Skip to main content

New on the blog:The brand knowledge base your agents actually cite

Privacy policy

This policy describes how Dubinga handles personal data. It is written for the product as it exists today and is updated when the product changes, not once a year.

Who we are

Dubinga is a multi-tenant marketing platform operated by the Dubinga team. For data you put into your workspace we act as a processor on your instructions; for your own account and billing details we act as a controller. Our registered entity name and postal address are published on the imprint page.

Imprint

What we collect

Account data (name, email, organization and role), workspace content (brand knowledge, campaigns, discussion transcripts, approvals), platform connection metadata and tokens, billing identifiers from our payment processor, and server logs needed to operate and secure the service.

Why we process it

To run the service you asked for, to bill you, to keep the platform secure and available, and to comply with law. We do not sell personal data, and we do not use your workspace content to train models.

Legal bases and hosting region

Each purpose above rests on a specific legal basis: performance of contract for providing the service you signed up for, legitimate interest for keeping the platform secure and improving it — which never includes model training — and consent for optional processing such as connecting marketing platforms and receiving optional emails. All production data is hosted on EU infrastructure in the European Union.

How tenants are separated

Tenant data is separated inside PostgreSQL by row-level security, enforced by the database itself rather than by application code remembering to filter. Access within your workspace follows the member roles you set.

AI model providers

Discussion content is sent to the model provider that runs your agents. If you store your own provider key, requests go to your own provider account and we never see the content of that exchange beyond what your workspace records. Provider choice and key storage are visible in your settings.

Google user data

Dubinga's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Signing in with Google gives us your basic profile — your name and email address. Connecting Google Ads, Google Analytics or YouTube lets us retrieve, on your instruction, campaign structure and performance metrics, analytics reports, and channel and video metadata. We use that data only to provide the features you see — the dashboards, the reports and the recommendations you approve — and we store it on EU infrastructure, isolated per tenant by database-enforced row-level security, with access tokens encrypted at rest. It is never sold, never used for advertising, never used to train generalized AI models, and transferred to no one beyond the subprocessors listed in this policy.

YouTube API Services

The YouTube features described above use YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service, and Google's handling of that data is described in the Google Privacy Policy — both linked below. Through YouTube API Services we access, on your instruction, channel and video metadata, performance metrics and the public comments on your videos, and we upload to your channel only the videos a person on your team approved. We store that data on EU infrastructure, isolated per tenant, refresh or delete it within 30 days, and share it with no one beyond the subprocessors listed in this policy. Beyond disconnecting YouTube in your Dubinga settings, you can revoke Dubinga's access to your YouTube data at any time on Google's security settings page, linked below.

YouTube Terms of ServiceGoogle Privacy PolicyRevoke access in Google security settings

Data from connected platforms

When you connect Meta, Google, TikTok, LinkedIn, X or another platform, we retrieve on your instruction: campaign structure and performance metrics, page and account metadata, audience aggregates, and the public engagement — comments and messages — addressed to your accounts. When you run lead ads, we also retrieve on your instruction the lead-form submissions people send you — name, email, phone and their answers to your form; your organization is the controller of that data, and it lives in your workspace until you delete the lead, the brand or the workspace. We use it for exactly two things: showing it to you, and preparing drafts your team approves. Engagement content follows each platform's own rules — LinkedIn member profile references are removed within 24 hours and LinkedIn member comments within 48 hours, and YouTube data is refreshed or deleted within 30 days. Disconnecting a platform deletes its stored access tokens and the engagement and inbox data synced from it promptly, with a daily sweep as the backstop; campaign records and lead submissions already imported into your workspace remain your workspace's own records — read-only, and deleted with the brand or workspace. We never sell platform data or lead submissions, never use them to train AI models, and process them only on your behalf.

Subprocessors

We use a small set of subprocessors: EU infrastructure hosting, a payment processor, and the AI model providers that run agents on the platform lane. PostgreSQL, file storage and the OAuth gateway run self-hosted on that same infrastructure rather than as separate subprocessors. The current list, with purposes and regions, is published on the subprocessors page, and we notify workspace owners before adding or replacing one.

See the current subprocessor list

How long we keep it

Workspace content lives as long as your workspace does. Ask us to delete a workspace and we delete its content, and backups are retained for at most 30 days before they rotate out. Billing records are kept as long as tax law requires.

Your rights

You can request access, correction, export, deletion or restriction of your personal data, and object to processing. Account and workspace content you can correct yourself in settings; export, deletion and restriction are handled by us — write to the privacy address below and we respond within one month.

International transfers

The service runs in a single region today. Where a subprocessor moves data outside your region, the transfer relies on standard contractual clauses or an equivalent lawful mechanism.

Deleting your data

Disconnecting a platform in settings deletes its stored access tokens from our systems at once and starts deletion of the engagement and inbox data we synced from it; campaign records and lead submissions already imported remain your workspace's own records until you delete the brand or workspace. Deleting a brand removes its campaigns, lead submissions, assets and discussions. For a whole workspace or your account, write to the privacy address below — actioned within one month, usually within days. The data-deletion page walks through every path, including what happens to backups.

How to delete your data

For US residents

If you live in California or a state with a similar privacy law, the same commitments hold in CCPA and CPRA vocabulary: we collect the categories described above — identifiers, commercial information and internet activity within your workspace — we do not sell personal information, and we do not share it for cross-context behavioral advertising. You can exercise the rights to know, delete and correct through the privacy address below, and we will not treat you differently for doing so.

Complaints to a supervisory authority

If you believe we handle your personal data unlawfully, you can lodge a complaint with a data-protection supervisory authority — Article 77 GDPR lets you choose the authority of your residence, your workplace or the place of the alleged infringement. We would welcome the chance to resolve it first: the privacy contact below answers within one month.

Security

Encryption in transit, encryption at rest for secrets such as provider keys, least-privilege database roles, and an approval audit trail that cannot be edited after the fact. We are not SOC 2 certified today; Type II is planned and we will say so here when it is done, not before.

Contact

Privacy and data-subject requests:
privacy@dubinga.com
Everything else:
hello@dubinga.com

We answer data-subject requests within one month.

This page is written to be read, not to be survived. If anything here is ambiguous, ask us and we will fix the wording.

Privacy policyTerms of serviceCookie policy