Legal
Privacy Policy
DALI Intelligence Ltd. Last updated 18 August 2026.
DALI Intelligence Ltd (“DALI”, “we”, “us”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share and protect personal data in connection with your use of our website (the “Site”) and our platform, products and features (the “Services”), and describes your rights and how to exercise them.
“Personal data” means any information relating to an identified or identifiable individual, for example your name, business email address, job role, or information generated through your interactions with our Services.
1. Scope of this Privacy Policy
This Privacy Policy applies where DALI is the data controller for personal data relating to visitors to and users of our Site and Services; customers and prospective customers, and their representatives; and suppliers, service providers and business partners, and their representatives.
This Privacy Policy does not apply to content that our customers submit to, upload to, or generate through the Services, including queries, documents, matter content and materials held in a customer’s private workspace (“Customer Content”). We process Customer Content as a data processor on behalf of our customers, who are the data controllers of that content, and our processing is governed by the agreement between DALI and that customer rather than by this Privacy Policy. Any request relating to personal data contained in Customer Content should be directed to the relevant customer. If we receive such a request directly, we will forward it to that customer.
2. What personal data we collect
Information you provide to us. When you or your organisation create a DALI account, we collect your name, business email address, job role, and account credentials. When you contact us with questions, feedback or support requests, we collect your name, business email address, and any information you choose to provide so we can assist you.
Information we collect automatically. When you use the Services we automatically collect log data (your IP address, browser type and settings, and the date, time and nature of your requests), device information (the device, operating system and browser you use), and usage data (the features you use, actions you take, and the dates, times and volume of your activity). We do not collect or store the substance of Customer Content through this, other than as permitted by the applicable customer agreement.
Information from third parties. Our customers may provide us with contact details of their personnel in order to set up and administer their access to the Services. Where relevant, we may also collect business contact details of prospective customers from publicly available sources.
Publicly available information in our sources. Our Services draw on publicly available legal material such as legislation, regulatory materials, guidance and published decisions. Some of this may include personal data. Where it does, that personal data is processed only so that the Services can provide accurate and relevant legal research and analysis. It is not processed in order to identify individuals.
3. How we use your personal data and our lawful bases
We use personal data for the purposes below. For each, we identify the lawful basis under the UK GDPR.
Providing and administering the Services, to create and manage your account, authenticate you, and deliver the Services to you and your organisation. Lawful basis: performance of a contract (Article 6(1)(b)).
Support, queries and communications, to respond to your questions, provide support, and send you service-related communications. Lawful basis: performance of a contract (Article 6(1)(b)) and legitimate interests (Article 6(1)(f)) in responding to and resolving your queries.
Security and prevention of misuse, to authenticate users, maintain security and access logs, detect and prevent fraud or misuse, and protect the integrity of our systems. Lawful basis: legitimate interests (Article 6(1)(f)) in keeping the Services and our users’ data secure.
Improving and developing the Services, to analyse how the Services are used so we can fix problems and improve features and performance. Lawful basis: legitimate interests (Article 6(1)(f)) in maintaining and improving our Services.
Legal compliance and protection of rights, to comply with legal obligations, respond to lawful requests, and establish, exercise or defend legal claims. Lawful basis: legal obligation (Article 6(1)(c)) and legitimate interests (Article 6(1)(f)) in protecting our rights.
Where we rely on legitimate interests, we have assessed that our interest is not overridden by your interests or rights. You can ask us for more information about that assessment.
4. Who we share your personal data with
We share personal data only as necessary and with appropriate safeguards, including with service providers who process personal data on our behalf to help us run the Services, including hosting, infrastructure and AI service providers, acting on our instructions under written contracts and listed in Section 5; professional advisers such as our lawyers, accountants and auditors, where relevant; authorities and others where legally required, where we must do so to comply with a legal obligation, respond to a lawful request, or protect our rights, users or the public; and in connection with a business transaction, where if we are involved in a merger, acquisition, financing or sale of assets, personal data may be disclosed to counterparties and their advisers and transferred as part of that transaction, subject to appropriate confidentiality protections.
