Privacy Policy
Last updated: 2 September 2026
1. Data controller
Dilaya is a service published and developed by the company Novopattern (EURL).
The controller of the personal data collected through Dilaya is: Novopattern, 60 rue François Ier, 75008 Paris, France, contact@dilaya.eu.
1 bis. Two distinct roles depending on the data
Dilaya processes two categories of data that do not follow the same regime, and it matters to tell them apart:
- The Customer's own data — their account, their billing, their use of the service. For these, Novopattern is the data controller: it decides why and how they are processed. That is the subject of this policy.
- The data the Customer places in their workspace — the information they store in the tools they create, including where it concerns their own customers, members or correspondents (messages received, contacts, orders). For these, the Customer is the data controller and Novopattern acts as a processor within the meaning of Article 28 of the GDPR: we host and process them solely on the Customer's instructions, in order to provide the service.
Accordingly, for that second category, Novopattern undertakes to:
- process the data only on the Customer's documented instructions;
- ensure the confidentiality of the persons authorised to access it;
- implement the security measures described in article 7;
- use only the sub-processors listed in article 4, and inform the Customer of any change;
- assist the Customer in handling requests from data subjects exercising their rights;
- return the data to the Customer at the end of the contract, and delete it on request;
- make available the information necessary to demonstrate compliance with these obligations.
It is for the Customer, as data controller, to have a legal basis for the data they place in the service and to inform the data subjects.
2. Data collected
Depending on how the service is used, the following data may be collected:
- identification and contact data: surname, first name, email, telephone, address;
- payment and billing data: the saved payment method (bank card, or bank details where that option is offered) is entered on Stripe's payment page and kept by Stripe — Dilaya holds only a technical reference; billing name and address, invoice history;
- account and usage data: login credentials, activity logs, tasks configured and carried out by the AI agents;
- website audience-measurement data: page viewed, origin, reading time and depth, device type and country, attached to a random identifier specific to your browser — never to your IP address, which is not kept, nor to your customer account;
- data transmitted through the third-party accounts connected by the Customer (e.g. Telegram messaging, social networks), strictly to the extent necessary to perform the automated tasks requested.
3. Purposes and legal bases
- Performance of the contract (provision of the service, billing, direct debit) — legal basis: performance of the contract;
- Support and communication with the Customer — legal basis: performance of the contract / legitimate interest;
- Compliance with legal obligations (accounting, fraud prevention) — legal basis: legal obligation;
- Improvement and security of the service — legal basis: legitimate interest.
4. Data recipients
Data may be transmitted, to the extent necessary, to:
- Stripe (Stripe Payments Europe Ltd, Ireland) — our payment provider. When the Customer saves a payment method or pays for a subscription, an additional seat or a domain name, they do so on a page hosted by Stripe: card details are entered and stored with Stripe, never by Dilaya. Stripe receives the account holder's email address, the organisation's billing name and address, the workspace identifier and the amounts invoiced; it issues the invoices and computes the applicable VAT;
- our bank (Qonto), where a payment is made by bank transfer;
-
our hosting providers and technical sub-processors, acting on instructions and under
contractual confidentiality commitments:
- Amazon Web Services — hosting of the infrastructure, databases and files, in data centres located in the European Union (Ireland); also acting as registrar when the Customer buys a domain name through Dilaya, in which case the registrant's data is transmitted to the registry for that domain;
- Anthropic — the AI models that run the conversations and the agents;
- OpenAI — semantic search, the AI features of the tools created by the Customer, and speech-to-text transcription of voice messages received by the Customer's bots, only where those features are enabled for their organisation;
- Postmark — sending transactional emails and sign-in codes;
- GitHub — hosting, in private repositories, of the source code of the websites created by the Customer, where they request it;
- Telegram, Meta (WhatsApp Business, Facebook, Instagram), LinkedIn and Composio — where the Customer chooses to connect one of those accounts to their service; the data exchanged is then limited to what the connected service requires.
- the competent authorities where the law requires it.
No data is sold to third parties for advertising purposes.
