Aller au contenu

Ce document n’est publié qu’en anglais et en espagnol, parce qu’un texte contractuel n’est pas traduit sans avocat. La version anglaise s’affiche ci-dessous.

Datta Privacy Policy

Version 0.0.1 · effective 24 August 2026

All documents

0 · The whole policy in one table

WhatExamplesWhere it livesWho can see itWhy we process itHow long
Your accountemail (encrypted), phone (derived code only), password (strong hash)Datta serversYou; our staff can not see your email or phoneCreating and protecting your accountWhile you have an account
Your vaultidentity, documents, financial data, employmentDatta serversYou and whoever you authorizeIt is the product: keeping your dataUntil you delete
Your verificationdocument data; the chip's official photoYour device (face) + your vault (document)You and whoever you authorizeProving you are youUntil you delete
Your address booksynced contacts, sealedDatta servers, encrypted under two keysYou; the subject of each datumYour multi-account agenda + the subject's rightsUntil you or the subject delete
AI agentswhich agent accessed, under which grantAudit logYouSo you see and control every accessAudit retention
Technical dataIP, device, sessionsDatta serversYou (history); securitySecurity, anti-fraud, rate limitingShort (see the section «How long we keep things»)
AdvertisingNoneThe app carries no advertising SDK and no advertising identifierNobodyWe run no advertisingNot applicable
Usage analyticswhich screen was used, whether a step finished or failed, how long it tookOur servers, never a third party'sOnly us, and as counts that point to nobodyUnderstanding where the product stalls so we can fix itDetail 7 days; counts 25 months

Three standing commitments: we don't sell data, we run no advertising, and we use the content of your vault for nothing except providing the service.

We do measure how Datta is used, because there is no way to improve it otherwise: which screens cost effort, which services stall, at which step a verification fails. That measurement is ours, it runs on our servers, it goes through no analytics vendor, it carries neither your name nor any identifier that follows you over time, and it is only ever read as counts. The detail is in the section «Exactly what data we process», and you can turn it off in one tap.

1 · Controller

1.1 Controller: DATTTA LLC, a Delaware limited liability company (United States), file 10563369, formed on 26 March 2026, trading as «Datta», with its address at 1201 N Orange St, Ste 7665, Wilmington, DE 19801-1186, United States. Privacy contact: datta.global/contact.

1.2 Data protection officer and designated contact for data protection matters in every market: Nicolás Suárez, nicolas@law10tic.com.

1.2 Three distinct roles, said plainly:

  • For your account, security, and service operation, Datta is the controller.
  • For the content of your vault, you decide what goes in, what leaves, and who sees it; Datta holds it on your instruction and uses it for no purpose of its own.
  • When a business processes your data through Datta (asks for documents, verifies your identity), that business is the controller of that processing and Datta its processor (DPA). Complain to the business; if it doesn't respond, write to us.

2 · Scope

Mobile app (iOS/Android), desktop console, datta.global website, APIs, and MCP server. For people and for businesses. 18+. The site additionally has its short notice for the contact form and the cookie policy (spoiler: the site uses no cookies).

3 · Exactly what data we process

3.1 Account and security

  • Email: stored encrypted; lookups use a blind index (a derived code that does not reveal the email).
  • Phone: we never store the number in the clear: only a derived code (HMAC) that lets us recognize it without reading it.
  • Password: Argon2id hash at recommended (OWASP) parameters; at creation we check against breached-password lists without sending your password (HIBP k-anonymity).
  • Passkeys (console): we store the public key and authenticator metadata.
  • Devices and sessions: technical device fingerprint (hashed), device token, 15-minute session tokens with rotated refresh; issuing a refresh records IP and user agent. All visible to you under "devices" and "access history".
  • OTP codes: stored hashed with a pepper and self-expiring.

3.2 The content of your vault

The categories you load: identity, documents, contact, address, employment, income, banking, credit, tax, assets, debt, social, compliance: plus whatever the catalog enables.