5. Sub-processors and international transfers
We use the following sub-processors to provide the Services. Some are located outside the UK, in which case transfers are protected by the safeguards described below.
| Sub-processor | Role | Location |
|---|---|---|
| Anthropic | Large language model provider | United States |
| OpenAI | Text embeddings provider | United States |
| Cohere | Reranking provider | United States |
| Neon | Managed database hosting | United Kingdom |
| Cloudflare | Object storage for uploaded documents | Global infrastructure |
| Upstash | Managed caching | European Union |
| Railway | Backend hosting and compute | European Union |
| Vercel | Frontend hosting | European Union |
The AI service providers listed above process query and document text in order to generate research, analysis and results. Client content sent to these providers is not used to train their models.
Our object storage provider operates globally distributed infrastructure, and the location at which stored data resides depends on the configuration of the storage bucket. Transfers outside the UK arising from that storage are covered by the safeguards described immediately below.
Where personal data is transferred outside the UK, in particular to our US-based AI service providers, we rely on the UK Addendum to the EU Standard Contractual Clauses as the transfer safeguard, supported by an assessment of the transfer and any additional measures required. Depending on the recipient, we may also rely on a UK adequacy determination or, in limited cases, a permitted exception under the UK GDPR. You can contact us for more information about the safeguards applying to a particular transfer.
6. Cookies
Our Site uses only strictly necessary cookies, those required for the Site and Services to function, such as maintaining your session and keeping your account secure. These do not require your consent, but we tell you about them here for transparency.
We do not currently use analytics, advertising or other non-essential tracking cookies. If we introduce them in future, we will first put in place a cookie banner to obtain your consent and publish a fuller cookie policy describing them.
7. How we keep your personal data safe
We take appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access, disclosure, alteration or destruction. These include encryption in transit and at rest, access controls, tenant isolation, and logging and monitoring.
DALI Intelligence Ltd holds Cyber Essentials certification. Further detail on our controls is available in our security overview on request, and summarised on our security page.
8. How long we keep your personal data
We keep personal data only for as long as necessary for the purposes described in this policy, and then delete or anonymise it.
| Data | Retention period |
|---|---|
| Account and identity data | For the life of your account and up to 12 months after account closure |
| Security and access logs | Up to 12 months |
| Usage data | Up to 26 months |
| Billing and transaction records | 6 years, to meet tax and accounting obligations |
| Support correspondence | Up to 24 months after the matter is resolved |
Where you are a user under an agreement between your organisation and DALI, we delete your data in accordance with that agreement. Where we are legally required to retain data, for example under bookkeeping or anti-money-laundering laws, we keep it for the period required by law.
9. Your rights
Under UK data protection law you have the following rights in relation to your personal data.
- Access.
- To be told whether we process your data and to receive a copy.
- Rectification.
- To have inaccurate or incomplete data corrected.
- Erasure.
- To have your data deleted in certain circumstances.
- Restriction.
- To ask us to limit our processing in certain circumstances.
- Objection.
- To object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Portability.
- To receive certain data in a machine-readable format, or have it transmitted to another controller.
- Withdraw consent.
- Where we rely on consent, to withdraw it at any time, without affecting processing carried out before withdrawal.
To exercise any of these rights, contact us using the details below. We may need to verify your identity before acting on a request. We will respond within one month, as required by law. Where personal data appears in Customer Content, your request should be directed to the relevant customer, as described in Section 1.
You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority, at ico.org.uk, though we would welcome the chance to address your concerns first.
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version on this page and update the last updated date above. Where required by law, we will provide additional notice.
11. Contact us
If you have any questions about this Privacy Policy or how we handle your personal data, please contact DALI Intelligence Ltd at contact@daliintelligence.com.