Privacy policy
What Dardaris collects, where it is held, who can reach it, and what you can ask us to do with it.
Effective 17 Sep 2026
On this page
- 1. Who we are
- 2. The two roles, and which one applies
- 3. What this notice covers
- 4. What we collect
- 5. Where we get it
- 6. What we do with your content
- 7. Analytics
- 8. Where the service runs, and what we do not promise about it
- 9. International transfers
- 10. Your copy in your browser
- 11. Who we share it with
- 12. Why we are allowed to process it
- 13. How long we keep it
- 14. Processors and sub-processors
- 15. The data processing agreement
- 16. What the automation does, and what AI does with your content
- 17. Children and minors
- 18. Your rights
- 19. If you are in the United States
- 20. How it is kept safe
- 21. Changes to this notice
- 22. Contact
- 23. Language
This is the full text. The short version is on the privacy summary, and every section there links back to the matching section here.
Two kinds of personal data pass through this product and they are not the same in law. There is data about you, the customer who signed up, and there is data about the people in your buildings, which you enter or which arrives in your inbox. This document says which is which every time it matters, because the answer changes who is responsible.
1. Who we are
1.1 Dardaris is a product of Techroun LLC, Shams Business Center, Sharjah Media City Free Zone, Al Messaned, Sharjah, trade licence number 2543150.01 issued by Sharjah Media City, tax registration number 105325244900001.
1.2 Dardaris is the product. The company named above is the one that operates and commercialises it, and it is the company you are dealing with: in this notice "we" and "us" mean that company, never the software. A request under this notice is made to it, and it is the company answerable for the processing described here.
1.3 Our seat is in Sharjah, the United Arab Emirates.
1.4 Our representative in the European Economic Area. We are established outside the European Economic Area, so the law there requires us to designate a representative in it. That appointment is in hand, and the representative's name and address are published here as soon as it is made. Until then, a request or a notice that would go to a representative reaches us directly at the address in the Contact section below, and it is handled in exactly the same way and to the same deadlines.
1.5 Our representative in the United Kingdom. We are established outside the United Kingdom, so the law there requires us to designate a representative in it. That appointment is in hand, and the representative's name and address are published here as soon as it is made. Until then, a request or a notice that would go to a representative reaches us directly at the address in the Contact section below, and it is handled in exactly the same way and to the same deadlines.
1.6 We have not appointed a data protection officer. We say that plainly rather than give an ordinary support address a title it does not hold: a data protection officer is a statutory role with statutory protections, and calling somebody one who has not been appointed misleads you about who you are writing to. Every request described below is handled by us directly.
2. The two roles, and which one applies
2.1 Where we are the controller. For the marketing site, the beta list, your account, your authorised users, sign-in and security, billing, support, and our own administration of the service, we decide why and how the data is processed, and this notice describes it.
2.2 Where we are your processor. For the content you put into the product, the buildings, the units, the leases, the rents, the payments, the arrears, the maintenance, the documents, the bookings, the messages and the notes, and for the people described in them, you are the controller and we act for you. We process it on your documented instructions, which in practice are the settings you choose, the workflows you enable and the actions you approve. That processing is governed by our data processing agreement rather than by this notice, and where the two disagree about your content, the agreement wins.
2.3 Which role applies is a question of fact and of law, not of which one suits us. There are places where both apply to the same record: a lease you entered is your content, and the log of who signed in and looked at it is ours. Where we say "your content" below, we mean the material we hold for you as your processor.
2.4 You are responsible for telling your tenants, guarantors, contractors, employees and anyone else in your portfolio what the law requires you to tell them, and for making sure the instructions you give us are lawful. We have no relationship with those people and you do, so that part cannot be done from here.
3. What this notice covers
3.1 The marketing site at the front, the sales and beta programme, the product behind the sign-in, our support, and the mail the product sends on your behalf.
3.2 It does not govern your content, which we process only for you and under the data processing agreement, and for which your own privacy notice speaks to the people in your portfolio. It does not cover a bank, an accountant, a syndic, a portal or any other service you also use, even when you paste something from one of them into Dardaris, and it does not cover a site you reach by following a link from here.
4. What we collect
4.1 Before there is an account. Asking for beta access keeps the address you gave us, together with the name, the rough size of your portfolio, the note and the invite code if you added any, as a single row in our database. It also keeps which button on the site you came through, and the campaign the link carried if it carried one, so we can tell where interest comes from; neither is used to build a profile of you or shared with anyone. Nothing is sent to that address until you follow a link we mail you to show it is yours, and the one-time token behind that link is deleted the moment it is used, or stops working seven days after it was sent. We also keep the wording you agreed to, as it was shown to you at the time, so that what you consented to can be proved rather than reconstructed. Every mail we send you carries a one-click link off the list; using it deletes your name, the size of your portfolio, your note and the campaign, and leaves the address and the fact you asked, which is the minimal record described in section 9. Writing to us through the contact form sends your name, your address, the subject, the category and your message to our support mailbox, where it is kept with the rest of the correspondence about your enquiry, and a copy goes back to you. We used to describe that as keeping nothing. That was wrong: a message in a mailbox is stored and processed like anything else, and it is described here as what it is.