Transfers outside the European Union
The infrastructure, the databases and the files are hosted in the European Union. However, some of the sub-processors listed above (in particular Anthropic, OpenAI, Postmark, GitHub, Meta, LinkedIn and Composio) are established in the United States, and Stripe, established in Ireland, transfers part of its processing there: using the corresponding features involves a transfer of data outside the European Union. Those transfers are governed by the safeguards provided for by the GDPR (the European Commission's standard contractual clauses and, where applicable, certification under the Data Privacy Framework). Details of the safeguards applicable to each sub-processor can be obtained at contact@dilaya.eu.
5. Retention periods
Data is retained for the duration of the contractual relationship, then archived for the periods required by legal and accounting obligations (in particular tax obligations), before deletion or anonymisation.
Periods applicable to the main categories:
- data in the Customer's workspace (tools created, content, files): for the whole duration of the contract. Stopping payment deletes nothing immediately: the workspace is paused and the data is handed back to the Customer on simple request to our support. It is then retained for 12 months from the date the workspace is paused, after which it is permanently deleted; the Customer is notified by email before that deadline, and may at any time request the return or the early deletion of their data;
- backups: a backup copy may remain after a tool is deleted, for the duration of the backup cycle, before being purged;
- sign-in sessions: 30 days;
- website audience measurement (pages viewed, origin, reading time — with no IP address): 25 months, then automatic deletion; the corresponding cookie expires after 13 months;
- technical logs and usage statistics (metadata: date, tool called, technical identifier — no content): up to 13 months;
- billing data: 10 years, in accordance with accounting obligations.
6. Your rights
In accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act, every person has a right of access, rectification, erasure, restriction, objection and portability regarding their data, as well as the right to give directions concerning what happens to their data after their death.
These rights may be exercised by writing to contact@dilaya.eu. A reply is provided within one month. In the event of disagreement, the data subject may lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr).
7. Security
Proportionate technical and organisational measures are implemented to protect data against unauthorised access, loss or alteration. In particular:
- separation by organisation: each organisation has its own workspace, and each tool created has its own database. Every access to data goes through a single control point that denies by default, and the authorisation is checked a second time, independently, at the storage level;
- separation of the websites created: the program running a website can reach only the data and files of its own tool;
- keys and secrets: the API keys the Customer entrusts to the service are stored encrypted, entered through a dedicated form, and are never displayed in a conversation nor written to the logs;
- encryption in transit (HTTPS) across all services;
- continuous backup of the databases.
8. Cookies and trackers
The dilaya.eu website uses no advertising cookie, no third-party tracker and no external analytics tool — no Google Analytics, no equivalent. No browsing data is sent to any third party, and no tracking takes place outside dilaya.eu.
Two cookies are used, and only two:
-
hereya_sid— session cookie. Purpose: keeping you signed in to your workspace and allowing your AI assistant to connect to Dilaya. Duration: 30 days. It contains only a session identifier, no personal data. -
dly_v— internal audience measurement. Purpose: counting visits, seeing which pages are read and where visitors come from, in order to improve the site. Duration: 13 months, not extended on each visit. It contains an opaque random identifier for your browser, and nothing else.
That measurement is strictly limited to what it measures: page viewed, origin (tagged link or referring site), reading time, reading depth, device type and country. Your IP address is never kept — the country is derived from it in flight and the address is then discarded, written neither to a database nor to a log. No browser fingerprint, no recording of mouse movements or individual clicks, no session replay, no cross-referencing with other sites. Browsing data is kept for 25 months, then deleted automatically.
As the session cookie is strictly necessary for the service you request, and as the audience measurement meets the conditions of the exemption for internal audience measurement (purpose limited to producing anonymous statistics, no cross-referencing with other processing and no transmission to third parties), both are exempt from prior consent under Article 82 of the French Data Protection Act and the CNIL's guidelines: no banner is therefore required.
Should cookies or trackers falling outside that scope be introduced later (advertising, personalisation, external analytics), this policy will be updated accordingly and a consent banner compliant with the applicable rules (CNIL) will be added before anything is placed.
9. Contact
For any question relating to this policy: contact@dilaya.eu.
10. Language
This English version is provided for convenience only. The French version is the legally binding text: in the event of any discrepancy or difference of interpretation between the two, the French version prevails.