Legal
Privacy Policy
Version 1.2, effective 19 July 2026
1. Who are we
dGENIX is a service of dGENIX B.V. (in formation), established in the Netherlands. Chamber of Commerce: 97916137. VAT number: NL005295840B15. Contact: contact@dgenix.nl.
dGENIX B.V. (in formation) is the data controller for the personal data processed through dGENIX in the context of your own account. If you use the platform to process personal data about others (for example your own customers or contacts), you are the data controller for that data and dGENIX acts as a processor, see section 8.
2. What data do we process
When using dGENIX, we process the following data:
- Account data: email address, display name and password (securely hashed, never stored in plain text).
- Assistant configuration: the name and settings of your assistant and the knowledge document you provide.
- Subscription and payment data: subscription status and invoice numbers via Stripe. Credit card details are processed solely by Stripe; we never store them ourselves.
- Content you enter or create: chat messages, notes and tasks (Workspace), memories in your AI memory, documents in your knowledge base, voice recordings (Voice), and images and files generated by the assistant.
- Data from connected services: if you connect an integration, GENI only processes the data needed for your request (for example emails, calendar items, files or CRM contacts).
- Integration tokens: encrypted OAuth tokens and API keys for the services you connect yourself (including Google Workspace, Microsoft 365, Slack, Notion, HubSpot, LinkedIn, Stripe, WhatsApp/Instagram, Telegram and CMS platforms). These are stored encrypted (AES-256-GCM) and never shared with third parties.
- Usage and activity data: credit consumption, executed tasks, activity logs and error logs.
- Scan data: if you use the free SEO/GEO scan, we process the domain you enter, your email address and your IP address to run the scan and link it to any account you create.
- Technical data: IP address, browser type and session metadata.
3. Why do we use your data
- Providing the dGENIX service (dashboard, AI assistant, skills, Growth Engines and optionally Telegram).
- Carrying out the tasks you give to GENI.
- Processing payments and invoicing via Stripe.
- Managing your account and subscription.
- Technical communication about the service (system notifications, security alerts).
- Security, abuse and fraud prevention.
- Improving the service based on aggregated, anonymised usage.
We do not send commercial newsletters unless you explicitly consent. We do not use the content of your conversations and data to train AI models, and the AI providers we use do not train their models on the data processed through their APIs.
4. Legal basis for processing
We process your personal data based on:
- Performance of contract (Art. 6(1)(b) GDPR): for everything necessary to provide the service.
- Legal obligation (Art. 6(1)(c) GDPR): for the statutory retention of invoice data.
- Legitimate interest (Art. 6(1)(f) GDPR): for security logging, abuse and fraud prevention and improving the service.
- Consent (Art. 6(1)(a) GDPR): for connecting integrations, non-functional cookies and marketing communications.
5. Sub-processors and transfers
To provide the service we use carefully selected processors. We only ever share the data needed for their task. We work with the following categories of recipients:
- Hosting and infrastructure (EU): our web application, marketing site and the server that runs the AI agent.
- Database, authentication and file storage.
- Payment processing: handled by a specialised payment provider; credit card details never reach us.
- AI providers: specialised parties for text, speech and image processing that carry out what you ask GENI. They do not train their models on the data processed through their APIs.
- Data providers for the Growth Engines: supplying SEO/GEO, backlink and AI-visibility data. They process the domain and keywords you provide, not account data.
- Email provider: for transactional emails and, if you subscribe, our newsletter. Only your email address is shared.
- Channels and connectors you connect yourself (for example Google Workspace, Microsoft 365, Telegram, WhatsApp/Instagram, and CRM or CMS platforms): data flows to that service on your initiative and under that service's terms.
We never sell your data to third parties or use it for targeted advertising. Where data is processed outside the EU, this is done on the basis of appropriate safeguards such as the EU Standard Contractual Clauses (SCCs). A current list of our specific sub-processors is available on request, for example when entering into a data processing agreement.
6. Retention periods
- Account and content data (notes, tasks, memory, knowledge base, files): as long as your account is active + up to 30 days after deletion.
- Invoice data: 7 years (statutory retention obligation).
- Usage and activity logs: up to 90 days.
- Integration tokens: deleted immediately upon disconnection or account deletion.
- Scan data (free scan): kept so we can link your scan to an account, and deleted on request.
7. Your rights (GDPR)
You have the right to:
- Request access to the data we process about you.
- Have incorrect data corrected.
- Have your data deleted (“right to erasure”).
- Restrict processing or object to it.
- Receive your data in a machine-readable format (data portability).
- Withdraw previously given consent.
You can delete your account and all associated data directly via Dashboard → Settings → Delete account. For other requests, send an email to contact@dgenix.nl. You also have the right to lodge a complaint with the relevant supervisory authority, in the Netherlands: Autoriteit Persoonsgegevens.
8. Third-party data you process
If you use dGENIX to process personal data about others, for example your own customers, leads or the recipients of a review campaign, you are the data controller for that data and dGENIX acts as a processor. You are responsible for a valid legal basis, the accuracy of that data and informing the data subjects, and you use the platform in accordance with the GDPR and our Terms of Service. We process that data solely to carry out your instructions and not for our own purposes. Business customers who require one can enter into a data processing agreement with us on request.
9. Cookies
dGENIX uses only functional cookies necessary for the operation of the service (session management). We do not place tracking or advertising cookies without your consent.
10. Security
We take appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS/TLS), securely hashed passwords, encrypted storage of integration tokens (AES-256-GCM), row-level security at database level, and strict access control based on minimal privileges.
11. Amendments
We may update this privacy policy. For material changes, you will receive a notification via email or a message in the dashboard. The most current version is always available at dgenix.com/privacy.
Questions about this policy?
Contact us at contact@dgenix.nl or read the Terms of Service.