Legal
Data Processing Agreement
1. Roles
Your organisation is the controller of the personal data in your workspace. Duna is the processor, acting only on your documented instructions (the instructions being your use of the product and this agreement).
2. Subject matter & duration
Processing of workspace data for the purpose of providing the Duna knowledge-assistant service, for the duration of your subscription and until data is deleted per Section 7.
3. Nature & purpose
Storing curated Q&As, matching employee questions against them, routing unanswered questions to your experts, and sending related notifications.
4. Categories of data & data subjects
- Data subjects: your employees and administrators.
- Data: names, email addresses, questions asked, curated answers, attachments your team uploads, and sign-in logs. Do not put special categories of data (Art. 9) into workspace content.
5. Sub-processors
You authorise the sub-processors listed in our Privacy Policy (Hetzner, OpenAI, Resend, Cloudflare). We will give notice before adding or replacing a sub-processor, and you may object on reasonable data-protection grounds. Transfers outside the EU (OpenAI, US) are covered by appropriate safeguards (Standard Contractual Clauses).
6. Security measures
- Encryption in transit (TLS); passwords hashed.
- Workspace-level tenant isolation; role-based access; optional 2FA.
- Data hosted on EU (Germany) servers; private attachment storage.
- Encrypted, rolling backups; server firewalled to required ports only.
7. Return & deletion
You can export your full knowledge base at any time from the product (JSON + Markdown). On termination, we delete workspace data within 30 days, save for backups which expire on their rolling schedule.
8. Assistance
We assist you, taking into account the nature of processing, with data subject requests, security, breach notification and data protection impact assessments.
9. Personal data breach
We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification obligations.
10. Audit
We make available the information necessary to demonstrate compliance with Art. 28 and allow for reasonable audits, on notice and subject to confidentiality.
