Skip to main content

Privacy notice

How dijitul Ltd handles personal data — both the data we hold about you as an account holder, and the data you send through the gateway.

dijitul Ltd Governed by the laws of England and Wales Version 0.1 (draft)

1. Who we are

dijitul Ltd is a company incorporated in England and Wales, company number TODO-COMPANY-NUMBER, registered office TODO-REGISTERED-ADDRESS. We are registered with the Information Commissioner's Office under reference TODO-ICO-REFERENCE.

TODO(legal): confirm whether a Data Protection Officer is required under UK GDPR Article 37 and, if appointed, insert the name and contact details here. If not required, state that a named individual is responsible for data protection and give their contact route.

2. Two different roles — please read this one

This notice covers two quite different things, and conflating them is the source of most confusion about AI services:

  • Account data — we are the controller. Information about you as a customer: your name, your work email address, billing details, and how you use the dashboard. We decide why and how this is processed, and this notice explains it.
  • Prompt content — we are a processor. Anything you or your users send through the API, including any personal data contained in a prompt. We process it only on your instructions. Your own privacy notice governs it, and our obligations to you are set out in the Data Processing Addendum, not here.

3. What personal data we collect about account holders

Category Examples Source
Identity and contact Name, work email address, organisation name, job title You, at registration
Account and credentials Hashed password, multi-factor settings, API key hashes and display prefixes You, and generated by us
Billing Billing address, VAT number, invoice history, card token You, and our payment processor
Usage metadata Timestamps, model requested, residency tier, regions, status codes, latency, token counts Generated automatically
Technical IP address, user agent, dashboard session data, audit-trail entries Generated automatically
Correspondence Support emails and their contents You

We do not knowingly collect special category data about account holders, and you should not send it to us in a support email.

4. Why we process it, and on what lawful basis

Purpose Lawful basis (UK GDPR Art. 6)
Providing the Service and administering your account Performance of a contract
Metering usage and invoicing Performance of a contract
Keeping the Service secure; detecting abuse and credential compromise Legitimate interests — operating a secure service
Diagnosing faults and improving reliability Legitimate interests — maintaining service quality
Retaining financial records Legal obligation
Product announcements and service notices Legitimate interests, or consent where marketing

Where we rely on legitimate interests, we have carried out a balancing assessment and you may ask for a summary of it. TODO(legal): complete and file the legitimate interests assessments before launch.

5. Prompt content — what actually happens to it

Prompt and completion bodies are not written to disk in normal operation. What we retain about a request is metadata: when it happened, which key made it, which model and residency tier were used, the status, the latency and the token counts.

If you have enabled PII detection, we record the types and counts of identifiers found — for example, “one email address, one NHS number”. We do not record the values. The configuration for this is described on the privacy modes page.

If you explicitly enable debug capture on a key, request and response bodies for that key are stored for a bounded window of at most 24 hours and are then purged automatically. This is off by default and switching it on is recorded in the audit trail.

Inference itself is performed on Amazon Bedrock, which is zero-data-retention by default: AWS does not store your prompts or completions, and the model provider has no access to them. Neither we nor any sub-processor uses your prompt content to train models.

6. Who we share personal data with

  • Amazon Web Services — our sub-processor for model inference. Prompt content is transmitted to AWS for the purpose of generating a response and is not retained by them.
  • Stripe — payment processing. We do not receive or store full card numbers.
  • TODO(legal): list remaining sub-processors and vendors — email delivery, error monitoring, analytics, hosting — with their role and location, and publish the list at a stable URL so that changes can be notified.
  • Professional advisers, and law enforcement or regulators where we are legally required to disclose.

We do not sell personal data, and we do not share it for third-party advertising.

7. International transfers

Account data is held in the United Kingdom. Inference is performed within the region scope of your residency tier: the United Kingdom on the UK tier, or the EU/EEA regions listed on the data residency page on the EEA tier.

Where a transfer outside the UK does occur, it is covered by appropriate safeguards. In respect of AWS, the AWS Data Processing Addendum, the EU Standard Contractual Clauses and the ICO's International Data Transfer Addendum are incorporated automatically into the AWS Customer Agreement.

TODO(legal): confirm the transfer position for each remaining vendor once the sub-processor list above is complete, and record the transfer risk assessments.

8. How long we keep it

  • Account records — for the life of the account and then TODO-ACCOUNT-RETENTION.
  • Request metadata — 90 days, then deleted.
  • Aggregated daily usage — retained for as long as needed for billing and financial record-keeping.
  • Debug capture bodies — at most 24 hours from capture.
  • Invoices and financial records — six years, in line with UK statutory requirements.
  • Audit trailTODO-AUDIT-RETENTION.

9. Your rights

Under UK GDPR you have the right to:

  • be informed about how your data is used — this notice;
  • request a copy of the personal data we hold about you;
  • have inaccurate data corrected;
  • request erasure, where no overriding basis for retention applies;
  • restrict or object to processing carried out on the basis of legitimate interests;
  • data portability for data you provided under a contract; and
  • withdraw consent at any time, where consent is the basis relied on.

To exercise a right, email support@dijitul.uk. We will respond within one month. If your request concerns prompt content rather than your account, it must be directed to the organisation that operates the account, because they are the controller for that data — we will assist them, but we cannot act on it directly.

10. Cookies

The marketing and documentation pages set no cookies and load no third-party assets. Everything on them is served from our own domain.

The dashboard sets a strictly necessary session cookie and a CSRF token cookie. These are required for the application to function and are exempt from the consent requirement under the Privacy and Electronic Communications Regulations.

TODO(legal): if any analytics or product-telemetry tooling is introduced, add it here with its purpose and duration, and implement a consent mechanism before it is deployed.

11. Security

API keys are stored as SHA-256 hashes and are displayed only once. Traffic is protected with TLS 1.2 or above. Administrative access requires multi-factor authentication and is limited to named staff. Our technical measures are described in more detail on the security page.

12. Children

The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Changes to this notice

We will update this notice when our processing changes. Material changes will be notified by email to account holders. The version identifier at the top of this page indicates the current version.

14. Contact and complaints

Contact us at support@dijitul.uk or by post at TODO-REGISTERED-ADDRESS.

If you are unhappy with how we have handled your personal data you may complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, or at ico.org.uk. We would prefer that you raised it with us first so that we have a chance to put it right.


Questions about this document should go to support@dijitul.uk. Nothing on this page is legal advice, and it does not create any obligation on dijitul Ltd until a settled version has been executed.