Updated: October 25th 2024

Privacy Policy

This Privacy Policy ("Policy") describes the information we collect, use, and share to support the Services available through our website, Daizy Scribe, and the Daizy Application ("Daizy App"). This policy applies to the entire Daizy ecosystem, and by using our Service, you agree to the terms outlined below.

Daizy Inc. ("Daizy," "we," "us," or "our") is committed to safeguarding your personal information. We act as the "Data Controller" for your personal data in line with data protection laws. If you have any questions, please contact us at privacy@daizy.com.

1. WHEN YOU BROWSE OR VISIT THE WEBSITE

Data We Collect

  • Identifiers: IP address, geographic location, browser type, operating system, and device types.
  • Cookies & Analytics: Information collected using cookies and log files (if additional Cookies are accepted).

Purpose

  • Analytics & Statistics: To analyze website traffic and improve user experience.
  • Performance Improvements: To enhance website features based on device and browsing information.

Legal Basis

  • Consent: For cookies that are not strictly necessary for website operation.
  • Legitimate Interest: For necessary cookies to maintain website functionality.

Third Parties We Share Data With

  • Google Analytics: For web analytics services.
  • HubSpot: For marketing and CRM functionalities.
  • Hotjar: For analyzing user behavior on the website.

For more information, please read our Cookies Policy.

Data Retention

We retain your data until it is no longer needed or until you request its deletion. We may retain anonymized data indefinitely for analytical purposes.

2. WHEN YOU CREATE A DAIZY SCRIBE ACCOUNT OR USE DAIZY SCRIBE DEMO

Data We Collect

  • Identifiers: Full name, email address, company name, and Daizy Scribe login details.
  • Content Data: Any content or reports generated using Daizy Scribe.
  • Additional Data: Any other information you voluntarily provide (such as portfolio holdings information when you create a portfolio in Daizy Scribe, or Custom Instructions you provide).

Purpose

  • Account Management: To create and manage your Daizy Scribe account.
  • Personalization: To personalize your experience and enhance services.
  • Service Notifications: To notify you of updates and changes to the Service.
  • Sharing: To enable you to share Daizy Scribe outputs with others.

Legal Basis

  • Performance of a Contract: Necessary for creating your Daizy Scribe account.
  • Legitimate Interest: For improving and securing the Service.

Third Parties We Share Data With

  • Amazon Web Services (AWS): For cloud hosting and data storage.
  • CK Editor: For document export (to Word or PDF) and real-time collaboration features. Data is encrypted and deleted after conversion.
  • HubSpot: For managing customer relationships and communications.
  • Google Analytics: For tracking service usage.

Data Retention

We retain your data as long as you maintain an active account. Anonymous data may be kept longer for analytical purposes.

3. WHEN YOU USE THE DAIZY APP

Data We Collect

  • Portfolio Data: Investment data such as holdings and online broker details (via third-party services like Plaid), if provided.
  • Device & Usage Information: IP address, geographic location, device type, and app interaction data.
  • Cookies & Log Files: Data related to usage behavior, device tokens for notifications (if enabled).

Purpose

  • Portfolio Creation: To enable daily analysis and portfolio updates.
  • Notifications: To send notifications and alerts based on your preferences.
  • Anonymized Data: To create anonymized data sets for market research and analysis.
  • Marketing: To send relevant service updates and offers.

Legal Basis

  • Performance of a Contract: To deliver portfolio management and alert services.
  • Consent: For marketing communications and notifications.

Third Parties We Share Data With

  • Amazon Web Services (AWS): For secure storage of portfolio and usage data.
  • Cognigy GmbH: For Daizy AI Insights services.
  • HubSpot: For customer management and communications.
  • Hotjar: For app analytics and performance monitoring.

Data Retention

We retain your data as long as you are an active user. Anonymized data may be retained for research purposes.

4. WHEN YOU CREATE AN ACCOUNT THROUGH THE DAIZY APP

Data We Collect

  • Identifiers: Full name, email address, login credentials (password or social login).
  • Additional Data: Any other information you provide voluntarily.

Purpose

  • Account Creation: To create your Daizy account and manage login credentials.
  • Personalization: To enhance your experience across the Daizy ecosystem.
  • Notifications: To inform you of changes to the Service.
  • Sharing: To enable content sharing features.

Legal Basis

  • Performance of a Contract: For managing your Daizy account and access to services.
  • Legitimate Interest: For personalizing and improving the Service.

Third Parties We Share Data With

  • Amazon Web Services (AWS): For secure hosting and storage.
  • HubSpot: For managing customer interactions.
  • Google Analytics: For tracking user interactions on the app and website.

Data Retention

Your data is stored as long as your account is active. Anonymized data may be retained for longer durations for analytics.

5. WHEN YOU INTERACT WITH THE DAIZY CHATBOT OR A PUBLIC DAIZY GPT

Data We Collect

  • Identifiers: OpenAI userID, email address (for Daizy Chatbot users only).
  • Conversation Data: Current session history and question inputs.

Purpose

  • Chatbot Interaction: To facilitate conversations and provide responses.
  • Service Improvement: To improve the chatbot's or GPTs future responses.

Legal Basis

  • Performance of a Contract: For chatbot and GPT services.
  • Legitimate Interest: For enhancing response quality and service.

