# Privacy Notice

Version: 2026-08-05

## 1. Who we are

d5s B.V. (“d5s”) is a Dutch besloten vennootschap with its registered office in Amsterdam, registered with the Dutch Business Register under number 42132069 and VAT identification number NL869866552B01 (“we”, “us”).

This Notice explains how we process personal data when you visit d5s websites, create or use an account, buy or evaluate our services, communicate with us, or otherwise interact with d5s.

For these activities, d5s normally decides why and how personal data is used and acts as controller. When a customer submits personal data in workspace content for d5s to process on the customer's instructions, the customer is normally the controller and d5s is its processor. That processing is governed by the applicable Data Processing Addendum (“DPA”), not only by this Notice.

## 2. How to contact us

- Privacy: privacy@d5s.tech
- General: hello@d5s.tech
- Legal: legal@d5s.tech
- Security reports: security@d5s.tech
- Postal address: Nieuwezijds Voorburgwal 104-108, 1012 SG Amsterdam

d5s is established in the Netherlands and has not appointed an Article 27 EU representative. Privacy questions and rights requests can be sent to privacy@d5s.tech.

## 3. Personal data we process

Depending on how you use d5s, we may process:

1. **Account and profile data:** name, business email, profile image, organisation, workspace membership, role, authentication identifiers, and preferences.
2. **Commercial data:** employer, job title, sales communications, quotes, Order Forms, subscription, plan, seats, billing contact, invoice data, VAT information, payment status, and transaction references. Payment-card details are handled by Stripe and are not intended to be stored by d5s.
3. **Customer content:** prompts, messages, instructions, files, generated outputs, memories, configurations, connector data, tool results, approvals, and other content submitted to or produced through a workspace.
4. **Usage and audit data:** feature activity, model/tool choices, timestamps, account and workspace identifiers, usage quantities, account-creation and order records, administrative changes, and audit events.
5. **Device, network, and log data:** IP address, browser/device type, operating system, request metadata, cookie or local-storage identifiers, diagnostic data, security events, and error reports.
6. **Support and communications:** contact-form email address and message, attachments, call or meeting notes and the names of participants, feedback, survey responses, communications preferences, and limited network/security metadata used to prevent abuse.
7. **Waitlist and marketing data:** name, email, company, role, country, intended use, deployment preference, consent record, and campaign interaction.
8. **Data from authorised integrations:** information a user instructs d5s to retrieve from a connected third-party service, subject to the permissions granted for that integration.

We ask customers not to submit special-category data, criminal-offence data, children's data, or other highly sensitive personal data unless the parties have expressly agreed that processing, safeguards, and instructions in writing.

## 4. Why we use personal data and our legal bases

We process personal data:

1. **To provide and administer the service:** create accounts and workspaces, authenticate users, run requested agents and tools, provide support, meter usage, administer subscriptions, and perform our contracts. Legal bases: contract performance and our legitimate interests in providing an enterprise service.
2. **To bill and keep records:** process payments, issue invoices, maintain accounting and tax records, and prevent payment fraud. Legal bases: contract, legal obligation, and legitimate interests.
3. **To secure and improve d5s:** detect abuse, investigate incidents, debug errors, monitor reliability, protect customers, and improve product usability and performance. Legal bases: legitimate interests and, where applicable, legal obligations.
4. **To communicate:** respond to contact and access requests, send requested confirmation and access-invitation messages, provide service and security notices, manage evaluations, and conduct proportionate business-to-business sales. Legal bases: steps requested before a contract, contract performance, and our legitimate interests.
5. **To send optional marketing:** send product news only where the recipient has made a separate, optional choice. Refusing marketing does not prevent an access request, confirmation message, or requested invitation. Legal basis: consent. You may withdraw consent at any time.
6. **To comply with law and protect rights:** respond to lawful requests, enforce agreements, establish or defend claims, and meet regulatory duties. Legal bases: legal obligation and legitimate interests.

Where we rely on legitimate interests, we balance those interests against the rights and reasonable expectations of the affected people. You may request further information about that assessment.

## 5. Customer content and AI services

d5s processes customer content to provide the features requested by authorised users and administrators. Depending on the selected configuration, content may be sent to model or infrastructure providers identified in our Subprocessor List.

d5s does not use customer content to train a d5s general-purpose model.

An authenticated user may choose no-training routing for model requests. When selected, d5s instructs AI Gateway to use only eligible provider routes that are not permitted to use the prompt or output for model training; the same effective choice applies to auxiliary model calls such as subagents, context compaction, web search, and deep research. Background jobs use the documented preference of their owner or workspace. If no-training routing is not selected, provider training and retention depend on the selected model, route, and provider terms disclosed in the Subprocessor List. d5s does not promise Zero Data Retention unless it is expressly stated for the applicable feature or Order.

AI-generated content may be inaccurate and may contain personal data supplied in the input or returned by an authorised source. Customers are responsible for choosing appropriate inputs, access permissions, review, and downstream use.

## 6. Sources of personal data

We receive personal data:

- directly from you;
- from your employer, organisation administrators, or other authorised users;
- from services you authorise d5s to connect to;
- automatically from devices, browsers, and service activity;
- from payment, authentication, infrastructure, support, and security providers;
- from public business sources or referral partners for proportionate B2B sales activity.

