For Business Clients & Platform Users
Dilog Pty Ltd (ABN 79 696 521 141)
Effective Date: May 15, 2026 · Version 1.1
| Applies to | Individuals and organisations accessing the Dilog Platform under a subscription, including account holders, administrators, and invited team members |
|---|---|
| Related policies | Website Privacy Policy · Participant Privacy Policy |
| Contact | privacy@dilog.ai |
1. About This Policy
This Privacy Policy explains how Dilog Pty Ltd (ABN 79 696 521 141) (Dilog, we, us, or our) collects, uses, discloses, and protects personal information from individuals who use our business platform as employees, contractors, or representatives of our business clients.
This policy applies to you if you access the Dilog platform under a subscription agreement. It covers both business (enterprise) clients and individual self-serve subscribers.
For information about how we handle customer data that your organisation provides to Dilog (such as data from your Customer Data Platform if applicable), please refer to the Data Processing Agreement between Dilog and your organisation.
For website visitors, see our Website Privacy Policy. For research interview participants, see our Participant Privacy Policy.
Dilog is subject to the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we interact with individuals in the EU, UK, or California, additional obligations under the GDPR, UK GDPR, and CCPA may also apply.
2. Who We Are
Dilog provides AI-powered customer research panels that enable businesses to gain insights into customer attitudes, preferences, and decision-making patterns. Our platform allows your team to query digital agents called Anonymised Reflective Profiles (ARPs) built from real customer interviews, where any PII is stripped from the context, providing authentic customer perspectives on demand.
ARPs use a context-injection architecture: participant data is not embedded into AI model weights but is injected at inference time. This is a deliberate design choice that enables clean data erasure and compliance with privacy law, and means participant identity remains separable from the ARP profile at all times.
3. Information We Collect
3.1 Account Information
When your organisation creates user accounts for the Dilog platform, we collect:
| Category | Examples |
|---|---|
| Identity | Full name, job title, department |
| Contact | Business email address, phone number (if provided) |
| Organisation | Company name, ABN/ACN or business registration number, billing address |
| Credentials | Passwords (stored in hashed form only; never stored in plain text) |
| Team members | Names and email addresses of invited users; their roles and access levels |
3.2 Payment and Billing Data
Payment processing is handled by Stripe, Inc for some accounts, and directly invoiced for others. Dilog does not receive or store your full card or bank account details. We do receive and retain:
| Category | Examples |
|---|---|
| Transaction records | Payment amounts, dates, subscription plan, billing period |
| Card reference | Last four digits of card, card type, expiry month/year (provided by Stripe for display and reconciliation purposes only) |
| Billing address | Address used for payment verification and GST invoicing |
| Invoice records | GST tax invoices generated for each transaction, retained for legal compliance |
For full details of how Stripe handles your payment data, see stripe.com/privacy.
3.3 Usage Information
When you use the Dilog platform, we automatically collect:
| Category | Examples |
|---|---|
| Query data | Queries submitted to research panels, research projects created and managed |
| Session data | Login timestamps, session duration, logout events |
| Feature usage | Features accessed, actions taken, navigation paths |
| Technical data | IP address, browser type, operating system, device type |
Query inputs and ARP outputs (together, “traces”) are logged via our observability tooling and may be reviewed by Dilog staff to improve prompt quality, ARP profile accuracy, and response realism. This review is distinct from AI model training — your data is never used to train or fine-tune any underlying language model. Trace review is conducted under internal confidentiality obligations and does not involve sharing your data with third parties. Enterprise clients who require traces to be excluded from quality review entirely may negotiate this in their Master Services Agreement.
3.4 Communications
We retain records of communications between you and Dilog, including support requests, feedback, billing dispute correspondence, and email exchanges. Retained for 36 months.