4.2 Account and organisation data. Your name, your business contact details, your organisation, your role, your settings, your authorised users and who among them administers the account.
4.3 Authentication and security data. A verifier derived from your password, never the password itself and never anything a stolen database turns back into one. A passkey's public key and its identifier, which cannot be used to sign in as you anywhere, here included. Records of the six-digit codes we send, of sessions, of sign-in attempts, of the address a request came from and of security events. The exact algorithms and parameters are in our technical and organisational measures rather than in this notice, because they change as the state of the art does and a privacy notice is a bad place to make a technical promise that has to keep up.
4.4 Billing and transaction data. Your plan, the number of units and of connected bank accounts it is charged for, your invoices, your tax and billing details, and the state of a payment. Payments are taken by Stripe. The card or debit details you pay with are typed into Stripe's own pages, at checkout and in its billing portal, and go to Stripe rather than to us, and so do the billing address and VAT number you give there. Section 14 lists everything Stripe receives.
4.5 Support and communications data. Your messages to us, their attachments, our replies, and the history of an enquiry. If you open an account and do not start a plan, we may ask you why, at most three times over about two weeks, and we keep the reasons you choose and anything you write back with your account.
4.6 Service and usage data. Which features are used, when, by which account, and the technical, diagnostic and error records a running service produces.
4.7 Your content. Everything you enter or import, and everything derived from it inside the product. Much of it is personal data about someone who is not you, most often a tenant.
4.8 AI inputs and outputs. The questions you ask the product, the instructions you give it, the documents and the content sent to a model as context, and what comes back: the extracted fields, the classifications, the drafts, the summaries and the answers. The numeric representations of your content that the search index is built from, called embeddings, are held for as long as the content they describe is, and they are treated as personal data because content that can be searched back to a person is personal data whatever shape it is stored in.
4.9 Beta and marketing data. Your business contact details, the size of your portfolio, an invite code, your preferences, and whether you opened what we sent.
4.10 Bank connection data. Only if you connect a bank account, which is optional. We receive the accounts you chose to share: their IBANs, the names of their holders and their balances, and the movements on them, each with its amount, its date, the name and account number of the other party and the payment reference. A movement can carry a tenant's personal data. What arrives is your content, held in the portfolio the way an imported bank statement is. We also hold the tokens a connection is read with, encrypted on our servers, and never your bank credentials. With the connection we keep which of the two services in clause 5.2 made it, the name that service gave the organization or the institution you connected, and who on your team connected it, and we go on keeping those, without the tokens, after the connection is taken back or ended, until the account closes.
4.11 Fields marked as required are the ones we need to open or run an account or to provide the feature you asked for; without them we may not be able to do that. Everything else is optional.
5. Where we get it
5.1 From you, when you type it, upload it or send it to us. From the customer or the administrator who invited you, if somebody else opened the account you use. From your use of the service, and from the browser and device you use it on. From a service you told us to connect to. And, for your content, from wherever you chose to bring it from, which is your choice and your responsibility to have the right to make.
5.2 Bank connections. A bank connection is provided by one of two account information services, and which of them reaches your bank is worked out by us rather than chosen by you. One is Ponto, a service of Isabel NV, a licensed account information service provider in Belgium, which we use wherever it reaches your bank. The other is Plaid, provided by the Plaid company its own terms name for where you are, which we use for the banks Ponto does not reach. You authorise the connection at that service and at your bank, under that service's own terms, and your bank credentials are typed into its page and never into ours. It then sends us what clause 4.10 describes, and tells us by a signed notification, called a webhook, when new movements arrive or a connection ends. We never ask either of them to initiate a payment.
6. What we do with your content
6.1 We process your content on your documented instructions, to provide, run, secure and support the service, to deal with a technical or security problem, to comply with the law, and as the data processing agreement otherwise sets out. Our people reach it only where that is reasonably necessary for one of those purposes, under confidentiality and under access controls.
6.2 We do not sell it, we do not disclose it for advertising, and we do not use it to train a general purpose or shared model, our own or anybody else's. Unless you have agreed otherwise with us in writing, that stays true, and it is true of everything the AI features described below read and produce.
6.3 We may produce and use aggregated statistics, and data that has been altered so that it no longer identifies you, your customer or any person and cannot reasonably be linked back to one, in order to run, secure, measure and improve the service. We do not try to reverse that, except to check that it worked. Data that merely has the name taken off it is not covered by this paragraph and is treated as personal data throughout.
