1. Who controls your personal data
DIRI AI is operated by František Mráz, IČO 07961731, trading as DIRI AI. The registered office and verified contact channels are provided in the Legal Notice. Privacy requests must be sent to privacy@diriai.com.
DIRI AI is normally the controller for website visits, individual accounts, trials, billing, support, security, product administration, first-party application operations, consented public-site analytics and direct marketing. Where an organisation supplies personal data in its workspace and determines why and how that data is used, that organisation is the controller and DIRI AI acts as its processor under the Data Processing Agreement. Users should first contact their organisation for requests about organisation-controlled workspace data.
2. Scope
This Policy applies to diriai.com, DIRI AI applications, subscriptions, trials, support and related
communications. Optional Google Analytics measurement is limited to supported English and Czech
public marketing pages on diriai.com and www.diriai.com; it does not run on application,
account, authentication, billing, legal, super-admin or preview routes. Separately, authenticated
application routes use privacy-minimised, server-side first-party operational analytics described in
this Policy. That processing is not GA4 and is not linked to GA4. This Policy does not govern a third
party's independent website or a customer's own use of exported data. The effective checkout must
identify any materially different processing before it begins.
3. Data we process
Depending on how you use DIRI AI, we may process:
- account and identity data: name, email address, account identifier, authentication events, selected language and age/eligibility confirmation;
- organisation data: employer or customer name, role, workspace membership, invitations, administrator actions and seat assignments;
- billing data: plan, billing country, business identifiers supplied by the customer, invoice and transaction references, payment status and limited card metadata supplied by the payment provider; DIRI AI does not need to receive the full card number;
- training content: scenarios, prompts, voice input, optional recordings, transcripts, annotations, scores, reports, coaching feedback and user responses;
- usage data: session timing, selected language and voice, feature use, allowance consumption, settings, exports and cancellation events;
- first-party application operational analytics: independently keyed HMAC pseudonyms for the tenant and user, a 15-minute UTC activity window, the last accepted activity time within that window, allowlisted locale, device class and application source, privacy-policy version, creation time and expiry time; authorised analytics queries also create a separate audit record containing HMAC pseudonyms for the administrator and query, the requested date range and granularity, included first-party sources, cache status, result status, privacy-policy version, request time and expiry time;
- device, network and security data: IP address, browser and device information, timestamps, session and request identifiers, error traces, audit records, abuse indicators and approximate location derived from network or billing evidence;
- support and communications data: messages, attachments, complaint details, survey answers and records needed to resolve the request;
- public marketing analytics data after consent: a first-party browser identifier, normalized allowlisted host/path, same-site allowlisted referrer path when present, pageview or one of three bounded interaction events, EN/CS language and allowlisted CTA/plan/campaign values, plus technical browser/network metadata necessarily exposed to Google such as IP address, user agent, timestamp and protocol headers;
- pre-consent volatile campaign handoff: the first allowlisted campaign source, medium and name,
capture time, state and a random per-document binding, held only in JavaScript memory for the
current page document for up to 30 minutes with no provider request, cookie, local storage,
session storage, raw query, referrer or arbitrary key; all
utm_*parameters are removed from the visible address immediately, and a reload, new tab or duplicated tab discards the handoff; and - preference and marketing data: cookie choices, newsletter opt-in evidence, unsubscribe or suppression status, consented campaign interaction data and the language of communications.
The Analytics event payload does not permit query strings, URL fragments, external referrer URLs, document titles, free text, names, email addresses, telephone numbers, account/customer/company identifiers, call content, recordings, transcripts, payment data, checkout/status tokens, User-ID or advertising identifiers supplied by DIRI AI. These payload restrictions do not remove the ordinary transport metadata described above or make all Analytics data anonymous under data-protection law.
First-party application operational analytics does not contain raw tenant or user identifiers, names, email addresses, telephone numbers, IP addresses, user-agent strings, precise location, referrer or full URL values, query strings, campaign parameters, Customer Content, call content, recordings, transcripts, prompts, support messages, payment data, free text or arbitrary metadata. Its HMAC pseudonyms remain personal data while DIRI AI can recompute them and are protected as such.
We obtain data from you, your workspace administrator, your device and use of the service, payment and infrastructure providers, Google Analytics only after the required choice, and lawful anti-fraud or security signals. We do not buy consumer profiles or sell personal data.
4. Why we process data and our legal bases
| Purpose | Typical data | GDPR/EEA legal basis |
|---|---|---|
| Create and operate an account, provide training sessions, reports, limits, exports and support | account, organisation, content, usage and communications | performance of a contract or steps requested before a contract; legitimate interests for B2B user administration where appropriate |
| Process subscriptions, invoices, renewals, refunds and accounting | account, billing, transaction and limited tax evidence | contract; compliance with legal obligations |
| Protect accounts, prevent repeat-trial abuse, investigate incidents and enforce rules | account, device, network, payment-provider signals, audit and abuse data | legitimate interests in secure, fair operation and establishment or defence of claims; legal obligation where applicable |
| Maintain and improve reliability and quality | minimised usage, error and support data; controlled samples only when authorised | legitimate interests in a reliable service; consent where required for optional recording, cookies or a materially different use |
| Operate and measure application reliability, capacity and bounded feature use | pseudonymous 15-minute activity windows, allowlisted locale/device/source values and access-restricted query audit | contract where strictly necessary to provide and secure the service; otherwise legitimate interests in reliable, secure and proportionate service operation, subject to minimisation and objection rights |
| Measure use of allowlisted public marketing pages with GA4 | consent choice, first-party cookie identifier, normalized host/path, bounded event/properties and transport metadata | consent; no Analytics tag or request before affirmative choice |
| Send service, security, billing and legal notices | contact, account and event data | contract, legal obligation or legitimate interests; these are not marketing messages |
| Send newsletters and offers | email, consent, preference and suppression data | consent where required; a permitted existing-customer exception only where local law clearly allows it and an easy opt-out is provided |
| Respond to rights requests, regulators and legal claims | identity, request, account, audit and communications data | legal obligation; legitimate interests in documenting compliance and claims |
Where we rely on legitimate interests, we assess necessity, impact and safeguards. You may request information about the relevant assessment and object to processing as described below. We will not switch a consent-based purpose to legitimate interests simply because consent was refused or withdrawn. Optional GA4 measurement remains off after refusal and under Global Privacy Control.
5. Training audio, transcripts and AI output
DIRI AI sends only the data needed for a requested training interaction to a voice or AI provider identified in the Subprocessor List and enabled for that function. Voice data is used to provide a simulated conversation; DIRI AI does not intend to use it for biometric identification, voiceprint matching or emotion recognition.
Recording storage is off by default. If an optional recording feature is enabled, the interface must disclose that fact, its purpose and retention before recording begins. A transcript, score or coaching suggestion can be wrong and must not be used as the sole basis for an employment or other legally significant decision.
Do not submit real customer secrets, payment-card data, credentials, health data, biometric data or other special-category data unless a separately approved feature expressly requires it and every necessary legal basis, notice and safeguard exists. DIRI AI does not use Customer Content to train general-purpose models without a separate, voluntary and specific choice and lawful basis.
Training data, Customer Content and first-party application operational analytics are outside the GA4 collection scope. GA4 does not run on application or account routes and does not receive Customer Content or the first-party application analytics pseudonyms. DIRI AI does not join these first-party operational records to GA4 identifiers or reports.
6. Automated processing
The service automatically generates simulations, transcripts, scores, suggestions, usage limits and reports. Security and fraud rules may flag or temporarily limit an account or repeat trial. These processes are not intended to make a solely automated decision producing legal or similarly significant effects. Where an automated restriction materially affects you, contact support@diriai.com to request human review, unless disclosure would compromise security or a legal investigation.
GA4 traffic reports are not used to score users, decide access, profile employees or make legal or similarly significant decisions.
7. When information is required
Account, eligibility, security and billing information marked as required is necessary to enter or perform the contract. If it is not provided, we may be unable to create an account, begin a card trial, process a payment or secure the service. Marketing consent and non-essential cookie/analytics consent are optional. Refusal or withdrawal does not prevent access to the public pages or core paid service.
8. Who receives data
Access is limited to authorised DIRI AI personnel and service providers that need the data for hosting, databases, caching, email, payments, error monitoring, security, voice or AI processing. Providers used for these functions and their purposes are listed in the Subprocessor List. Business messages sent to the DIRI AI role addresses are hosted, routed and stored through Google Workspace under a business account; they are not forwarded to a consumer mailbox. Providers acting as processors must be bound by data-protection terms. Payment providers may also act as independent controllers for regulated payment, fraud and compliance purposes.
After affirmative analytics consent, Google Analytics 4 receives the restricted public-site data
described in section 3. Google Ireland Limited is the contracting entity under the applicable Google
Analytics account agreement and Data Processing Terms. DIRI AI uses one Analytics property and one
web stream for diriai.com and www.diriai.com. Google's explanation of data processing for partner
sites is available at https://policies.google.com/technologies/partner-sites.
Umami, Vercel Web Analytics, Vercel Speed Insights, Cloudflare Web Analytics, pixels, replay, heatmaps, advertising audiences and Google Ads links are not analytics recipients under this Policy. Vercel and Cloudflare may still process separate infrastructure data for hosting, DNS, routing, storage or security as disclosed in the Subprocessor List.
First-party application operational analytics stays within DIRI AI's application hosting and database environment and is not sent to Google Analytics or another marketing-analytics provider. Access to its aggregate reports and query audit is restricted to authorised administrators.
We may disclose data to professional advisers, authorities, courts or transaction counterparties where lawfully necessary, proportionate and protected. We do not disclose Customer Content for third-party advertising.
9. International transfers
Where the applicable service and agreement allow, DIRI AI selects European processing regions, but global networks, support and providers may process data outside the EEA, United Kingdom or Switzerland. Before a restricted transfer, we must use an applicable adequacy decision, the European Commission's Standard Contractual Clauses with a transfer assessment and supplementary measures, or another lawful safeguard. A provider's marketing statement alone is not sufficient evidence. DIRI AI records the applicable safeguards in its Vendor and Transfer Register.
Google states that Analytics traffic from EU, Swiss and UK devices is collected through regional domains and servers before being forwarded to Analytics servers for processing. Google's processing terms permit processing where Google or its subprocessors maintain facilities and contain European transfer provisions. DIRI AI records the applicable transfer mechanism in its Vendor and Transfer Register.
You may request information about the relevant safeguard from privacy@diriai.com; confidential or security-sensitive terms may be redacted.
10. Retention
We keep personal data only for the shortest period needed for the purpose, contract, security and legal obligations. The default schedule is:
| Record | Default period |
|---|---|
| Active account and workspace | for the contract; deletion workflow starts after closure, subject to the periods below |
| Training transcripts, reports and related session data | up to 365 days by default, with earlier user or workspace deletion where available |
| Stored voice recording, only if the feature is expressly enabled | off by default; otherwise up to 30 days unless a shorter workspace setting applies |
| Prepared personal-data export | normally 24 hours after it is made available |
| Security and audit logs | normally up to 12 months; longer only for a documented incident, fraud investigation or claim |
| Payment, invoice and tax records | for the statutory accounting and tax period, which may be up to 10 years |
| Support and complaint records | normally up to 3 years after closure; longer for an unresolved claim or mandatory record |
| Transactional email delivery and webhook records | normally up to 90 days, excluding records required for a complaint or legal proof |
| Trial-abuse evidence | normally up to 3 years, minimised and access-restricted |
| First-party application activity windows | up to 35 days from the start of the relevant 15-minute UTC window |
| First-party application analytics query audit | up to 90 days from the authorised query |
| Marketing consent evidence other than browser-only analytics | while used and normally up to 3 years after the last reliance; a minimal suppression record may be kept as long as needed to honour an opt-out |
| Browser analytics choice | accepted: 365 days; rejected: 6 UTC calendar months; invalidated earlier after a material notice or provider-configuration change |
| GA4 first-party browser identifiers | up to 365 days from first consent on the current host; not renewed on page load |
| GA4 user-level and event-level data | 2 months, with reset on new activity off |
| GA4 standard aggregated reports | outside Google's two-month setting; retained only while needed for the stated measurement purpose and removed with property/data lifecycle |
Google states that expired user/event data is deleted through a monthly process and that its retention setting does not affect standard aggregated reports. DIRI AI therefore does not promise that every aggregated report is deleted after two months. The detailed Retention Policy explains provider deletion, the browser-only choice record, exceptions and legal holds.
Deletion from active systems does not guarantee immediate deletion from isolated encrypted backups; backups must expire on a verified provider cycle and must not be restored for ordinary use. Google's applicable processing terms and account deletion controls govern its processor copies in addition to the configured Analytics retention.
11. Your rights
Subject to the conditions and exceptions in applicable law, you may request:
- access to and a copy of your personal data;
- correction of inaccurate data;
- deletion or restriction of processing;
- portability of data you provided where processing is automated and based on consent or contract;
- objection to processing based on legitimate interests or to direct marketing;
- withdrawal of consent at any time, without affecting earlier lawful processing; and
- human review and information where applicable automated-decision rights arise.
Use privacy@diriai.com. We may request proportionate identity verification and normally respond within one month under the GDPR, subject to a lawful extension for complex or numerous requests. There is normally no fee, but the law permits a reasonable fee or refusal for manifestly unfounded or excessive requests. If a workspace customer controls the data, we will direct or assist the request under the DPA.
