Back to Home

GDPR Compliance

Last updated: June 17, 2025

At DIYAI, we are committed to protecting your personal data and ensuring compliance with the General Data Protection Regulation (GDPR). This page outlines how we collect, process, and protect your data in accordance with EU regulations.

On this page

Need help with GDPR?

Contact our Data Protection Officer for any questions or concerns.

Contact DPO

Data Collection Practices

Types of Personal Data We Collect

  • Account Information: Name, email address, phone number, and business information when you create an account.
  • Usage Data: Information about how you interact with our services, including access times, pages viewed, and features used.
  • Communication Data: Records of communications between you and our AI assistant, including call recordings, chat logs, and email correspondence.
  • Payment Information: Billing details and transaction records when you purchase our services.
  • Technical Data: IP address, browser type, device information, and cookies.

Purpose of Data Collection

We collect and process your personal data for the following purposes:

Service Provision

To provide and maintain our AI communication services, including call answering, chat support, and appointment scheduling.

Customer Support

To provide technical assistance, respond to inquiries, and resolve issues related to our services.

Service Improvement

To analyze usage patterns, improve our AI capabilities, and enhance the overall user experience.

Communication

To send service updates, security alerts, and administrative messages related to your account.

Legal Basis for Processing

We process your personal data in accordance with GDPR on the following legal grounds:

Contractual Necessity

Processing necessary for the performance of our contract with you to provide our services.

Legitimate Interests

Processing necessary for our legitimate business interests, such as improving our services and ensuring security.

Consent

Processing based on your explicit consent, which you can withdraw at any time.

Legal Obligation

Processing necessary to comply with our legal obligations under EU and member state law.

Your Rights Under GDPR

Under the GDPR, you have several rights regarding your personal data. We are committed to respecting these rights and have implemented processes to help you exercise them:

Right to Access

You have the right to request a copy of the personal data we hold about you and to check that we are lawfully processing it.

Right to Rectification

You have the right to request that we correct any incomplete or inaccurate personal data we hold about you.

Right to Erasure

You have the right to request that we delete your personal data when there is no good reason for us to continue processing it.

Right to Restrict Processing

You have the right to request that we suspend the processing of your personal data in certain scenarios.

Right to Data Portability

You have the right to request that we transfer your personal data to you or to a third party in a structured, commonly used, machine-readable format.

Right to Object

You have the right to object to the processing of your personal data where we are relying on a legitimate interest and for direct marketing purposes.

How to Exercise Your Rights

You can exercise any of these rights by contacting our Data Protection Officer. We will respond to all legitimate requests within one month.

Contact DPO

Data Protection Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

Encryption

All data in transit and at rest is encrypted using industry-standard encryption protocols (TLS 1.3, AES-256).

Access Controls

Strict access controls and authentication mechanisms to ensure only authorized personnel can access personal data.

Regular Backups

Regular data backups with secure storage to prevent data loss and ensure business continuity.

Intrusion Detection

Advanced intrusion detection and prevention systems to monitor and block suspicious activities.

Staff Training and Awareness

We ensure that our staff understands the importance of data protection through:

  • Regular data protection and security awareness training
  • Clear policies and procedures for handling personal data
  • Confidentiality agreements and data protection clauses in employment contracts

Third-Party Compliance

We ensure that any third-party service providers who process personal data on our behalf:

Data Processing Agreements

All third-party processors are subject to data processing agreements that comply with GDPR requirements.

Due Diligence

We conduct thorough due diligence on all third-party processors to ensure they maintain appropriate security measures.

Regular Audits

We conduct regular audits of our third-party processors to ensure ongoing compliance with data protection requirements.

Contact Information

If you have any questions about our GDPR compliance or would like to exercise your data protection rights, please contact our Data Protection Officer:

Data Protection Officer

Sarah Johnson
dpo@diyai.ai
+1 (800) 555-0123
DIYAI Inc., 123 Tech Avenue, San Francisco, CA 94107, USA

EU Representative

Thomas Weber
eu-rep@diyai.ai
+49 30 1234 5678
DIYAI GmbH, Friedrichstraße 123, 10117 Berlin, Germany

Contact Form

Use this form to submit a GDPR-related request or inquiry:

Our Commitment to Timely Responses

We are committed to responding to all GDPR requests within the following timeframes:

Initial Response

Within 48 hours of receiving your request

Data Access Requests

Within 30 days of verifying your identity

General Inquiries

Within 7 business days of receipt