Privacy Policy
Last updated: 25 September 2026
1. Introduction
This Privacy Policy explains how Dilagee Ltd (registered in England and Wales, company number 7140496, registered office at First Floor, Swan Buildings, 20 Swan Street, Manchester, M4 5JW) ("Dilagee", "we", "us", or "our") collects, uses, discloses, retains, and protects your personal data when you access or use our workforce management platform, website, and related services (collectively, the "Service").
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you are a business customer entering employee data into the Service, you are the data controller for that employee data, and Dilagee acts as a data processor on your behalf. You are responsible for ensuring you have a lawful basis to process your employees' personal data and for informing them of this Privacy Policy.
2. Information We Collect
2.1 Information You Provide Directly
- Account information: First name, last name, email address, phone number, password (stored in hashed form)
- Business information: Company name, industry, employee count, business address, city, postcode, selected plan
- Employee data: Staff names, email addresses, phone numbers, job titles, roles, hourly rates, employment details, and any other data you input into the Service on behalf of your employees
- Operational data: Shift schedules, time clock entries, break records, time-off requests, rota patterns, and attendance records
- Clock-in photos: Where your employer has switched on photo clock-in, a selfie taken on the phone or kiosk at the moment of clocking in, stored against that time entry and deleted after 90 days (see section 8)
- Compliance data: Daily check completions, temperature logs, hygiene records, food safety records, cleaning schedules, maintenance issues, stock checks, allergen information, and safety inspection data
- Training data: Course completions, certifications, training records, and document signatures
- Team messages: Messages your staff send each other using Dilagee's team messaging, including any photos or PDF files attached to them, with who sent each one, when, and who has read it (see section 2.4)
- Payment information: Billing details processed securely by our payment provider Stripe. We do not store your full card details on our servers; we store only your Stripe customer ID and subscription ID
- Communications: Contact form submissions (name, email, subject, message, optional file attachments), support requests, and correspondence with us
- Waitlist data: Email address submitted via our beta signup or waitlist forms
2.2 Information Collected Automatically
- Usage data: Pages visited, features used, actions taken within the Service, timestamps, and interaction patterns
- Device and browser data: IP address, browser type and version, operating system, device type, and screen resolution
- Cookies and similar technologies: Authentication tokens, session identifiers, preference settings, and analytics data (see our Cookie Policy for full details)
- Log data: Server logs including access times, error logs, and API request metadata
- Session replays: We record a video-style replay of your session — the screens you moved through and where you clicked, tapped and scrolled — so we can see where the product is confusing or broken. Everything you type is masked, as is every form input, including passwords and payment fields. On our website and web app this happens only if you accept analytics cookies, and rejecting them means no replay is recorded. In our mobile app, replays are currently recorded for all signed-in users; we are adding an in-app control for this, and until then you can opt out by emailing privacy@dilagee.com
- Crash and error reports: When something goes wrong we record the error, where it happened, and the device and account it happened on, so we can fix it
2.3 Information Generated by the Service
- AI-generated content: When you use our AI-powered tools, we send business context data (such as company information, employee count, location details, equipment data, and relevant operational parameters) to our AI sub-processor to generate documents including HACCP plans, risk assessments, fire safety policies, training courses, and other compliance materials
- Reports and analytics: Aggregated and individual reports generated from your operational data, including timesheets, rotas, inspection summaries, and compliance reports
- Audit logs: Records of administrative actions, data changes, and system events for security and compliance purposes
2.4 Team Messaging
Team messaging lets staff at the same business message each other: a channel for each site, a channel covering every site for businesses with more than one, and direct messages between two people. Messages can include photos and PDF files. Messages and their files are part of the employee data your business controls, and Dilagee processes them on its behalf (see section 1).
