Privacy Policy

Effective Date: 22 July 2026

1. Introduction

Dynamiq (“we,” “us,” or “our”) is committed to protecting the privacy of individuals who visit our websites, use our applications and services (collectively, the “Services”), or otherwise engage with us. Our Services are designed for generative AI applications, data analysis, and related ML/AI workflows. This Privacy Policy describes how we collect, use, store, process, and share your information in compliance with the General Data Protection Regulation (GDPR), SOC 2 principles, and HIPAA requirements (if applicable).

By using or accessing our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please refrain from using our Services.

2. Scope

This Privacy Policy covers the data we collect (i) through our Services, (ii) from visitors to our websites or mobile applications, and (iii) through other related online or offline offerings.

Where we process personal data on behalf of a customer who is subject to GDPR or HIPAA, we act as a Data Processor or Business Associate (as applicable). In such cases, the customer remains the Data Controller or Covered Entity, and our data processing is governed by contractual agreements (e.g., Data Processing Addendum, Business Associate Agreement).

3. Information We Collect

Information You Provide to Us

  • Account Information: When you sign up for an account or subscribe to our Services, we collect information such as your name, email address, billing details, and any other necessary fields.
  • Communications: We may collect information when you contact us by email, support tickets, or other channels, including chat logs, feedback, or requests.

Information Collected Automatically

  • Cookies & Tracking Technologies: We use cookies, web beacons, and similar technologies to track usage of our websites and Services. This includes IP addresses, browser types, referring pages, and other device identifiers. For more details, please see Section 12, “Cookies and Tracking.”

Information from Third Parties

  • We may receive information about you from our service providers, partners, or other third parties, such as analytics or hosting providers, but only where these parties are legally allowed to share such data with us.
  • Third-Party Integrations: If you connect third-party services to the Services, such as Google Workspace (for example, Google Drive), we may receive document metadata, document content, permissions, account identifiers, and other information necessary to provide the functionality you request.

Protected Health Information (PHI)

  • In cases where our Services process PHI on behalf of healthcare providers or other Covered Entities, we adhere to HIPAA requirements, which include implementing appropriate administrative, physical, and technical safeguards.

4. Legal Basis for Processing (GDPR)

We collect and process personal data based on one or more of the following legal grounds:

  • Consent: Where you have given clear consent for us to process your personal data for a specific purpose.
  • Contract: Where processing is necessary for the performance of a contract to which you are a party (e.g., Terms of Service).
  • Legal Obligation: Where processing is necessary for compliance with a legal obligation.
  • Legitimate Interests: Where processing is necessary for the purposes of our legitimate interests (e.g., improving our Services), unless overridden by your data protection interests or fundamental rights and freedoms. This basis does not apply to Google Workspace API data, which we process only to provide the user-facing features you request and never to train or improve generalized or foundational AI/ML models. See Section 6.

5. How We Use Your Information

  1. Provision and Maintenance of Services: To provide, maintain, troubleshoot, secure, and improve the Services. This does not include using Google Workspace API data, including raw or derived data, to create, train, fine-tune, or improve generalized or foundational artificial intelligence or machine learning models.
  2. Account Management: To manage user accounts, process billing, and handle customer support.
  3. Communication: To respond to inquiries, send administrative messages, and provide updates or notices about our Services.
  4. Security and Fraud Prevention: To monitor, detect, and protect against fraudulent or malicious activities.
  5. Aggregated Analytics: To analyze trends, usage, and activities in connection with our Services, in an anonymized or aggregated manner. This does not include Google Workspace API data (whether raw, aggregated, anonymized, or derived), which is used solely to provide or improve the user-facing features you request and is excluded from analytics conducted for any other purpose. See Section 6.
  6. Google API Services Compliance: Our use and transfer of information received from Google APIs, including Google Workspace APIs, adheres to the Google API Services User Data Policy, including the Limited Use requirements. For details on how we handle Google Workspace API data, see Section 6 (Google Workspace API Data).

6. Google Workspace API Data

Our Use of Google Workspace APIs

When you choose to connect your Google Workspace account (such as Google Drive) to the Services, we access and process Google Workspace API data only with your authorization and only for the purpose of providing the functionality you request. Depending on the features you use, this may include: connecting your Google Workspace account to the Services; indexing and organizing documents; retrieving document content and metadata; searching documents; generating summaries, answers, insights, or other AI-powered outputs; and respecting document permissions and access controls. We access only the Google Workspace data necessary to provide these features.

Compliance with Google's Limited Use Requirements

Our use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Workspace API data is used solely to provide and improve the user-facing functionality of the Services requested by the customer or authorized user.

We do not use Google Workspace API data, including raw data, aggregated data, anonymized data, derived data, embeddings, summaries, prompts, generated outputs, or other derivative representations, to create, train, fine-tune, or improve generalized or foundational artificial intelligence or machine learning models. Google Workspace API data is never sold and is never used for advertising, marketing, profiling, or any unrelated secondary purpose.

AI Processing

Certain features of the Services use artificial intelligence and machine learning technologies to process customer content at the direction of the customer. Where Google Workspace API data is processed using AI services, such processing occurs solely to provide the functionality requested by the customer, such as document search, retrieval, summarization, question answering, classification, extraction, or similar user-initiated features. The outputs generated are provided only to the customer or users authorized by the customer.

Third-Party AI Service Providers

To provide AI-powered functionality, we may use carefully selected third-party AI service providers acting as our service providers or subprocessors. When Google Workspace API data is processed by these providers: the data is processed solely on our behalf to provide the requested Services; the data is not transferred for the purpose of training or improving generalized or foundational AI or machine learning models; we use contractual and technical safeguards designed to prevent such use; and the providers may process the data only for the limited purpose of providing the requested functionality.

Access Controls

The Services are designed to respect the permissions associated with your Google Workspace account. Search results, document retrieval, and AI-generated responses are limited to Google Workspace content that the requesting user is authorized to access.

Data Retention and Deletion

Google Workspace API data is retained only for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce our agreements, or as otherwise described in this Privacy Policy. If you disconnect your Google Workspace account, we will stop accessing Google Workspace API data and will delete or de-identify cached Google Workspace API data in accordance with our retention practices, unless retention is required by law or for legitimate business purposes permitted under applicable law.

Security

Google Workspace API data is protected using administrative, technical, and organizational safeguards designed to protect it against unauthorized access, disclosure, alteration, or destruction. Access to Google Workspace API data is restricted to authorized personnel and systems that require such access to provide the Services.

Human Access

Our personnel do not access Google Workspace API data except when necessary to provide customer-requested support, maintain or secure the Services, comply with applicable law, or with the customer's authorization.

7. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with applicable legal obligations, contractual requirements, or legitimate business interests. Once the retention period has expired, we will securely delete or anonymize the data. Google Workspace API data is retained only as long as necessary to provide the Services or to comply with applicable legal obligations.

8. Your Rights (GDPR)

Subject to local laws, you have the following rights regarding your personal data:

  • Right of Access: The right to request confirmation of whether we process your personal data and a copy of such data.
  • Right to Rectification: The right to request correction of inaccurate or incomplete data.
  • Right to Erasure (“Right to be Forgotten”): The right to request the deletion of your personal data, subject to certain exceptions.
  • Right to Restrict Processing: The right to request the restriction of certain processing activities.
  • Right to Data Portability: The right to receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Object: The right to object to processing of your personal data, including for direct marketing.
  • Right to Lodge a Complaint: If you are in the EU/EEA, you have the right to lodge a complaint with your local supervisory authority.

Revoking Google Workspace Access: You may revoke Dynamiq's access to your Google Workspace data at any time through your Google Account security settings or by disconnecting the integration within the Services.

How to Exercise Your Rights

To submit a request to exercise any of the above rights, please contact us at legal@getdynamiq.ai. We may request proof of identity to verify and process your request.