How it is stored: sensitive data is envelope-encrypted with AES-256-GCM before it touches the database. Your account email, your address book, and your notification identifiers are encrypted too. Everything travels over TLS and rests on encrypted disks, with access control and an audit entry for every read.

Versioning: your vault keeps version history (deleting a field writes a new empty version; real erasure is the section «Your rights and how to exercise them» deletion flow).

3.3 Identity verification

Full detail in the biometric policy. Summary: document reading and face comparison happen on your device; your vault receives the document's text data and, if you use the NFC chip, the chip's signed contents including the document's official photo, which the server uses to validate the issuing country's signature and stores as a document of yours. When the external document-verification flow is active, that provider acts as a sub-processor and receives only the document images needed for the check; it is listed on the sub-processor page.

3.4 Your address book and the network

  • Your synced contacts are stored sealed under two keys: one yours (your agenda, your restore) and one derived from the subject's identifier (so the subject, if they arrive and verify, can exercise their rights): no column in the clear, neither identifier nor value. The server sees values only in transit during sync and discards them after sealing.
  • Counting matches without decrypting uses blind indexes.
  • Names, nicknames, notes, labels, and photos from your address book are never shown to others.
  • If someone has you saved and you don't use Datta: read the non-user notice, what we hold, what we cannot do with it, and how to delete yourself without creating an account.

3.5 AI agents

If you connect an agent (e.g. via claude.ai), you give it a bounded grant: read-only or write of categories you list, no wildcards, limited lifetime (default 1 hour, max 30 days), and a sensitivity ceiling by plan. You see the full grant history and revoke instantly. Every access lands in the audit log with the agent identified as the actor.

3.6 Technical and security data

  • IP and user agent: for rate limiting, session issuance, and risk signals (IP geolocation and proxy detection using local databases on our server: your IP is not sent to third parties for this).
  • Push: a notification token (encrypted in our database) to deliver notices through your operating system's messaging service, with its analytics disabled.
  • Device location: only while you have the app open and only when you ask for it. It serves two purposes. First, filling in an address when you tap "use my location" and confirming you are there. Second, delivering travel companion services: when you arrive in a new country or a new place, Datta can turn on the connected services that match your profile and your preferences. Those services start at your request and run only while you use them. There is no background tracking.
  • Application logs: the client log is local, silenced in release, with a sensitive-data redactor; the server records events with actor, resource, and result in an audit log that is cryptographically chained (rewrite-evident, verified against production).

3.7 Usage analytics

To improve Datta we need to know how it is used. This section says exactly what is measured, what is never measured, and how it is built so that it cannot point at you.

Status as of this version: usage measurement is not yet live on any surface. The rules below govern it and are in force from now; when it goes live, we will update this section first.

What is measured, in four groups and nothing else:

  • Product: at which step of signup or verification the flow ends and with what outcome, which screens get used, whether you come back at seven and at thirty days. Always with closed codes, never with text you wrote.
  • Service: how long each operation takes, which errors occur, and which external provider failed. It is what lets us fix an outage without waiting for you to report it.
  • Usage profile: how many people are on each plan, in each grouped market, with how many connected services. Always as counts, never as a record per person.
  • Connected services: which class of service was used and whether it worked, never who you talked to.

What is never measured. The content of your vault, neither whole nor summarized. Your name, your document, your photo, your date of birth, your address, your phone, or your email, neither in the clear nor turned into a code. Your biometric data, including any score. Your address book: no contact, no count, no relationship. Your conversations with the Brain. Which specific datum a third party asked for about you. Your precise location. No special-category data, even if you keep it in your vault. And nothing at all about a person who does not use Datta.

How it is built so it cannot point at you. Events carry no account identifier of yours. To join what happens inside one session we use a key derived from a secret that changes every twenty-four hours and is destroyed when it changes: past that window, joining two different days' activity is impossible, for us too. A session lasts four hours at most. Your IP address serves to derive the country and is discarded before anything is stored. And no figure is shown if there are so few cases behind it that it could point at a person: below that minimum the datum is grouped with the rest.

How long it lasts. The detail is deleted after seven days. The aggregate counts, which no longer identify anyone, are kept for twenty-five months.

