Privacy Policy for Daeda Workflows
Effective Date: 22 August 2026
Daeda Technologies Ltd (“Daeda”, “we”, “us”, or “our”) is a company registered in England and Wales under company number 17360943, with its registered office at 167–169 Great Portland Street, Fifth Floor, London, England, W1W 5PF. “Daeda Tech” and “Daeda Technologies” are trading references to Daeda Technologies Ltd and are not separate legal entities. This Privacy Policy explains how we collect, use, store, and protect information in connection with Daeda Notes, Daeda IDs, Daeda Screenshots, Daeda Throttle (formerly Daeda Essentials), Out of Office Workflows, and Smart Lead & Ticket Routing for Workflows (collectively, the “Apps”). Clean Dial and Dynamic Dropdowns have separate privacy notices.
For Customer Personal Data processed through an App, the Customer is generally the controller and Daeda acts as its processor. The Smart Lead & Ticket Routing Data Processing Agreement applies to that App where agreed; other Apps may have a service-specific DPA. Daeda acts as controller for its own account administration, billing, support, security, and legal-compliance data.
Under a written business-transfer and assignment agreement, agreements originally entered into with Daeda Technologies Pte. Ltd. automatically transfer to Daeda Technologies Ltd with effect from 6 September 2026 to the extent that the original agreement and applicable law permit assignment or transfer without further Customer consent. From that date, Daeda Technologies Ltd assumes the controller or processor role associated with each transferred agreement. A signed or negotiated agreement or DPA that prohibits transfer or requires consent or novation continues with Daeda Technologies Pte. Ltd. until that requirement is satisfied.
1. Information We Collect
Depending on the App and the Customer’s configuration, we may collect:
- HubSpot Portal IDs, authorised-user email addresses, OAuth credentials, permissions, and account configuration;
- CRM records, properties, owner and team data, routing inputs and outputs, workflow execution data, screenshots, notes, identifiers, validation data, and other information required for the selected App;
- subscription, billing-status, support, security, authentication, and operational information.
We do not intentionally request payment-card details, government-issued identifiers, special-category data, or other highly sensitive data. Those data may nevertheless be present in HubSpot records or free-text fields that a Customer chooses to make available. Customers should not provide sensitive data unless Daeda has expressly agreed to that processing in writing.
2. How We Collect Information
We collect information when you install or authorise an App through HubSpot, configure or use its features, run workflows, purchase a subscription, or contact us for support.
3. How We Use Information
We use information to provide App functionality; authenticate users; process workflows, routing, validation, screenshots, and CRM updates; administer accounts and billing; communicate service and support information; protect the Apps; diagnose errors; prevent abuse; and comply with legal obligations.
Depending on the context, we process information to perform our contract with you, pursue legitimate interests in operating and securing the Apps, comply with legal obligations, or act on consent where consent is required.
We do not sell personal data or share it for third-party advertising. External operational alerts are designed not to contain Customer Personal Data or customer-linked identifiers.
4. Data Sharing and Service Providers
We disclose information only as needed to provide, secure, support, and bill for the Apps, including to:
- HubSpot, for platform integration and App functionality;
- Supabase, for application data storage and supporting services;
- Hetzner, for application hosting and infrastructure;
- Stripe, for payment processing and subscription management;
- ScreenshotOne, where screenshot-generation features are used;
- Abstract API, where phone-number validation features are used; and
- professional advisers, authorities, or other recipients where disclosure is legally required or reasonably necessary to protect rights and security.
Not every provider is used by every App. Service-specific subprocessors are described in the applicable DPA and on our Subprocessor List. We provide at least 30 days’ advance notice of a new or replacement material subprocessor unless an emergency replacement is reasonably required for security, availability, or legal compliance. We do not treat a provider that receives only non-personal operational alert data as a subprocessor of Customer Personal Data.
5. Data Storage and Security
Application data may be stored using Supabase and on infrastructure hosted by Hetzner in Germany. We use reasonable technical and organisational measures designed to protect information, including encryption in transit, access controls, restricted administrative access, authentication controls, logging, monitoring, and vendor due diligence. Access is limited to authorised Daeda personnel who require it to operate and support the Apps.
6. Data Retention and Deletion
We retain information only for as long as reasonably necessary to provide and secure the applicable App, fulfil the purpose for which it was collected, and meet legal, regulatory, contractual, billing, security, fraud-prevention, accounting, tax, audit, dispute, and compliance obligations.
Retention and deletion commitments in an applicable DPA or written service-specific agreement take priority. Unless such an agreement specifies a fixed period, this Privacy Policy does not promise one. Data that remains in HubSpot or another customer-controlled system is subject to the Customer’s controls and retention settings.
7. Your Rights
Subject to applicable law, you may have rights to access, correct, erase, restrict, object to processing of, or receive a portable copy of your personal data. You may also complain to the UK Information Commissioner’s Office or another competent supervisory authority.
To exercise your rights, contact us at contact@daeda.tech. Where Daeda processes data solely on a Customer’s behalf, we may refer the request to that Customer.
8. International Transfers
Some service providers may process information outside the United Kingdom. Where required, we use an adequacy regulation, the UK International Data Transfer Agreement or UK Addendum, or another lawful safeguard. The applicable DPA provides further detail for Customer Personal Data.
9. Cookies and Tracking
The Apps do not use cookies or tracking technologies for advertising. Necessary authentication, session, security, and operational technologies may be used to provide the Apps.
10. Minors
The Apps are intended for business use and are not directed to individuals under 18 years of age.
11. Updates to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or for legal, regulatory, security, or operational reasons. We will communicate significant changes by email or in-product notice where appropriate.
12. Contact Us
For questions, concerns, or rights requests, contact Jack Tolley, Director, at contact@daeda.tech or write to Daeda Technologies Ltd, 167–169 Great Portland Street, Fifth Floor, London, England, W1W 5PF.