7. Analytics
7.1 Analytics run in your browser only if you accept them, and nothing analytical happens before you answer.
7.2 If you accept, PostHog records which pages are used and a small number of named product events, such as a lease being encoded or an indexation being prepared. The events are tied to a pseudonymous identifier and, once you are signed in, to your account id. Your name is not sent. Nothing from your portfolio is sent: not an amount, not an address, not a tenant. That is kept by the code rather than by our good intentions: automatic capture is off, page text and element attributes are masked, and what leaves is the handful of events we wrote by hand. If you refuse, the library is never started, no identifier is minted, no cookie is written and nothing is sent. The cookie policy lists every key by name.
7.3 Separately, and whatever you answered, our server records one event when an account's portfolio is first created. It carries the account id and nothing else, it places nothing on your device and reads nothing from it, and it happens once in the life of an account. We use it to count how many accounts have been activated, we rest it on our legitimate interest in measuring that, we keep it for 12 months, and we delete it when you ask us to delete your analytics data. An account id is not anonymous and this notice does not call it that.
7.4 You can change your answer at any moment, from the cookie preferences control on the cookie policy page or in the footer of any page on the public site. Withdrawing consent stops the processing from that point; it does not undo what was lawfully done before.
7.5 Bugs you report and features you ask for. When you fill in a report page we keep what you typed, who typed it, and the page you were on. Where you are not signed in we ask for an email address so that we can write back; where you are, we record your account instead. We also keep the same thing when you mention a fault or ask for something the product cannot do while you are talking to the assistant: what you said is recorded as a report so it reaches the people who can act on it, and the assistant does not interrupt the conversation to tell you so. Reports are grouped by what they are about, so that we can see how many people have hit the same thing. We rest this on our legitimate interest in knowing what to fix and what to build, we keep it for 24 months, it is never used to make any decision about you or your account, and you can ask us to delete yours.
8. Where the service runs, and what we do not promise about it
8.1 The database is Cloudflare D1, which is SQLite run by Cloudflare, holding the authentication tables and your content side by side. The files you upload, and the smaller copies the product derives from them, are held in Cloudflare R2, an object store run by the same provider, each filed under your account alone. The application runs as a Cloudflare Worker, placed to sit near that database. Mail leaves through Cloudflare's own sending binding. Analytics go to PostHog's European Union cloud.
8.2 There is no data residency commitment in the standard service, and this notice does not make one. Cloudflare, PostHog and any other provider we use run infrastructure, staff and their own sub-processors in more than one country. A D1 database has one primary location chosen when it is created, and a location hint is not a guarantee; requests, Workers execution, account metadata, backups, support access and analytics are not confined by it. Unless a signed order or a residency addendum says otherwise for your account, we do not promise that your content, your personal data, the backups, the traffic or the metadata stay in a particular country or region, and processing may happen outside the country you or the people in your portfolio are in.
8.3 If you need a region, ask before you sign up. Write to support@dardaris.com before you create an account or put anything in it. We will tell you what the current configuration is and whether what you need is feasible. A statement of the current primary location, a sales conversation or a support reply is information, not a commitment: a residency commitment exists only where somebody authorised to give one has given it in a signed document naming the data, the locations, the services, the exceptions and the price. Until that exists, deciding whether the standard service meets your requirement is yours to do, and you should not put the data in if a particular location is mandatory for you.
9. International transfers
9.1 Our seat is in Sharjah, the United Arab Emirates, which is outside the European Economic Area and has no adequacy decision from the European Commission. Your content stays on the infrastructure described above and is not copied into a second database at our seat, but we reach it from there to run and support the service, and under the GDPR that access is a transfer whether or not anything is copied. We say so here rather than leave it to be worked out from an address at the foot of the page.
9.2 Where personal data from the European Economic Area, the United Kingdom or Switzerland goes to a country without an adequacy decision, we rely, as applicable, on the standard contractual clauses adopted by the European Commission with the United Kingdom addendum or the Swiss adaptations where those apply, on an adequacy framework where one covers the transfer, or on another lawful mechanism, together with the further measures the case requires. Write to support@dardaris.com and we will send you the clauses we rely on, with the commercial terms redacted.
9.3 Isabel NV, which provides the Ponto bank connections in clause 11.4, is established in Belgium, inside the European Economic Area, so what we send it is not a transfer out of the Area. Plaid, which provides the other bank connections in that clause, processes in the United States as well as in the Area and the United Kingdom, so what reaches it can be a transfer out of the Area, made under clause 9.2. What either of them sends us is then held on the infrastructure described above, under clauses 9.1 and 9.2 like the rest of your content.