- Who can read a message: Only the people in that conversation. A site channel is visible to the staff who work at that site, and a direct message to the two people in it. Nobody at your business, including the account owner, can open a conversation in Dilagee that they are not part of. The one exception is an export (below)
- Photos and files: Stored privately. They can only be opened by people in the conversation, through links that expire after an hour
- Exports: On the Professional plan, the account owner and admins can export a person's messages, or a whole conversation, as a PDF for a workplace purpose such as a grievance or a dispute. An export includes removed messages and lists attached files by name. Every export records who ran it, when, what it covered and the reason they gave, and that record cannot be edited or deleted. The account owner and admins can see it
- When someone leaves: Removing a person from your team removes them from every conversation, normally within 15 minutes. Messages they sent stay in the conversation for the people still in it
- Removed messages: If a message is removed from a conversation, it is hidden from everyone in it, but the original is kept as part of your business's record
- Notifications: A push notification for a new message shows who sent it and in which conversation. It shows the message text only if the person receiving it has chosen to show message previews
- Our access: We do not read your team's messages, except where you ask us to for support, where we need to investigate a report of abuse or a security incident, or where the law requires it
3. How We Use Your Information
We process your personal data for the following purposes and on the following legal bases:
- To provide the Service (legal basis: contract performance) — Account creation, authentication, workforce management features, scheduling, compliance tools, AI document generation, and all core platform functionality
- To process payments (legal basis: contract performance) — Billing, invoicing, subscription management, trial administration, and refund processing via Stripe
- To send transactional communications (legal basis: contract performance) — Service notifications including shift reminders, daily check reminders, training assignments, document sign requests, time-off updates, stock alerts, inspection summaries, invoice notifications, and account-related emails
- To send marketing communications (legal basis: consent) — Product updates, feature announcements, newsletters, and promotional content. You can withdraw consent at any time (see Section 7)
- To improve the Service (legal basis: legitimate interest) — Analysing usage patterns, identifying bugs, optimising performance, and developing new features
- To ensure security (legal basis: legitimate interest) — Fraud prevention, rate limiting, abuse detection, CSRF protection, and maintaining platform integrity
- To comply with legal obligations (legal basis: legal obligation) — Tax regulations, employment law requirements, food safety record-keeping, and responding to lawful requests from authorities
- To provide customer support (legal basis: contract performance / legitimate interest) — Responding to enquiries, resolving issues, and managing your account
4. How We Share Your Information
We do not sell your personal data. We do not rent or trade your personal data. With one exception, described immediately below, we do not make your personal data available to third parties for their own purposes.
The exception is advertising measurement. If — and only if — you accept analytics and marketing cookies, we share a limited set of data with Meta so that we can measure which of our adverts lead to signups (see “Meta Platforms” below). Meta may use that data for its own purposes under its own privacy policy. If you reject cookies, no data is shared with Meta at all. You can change your choice at any time on our Cookie Policy page.
We share your data only in the following circumstances:
4.1 Sub-Processors and Service Providers
We use the following trusted third-party service providers who process data on our behalf under strict data processing agreements:
- Supabase (Supabase Inc.) — Database hosting, authentication, and session management. Data stored in the European Economic Area (EEA). Data processed: All account, employee, and operational data
- Stripe (Stripe Payments Europe Ltd) — Payment processing and fraud prevention. PCI-DSS Level 1 certified. Data processed: Customer name, email, payment method details, billing information
- OpenAI (OpenAI, L.L.C.) — AI-powered document generation. Data processed: Business context data including company information, employee counts, location details, equipment data, and operational parameters necessary to generate compliance documents. Note: OpenAI may retain API input data for up to 30 days for abuse monitoring purposes. We are working to minimise data retention with this provider
- Resend (Resend Inc.) — Transactional and marketing email delivery. Data processed: Recipient name, email address, and email content
- Vercel (Vercel Inc.) — Application hosting and content delivery. Data processed: Request metadata, IP addresses, and application traffic
- PostHog (PostHog Inc.) — Product analytics and session replay, on our EU instance. Used only with your consent to analytics cookies. Data processed: Pages viewed, features used, device and browser data, IP address, user ID and email once signed in, and video-style replays of app sessions. Replays mask all text you type and all form inputs, including passwords and payment fields
- Sentry (Functional Software, Inc.) — Crash and error reporting, on our EU instance. Data processed: Error messages and stack traces, the page or screen where the error occurred, device and browser data, IP address, and the signed-in user's ID and email
- Meta Platforms (Meta Platforms Ireland Ltd) — Advertising measurement via the Meta Pixel and Conversions API. Used only with your consent to marketing cookies, and only on our public website and signup pages — never inside the app or the mobile app. Data processed: Pages viewed on our website, and on signup your email address in irreversibly hashed form, your IP address and your browser user agent. Meta acts as an independent controller for this data
- Cloudflare (Cloudflare, Inc.) — Bot protection on our signup and login forms (Turnstile). Strictly necessary, so it runs regardless of cookie choice. Data processed: IP address, browser and device signals used to distinguish humans from bots
- Google (Google Ireland Ltd) — Maps and address lookup where you enter a site address. Data processed: The address text you enter and your IP address
- Expo (650 Industries, Inc.) — Delivery of push notifications to the Dilagee mobile app, through Apple's and Google's notification services. Data processed: The device's push token and the notification's title and text. For a team message that is the sender's name and the conversation's name, plus the message text only if the recipient has turned on message previews
- Square, SumUp and Zettle — Point-of-sale integrations, active only if you choose to connect your till. Data processed: Sales totals, transaction times and staff identifiers returned by your POS provider
4.2 Legal Requirements
We may disclose your data where required by law, regulation, legal process, or enforceable governmental request, including to:
- Comply with applicable laws or regulations
- Respond to valid legal processes (court orders, subpoenas, or statutory demands)
- Protect the rights, property, or safety of Dilagee, our users, or the public
- Detect, prevent, or address fraud, security, or technical issues
4.3 Business Transfers
In the event of a merger, acquisition, reorganisation, bankruptcy, or sale of all or a portion of our assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our Service before your data is transferred and becomes subject to a different privacy policy.
