Legal
Privacy Policy
This policy explains how Duna handles personal data for our website (askduna.com) and our product (app.askduna.com). We keep it plain, because trust is the point of what we build.
Who we are
Duna ("we") provides an AI knowledge assistant for businesses. For questions about this policy or your data, contact hello@askduna.com.
The website
Our marketing website (askduna.com) sets no cookies, uses no analytics or tracking, and loads no third-party scripts — fonts and images are served from our own servers. Visiting it does not create a profile of you.
The product
When your organisation uses Duna, we process data on behalf of your organisation (which is the "controller"). We act as a "processor". The data involved:
| Data | Why | Legal basis |
|---|---|---|
| Account: name, email, password (hashed) | Sign-in, notifications | Performance of contract |
| Workspace content: questions asked, curated Q&As, attachments | To provide the knowledge assistant | Performance of contract |
| Usage logs (e.g. IP at sign-in, timestamps) | Security, abuse prevention | Legitimate interest |
A strictly-necessary session cookie keeps you signed in. No advertising or analytics cookies are used.
Where your data lives
All application data is hosted on servers in Germany (EU). We keep no hard dependency on non-EU managed services for storage.
Processors we use
| Processor | Purpose | Location |
|---|---|---|
| Hetzner | Server hosting & backups | Germany (EU) |
| OpenAI | Embeddings & answer phrasing (AI) | United States |
| Resend | Transactional email (invites, resets) | EU region |
| Cloudflare | DNS, email routing, static site | Global CDN |
Note on OpenAI (US transfer): to match questions and phrase answers, question and Q&A text is sent to OpenAI in the United States, under their API terms (no training on the data). This is the one non-EU transfer; it is covered in our Data Processing Agreement. An EU-hosted model can be substituted for customers who require it.
Retention
We keep workspace data for as long as the account is active. Encrypted backups are retained on a rolling basis (14 daily / 8 weekly) and then deleted. On account closure, data is deleted within 30 days.
Your rights
Under the GDPR you can request access, correction, deletion, restriction, and portability of your data. Admins can export the full knowledge base (JSON + Markdown) from inside the product at any time. To exercise other rights, email hello@askduna.com; you also have the right to lodge a complaint with your data protection authority.
Security
Data is encrypted in transit (TLS). Passwords are hashed. Access is workspace-isolated and role-based, with optional two-factor authentication. Attachments are stored privately and never exposed on public URLs.
Changes
We'll update this page when our practices change and revise the date above.
