Legal
Privacy Policy
How Deeplomacy collects, uses, and protects the personal data processed through its platform.
Last updated: June 2026
On this page
1Data Controller
- Deeplomacy acts as data controller for all personal data collected through its platform.
- For any privacy-related request, you can contact the company directly at info@deeplomacy.ai or at Corso Re Umberto 7, Turin, Italy.
2Data We Collect
We collect and process the following personal data:
- Account information (for example, email address, display name, country preferences)
- Authentication and session data (for example, access tokens, session identifiers)
- Security-related data (for example, OTP verification, login activity)
- User activity logs relating to use of the platform
- Administrative audit records (for example, account approvals)
3Purposes and Legal Basis
We process personal data to:
- Create and manage your user account (legal basis: consent)
- Provide the platform services and manage access permissions (legal basis: performance of the contract)
- Keep the platform secure and prevent unauthorized access and fraud (legal basis: legitimate interest)
- Maintain audit logs for regulatory compliance and internal administration (legal basis: legitimate interest)
4Data Storage and Residency
- All personal data is stored and processed within the European Union (EU).
- The infrastructure providers that host personal data are located within the EU.
5Disclosure and Categories of Recipients
We may share data with the following categories of parties acting as data processors:
- Cloud infrastructure providers (hosting, storage, computing)
- Authentication and transactional email services
- Technical service providers for session management and caching
- Audience-measurement and analytics providers (processing only aggregate, anonymous usage data)
All data processors:
- Operate under GDPR-compliant Data Processing Agreements (DPAs)
- Use Standard Contractual Clauses (SCCs) where applicable
We do not sell personal data to third parties.
6International Data Transfers
- Personal data is not transferred outside the EU.
- No personal data is shared with third parties outside the EU.
Anonymous, aggregate usage statistics collected by our analytics tool (see Cookies) do not constitute personal data and are therefore not subject to the restrictions above.
7Data Retention
- Personal data is retained for as long as your account remains active.
- Session data is deleted automatically once the session expires, and in any case within 30 days.
- System logs are kept for a limited period strictly necessary for security, and in any case no longer than one month.
8Your Rights
You have the right to:
- Access your personal data
- Request the correction of inaccurate data
- Request the erasure of your data (the right to be forgotten)
- Request data portability
- Object to processing or request its restriction
You can exercise these rights by contacting the data controller.
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Rome, PEC protocollo@pec.gpdp.it) if you believe the processing of your personal data infringes applicable law.
10Data Security
We implement appropriate technical and organizational measures, including:
- Encryption of sensitive data
- Secure authentication systems
- Access controls and audit logs
11Changes to This Policy
We may update this policy if:
- New data processors are introduced
- New categories of data are collected
- The location of our infrastructure or data storage changes
We will inform you of relevant updates where required.
Questions about how we handle your data? Write to info@deeplomacy.ai.