Last updated: April 2026
Dilagee Ltd ("Dilagee", "we", "us") is fully committed to compliance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and the Data Protection Act 2018. We process personal data lawfully, fairly, and transparently, ensuring your rights are protected at every step.
This page explains how we meet our obligations under data protection law. It should be read alongside our Privacy Policy, Terms of Service, and Cookie Policy.
Dilagee acts as the data controller for personal data we collect directly from you in connection with your use of our platform, including account registration data, billing information, contact form submissions, and usage analytics.
When you (our business customer) input employee or workforce data into the Service, you are the data controller and Dilagee acts as the data processor on your behalf. As data controller, you are responsible for:
We offer Data Processing Agreements (DPAs) to all business customers, as required under Article 28 of the GDPR. Our DPA sets out the scope, nature, and purpose of processing, the types of personal data processed, categories of data subjects, and the obligations and rights of both parties. To request a DPA, contact dpo@dilagee.com.
We process personal data under the following legal bases as defined in Article 6(1) of the GDPR:
Under the UK GDPR and EU GDPR, you have the following rights:
How to exercise your rights: Email our Data Protection Officer at dpo@dilagee.com. We may ask you to verify your identity before processing your request. We will respond within one calendar month. In complex cases, we may extend this by up to two additional months, and we will inform you of any such extension within the first month.
No fee required: You will not normally have to pay a fee to exercise your rights. However, we may charge a reasonable fee or refuse a request if it is clearly unfounded, repetitive, or excessive.
We use the following sub-processors to deliver the Service. Each sub-processor processes data under a data processing agreement and is subject to appropriate safeguards:
| Sub-Processor | Purpose | Data Location | Transfer Mechanism |
|---|---|---|---|
| Supabase Inc. | Database hosting, authentication, session management | EEA (Frankfurt) | N/A (EEA) |
| Stripe Payments Europe Ltd | Payment processing, fraud prevention | EEA / US | SCCs, PCI-DSS certified |
| OpenAI, L.L.C. | AI-powered document generation | United States | SCCs, UK IDTA |
| Resend Inc. | Transactional and marketing email delivery | United States | SCCs, UK IDTA |
| Vercel Inc. | Application hosting, content delivery | Global (edge network) | SCCs, UK IDTA |
We will notify customers of any intended changes to sub-processors, giving you the opportunity to object before the change takes effect. To receive sub-processor change notifications, ensure your contact details are up to date in your account settings.
| Data Category | Retention Period | Basis |
|---|---|---|
| Account and profile data | Duration of account + 30 days after closure | Contract |
| Employee/workforce data | Duration of account + 30 days after closure | Contract |
| Payment and billing records | 6 years after transaction | Legal obligation (UK tax law) |
| Food safety and compliance records | Duration of account + 30 days after closure | Contract / Legal obligation |
| Contact form submissions | Up to 2 years | Legitimate interest |
| Waitlist/beta signup data | Until programme ends or deletion requested | Consent |
| Audit and admin action logs | Duration of account + 30 days after closure | Legitimate interest / Legal obligation |
| Marketing consent records | Duration of account + 3 years | Legal obligation (proof of consent) |
| Error and server logs | 90 days | Legitimate interest |
Your primary data is stored within the European Economic Area (EEA) on servers operated by Supabase in Frankfurt, Germany. However, some of our sub-processors are based in the United States (OpenAI, Resend, Vercel). Where personal data is transferred outside the EEA or the United Kingdom, we ensure compliance with Chapter V of the GDPR through:
You may request a copy of the relevant transfer safeguards by contacting dpo@dilagee.com.
We conduct Data Protection Impact Assessments (DPIAs) where processing is likely to result in a high risk to individuals' rights and freedoms, in accordance with Article 35 of the GDPR. This includes assessments for:
DPIAs are reviewed periodically and updated when there are material changes to processing activities.
We maintain a comprehensive data breach response plan in accordance with Articles 33 and 34 of the GDPR:
We implement appropriate technical and organisational measures in accordance with Article 32 of the GDPR to ensure a level of security appropriate to the risk, including:
Our Data Protection Officer (DPO) is responsible for overseeing our data protection strategy and compliance with data protection laws. The DPO can be contacted for any GDPR-related enquiries, data subject access requests, complaints, or concerns:
Email: dpo@dilagee.com
Post: Data Protection Officer, Dilagee Ltd, First Floor, Swan Buildings, 20 Swan Street, Manchester, M4 5JW
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data infringes data protection laws.
In the United Kingdom: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Telephone: 0303 123 1113.
In the EU: You may contact your local data protection authority. A list of EU data protection authorities is available on the European Data Protection Board website.
We would appreciate the opportunity to address your concerns before you contact a supervisory authority. Please reach out to our DPO at dpo@dilagee.com first.
We may update this GDPR Compliance page from time to time. Material changes will be communicated to customers via email at least 30 days before they take effect. The "Last updated" date at the top of this page indicates when the most recent changes were made.