Platform Privacy Policy

For Business Clients & Platform Users

Dilog Pty Ltd (ABN 79 696 521 141)

Effective Date: May 15, 2026  ·  Version 1.1

Applies toIndividuals and organisations accessing the Dilog Platform under a subscription, including account holders, administrators, and invited team members
Related policiesWebsite Privacy Policy · Participant Privacy Policy
Contactprivacy@dilog.ai

1. About This Policy

This Privacy Policy explains how Dilog Pty Ltd (ABN 79 696 521 141) (Dilog, we, us, or our) collects, uses, discloses, and protects personal information from individuals who use our business platform as employees, contractors, or representatives of our business clients.

This policy applies to you if you access the Dilog platform under a subscription agreement. It covers both business (enterprise) clients and individual self-serve subscribers.

For information about how we handle customer data that your organisation provides to Dilog (such as data from your Customer Data Platform if applicable), please refer to the Data Processing Agreement between Dilog and your organisation.

For website visitors, see our Website Privacy Policy. For research interview participants, see our Participant Privacy Policy.

Dilog is subject to the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we interact with individuals in the EU, UK, or California, additional obligations under the GDPR, UK GDPR, and CCPA may also apply.

2. Who We Are

Dilog provides AI-powered customer research panels that enable businesses to gain insights into customer attitudes, preferences, and decision-making patterns. Our platform allows your team to query digital agents called Anonymised Reflective Profiles (ARPs) built from real customer interviews, where any PII is stripped from the context, providing authentic customer perspectives on demand.

ARPs use a context-injection architecture: participant data is not embedded into AI model weights but is injected at inference time. This is a deliberate design choice that enables clean data erasure and compliance with privacy law, and means participant identity remains separable from the ARP profile at all times.

3. Information We Collect

3.1 Account Information

When your organisation creates user accounts for the Dilog platform, we collect:

CategoryExamples
IdentityFull name, job title, department
ContactBusiness email address, phone number (if provided)
OrganisationCompany name, ABN/ACN or business registration number, billing address
CredentialsPasswords (stored in hashed form only; never stored in plain text)
Team membersNames and email addresses of invited users; their roles and access levels

3.2 Payment and Billing Data

Payment processing is handled by Stripe, Inc for some accounts, and directly invoiced for others. Dilog does not receive or store your full card or bank account details. We do receive and retain:

CategoryExamples
Transaction recordsPayment amounts, dates, subscription plan, billing period
Card referenceLast four digits of card, card type, expiry month/year (provided by Stripe for display and reconciliation purposes only)
Billing addressAddress used for payment verification and GST invoicing
Invoice recordsGST tax invoices generated for each transaction, retained for legal compliance

For full details of how Stripe handles your payment data, see stripe.com/privacy.

3.3 Usage Information

When you use the Dilog platform, we automatically collect:

CategoryExamples
Query dataQueries submitted to research panels, research projects created and managed
Session dataLogin timestamps, session duration, logout events
Feature usageFeatures accessed, actions taken, navigation paths
Technical dataIP address, browser type, operating system, device type

Query inputs and ARP outputs (together, “traces”) are logged via our observability tooling and may be reviewed by Dilog staff to improve prompt quality, ARP profile accuracy, and response realism. This review is distinct from AI model training — your data is never used to train or fine-tune any underlying language model. Trace review is conducted under internal confidentiality obligations and does not involve sharing your data with third parties. Enterprise clients who require traces to be excluded from quality review entirely may negotiate this in their Master Services Agreement.

3.4 Communications

We retain records of communications between you and Dilog, including support requests, feedback, billing dispute correspondence, and email exchanges. Retained for 36 months.