9.4 Stripe, which takes payments as section 14 describes, is engaged through Stripe Payments Europe, Limited, in Ireland, inside the European Economic Area, which is the Stripe company its terms name for an account held outside the Americas, as ours is. What we send Stripe therefore arrives inside the Area. Stripe then passes it to Stripe, LLC in the United States and to other Stripe companies and service providers, in India among other countries, and that is a transfer out of the Area and out of the United Kingdom. Stripe makes it under its certification to the EU-U.S. Data Privacy Framework, the UK Extension to it and the Swiss-U.S. Data Privacy Framework, and otherwise under the standard contractual clauses with the United Kingdom's international data transfer addendum.
9.5 At home we are also subject to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. Where that statute and the GDPR both reach the same processing, we apply whichever gives the stronger protection. Nothing in this section removes an obligation that cannot lawfully be removed.
10. Your copy in your browser
10.1 The product keeps a copy of the portfolio for the signed-in account in your browser's localStorage, so a screen can draw before the network answers and a dropped connection does not empty the room. It contains your content, which includes personal data about other people, so it is not simply "your own data" and this notice does not describe it that way. Edits you have made and we have not yet accepted are kept beside it, so a dropped connection cannot lose your work, and a third key records which account the other two belong to so that a different person signing in on the same browser is never shown your copy.
10.2 Signing out removes all three. Clearing the site's data in your browser removes them too. They are listed as strictly necessary keys in the cookie policy, on the basis that the product is built to keep working when the network does not and that this storage is what makes that possible rather than merely making it faster.
10.3 Because that copy sits on a device rather than on a server, part of protecting it is yours. Use the product on a device and a browser profile you trust, sign out when you have finished on a shared or public machine, and tell us at support@dardaris.com if you think a device has been lost or a browser profile has been used by somebody else, so that the sessions can be revoked.
11. Who we share it with
11.1 We disclose personal data only as far as is reasonably necessary for the purposes in this notice, and then to:
- Cloudflare, PostHog, Stripe and the other providers listed below, for hosting, infrastructure, mail, analytics, payments, security and support;
- Isabel NV, as Ponto, or Plaid, if you connect a bank account, as clause 11.4 describes;
- the customer whose account the data belongs to, its administrators and its authorised users, according to the permissions they have set;
- our own people and contractors who need it, under confidentiality;
- professional advisers, auditors and insurers, under confidentiality;
- a regulator, a court, a law enforcement body or another authority, where the law requires it or where it is reasonably necessary to protect a right, somebody's safety, or the integrity of the service; and
- an actual or prospective buyer, investor or successor, in a financing, reorganisation, merger or sale, under confidentiality and with the safeguards the law requires.
11.2 We may also disclose data where you tell us to, or where the person it is about has agreed.
11.3 We do not sell personal data and we do not disclose it for cross-context behavioural advertising. That is true in the ordinary meaning of the words and in the statutory meaning some jurisdictions give them.
11.4 Bank connections. What each of the two services in clause 5.2 receives from us is not the same, so each is set out here. For Ponto: each time someone on a team starts a bank connection, until the team has completed one, we send Ponto the name and email address of the person connecting, and the team's name, whether it is a business or an individual, and its enterprise and VAT numbers and its address where you have given them, so that Ponto's own sign-up opens already filled in. Ponto can use that only to fill in a new sign-up, and only within five minutes of our sending it. When you link an account, or ask for a refresh from a screen, we send Ponto your IP address, which Ponto requires for every refresh it performs at your request. For Plaid: we send an identifier we mint for the person and the team, which names neither of them, and nothing else about you. Plaid's own window runs in your browser rather than on our servers, so what your bank and Plaid see of your device and your address they see directly, under Plaid's own notice and not through us. Isabel NV receives these as an independent provider under its own licence and its own terms with you, not as our processor, and Plaid receives what it receives on the same footing, which is why neither of them is in the table in section 14. What each does with what it receives is governed by its own privacy notice. In the product, disconnecting one account asks the service to stop sharing that account with us. Taking back a whole connection, or disconnecting the last account it reads, deletes the tokens we held for it and asks the service to end it. We also act at the service without being asked, in four cases. An account the bank shared with us that is not paired with one of your bank accounts within a day of its first being shared is let go, and the service is asked to stop sharing it. A paired account the service no longer shares with us stops being read, and its pairing ends here. When your team's plan has ended, every connection the team holds is ended at the service and the tokens we held for it are deleted. And an account connected before connected accounts were charged, which you did not agree to keep at its price by the date we told you, is let go in the same way as an account never paired.