On what basis, and how you opt out. The basis is the legitimate interest of running and improving the service, and that interest yields to yours: you can turn off your contribution to usage statistics from the app's settings, in one tap, without losing any feature. With the switch off the app stops sending the events; it is not that they are sent and then discarded.

None of this goes through a third party. There is no analytics SDK in the app, in the console, or on the site, and there will not be. The site's measurement, when it is turned on, will run on a tool we host ourselves, without cookies. The exact status is in the cookie policy.

3.8 What we do NOT do

No analytics, commercial crash-reporting, or advertising SDKs in the app, verified dependency by dependency. No cookies on the site. No selling data, ever. No purchased enrichment. No advertising profiles. No cross-app or cross-site tracking: we do not use the iOS advertising identifier, and Android's technical AD_ID permission is stripped from the package, so that no library can reintroduce it.

One single read deserves an explanation, because it looks like tracking and is not: the first time you open the app on Android, the parameter with which Google Play recorded the installation is read, solely to take you to the link you arrived from. It is read once, travels to no server, is not stored, and feeds neither attribution nor advertising.

PurposeDataBasis (GDPR and equivalents)
Creating and operating your account and vaultemail, phone, password, and the content you storeContract (art. 6(1)(b))
Verifying your identitydocument data, chip, and the face check on your deviceExplicit consent for biometrics (art. 9(2)(a)); contract for the rest
Address book and reciprocal networkthe contacts you sync, sealedContract (your agenda); legitimate interest with safeguards (sealed custody of third-party data)
Authorized agentswhich agent accessed, under which grant, and whatYour instruction (contract)
Security and anti-fraudIP, device, sessions, and the audit logLegitimate interest (protecting the service and data subjects); legal obligation where applicable
Operational communicationsemail/phoneContract. No marketing today; if it ever exists it will be opt-in with one-tap unsubscribe
Measuring usage to improve the serviceusage events with no account identifier (the section «Exactly what data we process»)Legitimate interest (art. 6(1)(f)), with a right to object and an opt-out switch in the app
Complying with lawthe minimum necessaryLegal obligation (art. 6(1)(c))

There are no automated decisions with legal effect on you except the identity verification result, which you can dispute with human review (biometrics).

5 · Who data is shared with

By default: nobody. Then, in three circles:

5.1 The recipients YOU choose: people, businesses, and agents you grant access to. Every reveal through the network is logged. Note: what a third party saw while authorized, they saw.

5.2 Providers running our infrastructure (our processors, under data processing terms; live list at datta.global/legal/subprocessors):

Provider categoryRoleWhat reaches itWhere
Server infrastructureHosts the serviceService data, with the encryption described aboveCanada, the United States or Europe
Offsite backupKeeps an encrypted copyOnly the encrypted backup, which the provider cannot openCanada
Transactional emailDelivers the service's emailsYour email and message contentUnited States
Messaging and voiceDelivers verification codesYour phone number and the codeGlobal (carrier routing)
Notification deliveryBrings the notice to your phoneThe notification identifier, with no analyticsGlobal
Document verificationServes the technical database to the component running on your deviceNothing personalNot applicable

5.3 Authorities: only under a valid, enforceable legal obligation, reviewed case by case; we notify you unless legally barred. We will publish aggregate request figures We will publish a transparency report with the number of requests received and answered.

Never: data sales, sharing for advertising, "data partners, " data brokers.

6 · Where your data lives and international transfers

Today: the primary infrastructure sits in Canada, the United States or Europe, and the encrypted backup with a different provider in another country (Canada).

Residency policy: Datta data is hosted only in Canada, the United States, or Europe. The data schema already versions per-jurisdiction retention and transfer rules for regionalization.

