Privacy Notice
Updated August 19, 2026
This privacy policy explains the type, scope, and purpose of processing personal data (hereinafter referred to as "data") in connection with the provision of our services, as well as within our online offering and its related websites, functions, and content (collectively referred to as the "Online Offering"). The terminology used, such as "processing" or "controller," is based on the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Controller
Robinson Guerra (for DREAVERR Digital Solutions LLP)
Email: [email protected]
Types of Data Processed
- Inventory Data: e.g., names, email addresses.
- Content Data: e.g., the questions you ask in the chat and your conversation history.
- Usage Data: e.g., token consumption, selected model tier, access times.
- Meta/Communication Data: e.g., device information, IP addresses.
- Payment Data: e.g., billing address and transaction details, processed by Paddle.
Categories of Data Subjects
Visitors and users of the Online Offering, including chat subscribers (hereinafter collectively referred to as "users").
Purpose of Processing
- To provide the chat service and generate answers to your questions.
- To store your conversations so you can return to them.
- To process payments and deliver services related to subscriptions.
- To meter token usage against your plan's budget.
- To respond to contact inquiries and communicate with users.
- To implement security measures and prevent abuse.
- For service improvement purposes.
Chat Content Data
Your questions and the generated answers are stored in your account so your conversations remain available to you. To generate answers, your questions and relevant transcript passages are processed by our AI infrastructure providers (model hosting). We do not use your conversations to train models, and we do not sell or share your conversation content with third parties for marketing purposes. You can delete conversations at any time; deleting your account deletes your conversations.
Legal Bases
The processing of personal data is based on the GDPR:
- Consent under Article 6(1)(a) GDPR.
- Fulfillment of contractual obligations under Article 6(1)(b) GDPR (e.g., providing the chat service, payment processing).
- Compliance with legal obligations under Article 6(1)(c) GDPR.
- Protection of legitimate interests under Article 6(1)(f) GDPR (e.g., fraud prevention, abuse prevention).
Security Measures
We implement technical and organizational measures to ensure an appropriate level of security, taking into account the risks to the rights and freedoms of natural persons. These include:
- Encrypted data transmission (TLS/HTTPS)
- Hashed password storage
- Hashed session tokens and secure authentication
- Access controls, logging, and monitoring
- Regular security reviews
Data Sharing
Personal data is shared with third parties only to the extent necessary:
- Infrastructure providers: Hosting and database services necessary to operate the Service.
- AI infrastructure providers: Questions and relevant context are processed by external model-hosting providers to generate answers. These providers process the data on our behalf and do not use it to train their models.
- Paddle.com: Subscription payments are processed by Paddle.com as the authorized merchant of record. Paddle collects and processes your payment data, billing information, and transaction details. For details, see Paddle's Privacy Policy. For data subject requests related to payment data, contact Paddle at preferences.paddle.com or [email protected].
- Email service providers: To deliver transactional emails such as account verification and password resets.
- Legal authorities: When required by law, court order, or governmental regulation.
Further sharing occurs only when legally required or necessary for fulfilling contractual obligations.
Data Transfers to Third Countries
Data may be transferred to third countries (outside the EU, EEA, or Switzerland) as part of service delivery, answer generation, and payment processing. We ensure that all data transfers comply with GDPR, for example, through Standard Contractual Clauses.
Data Subject Rights
Under applicable data protection laws, you have the following rights:
- Access your processed data and obtain copies.
- Rectify inaccurate data.
- Request deletion of your data.
- Restrict the processing of your data.
- Transfer your data to another controller (data portability).
- Withdraw your consent at any time with future effect.
- Object to data processing for direct marketing or based on legitimate interests.
- File a complaint with a supervisory authority.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
Cookies
Cookies are used to enable functionality such as session management, authentication, and your language preference. These are essential cookies strictly necessary for the Service to function and do not require consent under applicable cookie laws. We do not use advertising or third-party tracking cookies. Users can disable cookies in their browser settings, which may limit the functionality of the Online Offering.
Data Retention
Data is deleted in accordance with legal requirements when it is no longer necessary for the purposes for which it was collected. Account data and conversations are retained for as long as the account is active. Operational logs are retained for up to 90 days for security purposes. Upon account deletion, personal data will be removed within 30 days, except where retention is required by law.
Changes to This Privacy Policy
We reserve the right to update this privacy policy to reflect changes in legal requirements or our data practices. Users will be notified of significant changes.
Contact Information
For questions or concerns regarding this Privacy Notice, please contact us:
DREAVERR Digital Solutions LLP
Email: [email protected]
Address: 1103 - 11871 Horseshoe Way, Richmond, British Columbia, Canada V7A 5H5