GDPR Compliance

Last updated: April 2026

1. Our Commitment

Dilagee Ltd ("Dilagee", "we", "us") is fully committed to compliance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and the Data Protection Act 2018. We process personal data lawfully, fairly, and transparently, ensuring your rights are protected at every step.

This page explains how we meet our obligations under data protection law. It should be read alongside our Privacy Policy, Terms of Service, and Cookie Policy.

2. Data Controller and Data Processor Roles

2.1 Dilagee as Data Controller

Dilagee acts as the data controller for personal data we collect directly from you in connection with your use of our platform, including account registration data, billing information, contact form submissions, and usage analytics.

2.2 Dilagee as Data Processor

When you (our business customer) input employee or workforce data into the Service, you are the data controller and Dilagee acts as the data processor on your behalf. As data controller, you are responsible for:

  • Having a lawful basis to process your employees' personal data
  • Providing appropriate privacy notices to your employees
  • Responding to data subject access requests from your employees (we will assist you)
  • Ensuring the accuracy and relevance of employee data entered into the Service

2.3 Data Processing Agreements

We offer Data Processing Agreements (DPAs) to all business customers, as required under Article 28 of the GDPR. Our DPA sets out the scope, nature, and purpose of processing, the types of personal data processed, categories of data subjects, and the obligations and rights of both parties. To request a DPA, contact dpo@dilagee.com.

3. Lawful Basis for Processing

We process personal data under the following legal bases as defined in Article 6(1) of the GDPR:

  • Contract (Article 6(1)(b)): Processing necessary to provide our workforce management services, including account creation, authentication, scheduling, time tracking, compliance tools, AI document generation, payment processing, and transactional communications
  • Legitimate Interest (Article 6(1)(f)): Improving the platform, analysing usage patterns, preventing fraud, ensuring security, rate limiting, abuse detection, and maintaining platform integrity. We have conducted legitimate interest assessments for each of these purposes
  • Consent (Article 6(1)(a)): Marketing communications, newsletters, promotional content, and optional analytics cookies. You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal
  • Legal Obligation (Article 6(1)(c)): Compliance with employment law, tax regulations, food safety record-keeping requirements, health and safety obligations, and responding to lawful requests from regulatory authorities

4. Your Rights

Under the UK GDPR and EU GDPR, you have the following rights:

  • Right of Access (Article 15): Request a copy of all personal data we hold about you. We will respond within one calendar month
  • Right to Rectification (Article 16): Request correction of any inaccurate or incomplete personal data. You can also update most data directly within the Service
  • Right to Erasure (Article 17): Request deletion of your personal data ("right to be forgotten"). You can initiate account closure from your settings, which triggers permanent deletion within 30 days (after a 48-hour grace period)
  • Right to Restrict Processing (Article 18): Request that we limit how we use your data while a concern is being investigated
  • Right to Data Portability (Article 20): Request your data in a structured, commonly used, machine-readable format. The Service provides built-in export functionality for timesheets, rotas, compliance reports, and other data in Excel and PDF formats
  • Right to Object (Article 21): Object to processing based on legitimate interests or for direct marketing purposes. If you object to marketing, we will stop immediately
  • Rights Related to Automated Decision-Making (Article 22): We do not use solely automated decision-making or profiling that produces legal or similarly significant effects on you. Our AI tools generate content for your review and approval — they do not make decisions about individuals

How to exercise your rights: Email our Data Protection Officer at dpo@dilagee.com. We may ask you to verify your identity before processing your request. We will respond within one calendar month. In complex cases, we may extend this by up to two additional months, and we will inform you of any such extension within the first month.

No fee required: You will not normally have to pay a fee to exercise your rights. However, we may charge a reasonable fee or refuse a request if it is clearly unfounded, repetitive, or excessive.

5. Sub-Processors

We use the following sub-processors to deliver the Service. Each sub-processor processes data under a data processing agreement and is subject to appropriate safeguards:

Sub-ProcessorPurposeData LocationTransfer Mechanism
Supabase Inc.Database hosting, authentication, session managementEEA (Frankfurt)N/A (EEA)
Stripe Payments Europe LtdPayment processing, fraud preventionEEA / USSCCs, PCI-DSS certified
OpenAI, L.L.C.AI-powered document generationUnited StatesSCCs, UK IDTA
Resend Inc.Transactional and marketing email deliveryUnited StatesSCCs, UK IDTA
Vercel Inc.Application hosting, content deliveryGlobal (edge network)SCCs, UK IDTA

We will notify customers of any intended changes to sub-processors, giving you the opportunity to object before the change takes effect. To receive sub-processor change notifications, ensure your contact details are up to date in your account settings.