12. Why we are allowed to process it
12.1 This section is about the data for which we are the controller. Where we act as your processor, you decide the lawful basis and we act on your instructions under the data processing agreement.
| What we do | What it uses | On what basis |
|---|---|---|
| Open and run an account for a customer who contracted with us | Account, authentication and service data | Performance of that contract, and steps taken before it at your request |
| Administer the authorised users of a business customer | Account, organisation and usage data | Our legitimate interest in running and administering the customer relationship |
| Invoice, account and pay tax | Account, billing and transaction data | The contract, and legal obligations that apply to us |
| Keep the service up, authenticate a user, rate-limit sign-in attempts, investigate abuse, troubleshoot and enforce our terms | Authentication, technical, audit and support data, and your content where it is necessary | Our legitimate interest in protecting the service, our customers and our legal rights, and legal obligations where they apply |
| Answer an enquiry or a support request | Contact, support and the relevant account data | The contract or steps before it, and our legitimate interest in supporting a customer |
| Analytics in your browser | Cookie and device identifiers and the named events | Your consent, and nothing else |
| The one server-side account-creation event | The account id | Our legitimate interest in measuring activation, balanced and recorded, and subject to objection |
| The beta list and business-to-business marketing | Contact details and preferences | Your consent where it is required, otherwise our legitimate interest in marketing to a business, always with a way out |
| Ask an account that did not start a plan what held it back, and offer it a longer trial | Your name, your email address, whether your team holds a plan, and the answers you give | Our legitimate interest in understanding why the service did not suit you and in improving it, with a link in every one of those emails to stop them |
| Index your content, answer a question about it and run an automation you enabled, using the AI features described below | Your content, the documents in it and the AI inputs and outputs | Your instructions to us as your processor. You hold the lawful basis for the people in your portfolio |
| Connect a bank account through Ponto or Plaid, and refresh it, when you ask us to | For Ponto, the name and email address of the person connecting, the team's details in clause 11.4, and the IP address an account was linked or a refresh was asked from. For Plaid, an identifier we mint for the person and the team, and nothing that names either of them | Performance of the contract, and steps taken before it at your request. The accounts and movements that come back are your content, processed on your instructions |
| Comply with the law, and bring or defend a claim | Whatever is relevant | Legal obligations, and our legitimate interest in compliance and in our legal rights |
12.2 Where we rely on a legitimate interest, we have weighed it against your interests and rights and recorded the result, and you can object; where the objection succeeds we stop.
12.3 We do not tell you what your own lawful basis is for the tenants and contractors in your portfolio. That depends on your jurisdiction, your purpose, your relationship with them and what you hold, and a supplier who hands you a legal conclusion about it is a supplier who has made your problem into a wrong answer. You warrant in the terms that you have one.
13. How long we keep it
13.1 We keep personal data for as long as is reasonably necessary for the purposes above, taking account of your instructions, our contracts, security, the law and the periods within which a claim can still be brought.
| What | How long |
|---|---|
| Your content, after the account closes | 30 days, to let you export or reactivate, then removed from active systems |
| Database history and backups | Up to 30 days after removal from active systems, on the provider's own cycle. This is Cloudflare D1's Time Travel window, it is not ours to shorten, and a deletion promise that ignored it would not be true |
| Account and organisation records | 90 days after closure, except what billing, security, a dispute or the law requires us to keep |
| Invoices and accounting records | For as long as tax and accounting law requires |
| Support correspondence | 24 months after the matter closes, longer if the account, an incident or a claim is still live |
| Bug reports and feature requests | 24 months. Kept whether you filled in a report page or mentioned it to the assistant, and grouped by what it is about so we can count how many people asked |
| Security and technical logs | 90 days, unless one is set aside for an investigation, an enforcement or a claim |
| AI inputs, outputs and search index entries | The same as the content they came from, and removed with it |
| The tokens a bank connection is read with | Until the connection is taken back, by you or at the service that provides it, ended by us because your plan ended, or replaced by a newer one, and deleted then. A connection started and never finished is deleted after a day |
| Which service made the connection, the name it gave what you connected, and who on your team connected it | While the connection stands, and after it is taken back or ended, without the tokens, until the account closes |
| A file uploaded only to be read, before there is a record to file it against | 24 hours, deleted by the object store's own expiry rule whether or not you go on to save anything. A title deed read to fill in a new building is the case this covers: if you then add the building, the copy filed against it is your content and follows the row above instead |
| Analytics | 12 months from collection |
| The beta list | 12 months from the last contact, or until you ask to come off it, whichever is first. We keep a minimal record of the fact you opted out, so that we can honour it |
| Your answers to why you did not start a plan, and when we asked | For as long as the account exists, and erased with it |
| Sessions | 7 days without use, and sooner if revoked |
| Sign-in codes | 5 minutes |
| Consent and compliance records we hold | For as long as we need them to show what was agreed, and through the period a claim can be brought. The wording you agreed to on the beta list is one of them; your answer on analytics is not, because it is kept in your browser and is never sent to us |
13.2 We may keep something longer where the law requires it, where we have been asked to preserve it, or where it is reasonably necessary to bring or defend a claim, to enforce an agreement, to prevent fraud or to protect the service. That is an exception for a reason that exists, not a reason to keep everything.
