انتقل إلى المحتوى

داينمو. محرك الأعمال الأول

هذه الصفحة متاحة حاليًا باللغة الإنجليزية فقط.

Privacy Policy

In force

1.0

Last updated:

This policy explains how DYNAMO (“Dynamo”, “we”, “us”) handles personal data. It has two parts: Part A covers this website, the signup and the status page, where we decide why and how data is used. Part B covers the DynamoOS platform, where our customers decide and we process the data for them.

1.Who we are and what this policy covers

1.1Controller for Part A: DYNAMO, a company incorporated in the United Kingdom. Contact for privacy matters: privacy@dynamoos.com.

1.2Part A applies to visitors of this website, to people who send us a message, to people who create a workspace through the signup, and to people who subscribe to status notifications.

1.3Part B applies to data that a customer and its users enter into a DynamoOS workspace. For that data the customer is the controller and we are the processor, on the terms of the Data Processing Agreement. If you are an employee or contact of one of our customers, please address requests about that data to your organization first.

1.4This policy is read together with the Terms of Service, the Cookie notice, the Data Processing Agreement and the Subprocessors list.

1.5We process personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where other data protection laws apply to the individuals concerned, such as the EU General Data Protection Regulation or the Saudi Personal Data Protection Law (PDPL) and its implementing regulations, we follow them as well.

2.Part A: information we collect on the website and in the signup

2.1We collect only what is needed for the purpose stated. The table lists each category, where it comes from and why we use it.

Personal data collected through the website, the signup and the status page
CategoryDataSource and purpose
Contact and demo requestsName, e-mail, company, country, company size, area of interest, your messageYou provide it in the contact form. We use it to answer your request, arrange demonstrations and follow up on your enquiry.
Signup: accountFull name, e-mail, passwordYou provide it when you create a workspace. We use it to verify your e-mail address, create the owner account of your workspace and let you sign in. The password becomes the owner’s sign-in password and is stored by the workspace in protected (hashed) form.
Signup: organizationCompany name, country, company size, industry, telephone number (optional), workspace address (the name that becomes your workspace address)You provide it. We use it to set up your organization in the workspace, to set up your workspace and to contact you about your trial.
Signup: planChosen plan and apps, number of users, billing cycle, payroll employees, extra storageYou choose it. We use it to configure your trial and subscription and to prepare your first invoice.
Verification codesA six-digit code sent to your e-mail, and a record that it was verifiedWe e-mail the code to prove that you control the address. The code is stored only in a protected (hashed) form, is valid for ten minutes and allows a limited number of attempts.
IP addressThe network address your device uses to connectUsed to limit repeated requests (rate limiting) and to protect the signup, the contact form and the status page from abuse. It is also part of the technical logs below.
Country from your IP addressThe country your IP address belongs toLooked up on our own server in an offline country database (IP to Country Lite by DB-IP, db-ip.com, licensed under CC BY 4.0) to show prices in the currency of your country. Neither the address nor the result is stored for this purpose.
Status page subscriptionE-mail address you subscribe withYou provide it to receive incident and maintenance notices. We send a confirmation message, then notices, and you can unsubscribe from any message.
Technical logsIP address, browser type, pages and interfaces requested, time and responseRecorded by our servers and hosting infrastructure to run, secure and troubleshoot the website. Not used for advertising.
Service messagesOur e-mails about verification, workspace readiness, billing, security and changes to the ServicesSent because you use the Services. They are not marketing messages.

2.2Nothing is collected from you automatically for advertising or analytics. The website sets no cookies, includes no analytics or advertising scripts and no third-party trackers. The Cookie notice describes the small items the website keeps in your browser.

2.3You do not have to provide this data, but we cannot respond to a request or create a workspace without the data marked as needed for it.

3.Part A: how and why we use it (purposes and legal bases)

PurposeLegal basis
Answer contact and demo requests and take steps you ask for before a contractTaking steps at your request before entering into a contract; our legitimate interest in running our business
Create and verify your account, provision and run your workspace, provide support, invoice and collect paymentPerformance of the contract with you or your organization (the Terms of Service)
Rate limiting, abuse prevention and security of the website and signupOur legitimate interest in protecting the Services and users; legal obligations where they apply
Status notifications you subscribed toYour consent, which you can withdraw by unsubscribing
Service messages about security, changes and billingPerformance of the contract; our legitimate interest in keeping you informed
Compliance with law, responding to authorities, defending legal claims, tax and accounting recordsLegal obligation; our legitimate interest in establishing, exercising or defending legal claims

3.1Where the law requires consent for a purpose, we ask for it, and you may withdraw it at any time without affecting processing already carried out. We do not use personal data for automated decisions that have legal or similarly significant effects on individuals.

3.2We do not send marketing e-mails unless you ask for them or the law allows them, and you can opt out of them at any time.

4.Part A: recipients and subprocessors

4.1We do not sell personal data and we do not share it for advertising.

4.2Inside our organization, access is limited to staff who need it for the purposes above.

4.3Signup data is processed by Dynamo Control, our own administration system, which creates and manages workspaces. Contact form messages are delivered to DYNAMO’s own team, by e-mail or to our own systems. If we use a third-party service for them, it is listed on the Subprocessors page before it is switched on.

4.4Today we do not use a third-party processor for the personal data described in Part A. The Subprocessors page lists the categories of provider (such as e-mail delivery, object storage and payment provider) that we will name there before they are switched on, and how we give notice of changes.

4.5We may disclose personal data to professional advisers under confidentiality duties, to a successor in a business transfer, and to authorities where the law requires it.

