Privacy Policy

How DIGIAI handles personal data on this website and on the InfosecAgent platform.

Draft. The highlighted placeholders below must be completed and reviewed before this page is promoted or linked in customer-facing material.

Last updated: [TO CONFIRM: date, before publication]

1. Who we are

InfosecAgent is operated by DIGIAI ([TO CONFIRM: full legal entity name, registered office address]), the data controller for personal data collected through this website. For customer content processed inside the platform (see section 3), we act as a data processor on behalf of our customers.

2. Data we collect on this website

  • Contact by email or booking: if you email us or book a walkthrough via our scheduling provider, we receive the details you provide (name, email, message, booking time).
  • Local storage: the site stores a display preference (theme) in your browser. It is not used for tracking.
  • Analytics: [TO CONFIRM: state whether any analytics run on the marketing site — none are currently configured in the application code]

3. Data processed inside the platform

Platform accounts (name, email, role, organisation membership) are processed to provide the service. Documents, interview answers, and assessment content uploaded by customer organisations are processed on the instructions of that customer under a data processing agreement — DIGIAI does not use customer content for any other purpose. [TO CONFIRM: reference DPA availability and how to request it]

4. Purposes and legal bases

[TO CONFIRM: map each processing activity to its GDPR Art. 6 legal basis — typically: responding to enquiries (legitimate interest / pre-contractual steps), providing the platform (contract), security and abuse prevention (legitimate interest)]

5. Where data is processed and sub-processors

  • Hosting: [TO CONFIRM: hosting provider and region(s), including the EU single-tenant deployment option]
  • AI processing: [TO CONFIRM: list LLM providers used for assessment processing and their data-use terms (no training on customer data)]
  • Email and scheduling: [TO CONFIRM: email provider; Calendly for bookings]

6. Retention

[TO CONFIRM: retention periods — e.g. enquiry emails, platform accounts, customer content deletion on contract end]

7. Your rights

Under the GDPR you have the right to access, rectify, erase, and port your personal data, to restrict or object to processing, and to lodge a complaint with a supervisory authority (in Greece, the Hellenic Data Protection Authority). To exercise any of these rights, contact us at info@digi-ai.tech.