## 7. Who receives personal data

We may disclose personal data to:

1. authorised users and administrators within the relevant organisation or workspace;
2. infrastructure, hosting, authentication, email, mailbox, diagnostics, and model-routing providers listed in our Subprocessor List, including AWS, Vercel, WorkOS, Resend, Google Workspace, Slack, Sentry, Cloudflare, and the provider that serves a requested model call;
3. Stripe and other payment, fraud-prevention, tax, or financial-service recipients acting as processor, independent controller, or both for their respective activities;
4. third-party integrations, model endpoints, communication destinations, or other recipients that a customer or user directs us to use;
5. Google when the application retrieves directly hosted Google Fonts resources;
6. professional advisers, auditors, insurers, financing counterparties, and transaction advisers subject to appropriate confidentiality;
7. public authorities or other parties when required by law or reasonably necessary to protect rights, security, and safety; and
8. a successor in a merger, acquisition, financing, reorganisation, or sale, subject to appropriate safeguards.

We do not sell personal data or share it for cross-context behavioural advertising.

## 8. International transfers

Core customer data is stored in the regional AWS environment selected for the service, initially eu-central-1 (Frankfurt) for the EU service. Identity, website delivery, email, diagnostics, payments, AI Gateway, model inference, and customer-directed integrations may involve processing in the United States or other countries identified in the Subprocessor List.

Where a recipient is outside the European Economic Area, d5s uses an applicable adequacy decision, the European Commission Standard Contractual Clauses, the EU-US Data Privacy Framework where available, or another lawful transfer mechanism, with supplementary measures where required. Customer-directed integrations transfer data to the destination selected by the customer under that destination's terms. Contact privacy@d5s.tech to request information about applicable safeguards.

## 9. Retention

We keep personal data only as long as necessary for the purposes above, including legal, accounting, security, and dispute requirements:

- account and profile data: while the account is active, then deleted or irreversibly anonymised within 30 days after closure, except for the limited records described below;
- organisation and customer content: while the service is active, during a 30-day retrieval period after termination, and for up to 30 additional days while deletion from active systems completes;
- billing, invoice, credit, and tax records: seven years after the end of the relevant financial year, or longer where a specific legal obligation requires;
- ordinary application and infrastructure logs: generally seven days; security-incident evidence may be isolated for the investigation and any related legal-claim period;
- audit and usage records: retained only for the applicable security, billing, abuse-prevention, or legal purpose, with closed-user and deleted-resource identifiers anonymised when direct identification is no longer required;
- contact, support, and sales communications: until the request or commercial relationship is resolved, then only while reasonably needed for follow-up, a legal claim, or an applicable record-keeping obligation;
- unconfirmed access requests: seven days from submission, after which the record is deleted by the automated cleanup process;
- confirmed access requests: until general availability opens, the request is provided, refused, withdrawn, or 24 months have passed, whichever occurs first;
- optional marketing records: until consent is withdrawn or the marketing activity ends; a minimal suppression record may be retained as necessary to honour the opt-out; and
- backups and non-current object versions: deleted data remains isolated and unavailable for ordinary use and expires within seven days after active-system deletion.

If a backup is restored, d5s reapplies completed deletion and anonymisation records before returning the restored system to ordinary use. Legal holds are limited to authorised records, purposes, and periods.

## 10. Your rights

Subject to applicable law, you may ask to:

- access your personal data;
- correct inaccurate or incomplete data;
- erase data;
- restrict processing;
- object to processing based on legitimate interests or direct marketing;
- receive portable data you provided where applicable;
- withdraw consent without affecting earlier lawful processing;
- lodge a complaint with the Autoriteit Persoonsgegevens or another competent supervisory authority.

When d5s processes customer content only on a customer's instructions, please direct your request to that customer. We will assist the customer as required by the DPA. We may verify identity and may retain limited information where law permits or requires it.

## 11. Automated decisions

d5s does not make decisions about individuals that produce legal or similarly significant effects solely by automated means in its controller activities.

Customers control their own workflows and must implement appropriate human review and legal safeguards before using automation in consequential contexts.

## 12. Security

We use technical and organisational measures designed to protect personal data, taking account of risk. Where we process personal data on a customer's behalf, the measures we commit to are described in Annex 2 of the Data Processing Addendum. No method of storage or transmission is completely secure.

## 13. Cookies and browser storage

Our Cookie Notice explains the cookies and similar technologies used on d5s websites and applications, their purposes, providers, and retention. Where consent is required, we request it before setting the relevant technology and provide a way to withdraw it.

## 14. Children

d5s is a business service and is not intended for children. Users must be at least 18 or the age required to enter a binding business agreement in their jurisdiction. We do not knowingly collect children's personal data in our controller activities.

## 15. Changes

We may update this Notice as our services or legal obligations change. The page will show the current version and effective date. We will provide additional notice of material changes where required.

## 16. Complaints

Please contact privacy@d5s.tech first so we can try to resolve your concern. You may also complain to the Dutch Data Protection Authority:

Autoriteit Persoonsgegevens
https://autoriteitpersoonsgegevens.nl/