14. Processors and sub-processors
| Who | What they do for us | Where |
|---|---|---|
| Cloudflare | Hosting, the Workers the application runs on, the D1 database that holds your content and your account, the R2 store that holds the files you upload and the copies derived from them, outbound mail, and part of the AI inference, indexing and pipeline services the features below run on | Cloudflare's global network. The database has one primary location, which we will tell you on request, subject to the section above. Inference and indexing are not confined to it |
| OpenAI | Inference for the AI features below: reading a document you upload and returning what it says, as structured fields or as text you can edit, answering a question about your portfolio, working out what a message that arrived in a mailbox you connected is about, and drafting text you asked for, including the reply to such a message. It receives the content those features are pointed at, and nothing else | The United States, and OpenAI's own infrastructure elsewhere |
| PostHog | Product analytics in your browser if you accepted them, and the one server-side account-creation event | PostHog's European Union cloud |
| Stripe | Taking payment for your plan and keeping its invoices. It receives the team's name; the team's contact email, or the email of the person who started the plan when the team has none; the team's billing address and VAT number, from Settings or from Stripe's own pages; the team's id, kept on Stripe's record of the customer so that a payment can be traced back to the team; the plan, the number of units it is charged for and the number of connected bank accounts it is charged for; and the card or debit details you type into Stripe's own pages. Nothing else from your portfolio reaches it | Ireland, where Stripe Payments Europe, Limited, the Stripe company we contract with, is established, and the United States, India and the other countries Stripe names in its own privacy notice |
14.1 Each is engaged under written terms that hold them to data protection and confidentiality obligations, and each uses sub-processors of its own, which they publish and keep current on their own sites. Their lists are part of this one: Cloudflare's sub-processors, OpenAI's sub-processors, PostHog's sub-processors and Stripe's sub-processors.
14.2 The models run on Cloudflare and on OpenAI. The AI features described below send your content to models run by those two and to nobody else. Which one handles a given feature is our choice and can change between them without notice, so treat both as receiving anything those features are pointed at. No content is sent to any other model provider. If that ever changes, the provider is named in this table, this section is updated and the change is published here before a single document reaches it, and we will ask for consent where the law requires it.
14.3 Sending your content to OpenAI is a transfer out of the European Economic Area and the United Kingdom. OpenAI processes in the United States. That transfer is made under the standard contractual clauses in our agreement with them, and the safeguards, the risks and your rights in respect of it are the same ones set out under "Where your data goes" above. If you need your content kept away from a United States processor, tell us before you upload it: the answer today is that we cannot offer the AI features on those terms, not that we can quietly arrange it.
14.4 If we add or replace a processor, we publish it here before it starts, and the notice period and the way to object are in the data processing agreement.
14.5 Stripe acts for us, and on its own account. Stripe processes what it receives for us when it takes a payment, keeps a payment method on file and issues an invoice. For purposes of its own it decides for itself, among them choosing the banks and payment networks a payment goes through, detecting and preventing fraud, loss and security risks, improving its own services, and meeting the law that applies to it, the identity and anti-money-laundering checks financial law places on it included. For those it answers for that processing as a controller, under its own privacy notice. The card or debit details you type into its pages stay with Stripe: what we read back is the card's brand, its last four digits and its expiry date, so that Billing can say what you pay with.
15. The data processing agreement
15.1 This notice is not a data processing agreement and does not try to be one. Article 28 of the GDPR requires a written contract between you as controller and us as processor for your content, covering the subject matter and duration, the nature and purpose, the categories of data and of people, your documented instructions, confidentiality, security, sub-processors, help with the rights of the people in your portfolio, help with an incident or an assessment, deletion or return at the end, and the information you need to verify all of it.
15.2 That agreement forms part of your contract with us and is published as the data processing agreement. Where it and this notice disagree about your content, it wins.
16. What the automation does, and what AI does with your content
16.1 Dardaris acts on your portfolio: it indexes what you put in, answers questions about it, prepares an indexation, drafts a reminder, triages an issue, files a document.