6. Data Retention Schedule

Data CategoryRetention PeriodBasis
Account and profile dataDuration of account + 30 days after closureContract
Employee/workforce dataDuration of account + 30 days after closureContract
Payment and billing records6 years after transactionLegal obligation (UK tax law)
Food safety and compliance recordsDuration of account + 30 days after closureContract / Legal obligation
Contact form submissionsUp to 2 yearsLegitimate interest
Waitlist/beta signup dataUntil programme ends or deletion requestedConsent
Audit and admin action logsDuration of account + 30 days after closureLegitimate interest / Legal obligation
Marketing consent recordsDuration of account + 3 yearsLegal obligation (proof of consent)
Error and server logs90 daysLegitimate interest

7. International Data Transfers

Your primary data is stored within the European Economic Area (EEA) on servers operated by Supabase in Frankfurt, Germany. However, some of our sub-processors are based in the United States (OpenAI, Resend, Vercel). Where personal data is transferred outside the EEA or the United Kingdom, we ensure compliance with Chapter V of the GDPR through:

  • Standard Contractual Clauses (SCCs): EU Commission-approved model clauses included in our agreements with US-based sub-processors
  • UK International Data Transfer Agreement (IDTA): Or the UK Addendum to the EU SCCs, as required for transfers from the United Kingdom
  • Supplementary measures: Including encryption in transit and at rest, access controls, and data minimisation practices
  • Transfer Impact Assessments: We assess the data protection laws of recipient countries to ensure adequate protection

You may request a copy of the relevant transfer safeguards by contacting dpo@dilagee.com.

8. Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) where processing is likely to result in a high risk to individuals' rights and freedoms, in accordance with Article 35 of the GDPR. This includes assessments for:

  • Processing of employee data at scale on behalf of business customers
  • Use of AI-powered tools that process business and operational data
  • International data transfers to sub-processors outside the EEA

DPIAs are reviewed periodically and updated when there are material changes to processing activities.

9. Data Breach Procedures

We maintain a comprehensive data breach response plan in accordance with Articles 33 and 34 of the GDPR:

  • Detection and containment: We monitor our systems for security incidents and will act immediately to contain any breach
  • Supervisory authority notification: Where a breach poses a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach
  • Data subject notification: Where a breach poses a high risk to individuals' rights and freedoms, we will notify affected individuals without undue delay
  • Customer notification: Where we are acting as a data processor, we will notify you (the data controller) without undue delay upon becoming aware of a breach affecting your data
  • Documentation: All breaches are documented, including their effects and the remedial actions taken, regardless of whether notification is required

10. Security Measures

We implement appropriate technical and organisational measures in accordance with Article 32 of the GDPR to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit (TLS/SSL) and at rest
  • Password hashing using industry-standard cryptographic algorithms
  • Row-Level Security (RLS) policies for multi-tenant data isolation
  • Rate limiting and CAPTCHA protection on public-facing endpoints
  • Principle of least privilege for all system access
  • Regular review of access permissions and security configurations
  • Secure session management via HTTP-only cookies
  • Input validation and output encoding to prevent injection attacks

11. Data Protection Officer

Our Data Protection Officer (DPO) is responsible for overseeing our data protection strategy and compliance with data protection laws. The DPO can be contacted for any GDPR-related enquiries, data subject access requests, complaints, or concerns:

Email: dpo@dilagee.com

Post: Data Protection Officer, Dilagee Ltd, First Floor, Swan Buildings, 20 Swan Street, Manchester, M4 5JW

12. Supervisory Authority

You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data infringes data protection laws.

In the United Kingdom: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Telephone: 0303 123 1113.

In the EU: You may contact your local data protection authority. A list of EU data protection authorities is available on the European Data Protection Board website.

We would appreciate the opportunity to address your concerns before you contact a supervisory authority. Please reach out to our DPO at dpo@dilagee.com first.

13. Changes to This Page

We may update this GDPR Compliance page from time to time. Material changes will be communicated to customers via email at least 30 days before they take effect. The "Last updated" date at the top of this page indicates when the most recent changes were made.