4. How We Use Your Information

We use the information we collect to:

PurposeDescription
Provide servicesAuthenticate your access, process queries, deliver research insights and panel outputs, and iterate to guarantee the accuracy of the responses and output.
ARP qualityReviewing traces to improve system prompts, refine ARP profile attributes, and improve response realism and accuracy. Aggregated analysis of output patterns to calibrate panels.
Billing and administrationProcess payments via Stripe, manage subscriptions, generate invoices, handle renewals and cancellations.
Account managementManage user roles and permissions, send account notifications and service updates.
SupportRespond to your requests, troubleshoot issues, resolve billing disputes.
SecurityProtect against unauthorised access, detect abuse, maintain platform integrity.
Product improvementAnalyse aggregated, de-identified usage patterns to improve features and performance.
Legal complianceMeet regulatory requirements, retain records as required by law, respond to lawful requests.
CommunicationsSend service updates and, with consent, product news and marketing.
We do not use and prohibit your ARP query inputs or outputs for LLM base model training. We may review traces to improve prompt quality, ARP profile accuracy, and response realism. Any such review is conducted by Dilog staff under confidentiality obligations and does not involve sharing your data with third parties.

5. Legal Basis for Processing

We process your personal information based on:

  • Contract: Processing necessary to provide the Platform services and fulfil obligations under the Platform Subscription Agreement or Master Services Agreement, including account management, billing, and panel delivery.
  • Legitimate interests: For security, service improvement, platform analytics, and business operations, where these do not override your privacy rights.
  • Consent: For optional communications such as marketing emails, where we seek your agreement separately.
  • Legal obligation: Compliance with the Privacy Act, tax laws, and other applicable regulations.

For subscribers subject to GDPR or UK GDPR, the above identifies our lawful basis under Article 6. We rely on explicit participant consent (obtained during the interview process) for any special category data that may be reflected in ARP profiles.

6. Who We Share Your Information With

6.1 Your Organisation

Your organisation account administrator may have access to your account information and usage data. Your queries and research projects may be visible to other authorised users within your organisation account.

6.2 Service Providers (sub-processors)

We share information with the following third-party service providers. All sub-processors are contractually bound to process data only on our instructions and to implement appropriate security measures.

ProviderLocationPurpose
Stripe, Inc.United StatesPayment processing and subscription billing
OpenRouterUnited StatesAPI gateway routing queries to AI model providers
LangfuseEuropean UnionLLM observability and tracing — logs AI query inputs and outputs for monitoring, debugging, and quality assurance
Anthropic / OpenAI / Google GeminiUnited StatesAI model providers for ARP query processing (accessed via OpenRouter)
CoolifyAustralia (Dilog infrastructure)Application deployment and infrastructure management — data remains within Dilog-controlled servers
Amazon Web Services (AWS)United States / AustraliaCloud infrastructure and data storage
HubSpotUnited StatesAccount and CRM management, billing communications
Google AnalyticsAustralia / United StatesOnsite tracking and reporting for improvements and quality assurance. Not firing events with query data in logged-in app state.
Google WorkspaceAustralia / United StatesInternal communications and transactional email

We will update this list as new sub-processors are engaged and notify affected clients as required by applicable law or any executed Data Processing Agreement.

6.3 Other Disclosures

We may also disclose your information:

  • Where required by law, court order, or government authority (we will notify you where legally permitted to do so);
  • To protect the rights, property, or safety of Dilog, our clients, or the public;
  • In connection with a merger, acquisition, or sale of assets (with notice to your organisation where practicable).

We do not sell your personal information. We do not share your query data or ARP outputs with third parties for their own commercial purposes.

7. Cookies and Tracking Technologies

We use cookies and similar technologies within the Platform to:

  • Essential cookies: Enable core functionality such as authentication and session management. These cannot be disabled without preventing use of the Platform.
  • Analytics cookies: Understand how users interact with the Platform to improve the service. We use privacy-respecting analytics tools and do not enable advertising or cross-site tracking.
  • Preference cookies: Remember your settings and display preferences across sessions.

You can manage cookie preferences through your browser settings. Disabling essential cookies will prevent you from using the Platform. We do not use advertising or behavioural tracking cookies within the authenticated Platform environment.

8. Data Security

We implement technical and organisational measures appropriate to the sensitivity of Platform data, including:

  • Encryption of data in transit (TLS 1.2+) and at rest for all personal data;
  • Role-based access controls limiting employee access to personal data on a need-to-know basis;
  • Multi-factor authentication available for all platform user accounts;
  • Pseudonymisation of research participant identity data, held in air-gapped storage separate from ARP profiles;
  • Context-injection architecture: participant data is never embedded in AI model weights, enabling clean data erasure and reducing re-identification risk;
  • Audit logging of platform access and material actions; and
  • Regular security assessments and access reviews, and breach notification procedures under the Australian Notifiable Data Breaches scheme.