16.2 Your content and your documents are read by AI models where a feature needs them read. This is the part of the product most worth understanding, so it is written out rather than summarised. Where you use a feature that indexes your portfolio, answers a question about it, extracts a figure or a date from a document, or runs an automation you have switched on, your content and the documents you upload are processed by machine learning models: they are read, turned into the numeric representations a search index is built from, classified, extracted from, and used as the context a question is answered against. That covers leases, invoices, certificates, correspondence, notes and anything else you put in, including the personal data in them about tenants, guarantors, contractors and anyone else. Where you connect a mailbox, the messages that arrive in it and the documents attached to them are read the same way, so that what a message is about can be worked out, filed against the right lease or property, and a reply drafted for you. This describes the whole of what a model may be given, so that you can judge it once rather than feature by feature; a feature that reaches its answer without a model sends nothing to one, and storing a file is not the same as reading it.
16.3 Where those models run. On Cloudflare and on OpenAI, and on nobody else. Cloudflare runs models on the same platform the rest of the service runs on, under the same written terms. OpenAI runs the rest, in the United States, and clause 14.3 covers what that transfer rests on. Your content is not sent to Anthropic, to Google or to any other model provider, and if that ever changes we will name the provider in the table above and update this section before it processes anything. We do not undertake to tell you which of the two read a particular document: assume either did.
16.4 What is not done with it. Your content is not used to train a general purpose or a shared model, ours or a provider's. Neither provider trains on what the product sends them: that is what their terms for the services we use commit them to, and it is a term of our agreement with each. Your content is not pooled with another customer's. It is not used to improve anything outside your own account, except as aggregated statistics or as data altered so that it no longer identifies anyone, which is described under "What we do with your content" above.
16.5 How long the model provider holds it. Inputs and outputs held by us follow the same retention as the content they came from, and go when it goes. That is not the whole answer, because a provider keeps its own copy for a while: OpenAI retains what is sent to its interface for up to 30 days so that it can investigate abuse, and deletes it after that unless the law obliges it to keep it longer. So a document read by that feature exists on a third party's systems for up to a month after you delete it here, and telling you that is more useful than a deletion promise this notice cannot keep on another company's behalf.
16.6 What an output is worth. A model's output is a probability, not a finding. It can be incomplete, out of date, wrong, or wrong in a way that looks right, and it is a draft or a piece of decision support rather than legal, accounting, tax or professional advice. Check the source before you act on it. We do not warrant that an output is accurate, complete, lawful or fit for what you want to do with it, and you and your authorised users are responsible for reviewing it, for exercising your own judgement and for every decision you take.
16.7 The controls around it. Every action carries a tier deciding whether it happens on its own or waits for you. The rules resolving that tier can make it stricter and never looser. An action writes an audit record with a summary you can read. A step that stops names the limit that stopped it. Which controls and which records you get depends on the feature and on how you have configured it, and the things that carry legal weight are held for your approval by design.
16.8 What it must not be used for. The service is not designed or authorised to be the sole basis of a decision about a person's eligibility for housing, tenant selection, creditworthiness, the rent they are offered, a benefit, a termination, an eviction or an enforcement, or of any other decision that has a legal effect on them or affects them similarly. You must not use it that way, and you must not configure a workflow that has that effect indirectly. If you want to build something of that kind, come and talk to us first, because that is a different product with a different assessment behind it.
16.9 We do not intend the service to take, on our own behalf, a solely automated decision producing a legal or similarly significant effect on a tenant or anyone else. You remain responsible for how you configure a workflow, for reviewing what it produces, and for a person being properly involved before anything with legal weight goes out in your name. Where we ourselves make such a decision, we will give you the information and the safeguards the law requires. We do use automated measures to detect abuse and protect accounts, which is a different thing and is covered by the security section.
16.10 If you think an automated step has affected somebody unfairly, write to support@dardaris.com and we will look at the audit record with you.
17. Children and minors
17.1 The service is sold to businesses. Nobody under 18 should hold an account or be an authorised user.
17.2 Your content may nonetheless describe a minor, because minors live in buildings and appear on leases as occupants. Where it does, you are the controller of that data: it is for you to make sure the processing is lawful, to keep it to what is necessary, and not to put in more about a child than managing the tenancy actually requires. We do not claim not to hold data about children, because that would be untrue.
18. Your rights
18.1 Subject to the conditions and the exceptions the law attaches to each of them, you may ask us for a copy of the personal data we hold about you, to correct it, to delete it, to restrict what we do with it, to object to processing we base on a legitimate interest, and to receive it in a portable form. You may withdraw a consent at any time, which stops the processing from then on and does not make what came before unlawful, and you may object to direct marketing at any time with no reason and no consequence. These rights are not absolute and not every one of them reaches every category or purpose.
18.2 Write to support@dardaris.com. We may ask for what we reasonably need to be sure who you are, that you are entitled to make the request, and what it covers. We answer without undue delay and normally within one month; where the law allows, we may take up to two further months for a complex or repetitive request and we will tell you inside the first month if we do. We may charge a reasonable fee, or decline, where a request is manifestly unfounded or excessive. We may keep what an exception lets us keep, including what we need in order to comply with the law or to bring or defend a claim.