Third Parties We Share Data With

  • OpenAI: For public-facing GPT interactions.
  • HubSpot: For managing customer support interactions.

Data Retention

Chatbot and GPT interaction data is retained for as long as necessary to improve the service. Data may be deleted upon request.

6. WHEN YOU SIGN UP FOR OUR EMAIL LIST

Data We Collect

  • Email Address: Collected when you opt-in to our email list.

Purpose

  • Marketing: To send you marketing communications and service updates.

Legal Basis

  • Consent: For receiving email communications.
  • Legitimate Interest: To send you relevant updates about Daizy.

Third Parties We Share Data With

  • HubSpot: For managing email marketing communications.
  • Google Analytics: For analyzing email engagement metrics.
  • Hotjar: For evaluating email performance.

Data Retention

We retain your email data until you unsubscribe from our mailing list.

7. DATA RETENTION

We retain your personal data while you are an active user of Daizy. Once your account is closed, we delete all personal information except for anonymous or legally required records.

For third-party retention policies (e.g., AWS, Google, CK Editor), please see below.

SHARING YOUR INFORMATION

We also share your information with the following third parties:

Hubspot, Inc provides Customer Relationship Management software to DAIZY. Data transferred to HubSpot is securely processed and stored in the United States. Transfers to the United States require that appropriate safeguards are put in place, in order for the transfer to be lawful, namely via the use of standard data protection clauses approved by the European Commission and the UK Information Commissioner. We have adopted the standard EU data protection Model Clauses which are standardized contractual clauses used in agreements between service providers and their customers to ensure that any personal data that leaves the EEA will be transferred in compliance with EU data-protection law and meet the requirements of the EU Data Protection Directive 95/46/EC.

Amazon Web Services, Inc (AWS) provides IT hosting and database services for DAIZY. We securely store your portfolio holdings and portfolio analysis information on Amazon Web Services systems in order to provide DAIZY services. Amazon employees do not have access to this information (which is securely encrypted).

Google Analytics, which provides web analytics service to DAIZY. Google maintains servers around the world and your information may be processed on servers located outside of the country where you live. Data protection laws vary among countries, with some providing more protection than others. To learn more about Google’s privacy practices, please visit https://policies.google.com/privacy?hl=en-US#intro

Hotjar, Ltd., which provides web analytics tools to analyze traffic data. Personal Data collected by Hotjar is stored in the EU. However, in some limited cases, customer information may be accessed from, or other Personal Data (e.g., email) may be transferred, outside of the EU. These countries may have different data protection laws. Hotjar endeavors to ensure appropriate safeguards are in place requiring that Personal

Data will remain protected. Hotjar has concluded Standard Contractual Clauses with entities whom they share Personal Data with outside of the EU. Further details about this can be found in their article on Data Storage. To learn more about HotJar’s privacy practices, please visit https://www.hotjar.com/legal/policies/privacy/

CK Editor, who provide data export services for Daizy Scribe reports. When reports are exported to MS Word or PDF files, the report contents are shared with CK Editor SaaS servers purely for the purpose of conversion to Word or PDF. The service is stateless and after the conversion the original data is deleted from CK Editor servers. All data is encrypted in transit and at rest for this service. Data is also shared to CK Editor when you use the collaboration features within Daizy Scribe – this includes comments, tracked changes, and real-time collaborative editing. All real-time collaboration data is stored securely and is removed 24hrs after the last user’s session disconnects. Historical document tracked changes, comments and revision history are stored securely and encrypted with a key that differs for each client environment. To learn more about CK Editor’s security and privacy practices, please visit https://ckeditor.com/docs/cs/latest/guides/system-security.html

8. YOUR RIGHTS (GDPR & CCPA)

Under GDPR

You have the right to:

  • Access your personal data.
  • Correct inaccurate data.
  • Request Deletion ("Right to be Forgotten").
  • Restrict Processing.
  • Object to data processing.
  • Withdraw Consent at any time.

Under CCPA

California residents have the right to:

  • Know what personal data we collect and how we use it.
  • Request Deletion of their data.
  • Opt-Out from the sale of personal information (Daizy does not sell data).
  • Non-Discrimination for exercising their rights.

You can exercise your rights by contacting privacy@daizy.com.

9. DATA SECURITY

We take appropriate security measures to protect your personal data, including:

  • Encryption: All data is encrypted in transit and at rest using industry-standard encryption methods.
  • Access Control: Access to your data is restricted to authorized personnel, using role-based access controls (RBAC) to ensure that only those who need access for their roles can handle sensitive information.
  • Regular Audits: We conduct security reviews and audits to maintain data protection standards. Incident Response: In the event of a security breach, we have established protocols to contain the incident, assess its impact, and remediate any issues.
  • Notification: If we determine that a data breach poses a significant risk to your personal information, we will notify affected users promptly, in accordance with applicable laws and regulations.

Please note, while we are dedicated to protecting your data, no system is entirely immune to security threats. We continue to evolve and improve our security measures to mitigate these risks.

10. CHANGES TO THIS PRIVACY POLICY

We reserve the right to update this Privacy Policy from time to time. Any significant changes will be notified through email or a prominent notice on our website. The date at the top of this document reflects the last update.

11. CONTACT US

For any questions regarding this Privacy Policy or to exercise your rights, please email us at privacy@daizy.com.