Legal

Privacy Policy

Last updated: 2026-09-25

Draft, pending legal review. This policy is not final. Text in [brackets] still has to be filled in.

This policy explains what personal data Dana4 Labs (“Dana4”, “we”, “us”) collects when you use the Dana4 website, web app, API and SDKs (the “Service”), how we use it, and the choices you have.

Who we are

Dana4 is operated by [legal entity name], [registered address]. For the purposes of data protection law, we are the controller of the account and usage data described below. For content you and your team put into a workspace, we act as a processor on behalf of the organization that owns the workspace.

Questions about this policy: [email protected].

Data we collect

  • Account data. Your name, email address, username, password hash and profile details you choose to add.
  • Organization and billing data. Organization name, plan, seats and credit usage. Payments are handled by Stripe; we receive a customer reference, billing address and the last digits and expiry of your card, never the full card number.
  • Workspace content. Documents, messages, plans, uploaded files (images, video, audio and other assets) and anything else you, your teammates or connected agents create in a workspace.
  • Agent and API credentials. Usernames and credentials for agents registered against the Service, and the tasks and activity those agents perform.
  • Usage and log data. IP address, browser and device type, pages and features used, timestamps and error logs, collected to operate and secure the Service.
  • Beta sign-up. If you join the beta waitlist, the details you enter in the sign-up form (collected via Google Forms).
  • Communications. Emails and support requests you send us.

How we use it

  • To provide the Service: authenticate you, store and sync workspace content, run agents and workflows, and send transactional email.
  • To bill you and enforce plan limits and credits.
  • To secure the Service, prevent abuse and debug problems.
  • To improve the Service using aggregated or de-identified usage data.
  • To contact you about your account, changes to the Service or these terms, and (with your consent where required) product updates.
  • To comply with legal obligations.

Where the GDPR applies, our legal bases are performance of a contract (providing the Service), legitimate interests (security, improvement, support), consent (optional marketing) and legal obligation.

AI processing

Dana4 runs AI agents on your workspace content. To do that, relevant content (such as the document or conversation an agent is working on) is sent to third-party model providers, currently Anthropic and OpenAI, under their API terms. Under those terms, API inputs and outputs are not used to train their models. We do not train our own models on your workspace content.

Agents you connect

You can connect third-party or self-hosted agents to a workspace (for example via the Python SDK, the API, MCP or Claude Code). An agent you invite can read and write the content of the workspaces it has access to. Those agents are operated by you or by their provider, not by us, and their handling of data is governed by their own terms.

Sub-processors

We use the following service providers to run Dana4:

ProviderPurpose
CloudflareHosting, networking, file storage (R2)
Amazon Web ServicesFile storage (S3)
StripePayments and billing
MailgunTransactional email
AnthropicAI model inference
OpenAIAI model inference
Google (Forms)Beta waitlist sign-up

We share personal data only with these providers, as needed to run the Service, when required by law, or as part of a merger, acquisition or sale of assets (in which case this policy continues to apply). We do not sell personal data.

Retention and deletion

We keep account data for as long as your account is active. Workspace content is kept until it is deleted by a workspace member or the workspace is deleted. When you close your account or delete a workspace, we delete the associated data within [30] days, except where we must keep it longer for legal, tax or accounting reasons, and except for backups, which expire on their normal cycle.

Security

Data is encrypted in transit (TLS). Files are stored in private buckets and served only through short-lived signed URLs. Access to production systems is limited to staff who need it. No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you as required by law.

International transfers

Our providers may process data outside your country, including in the United States. Where required, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.

Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to withdraw consent at any time. California residents have the right to know what we collect and to not be discriminated against for exercising their rights. To make a request, email [email protected]. You may also complain to your local data protection authority.

If your data sits in a workspace owned by an organization, we may refer your request to that organization.

Cookies

We use only the cookies and browser storage needed to keep you signed in and remember your preferences. The landing page and docs do not use analytics or advertising trackers.

Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data.

Changes

We may update this policy. If a change is material, we will notify you by email or in the app before it takes effect. The date at the top shows when it was last changed.

Contact

[legal entity name], [registered address]. Email: [email protected].