Privacy Policy
Last Updated: June 27, 2026 · Effective: June 27, 2026
Dakdan LLC ("Company," "we," "us") operates the dakdan.ai platform (the "Service"). This Privacy Policy explains what personal information we collect, how we use and share it, and your rights. It is incorporated into our Terms of Service.
1. Scope
This Policy covers personal information processed through the Service's website, dashboard, APIs, and related communications. It does not cover third-party services you connect (e.g., SAM.gov, AI providers, PayPal, CRM), which have their own policies.
2. Information We Collect
a. Information you provide
- Account & profile: name, email, password (stored only as a salted hash), company/tenant details, role.
- Organization/entity data: company profiles, capability statements, NAICS codes, contacts, past performance, and similar contracting information you enter.
- Support communications: messages you send to support (including AI-assistant chats and tickets).
b. Credentials you connect (BYO)
- Third-party API keys and SMTP credentials you choose to store. These are encrypted at rest and used only to perform actions you direct. We do not display them back in plaintext.
c. Billing information
- Subscription plan, status, and transaction metadata. Payment-card details are handled by PayPal, not stored by us.
d. Information generated by the Service
- Opportunity/bid records retrieved on your behalf, match scores, and AI-generated proposal drafts.
e. Information collected automatically
- Log and device data (IP address, browser type, timestamps, pages), and cookies/session identifiers needed to operate the Service. See Section 8.
We do not intentionally collect special-category data (e.g., health, biometric) and ask that you not submit it.
3. How We Use Information
We use personal information to: (a) provide, operate, secure, and improve the Service; (b) authenticate users and maintain sessions; (c) process subscriptions and prevent fraud; (d) run the scan→score→draft pipeline using your configuration and credentials; (e) provide support (including the AI assistant); (f) send service, security, and (with consent where required) marketing communications; and (g) comply with law and enforce our Terms.
AI processing. When you use AI features, relevant content is sent to the AI provider you configure (your own key) or, where applicable, our configured provider, solely to generate output for you. We do not sell your Customer Content, and we do not use it to train third-party foundation models except as you direct through your chosen provider.
4. Legal Bases (EEA/UK – GDPR)
Where GDPR applies, we process personal data on these bases: performance of a contract (providing the Service), legitimate interests (securing and improving the Service, fraud prevention), consent (optional marketing, certain cookies), and legal obligation. You may withdraw consent at any time.
5. How We Share Information
We share personal information only as follows:
- Subprocessors / service providers that help us run the Service, under contract and confidentiality. Current categories include:
- Hosting & database: Supabase (managed PostgreSQL).
- Payments: PayPal.
- AI/LLM providers: the provider you configure (e.g., Anthropic, OpenAI) and/or our default provider.
- Email delivery: your configured SMTP/email provider.
- CRM (optional): GoHighLevel, if you enable it.
- Bid-data sources you query (e.g., SAM.gov and subscription feeds) receive only the requests needed to retrieve opportunities.
- Legal & safety: when required by law, subpoena, or to protect rights, safety, and the integrity of the Service.
- Business transfers: in a merger, acquisition, or asset sale, subject to this Policy.
- With your direction: to recipients you choose (e.g., emailing a proposal to a contracting officer).
We do not sell personal information for money. See Section 9 regarding "sharing"/"selling" as defined by California law.
6. Multi-Tenant Data Separation
The Service is multi-tenant. We use access controls and tenant scoping designed to keep each tenant's data separated from other tenants. Authorized platform administrators may access tenant data to provide support, troubleshoot, or comply with law; such access is logged. Resellers can access data of tenants within their own organization.
7. Data Retention
We retain personal information for as long as your account is active and as needed to provide the Service, then for a reasonable period to comply with legal, accounting, audit, and dispute-resolution needs. You may request deletion (Section 10). Some records (e.g., billing) are retained as required by law. Encrypted credentials are deleted when you remove them or when the account is closed.
8. Cookies & Tracking
We use strictly necessary cookies/session tokens to authenticate you and operate the Service. If we use analytics or non-essential cookies, we will disclose them and obtain consent where required. You can control cookies through your browser; disabling essential cookies may break the Service.
9. Your California Privacy Rights (CCPA/CPRA)
California residents have the right to: know/access the personal information we collect; request deletion; request correction; and opt out of "sale" or "sharing" for cross-context behavioral advertising. We do not sell personal information and do not share it for cross-context behavioral advertising. We will not discriminate against you for exercising these rights. To exercise rights, contact privacy@dakdan.com. We will verify requests and may use an authorized agent process.
10. Your GDPR/UK Rights
If GDPR/UK GDPR applies, you have rights to access, rectification, erasure, restriction, portability, and objection, and to lodge a complaint with a supervisory authority. To exercise rights, contact privacy@dakdan.com. We respond within the timeframes required by law.
11. International Transfers
We may process information in the United States and other countries. Where required, we use appropriate safeguards (e.g., Standard Contractual Clauses) for cross-border transfers.
12. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption of stored credentials, hashed passwords, signed session tokens, access controls, and audit logging. No method of transmission or storage is 100% secure; we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and authorities as required by law.
13. Children's Privacy
The Service is for business use and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child provided information, contact privacy@dakdan.com and we will delete it.
14. Third-Party Links & Services
The Service may link to or integrate third-party services. We are not responsible for their privacy practices. Review their policies.
15. Changes to This Policy
We may update this Policy. Material changes will be notified by email and/or in-app and reflected by the "Last Updated" date. Continued use after the effective date constitutes acceptance.
16. Contact
Privacy questions or requests: privacy@dakdan.com · Dakdan LLC, Severance, CO 80550. EU/UK data protection contact (if appointed): privacy@dakdan.com.