

Contact

Privacy requests, subprocessor lists, and data protection questions:

Dipp AI Technologies, Inc.
One Manhattan West, 51st Floor
New York, NY, United States
legal@dippai.com

Ask us to delete your data.

Start a verified deletion request and we will confirm by email before anything is removed. Consent statement version 2026-01-v1.