5.International transfers

5.1Today we do not engage any third-party processor for the personal data described in this policy. Where we or a provider we engage later process or store personal data outside the United Kingdom, we will list the provider and location on the Subprocessors page before the transfer starts and will rely on a transfer mechanism recognised by the UK GDPR, such as an adequacy regulation, the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with the safeguards that any other applicable law requires.

5.2A customer chooses the storage location for its workspace files (a global location, a regional location, or its own storage). Choosing a location is a technical choice. It is not by itself a legal statement about data residency or compliance. The platform runs on servers that Dynamo operates, in Germany.

6.Retention

6.1We keep personal data only as long as needed for the purposes in this policy, and then delete or anonymize it.

DataHow long
Contact and demo requestsAs long as needed to answer and to keep a record of the business relationship, then deleted or anonymized, and in any event within 24 months of our last contact.
Verification codesValid for ten minutes. Expired and old codes are removed by a daily clean-up.
Owner password during signupHeld in encrypted form by our administration system only until the workspace is created, then deleted from it. A daily clean-up removes passwords of abandoned or failed signups. The workspace keeps the password only as a hash.
Signup record (name, e-mail, organization, plan, workspace address)For the life of the workspace and the subscription, then for up to six years for tax, accounting and legal claims.
Invoices and payment recordsAs long as the law requires for tax and accounting records.
Status page subscribersUntil you unsubscribe.
Technical logs and IP addresses used for rate limitingRate-limit counters are short-lived. Server logs rotate automatically: older entries are overwritten as new ones are written, and logs are kept only as long as needed to run and secure the website.
Workspace data (Part B)As the customer decides while its subscription is active. After cancellation, the sequence in the Terms of Service applies: read-only access, an export window, then deletion only after a two-person approval.

7.Part B: the DynamoOS platform

7.1A customer’s workspace holds the data the customer chooses to enter, which may include personal data of its employees, customers, suppliers and contacts, and files it stores. The customer is the controller of that data and decides why and how it is used. We process it as a processor, only on the customer’s documented instructions, as set out in the Data Processing Agreement.

7.2Each customer has its own workspace with its own database and storage area. We do not use customer data for our own purposes, we do not sell it, and we do not use it to train artificial-intelligence models.

7.3We may access a workspace only where needed to provide the Services, to respond to a support request, to prevent or resolve a security or technical problem, or where the law requires it. Operator actions are recorded in an audit trail.

7.4If you are an individual whose data is in a customer’s workspace, the customer is responsible for answering your requests. If you contact us, we will pass your request to the customer unless the law requires us to answer you directly.

7.5Dynamo AI, when switched on for a workspace, works within the permissions of the user asking and stores conversations in the customer’s workspace. The Responsible AI page explains this.

8.Security

8.1We protect personal data with organizational and technical measures that fit the risk: role-based access control, per-workspace databases and storage areas, encrypted transport (TLS), hashed or encrypted storage of credentials, an audit trail of operator actions, daily backups, and staff access limited to what is needed. The Security page describes these measures in detail.

8.2No system is completely secure. If we become aware of a breach of personal data that we control, we will notify affected individuals and the competent authority as the law requires. For the platform, we notify the customer without undue delay, as the Data Processing Agreement sets out.

9.Your rights

9.1Under the UK GDPR and the other data protection laws that apply to you, you have rights over your personal data. Depending on the law and the circumstances, they include the right to:

  • be informed about how your data is collected and used (this policy);
  • access your personal data and receive a copy of it;
  • correct data that is inaccurate or incomplete;
  • ask us to delete your data where it is no longer needed or the law gives you that right;
  • withdraw consent where we rely on it, for example by unsubscribing from status notices;
  • object to or ask us to restrict certain processing, including processing based on our legitimate interest;
  • receive your data in a structured, commonly used format (portability) where the law gives you that right;
  • not be subject to a decision based solely on automated processing that significantly affects you.

9.2To exercise a right, e-mail privacy@dynamoos.com from the address concerned, saying what you ask. We may ask for information to confirm who you are. We answer within the time the law sets and in any event within 30 days, and tell you if we need more time or cannot meet a request, and why. We do not charge for ordinary requests.

9.3Rights are not absolute. We may need to keep data where the law requires it or to establish or defend legal claims.

10.Complaints

10.1Please contact us first at privacy@dynamoos.com so that we can try to resolve your concern. You also have the right to complain to a supervisory authority. In the United Kingdom that is the Information Commissioner’s Office (ICO). If you live elsewhere, you may complain to your local data protection authority, for example the Saudi Data and AI Authority (SDAIA) in Saudi Arabia.

11.Children

11.1The website and the Services are for businesses and are not directed to children. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact privacy@dynamoos.com and we will delete it.

12.Links and third-party services

12.1The website may link to other sites, for example a status page hosted elsewhere or an authority’s website. Their privacy practices are theirs. Services that a customer connects to its workspace (for example an identity provider or a government platform) are governed by the customer’s own agreement with that provider.

13.Changes to this policy

13.1We may update this policy. The version and date at the top of the page show when it was last revised. For material changes that affect how we use data about you, we will tell workspace owners by e-mail or in the workspace before the change takes effect.

14.Contact

14.1Privacy questions and requests: privacy@dynamoos.com. General contact: sales@dynamoos.com. By post: our registered office in the United Kingdom.

Company details

Company
DYNAMO
Incorporated in
United Kingdom
Sales and general e-mail
sales@dynamoos.com
Privacy e-mail
privacy@dynamoos.com
Security e-mail
security@dynamoos.com