4. How We Use Your Information
We use the information we collect to:
| Purpose | Description |
|---|---|
| Provide services | Authenticate your access, process queries, deliver research insights and panel outputs, and iterate to guarantee the accuracy of the responses and output. |
| ARP quality | Reviewing traces to improve system prompts, refine ARP profile attributes, and improve response realism and accuracy. Aggregated analysis of output patterns to calibrate panels. |
| Billing and administration | Process payments via Stripe, manage subscriptions, generate invoices, handle renewals and cancellations. |
| Account management | Manage user roles and permissions, send account notifications and service updates. |
| Support | Respond to your requests, troubleshoot issues, resolve billing disputes. |
| Security | Protect against unauthorised access, detect abuse, maintain platform integrity. |
| Product improvement | Analyse aggregated, de-identified usage patterns to improve features and performance. |
| Legal compliance | Meet regulatory requirements, retain records as required by law, respond to lawful requests. |
| Communications | Send service updates and, with consent, product news and marketing. |
5. Legal Basis for Processing
We process your personal information based on:
- Contract: Processing necessary to provide the Platform services and fulfil obligations under the Platform Subscription Agreement or Master Services Agreement, including account management, billing, and panel delivery.
- Legitimate interests: For security, service improvement, platform analytics, and business operations, where these do not override your privacy rights.
- Consent: For optional communications such as marketing emails, where we seek your agreement separately.
- Legal obligation: Compliance with the Privacy Act, tax laws, and other applicable regulations.
For subscribers subject to GDPR or UK GDPR, the above identifies our lawful basis under Article 6. We rely on explicit participant consent (obtained during the interview process) for any special category data that may be reflected in ARP profiles.
6. Who We Share Your Information With
6.1 Your Organisation
Your organisation account administrator may have access to your account information and usage data. Your queries and research projects may be visible to other authorised users within your organisation account.
6.2 Service Providers (sub-processors)
We share information with the following third-party service providers. All sub-processors are contractually bound to process data only on our instructions and to implement appropriate security measures.
| Provider | Location | Purpose |
|---|---|---|
| Stripe, Inc. | United States | Payment processing and subscription billing |
| OpenRouter | United States | API gateway routing queries to AI model providers |
| Langfuse | European Union | LLM observability and tracing — logs AI query inputs and outputs for monitoring, debugging, and quality assurance |
| Anthropic / OpenAI / Google Gemini | United States | AI model providers for ARP query processing (accessed via OpenRouter) |
| Coolify | Australia (Dilog infrastructure) | Application deployment and infrastructure management — data remains within Dilog-controlled servers |
| Amazon Web Services (AWS) | United States / Australia | Cloud infrastructure and data storage |
| HubSpot | United States | Account and CRM management, billing communications |
| Google Analytics | Australia / United States | Onsite tracking and reporting for improvements and quality assurance. Not firing events with query data in logged-in app state. |
| Google Workspace | Australia / United States | Internal communications and transactional email |
We will update this list as new sub-processors are engaged and notify affected clients as required by applicable law or any executed Data Processing Agreement.
6.3 Other Disclosures
We may also disclose your information:
- Where required by law, court order, or government authority (we will notify you where legally permitted to do so);
- To protect the rights, property, or safety of Dilog, our clients, or the public;
- In connection with a merger, acquisition, or sale of assets (with notice to your organisation where practicable).
We do not sell your personal information. We do not share your query data or ARP outputs with third parties for their own commercial purposes.
7. Cookies and Tracking Technologies
We use cookies and similar technologies within the Platform to:
- Essential cookies: Enable core functionality such as authentication and session management. These cannot be disabled without preventing use of the Platform.
- Analytics cookies: Understand how users interact with the Platform to improve the service. We use privacy-respecting analytics tools and do not enable advertising or cross-site tracking.
- Preference cookies: Remember your settings and display preferences across sessions.
You can manage cookie preferences through your browser settings. Disabling essential cookies will prevent you from using the Platform. We do not use advertising or behavioural tracking cookies within the authenticated Platform environment.
8. Data Security
We implement technical and organisational measures appropriate to the sensitivity of Platform data, including:
- Encryption of data in transit (TLS 1.2+) and at rest for all personal data;
- Role-based access controls limiting employee access to personal data on a need-to-know basis;
- Multi-factor authentication available for all platform user accounts;
- Pseudonymisation of research participant identity data, held in air-gapped storage separate from ARP profiles;
- Context-injection architecture: participant data is never embedded in AI model weights, enabling clean data erasure and reducing re-identification risk;
- Audit logging of platform access and material actions; and
- Regular security assessments and access reviews, and breach notification procedures under the Australian Notifiable Data Breaches scheme.
