This Privacy Policy explains how DirectiveAI ("we", "us", or "the Company") collects, uses, retains, and discloses personal information when you use our website, products, and services (collectively, the "Services"). We are committed to processing personal information lawfully, fairly, and transparently, in accordance with the General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and other applicable data protection laws.
This policy applies to all visitors, registered users, and customers of the Services. It does not apply to third-party websites or services, which are governed by their own privacy practices.
1. Data Controller & Contact
DirectiveAI is the data controller responsible for your personal information under this policy, except where we act as a processor on behalf of a customer under a separate Data Processing Agreement (DPA). You may contact us at any time:
Privacy enquiries: privacy@directiveai.org
Data Protection Officer: dpo@directiveai.org
Postal address: available on request.
You may also lodge a complaint with your local data protection authority. We would, however, appreciate the opportunity to address your concerns directly before you do so.
2. Information We Collect
We collect only the categories of personal information necessary to provide and operate the Services.
2.1 Information you provide directly
Account data: name, email address, and a salted hash of your password when you create an account.
Profile data: organization name, role, and preferences you choose to provide.
Support data: the contents of messages and attachments you send to our support or privacy team.
Billing data: billing address and tax identifiers where required to issue invoices. Card numbers are handled by our payment processor and never stored on our infrastructure.
2.2 Information collected automatically
Usage data: pages visited, features used, timestamps, and approximate location derived from IP address.
Technical data: browser type, operating system, device identifiers, and referral URL.
Cookies and local storage: authentication tokens, preferences, and analytics identifiers (see our Cookie Policy).
2.3 Information we do not collect
We do not collect sensitive personal data (health, racial or ethnic origin, religious beliefs, biometric data) unless you voluntarily submit it, in which case we process it only with your explicit consent.
We do not sell personal information to third parties, and we do not use it for cross-context behavioral advertising.
3. How We Use Your Information
Each purpose below is tied to a legal basis under the GDPR:
Providing the Services: creating and managing accounts, authenticating sessions, and processing transactions. Basis: performance of a contract.
Service improvement: analyzing usage patterns to fix bugs, improve reliability, and develop new features. Basis: legitimate interests.
Security and fraud prevention: detecting abuse, protecting accounts, and investigating incidents. Basis: legitimate interests and legal obligation.
Communications: transactional messages, security alerts, and, where you have opted in, product updates. Basis: contract, consent, or legitimate interests.
Legal compliance: responding to lawful requests from public authorities. Basis: legal obligation.
We will not use your personal information for a purpose incompatible with those listed above without obtaining your consent or otherwise complying with applicable law.
4. Sharing & Sub-processors
We share personal information only as described below, under written agreements that impose equivalent confidentiality and security obligations:
Sub-processors: third parties that process data on our behalf to deliver the Services (cloud hosting, transactional email, analytics). A current list is available on request from privacy@directiveai.org.
Professional advisors: lawyers and accountants bound by confidentiality, to the extent necessary for their engagement.
Legal requirements: where disclosure is required by law, court order, or to protect the rights, property, or safety of DirectiveAI, our users, or the public.
5. International Data Transfers
DirectiveAI operates globally and personal information may be processed in countries other than your country of residence. Where personal information is transferred outside the European Economic Area, the United Kingdom, or Switzerland, we rely on recognized transfer mechanisms, including Standard Contractual Clauses adopted by the European Commission and supplementary measures where required. A copy is available on request.
6. Data Retention
We retain personal information only as long as necessary for the purposes set out in this policy or as required by law:
Account data: for the duration of your account, plus 30 days after deletion to allow recovery, then permanently erased.
Usage and technical data: up to 13 months, aggregated where feasible.
Support communications: up to 24 months from last interaction.
Billing records: up to 7 years as required by tax and accounting law.
Security logs: up to 12 months, unless an active investigation requires longer retention.
When retention is no longer required, data is deleted or irreversibly anonymized.
7. Security
We implement technical and organizational measures appropriate to the risk of processing, including encryption of data in transit using TLS 1.2 or higher, encryption of data at rest, strict access controls based on least-privilege principles, regular security reviews, and documented incident-response procedures.
No system can be guaranteed completely secure. In the event of a personal data breach affecting your rights or freedoms, we will notify the competent supervisory authority and affected individuals without undue delay, in accordance with Article 34 of the GDPR.
8. Your Privacy Rights
Depending on your jurisdiction, you may exercise the following rights. To do so, contact privacy@directiveai.org. We will respond within one month, extendable by two further months where requests are complex.
Access: receive a copy of the personal information we hold about you.
Rectification: correct inaccurate or incomplete information.
Erasure: request deletion, subject to legal retention obligations.
Restriction: request that we limit processing in certain circumstances.
Portability: receive your data in a structured, machine-readable format.
Objection: object to processing based on legitimate interests or for direct marketing.
Withdraw consent: withdraw consent at any time where processing relies on it, without affecting prior lawfulness.
Residents of California may exercise rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell or share personal information as defined by the CCPA. To submit a verifiable consumer request, email privacy@directiveai.org.
9. Children's Privacy
The Services are not directed to individuals under the age of 16, and we do not knowingly collect personal information from children. If you believe we have collected information from a child in violation of applicable law, contact privacy@directiveai.org and we will take steps to delete that information.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. The "Updated" date above indicates when the policy was last revised.
Material changes will be notified by email to registered users and by a prominent notice on the website at least 30 days before they take effect.
Non-material changes (clarifications or administrative updates) take effect upon publication.
Archived versions are available on request.
11. Definitions
Personal information: any information relating to an identified or identifiable natural person.
Controller: the entity that determines the purposes and means of processing.
Processor: an entity that processes personal data on behalf of the controller.
Services: the DirectiveAI website, products, and services covered by this policy.
Contact
Questions about your data? Email privacy@directiveai.org and our privacy team will respond within one month.
This document is provided for informational purposes and does not constitute legal advice.