Duna

Legal

Privacy Policy

Last updated: 13 July 2026

This policy explains how Duna handles personal data for our website (askduna.com) and our product (app.askduna.com). We keep it plain, because trust is the point of what we build.

Who we are

Duna ("we") provides an AI knowledge assistant for businesses. For questions about this policy or your data, contact hello@askduna.com.

The website

Our marketing website (askduna.com) sets no cookies, uses no analytics or tracking, and loads no third-party scripts — fonts and images are served from our own servers. Visiting it does not create a profile of you.

The product

When your organisation uses Duna, we process data on behalf of your organisation (which is the "controller"). We act as a "processor". The data involved:

DataWhyLegal basis
Account: name, email, password (hashed)Sign-in, notificationsPerformance of contract
Workspace content: questions asked, curated Q&As, attachmentsTo provide the knowledge assistantPerformance of contract
Usage logs (e.g. IP at sign-in, timestamps)Security, abuse preventionLegitimate interest

A strictly-necessary session cookie keeps you signed in. No advertising or analytics cookies are used.

Where your data lives

All application data is hosted on servers in Germany (EU). We keep no hard dependency on non-EU managed services for storage.

Processors we use

ProcessorPurposeLocation
HetznerServer hosting & backupsGermany (EU)
OpenAIEmbeddings & answer phrasing (AI)United States
ResendTransactional email (invites, resets)EU region
CloudflareDNS, email routing, static siteGlobal CDN

Note on OpenAI (US transfer): to match questions and phrase answers, question and Q&A text is sent to OpenAI in the United States, under their API terms (no training on the data). This is the one non-EU transfer; it is covered in our Data Processing Agreement. An EU-hosted model can be substituted for customers who require it.

Retention

We keep workspace data for as long as the account is active. Encrypted backups are retained on a rolling basis (14 daily / 8 weekly) and then deleted. On account closure, data is deleted within 30 days.

Your rights

Under the GDPR you can request access, correction, deletion, restriction, and portability of your data. Admins can export the full knowledge base (JSON + Markdown) from inside the product at any time. To exercise other rights, email hello@askduna.com; you also have the right to lodge a complaint with your data protection authority.

Security

Data is encrypted in transit (TLS). Passwords are hashed. Access is workspace-isolated and role-based, with optional two-factor authentication. Attachments are stored privately and never exposed on public URLs.

Changes

We'll update this page when our practices change and revise the date above.

Data Processing Agreement →