No method of electronic storage or transmission is completely secure. We cannot guarantee absolute security, but we will notify you and the relevant regulator in the event of a data breach as required by law.
9. International Data Transfers
As described in Section 6.2, we use service providers located in the United States and other countries. Your data may be transferred to and processed in those jurisdictions, which may not have data protection laws equivalent to those in Australia.
When we transfer data internationally, we ensure appropriate safeguards are in place, including Data Processing Agreements and, where applicable, Standard Contractual Clauses. By using the Platform, you acknowledge these international transfers are necessary to provide the services.
10. Your Rights
Depending on your location, you have the following rights regarding your personal information:
| Right | Description |
|---|---|
| Access | Request a copy of personal information we hold about you |
| Correction | Ask us to correct inaccurate or incomplete information |
| Deletion | Request deletion of your personal information (subject to legal retention requirements) |
| Portability | Receive your data in a structured, machine-readable format (GDPR / CCPA) |
| Objection | Object to processing based on legitimate interests |
| Restrict processing | Request we limit how we use your data in certain circumstances |
| Withdraw consent | Withdraw consent at any time where processing is based on consent |
| Marketing opt-out | Unsubscribe from marketing communications via the unsubscribe link in any email |
To exercise any of these rights, contact us at privacy@dilog.ai. We will respond within 30 days (or sooner where required by law). We may verify your identity before processing a request. Some requests may need to be directed through your organisation administrator, who is the data controller for team member data.
11. Data Retention
We retain your information as follows:
| Data Type | Retention Period |
|---|---|
| Account information | Duration of subscription + 12 months after termination |
| Payment and billing records | Duration of subscription + 7 years (tax compliance requirement) |
| Usage logs and session data | 36 months for security and analytics purposes |
| Query history and panel outputs | Duration of subscription; deleted or anonymised on termination (30-day export window applies) |
| Support communications | 36 months |
| Security and access logs | 12 months |
| Aggregated analytics | Indefinitely (no personal identifiers retained) |
Where you request deletion of your account before the retention period expires, we will delete or anonymise personal data promptly, except where retention is required by law (e.g. tax and billing records).
12. Your Organisation’s Customer Data
If your organisation connects its Customer Data Platform (CDP) or provides customer data to Dilog for panel enrichment, that data is governed by the Data Processing Agreement between Dilog and your organisation. It is completely optional for your organisation to connect any such data for enhancement of the panel, at your sole discretion during the course of your contract with Dilog. Dilog acts as a data processor for such data, and your organisation remains the data controller. This Platform Privacy Policy does not apply to your organisation’s customer data.
13. Research Panel Data
The research panels you query contain profiles built from interviews with participants who provided their informed consent. You receive only pseudonymised, synthesised responses. You must not attempt to re-identify individual participants or use panel insights in ways that could harm the individuals whose attitudes are reflected. Your use of panel data is governed by the Platform Subscription Agreement or Master Services Agreement.
14. Changes to This Policy
We may update this policy from time to time. Material changes will be notified through the platform and by email to account administrators at least 15 days before they take effect. The current version is always available at dilog.ai/privacy/platform.
15. Contact Us
If you have questions about this policy or wish to exercise your rights:
Dilog Pty Limited (ABN 79 696 521 141)
Email: privacy@dilog.ai
Address: Level 2, Suite 9/56 Bowman St, Pyrmont NSW 2009, Australia
Website: https://dilog.ai/
16. Complaints
If you believe we have breached your privacy, please contact us first at privacy@dilog.ai. If you are not satisfied with our response, you may lodge a complaint with:
- Australia: Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au
- New Zealand: Office of the Privacy Commissioner — www.privacy.org.nz
- EU / UK: Your local Data Protection Authority
- California: California Privacy Protection Agency — cppa.ca.gov
— End of Platform Privacy Policy —
All privacy policies