18.3 Where the request is about your content rather than about you. The tenant, guarantor or contractor should go to the landlord or manager who holds their data, because that is the controller. If such a request reaches us first we will refer or forward it to that customer. We help our customers answer them, as the data processing agreement requires, and we do not charge the person making the request.
18.4 Complaining. You can complain to a supervisory authority. Because we are established in Sharjah, the United Arab Emirates, the authority for the company at home is the UAE Data Office. We have no main establishment in the European Union, so there is no single lead authority for us there and no one-stop shop: if you are in the European Economic Area you may complain to the supervisory authority of the country you live in, the country you work in, or the country where you think the problem happened. In the United Kingdom that is the Information Commissioner's Office. You do not have to come to us first, though we would rather you did.
19. If you are in the United States
19.1 Where a state privacy law applies to you, this section applies with it, and where it conflicts with anything above, this section wins for you.
19.2 The categories of personal information we collect, the sources they come from, the purposes we use them for and who we disclose them to are set out in "What we collect", "Where we get it", "Why we are allowed to process it" and "Who we share it with" above, and they are the disclosures those laws ask for.
19.3 We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in the California Consumer Privacy Act and in the comparable statutes of the other states, and we have not done so in the last twelve months. We do not knowingly do either with the personal information of anyone under 16.
19.4 Sensitive personal information. We do not collect it in order to infer anything about you, and we do not use or disclose it for any purpose beyond the ones those laws permit without a right to limit. Your content may contain something a statute treats as sensitive if you put it there, and you should not put it there unless you have to.
19.5 Your rights. Depending on your state, you may have the right to know what we collect and what we do with it, to a copy of it, to correct it, to delete it, to opt out of sale, sharing or targeted advertising, to limit the use of sensitive personal information, to appeal a decision we make on a request, and not to be discriminated against for exercising any of them. We do not offer a financial incentive for personal information.
19.6 Make a request at support@dardaris.com. An authorised agent may make one for you, with proof that you authorised them and enough for us to verify you. If we refuse a request we will tell you why, and you can appeal by replying to that answer with the word appeal in it; we will answer the appeal within the period your state's law allows and tell you how to escalate it to your attorney general if you are still unhappy.
19.7 Where you are a resident whose data reaches us as our customer's content rather than as our own, we act as that customer's service provider or processor, we use the data only to perform the service for them, and a request about it belongs with them.
20. How it is kept safe
20.1 We use technical and organisational measures designed to protect personal data, chosen against the nature of the processing and the risks it carries. They include encryption in transit, protection of credentials by a one-way function rather than storage of anything that can be turned back into a password, a verification code before a first sign-in, support for passkeys, access controls, session management and revocation, rate limiting, logging, secure development practice, backups, vulnerability management and an incident response procedure. We review them and we may change them, as long as the protection overall is not materially reduced.
20.2 No service, no transmission and no storage is completely secure, and we do not promise that nothing will ever go wrong, that the service will never be interrupted, or that no unauthorised access will ever occur. What we promise is to use measures appropriate to the risk and to tell you when we should.
20.3 Part of it is yours. Keep your devices, your browser profiles, your mailbox, your credentials and your passkeys secure. Give each authorised user the permissions they need and not more. Look at what an integration or an export takes out of the product. Sign out on a shared machine. And tell us at once if you think somebody else has got in.
21. Changes to this notice
21.1 The effective date at the top is a literal date that changes when the document changes. It is never taken from the clock of the machine that served the page, because a document dated by the server is dated wrongly the moment it comes out of a cache.
21.2 We may update this notice as the service, the law or our practices change. When we do, we publish the new version here and move that date. Where a change materially affects your privacy we will give you further notice, by email or in the product, before it takes effect where that is practicable; a change we have to make quickly for a legal, security or fraud reason may take effect sooner. Where the law requires consent for a new purpose or a new technology, we will ask for it. A change to what analytics does also bumps the version of the cookie policy, which asks everybody again.
21.3 Continuing to use the service is not by itself a consent, in any case where the law requires a real one.
22. Contact
22.1 support@dardaris.com, or by post to Techroun LLC, Shams Business Center, Sharjah Media City Free Zone, Al Messaned, Sharjah.
23. Language
23.1 This document is written in English, and the English text is the operative version to the extent the law permits. We publish translations of it so that it can be read in the language you work in. A translation is an approximation offered as a reading aid, it is not a second original, nobody is bound by its wording, and where it differs from the English text the English text is the one that applies.
23.2 If English is not a language you read comfortably and something here matters to you, write to support@dardaris.com and we will explain the passage. That is help with reading this document, not a change to what it says.