9. Data Security

SOC 2 Compliance

We implement safeguards and controls aligned with SOC 2 principles (Security, Availability, Confidentiality, Processing Integrity, and Privacy) to protect the confidentiality and integrity of the personal data entrusted to us. Our measures include, but are not limited to:

  • Encryption: Data is encrypted at rest and in transit where feasible.
  • Access Controls: Role-based access controls and authentication mechanisms are in place to prevent unauthorized data access.
  • Monitoring and Audits: Regular security assessments, intrusion detection, and third-party audits to maintain compliance with our security obligations.

Access to Google Workspace API data is restricted according to the principle of least privilege and is protected using administrative, technical, and organizational security measures.

HIPAA Compliance

For protected health information (PHI), we follow HIPAA safeguards, including:

  • Administrative Safeguards: Policies and procedures to manage the selection, development, implementation, and maintenance of security measures.
  • Physical Safeguards: Controlled facility access, hardware security, and disposal procedures.
  • Technical Safeguards: Access control, audit controls, integrity checks, and transmission security measures for PHI.

10. Data Sharing and Subprocessors

We only share personal data with third parties under the following circumstances:

  • Service Providers (“Subprocessors”): We engage trusted third-party vendors to perform certain business-related functions (e.g., hosting, analytics, or email delivery). Each subprocessor is vetted for security and privacy practices, and we have Data Processing Agreements in place as required by GDPR. Some Service Providers provide artificial intelligence or machine learning capabilities. Where such providers process Google Workspace API data on our behalf, they do so solely for the purpose of providing the requested functionality. Google Workspace API data is not transferred to such providers for the purpose of creating, training, fine-tuning, or improving generalized AI or machine learning models.
  • Business Transfers: In connection with a corporate transaction, such as a merger, acquisition, or asset sale, your data may be transferred. We will notify you of any such transfer and any choices you may have regarding your information.
  • Legal or Compliance Reasons: We may share data to comply with applicable laws, respond to lawful requests (e.g., subpoenas or court orders), or protect our legal rights.

Sub-processor List: We maintain a public list of the third-party sub-processors we engage to process personal data on our behalf. You can view our current sub-processors here,

11. International Data Transfers

If we transfer personal data outside of the European Economic Area (EEA) to countries that may not provide the same level of data protection as your home jurisdiction, we implement appropriate safeguards, such as Standard Contractual Clauses (SCCs), and ensure an adequate level of protection.

12. Cookies and Tracking

We use Cookiebot by Usercentrics to manage user consent for cookies and tracking technologies on our website. When you visit our site, Cookiebot presents a cookie banner allowing you to opt in or out of different types of cookies (e.g., necessary, preferences, statistics, marketing).

Your cookie preferences are stored securely and can be modified at any time using the “Cookie Settings” link in the footer of our site.

You can view a full list of the cookies we use by visiting our Cookie Declaration.

13. Children’s Privacy

Our Services are not intended for individuals under the age of 13 (or 16 where applicable under GDPR). We do not knowingly collect personal data from children. If you believe a child under this age has provided personal data, please contact us immediately at legal@getdynamiq.ai,  and we will take steps to delete or anonymize the information.

14. Data Breach Notification

We maintain a security incident response policy. In the event of a personal data breach or PHI breach, we will notify affected individuals and/or relevant supervisory authorities (e.g., under GDPR or HIPAA) without undue delay and in accordance with applicable legal requirements.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we do, we will post the revised policy on our website and update the “Effective Date” above. We encourage you to review this page periodically for the latest information.

16. Contact Us

If you have any questions or comments about this Privacy Policy, or wish to exercise your rights, please contact us at:

Dynamiq
Attn: Privacy Officer
Dynamiq Technologies Inc., 1111B S Governors Ave STE 6798, Dover, DE 19904 US.
Email: legal@getdynamiq.ai

EU Representative

Pursuant to Article 27 of the General Data Protection Regulation (GDPR), Dynamiq Technologies, Inc. has appointed the following representative in the European Union:

Maria-Elena Tzanev
Email: mariaelena@getdynamiq.ai
Address: Milan, Italy

EU data subjects and supervisory authorities may contact our representative for any inquiries related to the processing of personal data under the GDPR.

Thank you for trusting Dynamiq with your data. We take your privacy and security seriously and are committed to continual improvement in compliance with GDPR, SOC 2, and HIPAA.