4.4 With Your Consent
We may share your data with third parties where you have given explicit consent to do so.
5. International Data Transfers
Your primary data is stored within the European Economic Area (EEA) on servers operated by Supabase. Our analytics and error-reporting providers (PostHog, Sentry) are configured to use their EU regions, so that data stays in the EEA too. However, some of our sub-processors — OpenAI, Resend, Vercel, Cloudflare, Expo and Meta — are based in, or route data through, the United States. Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs, as applicable
- Supplementary technical and organisational measures to protect data in transit and at rest
You may request a copy of the relevant transfer safeguards by contacting our Data Protection Officer at dpo@dilagee.com.
6. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Password hashing using industry-standard algorithms
- Row-Level Security (RLS) policies ensuring multi-tenant data isolation
- Rate limiting on authentication and sensitive API endpoints
- CAPTCHA protection on public-facing forms
- Regular security reviews and access controls
- Principle of least privilege for internal access to data
- Secure session management via HTTP-only cookies
While we take all reasonable steps to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but will notify you and any applicable regulator of a breach where we are legally required to do so.
7. Your Rights and How to Opt Out
Under the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and other applicable data protection laws, you have the following rights:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal data ("right to be forgotten")
- Right to restrict processing: Request that we limit how we use your data
- Right to data portability: Request your data in a structured, commonly used, machine-readable format. You can export your data (timesheets, rotas, reports) via the Service at any time
- Right to object: Object to processing based on legitimate interests or direct marketing
- Right to withdraw consent: Where processing is based on consent, withdraw at any time without affecting the lawfulness of prior processing
- Rights related to automated decision-making: We do not use automated decision-making or profiling that produces legal or similarly significant effects on you
How to Opt Out
- Marketing emails: Click the "unsubscribe" link in any marketing email, or email us at privacy@dilagee.com to opt out of all marketing communications. You will continue to receive essential transactional emails related to your account and use of the Service
- Cookies: Manage your cookie preferences through your browser settings. See our Cookie Policy for details
- Account deletion: You can request account closure from your account settings. There is a 48-hour grace period during which you can cancel the request. After 48 hours, your account will be deactivated, and all data will be permanently deleted within 30 days
- Data access or erasure requests: Email our Data Protection Officer at dpo@dilagee.com. We will respond within 30 days (or one calendar month, as required by law)
To exercise any of these rights, contact our Data Protection Officer at dpo@dilagee.com. We may ask you to verify your identity before processing your request. If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or your local supervisory authority.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy:
- Active accounts: Data is retained for the duration of your account and active subscription
- After account closure request: 48-hour grace period to cancel, followed by account deactivation. All data is permanently deleted within 30 days of deactivation
- Team messages and their files: Kept for as long as the account is active, and deleted with the rest of the account's data after it is closed, as above
- Clock-in photos: Deleted automatically 90 days after the clock-in they belong to. The time entry itself is kept as operational data
- Contact form submissions: Retained for up to 2 years for customer support and record-keeping purposes
- Waitlist/beta signup data: Retained until the waitlist programme ends or you request deletion
- Payment records: Retained as required by tax and accounting regulations (typically 6 years under UK law)
- Legal hold: Data may be retained beyond standard periods where required to comply with legal obligations, resolve disputes, or enforce our agreements
9. Children's Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete that data promptly. If you believe we have collected data from a child under 16, please contact us at privacy@dilagee.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable laws. We will notify you of material changes by email to the address associated with your account and/or by posting a prominent notice on the Service at least 30 days before the changes take effect. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.
11. Contact Us
Data Controller: Dilagee Ltd, registered in England and Wales (company number 7140496), registered office at First Floor, Swan Buildings, 20 Swan Street, Manchester, M4 5JW.
Data Protection Officer: dpo@dilagee.com
Privacy enquiries: privacy@dilagee.com
General enquiries: Visit our contact page
Supervisory authority: You have the right to lodge a complaint with the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom.