Who we are
DynasAI (DynasAI) operates the website at dynasai.aiand the product workspace at app.dynasai.ai. Contact:hello@dynasai.ai.
For the marketing site and sales enquiries, DynasAI is the controller of the personal data you send us. For customer workspace content (your documents, systems, prompts, and agent logs in a paid or trial tenant), DynasAI typically acts as a processoron your instructions. You remain controller of that customer data. A data processing agreement (DPA) is available on request for enterprise contracts.
Two layers of data
DynasAI is a front layer: identity, workflows, evaluation, and governance. Backend compute, storage, and model APIs run on Amazon Web Services, Microsoft Azure, or Google Cloud — either in a DynasAI-managed template or in your own account / VPC, as you choose.
- Site & sales data (this website, contact forms, analytics) is processed by DynasAI as controller.
- Customer workspace data stays under your control. We do not use it to train public foundation models. Residency (for example EU or US regions) follows the cloud and region you select. See Governance andcloud partners.
What we collect
Depending on how you use DynasAI, we may process:
- Enquiry data — name, email, company, and message if you contact us, request a sprint, or verify a one-time code to open a gated playbook (stored as a sales lead).
- Account data — workspace identity (SSO or email), role, and audit metadata when you use app.dynasai.ai.
- Usage data — pages viewed on this site via Google Tag Manager. Tags configured in GTM (including Google Analytics 4 if enabled) may collect device and approximate location data.
- Customer content — files, connectors, prompts, retrieval context, and agent traces that you or your users put in a workspace. That content is processed to provide the service, not for DynasAI’s own marketing.
We do not require special-category data for the marketing site. Do not send it in contact forms.
How we use data
- Respond to sales and support requests.
- Provide, secure, and improve the workspace (including evals, logging, and abuse prevention).
- Understand site performance and content (analytics, subject to cookies/consent).
- Meet legal duties (tax, accounting, GDPR/US privacy requests, security incidents).
We do not sell personal data. We do not share it for cross-context advertising unless you enable advertising tags in GTM after consent.
GDPR legal basis
The EU AI Act does not replace GDPR. Where GDPR applies, we rely on:
- Contract (Art. 6(1)(b)) — to provide a workspace or respond to a requested demo.
- Legitimate interests (Art. 6(1)(f)) — site security, product improvement of the marketing site, B2B outreach where permitted. You may object.
- Consent (Art. 6(1)(a)) — non-essential cookies/analytics once Consent Mode is configured.
- Legal obligation (Art. 6(1)(c)) — where we must retain or disclose records.
Customer content in a tenant is processed under your instructions (Art. 28). You are responsible for a lawful basis for the personal data you load into agents — including training, retrieval, and monitoring. DynasAI does not create that basis for you.
AI, agents, and training
- Agents may send prompts and retrieved snippets to model APIs on the cloud you select (for example Bedrock, Azure OpenAI, Vertex AI).
- We design the service so customer content is not used to train public models operated by DynasAI.
- Third-party model providers have their own terms. Enterprise deployments should use provider options that disable training on your prompts where available.
- Human-in-the-loop gates and traces support GDPR Art. 22 (no solely automated decision with legal or similarly significant effect without a human path) and EU AI Act logging/transparency duties. Product detail: governance.
Sharing and subprocessors
We share personal data only as needed to run the service:
- Cloud backends — AWS, Azure, or GCP for hosting, storage, and model APIs, in the account/region you choose or a managed template.
- Google Tag Manager — container for site tags in production (GTM-KDPPRVV2).
- Professional advisers — lawyers, accountants, under confidentiality.
- Authorities — when required by law.
A current subprocessor list for enterprise customers is available on request.
International transfers
If you are in the EEA/UK and data is processed in the US or another third country, we use appropriate safeguards (for example Standard Contractual Clauses and supplementary measures) with subprocessors. You can keep EU personal data in EU cloud regions when you select that residency model.
Retention
- Enquiry email — as long as needed to handle the request, then deleted or archived per our mail retention practice.
- Analytics — per GTM/GA configuration (typically 2–14 months for event data unless you set otherwise).
- Workspace traces and content — per your tenant settings and contract; default designed to support audit windows (including six-month+ logging patterns used for AI Act-style record-keeping) unless you configure shorter retention.
Your rights (EU & US)
GDPR / UK GDPR: access, rectification, erasure, restriction, portability, and objection (including to legitimate-interests processing). You may lodge a complaint with your supervisory authority. For automated decisions that produce legal or similarly significant effects, you can request human review.
US (including CCPA/CPRA and other state laws where they apply): you may have the right to know, delete, correct, and opt out of sale/share. DynasAI does not sell personal information as those laws define sale. We do not discriminate for exercising privacy rights.
To exercise rights, email hello@dynasai.ai with enough detail to locate your data. For workspace content, we may redirect you to your organization’s admin (the controller).
Security
We use encryption in transit, access controls, logging, and environment isolation. Customer deployments can use customer-managed keys where the chosen cloud supports them. No method of transmission is 100% secure. See Governance & Securityfor product controls. We do not claim a completed SOC 2 audit on this page; enterprise questionnaires and control descriptions are available on request.
Cookies
See the Cookie Policy. Theme preference is stored in localStorage (not a tracking cookie). Production GTM may set cookies once tags and Consent Mode are configured.
Contact
Privacy requests: hello@dynasai.ai.
Product security review: Contact.
We will update this policy when our processing changes. The date above is the latest revision.