Mechanisms by user origin (counsel to confirm the map):

  • EU/EEA: the Commission's adequacy decision for Canada (PIPEDA scope, partial; verify fit) plus Standard Contractual Clauses (2021/914) as belt and suspenders; for the US, Standard Contractual Clauses with a transfer impact assessment, while no DPF certification exists.
  • UK: IDTA / UK Addendum; UK-Canada adequacy carried over.
  • Switzerland: Swiss annex to the SCCs; FDPIC adequacy list.
  • Colombia: international transfer/transmission per Ley 1581 and SIC circulars (adequate countries or authorization/transmission contract).
  • Mexico / Ecuador / Panama / El Salvador: notice + consent or contract per local law.

7 · How long we keep things

The full policy, including what survives a backup restore and why, is in retention and deletion. Summary:

DataRule
Vault contentUntil you delete it or close the account
Deleted accountDeleted status + identifiers released + destruction of your encryption keys; physical purge scheduled
BackupsRotation: 7 days on-server, 14 days for the encrypted offsite copy, a deletion leaves every backup within that cycle
Agenda-deletion evidence (tombstones)Kept without the datum (derived codes only) as proof the deletion happened · period datta.global/contact
Audit and access logs7 years
Sessions and OTPSelf-expiring (15-min tokens; OTP minutes; rotated refresh)
Usage analyticsDetail 7 days; aggregate counts 25 months; neither layer carries an account identifier (the section «Exactly what data we process»)

8 · Security

Operating today, verifiable in code: TLS 1.3 and two-year HSTS; Argon2id; AES-256-GCM envelope encryption for sensitive fields, the address book, and email; blind indexes instead of identifiers; rate limits on all sensitive endpoints; a chained, rewrite-evident audit log verified against production; administrative staff without access to your email or phone, with every individual lookup audited; encrypted backups outside the primary provider.

Incidents: if a breach affects your data we will notify you and the competent authority within legal deadlines (72h under GDPR; local equivalents), with what we know and what we are doing. Vulnerability disclosure channel: datta.global/contact.

9 · Your rights and how to exercise them

In-product, today: export your data (account/export), deactivate the account (reversible), delete it (final), list and close sessions and devices, view your access history, manage agent grants.

Honest limitation of today's export: the V1 export covers identity, profile, devices, and sessions; it does not yet include all vault content: declared in the code and in the export result itself. Until that closes, ask us for the rest through the channel below and we will deliver it manually in a portable format.

Direct channel: datta.global/contact, identity verified with your own account or, if you are not a user, with proof of possession of the identifier (non-user notice). We respond within ≤30 days (or your law's shorter deadline: 15 business days for claims in Colombia, etc.).

Rights by regime: access, rectification, erasure, objection, restriction, portability, consent withdrawal, no discrimination for exercising them, and complaint to your authority (annexes A–E). For the address-book module you additionally have reciprocal deletion: removing your datum from other people's synced address books, a product right stronger than any statute requires.

10 · Children

Datta is 18+. We do not direct the service at children or knowingly open their accounts; if we detect one, we close it and delete its data.

11 · Changes to this policy

Material changes: 15 days' notice in-app or by email, with a summary of what changed. Versioned history at datta.global/legal. Effective date at the foot.

12 · Notifications

Datta tells you what happens in your account: when someone requests access to a datum of yours, when a permission is granted or revoked, when a verification finishes, and when something relevant to your security happens, such as a sign-in from a new device.

These are service notices. We send no advertising or promotions through this channel. If we ever wanted to use it for something other than running the service, we would ask you first and you could say no without losing anything.

To deliver a notice to your phone we need an identifier that your operating system gives the app. We store it encrypted, it serves only to deliver the message, and it cannot identify you outside Datta. You can turn notifications off whenever you want, from the app's settings or your operating system's, and that affects neither your account nor your data.

13 · Jurisdiction annexes

Choose your country to see what the law of your residence adds to this policy. If your country is not listed, the global annex applies.

Everything above applies. You exercise your rights of access, correction, deletion, portability and objection through the same channels described in the section «Your rights and how to exercise them», and we answer within the deadlines your law sets. If your country requires something this policy does not cover, write to us and we will resolve it: the law of your residence prevails over this document.

Back to home

DATTA / Vos données. Vos conditions.

Parlez avec Datta

Nous explorons: Vos données. Vos conditions..