Политика конфиденциальности

Обновлено 8 сентября 2026 · Версия 2.0

Официальная версия — на английском.

1. Operator and contact

Dahl Inference is operated by FROMZERO OÜ, an Estonian private limited company, registry code 17062264, registered address Ahtri 12, 10151 Tallinn, Estonia. dahl.global is operated by FROMZERO OÜ.

Privacy enquiries and requests: [email protected].

This policy covers the website, browser chat, inference API, accounts, payments and support offered at dahl.global and inference.dahl.global. It does not automatically cover other FROMZERO products or independent third-party services.

FROMZERO is the controller for personal data used for its own account administration, billing, website analytics, security and legal purposes. Where an organisational customer determines the purposes of processing its submitted content and we act only on its documented instructions, we act as processor, or subprocessor where appropriate, under the applicable data processing agreement. Those roles depend on the actual processing. This notice does not replace a required data processing agreement.

2. Information processed

The information involved depends on the features you use and the material you submit. Processing a request does not necessarily mean retaining its content after completion.

Information can also originate from an organisation whose application you use or a person who includes your data in a request. Where required, we provide information about indirectly collected data or assist the responsible customer in doing so.

Providing information necessary for authentication, inference or payment is a condition of using that function. Optional information is not required for unrelated functions. Do not submit unnecessary personal information or account secrets in prompts or support correspondence.

3. Purposes and legal bases

We process personal data only on an applicable legal basis and for a defined purpose:

  • Providing an individual's requested Service and purchases: performance of a contract or necessary steps requested before a contract, Article 6(1)(b) GDPR, to the extent the processing is objectively necessary.
  • Managing organisational customer relationships: legitimate interests, Article 6(1)(f), in administering the relationship and communicating with its authorised contacts, balanced against their rights.
  • Security, reliability, fraud prevention and troubleshooting: legitimate interests in protecting the Service, customers and infrastructure, or a specific legal obligation where applicable. Processing is limited to what is necessary and proportionate.
  • Website measurement: consent where required for analytics technologies and their associated processing. Where a configuration lawfully operates without consent, the basis is our legitimate interest in understanding aggregate website use, subject to the applicable balancing assessment and objection rights. This does not dispense with consent where device-storage or tracking law requires it.
  • Accounting, tax and binding legal requirements: compliance with applicable legal obligations, Article 6(1)(c).
  • Complaints, investigations and legal claims: legitimate interests in establishing, exercising or defending rights, or a binding legal obligation where applicable.

When we act as a processor, the customer's lawful documented instructions and data processing agreement govern processing; the customer is responsible for the legal basis for its purposes. Acceptance of the Terms is not consent to every possible use of personal data.

4. Inference and content handling

Requests are processed through the broker and the computing infrastructure required to produce a response, including gateway and inference operators where used. Processing may involve independent operators in a distributed network. Do not assume that transport encryption prevents a computing operator from accessing content during execution.

We seek to minimise retained content, but do not offer a general zero-retention, anonymity or end-to-end-confidentiality guarantee under the standard Service. Necessary operational records and relevant incident or legal evidence may be retained under section 7. A pseudonymous account or wallet does not necessarily make related data anonymous.

The purposes stated in this policy do not grant an unrestricted right to publish private prompts, sell personal data or train models on customer content. A materially different purpose requires the applicable legal basis, information and, where necessary, consent or customer instructions before processing. This policy does not claim that all independent model or infrastructure providers follow identical practices. Our obligations concerning providers and lawful processing remain applicable.

Do not submit special-category data, criminal-offence data, private keys, payment-card secrets or sector-regulated confidential information without a separate arrangement that permits and protects that use. Contact us before using the Service to process third-party personal data on behalf of an organisation where a data processing agreement is required. A restriction on submissions does not remove obligations toward data actually received.

5. Recipients and service providers

Personal data may be available to authorised personnel, relevant infrastructure providers and other recipients as necessary for the purposes above. The infrastructure and recipient categories include:

Prometheus and Grafana are hosted on the operator's own server for monitoring. Their installation alone does not make the software developers recipients of customer data.

Provider names above identify the services used. The precise processing role depends on the function and contractual arrangement. Processors acting on our behalf must be engaged under the arrangements required by law. Payment providers may also act independently for their own payment, fraud-prevention and regulatory purposes. Information about recipients relevant to your data can be requested at [email protected]; legally required specific disclosures and any applicable subprocessor information remain available under the relevant rights and agreements.

Current payment processing uses NOWPayments for cryptocurrency. Your payment details may be collected directly by that provider. Adding a different payment method requires the relevant privacy information to be provided before the new processing begins. Public blockchain entries may remain visible independently of Dahl; closing an account cannot erase a public ledger entry. We remain responsible for our own processing of linkable transaction information.

