Privacy Policy
Last updated: [EFFECTIVE DATE]
This Privacy Policy explains how [COMPANY LEGAL NAME] ("Datius", "we", "us") collects, uses, and protects personal information when you use the Datius website and service (the "Service"). It also explains the rights you have over that information.
1. Two kinds of data, two roles
Datius handles personal information in two different capacities:
- Account Data — information about you as a user of the Service (for example your name and email). For Account Data, Datius is the controller: we decide why and how it is used, and this policy governs it.
- Customer Data — the telemetry your organization sends to the Service (signal values, tags, and timestamps). Your organization decides what to send and why, so your organization is the controller of that data and Datius acts as its processor, handling it only to provide the Service and as your organization instructs. If Customer Data includes information about your own end users, please direct any privacy requests about it to the organization that collected it.
2. Information we collect
Account Data
- Profile information — your name, email address, and profile image, provided when you sign up through our authentication provider, Clerk.
- Workspace information — the organizations and workspaces you belong to, your roles, and invitations you send (including the invitee's email address).
- Activity information — when you last signed in, which organization and workspace you last used, and when API keys you created were last used.
- Configuration you provide — settings such as alert rules, the email addresses and webhook URLs alerts are sent to, and credentials for storage or email servers you connect. Credentials are encrypted at rest; API keys are stored only as a one-way hash.
Customer Data
Whatever telemetry your organization chooses to send to the Service. We do not inspect it for any purpose other than providing the Service — storing it, querying it for your dashboards and reports, and evaluating your alert rules against it.
Technical information
Our authentication provider, Clerk, processes information such as your IP address and browser details to sign you in securely and protect accounts from abuse. The Datius application itself does not record your IP address or browser details in its database.
3. How we use information
- To provide, operate, and maintain the Service.
- To authenticate you and keep accounts and data secure.
- To send the notifications you configure, such as alert emails and webhooks, and service-related messages such as invitations.
- To respond to support requests and communicate with you.
- To comply with legal obligations and enforce our terms.
We do not sell personal information, share it for cross-context behavioral advertising, or use it to build advertising profiles.
4. Legal bases (EU/UK users)
Where the GDPR or UK GDPR applies, we rely on:
- Performance of a contract — to provide the Service you signed up for.
- Legitimate interests — to secure the Service, prevent abuse, and improve reliability, balanced against your rights.
- Legal obligation — where the law requires us to keep or disclose information.
- Consent — where we ask for it; you can withdraw it at any time.
5. Who we share information with
We share personal information only with service providers that help us run the Service, under contracts that limit their use of it to providing services to us:
| Provider | Purpose |
|---|---|
| Clerk | Sign-in, account management, and account security |
| [HOSTING PROVIDER] | Hosting the Service |
| [MANAGED DATABASE / CACHE PROVIDER] | Storing account and configuration data |
| [OBJECT STORAGE PROVIDER] | Storing Customer Data (telemetry files) |
Destinations you configure. If your organization connects its own storage bucket, email (SMTP) server, or alert webhook, the Service sends data there at your organization's direction. Those services are chosen and controlled by your organization and their own terms apply.
We may also disclose information when required by law, to protect the rights and safety of our users or the Service, or as part of a merger or acquisition (in which case this policy continues to apply to the information transferred).
6. Cookies and local storage
Datius does not use analytics, advertising, or tracking cookies. We use only:
- Essential cookies set by Clerk to keep you signed in securely.
- A functional cookie that remembers whether the app's sidebar is open.
- Browser local storage for interface preferences, such as theme, view mode, and your last-used workspace. This never leaves your browser.
7. How long we keep information
- Account Data is kept while your account is active. You can ask us to delete it at any time (see Your rights).
- Customer Data is kept according to each workspace's retention settings. On the Community plan, data older than 90 days is deleted automatically. Your organization can delete signals, workspaces, or the entire organization at any time, which deletes the associated data stored by Datius.
- Data in a storage bucket your organization connected itself stays in that bucket; deleting it there is your organization's responsibility.
- Deleted data may remain in backups for up to [BACKUP RETENTION PERIOD] before being permanently removed.
8. Security
We protect information with measures appropriate to its sensitivity, including encryption in transit, encryption at rest for credentials you provide (AES-256-GCM), one-way hashing of API keys, and role-based access controls within organizations and workspaces. No system is perfectly secure; if we learn of a breach affecting your personal information, we will notify you as required by law.
9. International transfers
Datius is hosted in [PRIMARY DATA-HOSTING REGION, e.g. the United States]. If you use the Service from elsewhere, your information is transferred there. Where the GDPR or UK GDPR applies, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
10. Your rights
EU and UK residents
You have the right to access, correct, or delete your personal information; to restrict or object to certain processing; to receive your information in a portable format; to withdraw consent; and to lodge a complaint with your local data protection authority.
California residents
Under the CCPA as amended by the CPRA, you have the right to know what personal information we collect and how we use and disclose it; to delete it; to correct it; and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of. We will not discriminate against you for exercising these rights. In the past 12 months we have collected these categories of personal information, for the purposes in section 3:
| Category | Examples |
|---|---|
| Identifiers | Name, email address, account ID |
| Internet or electronic activity | Sign-in times, last-used workspace, API key usage times |
| Professional information | Organization and workspace membership and role |
How to exercise your rights
Email [PRIVACY CONTACT EMAIL]. You can do this yourself or through an authorized agent. We will verify your identity, usually by confirming the request from your account's email address, and respond within one month (GDPR) or 45 days (CCPA). To delete your account entirely, email us from your account's email address; to delete an organization and all of its data, an organization admin can do so in Organization Settings.
For Customer Data, contact the organization that sent it — we will help them respond to your request.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will delete it.
12. Changes to this policy
We will post any changes here and update the "Last updated" date. If a change is material, we will notify you by email or in the Service before it takes effect.
13. Contact
[COMPANY LEGAL NAME]
[COMPANY POSTAL ADDRESS]
[PRIVACY CONTACT EMAIL]