Analytics uses no DIRI AI account identifier or User-ID, so an account email does not by itself identify a browser in GA4. You can stop future collection through Cookie settings and clear local cookies. DIRI AI will use available Google deletion controls where a request can be matched without collecting unnecessary additional identifiers.
For first-party application operational analytics, DIRI AI keeps activity HMAC key versions for the applicable 35-day activity-record lifetime and administrator/query HMAC key versions for the full 90-day query-audit lifetime. For an authenticated access, export or approved deletion request, DIRI AI uses every key version retained for the relevant lifetime to locate, export or delete matching activity and query-audit records. The lookup is performed only for the request, does not create a GA4 link, and remains subject to lawful security, claim and record-retention exceptions.
You may complain to the Office for Personal Data Protection of the Czech Republic or another competent supervisory authority, and you may seek a judicial remedy. Authority details are in the Legal Notice.
12. Marketing and analytics choices
Newsletter subscription must use a clear, separate choice and evidence of what was agreed. Every marketing email must identify the sender and contain a working unsubscribe method. Withdrawal is free and will stop future marketing after the operational suppression process completes. Service, billing, security and legally required messages may continue while relevant to the account.
GA4 traffic measurement uses a separate optional choice. Basic Consent Mode keeps the Google tag fully blocked before affirmative consent and after refusal. A visitor can later withdraw through Cookie settings; the page removes the tag, attempts to clear first-party Analytics cookies and reloads without Analytics. Global Privacy Control keeps optional analytics off. Consent is bound to the EN/CS notice version and GA4 provider-configuration version, so a material change makes the stored choice stale.
The optional analytics configuration does not include advertising audiences, cross-site tracking, advertising or conversion pixels, retargeting, session replay, heatmaps, Google Ads links, advertising personalisation or Google Analytics advertising features. We will not treat an account signup, closed banner, scrolling, silence or pre-ticked box as analytics or marketing consent.
Rejecting or withdrawing optional GA4 measurement does not disable the privacy-minimised first-party application operational analytics used to provide, secure and maintain the service. Those records use the legal bases, safeguards, retention periods and objection rights described above and are never linked to GA4.
13. Children
DIRI AI is not directed to children under 13 and does not knowingly offer them an account or process their voice. A user aged 13 to 17 may not complete direct self-service checkout. A parent, legal guardian or authorised customer organisation must create or accept the account/subscription, assume the payment obligation and satisfy any additional local requirements. An organisation route does not replace parental permission where applicable law requires it. Optional consent-based processing is not enabled for such a user unless the user or holder of parental responsibility may validly provide it under the applicable law.
For a Czech user, where Article 8 GDPR consent is the legal basis for an optional information- society-service activity, a user under 15 requires authorisation by the holder of parental responsibility. Contractual capacity is assessed separately and may require adult or guardian acceptance even when the data-protection consent threshold is met.
Signup must use a neutral age control and minimise the retained age evidence. If we learn that an under-13 user supplied personal data, we will suspend the affected processing, seek proportionate verification where lawful and delete the data unless retention is legally required. Contact privacy@diriai.com without sending identity documents unless requested through a secure channel.
14. Security
We use risk-based organisational and technical measures described in the Security Overview and, for processor data, the DPA. No system is perfectly secure. Send suspected vulnerabilities or incidents to security@diriai.com and do not include unnecessary personal data in the initial report.
DIRI AI limits Analytics to consented allowlisted hosts, paths, events and properties, keeps advertising settings off and supports withdrawal. These restrictions reduce data but do not eliminate all privacy or provider risk.
15. Regional rights outside the EEA
If a law in your supported location gives additional privacy rights, we will honour them where it applies. This may include rights to know, access, correct, delete, obtain a portable copy, opt out of sale or targeted advertising, limit certain sensitive-data uses, withdraw consent, or appeal a decision. DIRI AI does not sell personal data and must not enable targeted-advertising disclosure without a region-appropriate notice and opt-out or consent.
This section does not mean DIRI AI is offered in every country or US state. Paid availability is limited to locations and customer categories accepted by checkout after the applicable tax, regulatory and provider assessment.
16. Changes and contact
We will publish a dated version and give appropriate advance notice of a material change. A new purpose or provider requiring consent will not begin merely because this Policy changed. Archived versions must remain available. A material change to the GA4 provider, notice or collection scope invalidates the stored browser choice and requires a new decision.
Controller identity and address are in the Legal Notice. Privacy contact: privacy@diriai.com.
Version: 1.2.0. Effective date: 30 August 2026.