No method of electronic storage or transmission is completely secure. We cannot guarantee absolute security, but we will notify you and the relevant regulator in the event of a data breach as required by law.

9. International Data Transfers

As described in Section 6.2, we use service providers located in the United States and other countries. Your data may be transferred to and processed in those jurisdictions, which may not have data protection laws equivalent to those in Australia.

When we transfer data internationally, we ensure appropriate safeguards are in place, including Data Processing Agreements and, where applicable, Standard Contractual Clauses. By using the Platform, you acknowledge these international transfers are necessary to provide the services.

10. Your Rights

Depending on your location, you have the following rights regarding your personal information:

RightDescription
AccessRequest a copy of personal information we hold about you
CorrectionAsk us to correct inaccurate or incomplete information
DeletionRequest deletion of your personal information (subject to legal retention requirements)
PortabilityReceive your data in a structured, machine-readable format (GDPR / CCPA)
ObjectionObject to processing based on legitimate interests
Restrict processingRequest we limit how we use your data in certain circumstances
Withdraw consentWithdraw consent at any time where processing is based on consent
Marketing opt-outUnsubscribe from marketing communications via the unsubscribe link in any email

To exercise any of these rights, contact us at privacy@dilog.ai. We will respond within 30 days (or sooner where required by law). We may verify your identity before processing a request. Some requests may need to be directed through your organisation administrator, who is the data controller for team member data.

11. Data Retention

We retain your information as follows:

Data TypeRetention Period
Account informationDuration of subscription + 12 months after termination
Payment and billing recordsDuration of subscription + 7 years (tax compliance requirement)
Usage logs and session data36 months for security and analytics purposes
Query history and panel outputsDuration of subscription; deleted or anonymised on termination (30-day export window applies)
Support communications36 months
Security and access logs12 months
Aggregated analyticsIndefinitely (no personal identifiers retained)

Where you request deletion of your account before the retention period expires, we will delete or anonymise personal data promptly, except where retention is required by law (e.g. tax and billing records).

12. Your Organisation’s Customer Data

If your organisation connects its Customer Data Platform (CDP) or provides customer data to Dilog for panel enrichment, that data is governed by the Data Processing Agreement between Dilog and your organisation. It is completely optional for your organisation to connect any such data for enhancement of the panel, at your sole discretion during the course of your contract with Dilog. Dilog acts as a data processor for such data, and your organisation remains the data controller. This Platform Privacy Policy does not apply to your organisation’s customer data.

13. Research Panel Data

The research panels you query contain profiles built from interviews with participants who provided their informed consent. You receive only pseudonymised, synthesised responses. You must not attempt to re-identify individual participants or use panel insights in ways that could harm the individuals whose attitudes are reflected. Your use of panel data is governed by the Platform Subscription Agreement or Master Services Agreement.

14. Changes to This Policy

We may update this policy from time to time. Material changes will be notified through the platform and by email to account administrators at least 15 days before they take effect. The current version is always available at dilog.ai/privacy/platform.

15. Contact Us

If you have questions about this policy or wish to exercise your rights:

Dilog Pty Limited (ABN 79 696 521 141)

Email: privacy@dilog.ai

Address: Level 2, Suite 9/56 Bowman St, Pyrmont NSW 2009, Australia

Website: https://dilog.ai/

16. Complaints

If you believe we have breached your privacy, please contact us first at privacy@dilog.ai. If you are not satisfied with our response, you may lodge a complaint with:

  • Australia: Office of the Australian Information Commissioner (OAIC)www.oaic.gov.au
  • New Zealand: Office of the Privacy Commissionerwww.privacy.org.nz
  • EU / UK: Your local Data Protection Authority
  • California: California Privacy Protection Agencycppa.ca.gov

— End of Platform Privacy Policy —

All privacy policies