Necessary information may be disclosed for a binding legal demand, a lawful investigation, or the establishment, exercise or defence of claims. In a sale or reorganisation, relevant business information may be shared under appropriate confidentiality and data protection safeguards and any required notice. These purposes do not authorise indiscriminate disclosure.

6. International processing

The standard Service does not promise that all processing takes place in Estonia or exclusively within the EEA. Distributed computing, cloud services and authorised provider access can involve international processing.

Transfers of personal data outside the EEA are subject to applicable law. Depending on the recipient and destination, the required basis may be an applicable adequacy decision or appropriate safeguards, such as standard contractual clauses together with necessary assessments and supplementary measures. A customer's acceptance of this policy does not itself create a valid transfer mechanism.

You can obtain information about destinations and safeguards applicable to your data and request a copy of relevant safeguards from [email protected], subject to lawful redaction. Contractual processing-region commitments apply only where expressly agreed and supported by the relevant Service arrangement. We remain responsible for the transfer requirements applicable to our role.

7. Retention and legal preservation

We retain personal data for the relevant purpose and applicable legal requirements. Where the period cannot be determined in advance, it is determined by the criteria below. Any applicable fixed statutory period or more specific retention information provided for a feature takes precedence.

We may preserve necessary evidence despite an account closure or deletion request where law requires or permits it. Preservation is limited to relevant information, with restricted access and reassessment when the basis ends. A theoretical possibility of a future complaint does not justify indefinite retention of all traffic.

When the lawful retention basis ends, information is deleted or genuinely anonymised. Merely removing a name or replacing it with an identifier does not necessarily anonymise it. Genuinely anonymous statistics may be retained without a personal-data retention period.

For processing on a customer's behalf, return and deletion follow the applicable data processing agreement and lawful instructions, subject to binding law. We cannot recreate erased data to answer a request, but rights concerning information still held remain available.

8. Cookies, local storage and analytics choices

The browser interface uses storage where needed for requested functions such as authentication and preferences. PostHog Cloud is used for landing-page statistics. Where analytics or other non-essential storage requires consent, that consent must be obtained before activation and must be withdrawable. Essential functionality is distinguished from optional tracking.

Browser settings can inspect, restrict or clear cookies and local storage, although disabling necessary storage may prevent a requested function from working. Data held on a device may need to be cleared on that device; an account request does not itself erase all browser copies. Browser settings do not replace our obligation to obtain prior consent where required.

You may contact [email protected] regarding analytics choices or object to processing based on legitimate interests. Consent-based activity stops on withdrawal, without affecting the lawfulness of earlier processing or a separate lawful basis for retaining limited evidence.

9. Security and automated processing

We apply safeguards appropriate to the risks and our legal role. The standard Service does not guarantee perfect security, recovery of every lost credential or uninterrupted access. These limitations do not exclude statutory security or breach-notification duties.

Automated systems may check traffic and payments, detect abuse and enforce operational limits. You may contest an account restriction and request human review at [email protected]. Where a decision falls within applicable rules on solely automated decisions with legal or similarly significant effects, we provide the information and safeguards required by those rules. Ordinary generation of an AI response does not itself authorise significant decisions about an individual.

Protect your credentials, limit permissions and avoid including unnecessary personal or confidential information in requests.

10. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction or portability of your personal data. You may withdraw consent and object to processing based on legitimate interests, including objecting to direct marketing where relevant. Statutory conditions and exceptions apply, including necessary preservation for legal obligations and claims.

Contact [email protected]. We may ask for proportionate information to identify records and verify your entitlement. Do not send an API key or login secret. A pseudonymous account may make verification harder but does not erase your rights.

For GDPR requests, we respond without undue delay and normally within one month. Where law permits an extension for complexity or the number of requests, we notify you of the reasons within the initial month; the extension may be up to two further months. Requests are normally free; any permitted fee or refusal must meet the legal conditions and be explained with information about remedies.

If we process the relevant information only on behalf of an organisational customer, we refer the request to that customer and assist as required. Rights belonging to its users are not removed by the customer's agreement with Dahl.

You may complain to the Estonian Data Protection Inspectorate or another competent supervisory authority, including the authority in your habitual residence, workplace or place of the alleged infringement where GDPR permits. Contacting us first is not a condition for exercising that right.

11. Age, other laws and policy changes

The Service is intended for people aged 18 or older. Contact us if you believe a child has supplied information contrary to that restriction; we will handle the matter under applicable law.

Mandatory rights under other applicable privacy laws remain available. Where additional notices or choices are required for a jurisdiction or feature, they supplement this policy. Contractual liability limits do not override data subjects' non-waivable rights.

We may update this policy to reflect changes in practices or law and provide additional notice or obtain consent where required. Updates do not retrospectively authorise incompatible processing or expand a customer's instructions merely by being published.

FROMZERO OÜ — [email protected]