← Back to application

Privacy Policy

Last updated: March 10, 2026

Dragonfl.ai ("we", "us", or "our") operates an enterprise AI platform that provides sales automation, lead management, voice AI, and knowledge management services to business organizations. This Privacy Policy explains what personal data we collect, how we use it, your rights, and how to contact us.

This policy applies to all users of the Dragonfl.ai platform and is designed to comply with applicable privacy regulations including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and other applicable data protection laws.

HIPAA Notice

Dragonfl.ai is not designed or certified as a HIPAA-compliant platform. If your organization operates in a healthcare context and may process Protected Health Information (PHI), please contact us before use. We do not knowingly process PHI without appropriate data processing agreements.


1. Data Controller

Dragonfl.ai is the data controller for personal data processed through this platform. For questions about this policy or to exercise your rights, contact us at:

Where your organization is an enterprise customer using the platform (a "Business Customer"), your organization may act as a separate data controller or data processor for data it submits to the platform (e.g., lead contacts). Please consult your organization's privacy notice for those processing activities.

2. Personal Data We Collect

2.1 Account & User Data

When you register and use the platform, we collect:

  • First name, last name, email address, phone number
  • Profile picture (if uploaded)
  • Authentication identifiers (Auth0 user ID)
  • Account status, email verification status
  • Organization membership and assigned roles
  • Invitation history, last login timestamp, account creation date
  • Notification preferences

2.2 Lead & Contact Data

As part of CRM and sales automation features, your organization may store contact data about third parties ("leads"), including:

  • Full name, email address, phone number
  • Job title, company name, industry
  • LinkedIn profile URL and professional information
  • Notes, research reports, and meeting records
  • Call status, call duration, call transcripts, and call recording URLs
  • Communication preferences (call-me-back, content consent flags)
  • HubSpot CRM contact ID (if integrated)

Note for lead contacts: If you are a third-party contact ("lead") whose data was entered into the platform by a Business Customer, you should contact that organization directly regarding your data rights. We process this data on behalf of the Business Customer as a data processor.

2.3 Voice Call & Meeting Data

When automated phone calls are made via our voice AI integration (Vapi.ai):

  • Call audio is processed for transcription in real time
  • Call transcripts and AI-generated summaries are stored in our database
  • Call recording URLs are retained (stored by Vapi.ai)
  • Call metadata: duration, start/end time, status, end reason
  • Meeting scheduling details and calendar timeslots

Important: Phone calls may be recorded. Call participants are notified of recording by the AI agent at the start of each call as required by applicable law.

2.4 AI-Generated Research & Content

  • Client, company, and industry research reports generated by AI workflows
  • AI-enhanced meeting notes and agendas
  • Knowledge base documents, embeddings, and case studies uploaded by your organization
  • Chat conversations with knowledge base AI agents

2.5 Demo Request Data

  • Demo configuration details (project names, URLs, shop settings)
  • Product catalogue information
  • Provisioning credentials (stored encrypted)

2.6 Calendar & Integration Credentials

If your organization connects calendar integrations (MS Outlook, Cal.com, Calendly), we store:

  • OAuth access and refresh tokens (encrypted at rest)
  • Calendar API keys (encrypted at rest)
  • Timezone preferences

2.7 Usage & Technical Data

  • Session identifiers and authentication tokens (stored in secure HTTP-only cookies)
  • CSRF protection tokens
  • UI preference data (sidebar state stored in a 7-day browser cookie)
  • Credit usage logs and transaction records
  • API key last-used timestamps
  • Role assignment audit trails

3. Cookies

We use the following cookies. No third-party tracking or advertising cookies are used.

NamePurposeDurationType
__dragonflai_sidUser session management and authentication8 hoursStrictly necessary
csrfCross-site request forgery (CSRF) protection8 hoursStrictly necessary
sidebar_stateRemembers sidebar open/collapsed preference7 daysFunctional
cookie_notice_dismissedRecords that you dismissed the cookie notice (localStorage)PersistentFunctional

The session and CSRF cookies are strictly necessary for the platform to function and cannot be disabled. The sidebar preference and cookie notice cookies can be cleared via your browser settings at any time without affecting platform functionality.

4. How We Use Your Data

We process personal data for the following purposes and legal bases (GDPR Article 6):

Providing the platform services

Contract (Art. 6(1)(b) GDPR)

Authentication, session management, lead management, CRM features, demo provisioning, knowledge base access.

AI-powered features

Contract / Legitimate interest (Art. 6(1)(b)(f))

Research generation, note enhancement, meeting agendas, voice call transcription, knowledge base chat — require processing lead and content data via AI models.

Security and fraud prevention

Legitimate interest (Art. 6(1)(f) GDPR)

Session fingerprinting, CSRF protection, rate limiting, audit logging.

Email notifications

Contract / Legitimate interest

Account verification, password reset, demo status updates, lead sharing notifications.

Platform improvement and analytics

Legitimate interest

Credit usage tracking, error logging, performance monitoring. No behavioral or marketing analytics are performed.

Legal compliance

Legal obligation (Art. 6(1)(c) GDPR)

Retaining records as required by applicable laws.

5. Third-Party Service Providers

We share personal data with the following third-party service providers solely to deliver our services. All sub-processors are bound by data processing agreements:

ProviderPurposeData SharedRegion
Auth0Authentication & identity managementName, email, phone, password (hashed)US (configurable)
BrevoTransactional email deliveryEmail, name, verification/reset linksEU
Vapi.aiVoice AI and phone call automationPhone number, call audio, transcript, agent configUS
OpenAI (via Mastra)AI research generation, note enhancement, embeddings, chatLead/contact info, document content, conversation contextUS
Deepgram (via Vapi)Speech-to-text transcriptionCall audio streamsUS
Microsoft (Azure / Graph API)Calendar integration (MS Outlook)Calendar tokens, meeting scheduling requestsConfigurable
Cal.com / CalendlyAlternative calendar integrationsCalendar API keys, scheduling requestsUS/EU
HubSpotCRM synchronization (optional)Lead name, email, phone, companyUS
MinIO / S3File and document storageUser profile pictures, knowledge base and case study filesConfigurable

We do not sell personal data to third parties. We do not use personal data for advertising or marketing profiling. We do not share data with third parties beyond those listed above.

6. International Data Transfers

Some of our sub-processors are located in the United States. When personal data is transferred from the European Economic Area (EEA), the UK, or Switzerland to the US, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs) — EU Commission-approved SCCs are in place with US sub-processors (Auth0/Okta, OpenAI, Vapi, Deepgram) where required.
  • EU-US Data Privacy Framework — Where sub-processors are certified under the EU-US Data Privacy Framework, we rely on that adequacy mechanism.
  • Brevo is an EU-based provider (headquartered in France) and does not require cross-border transfer safeguards for EU data.

You may request a copy of the applicable transfer safeguards by contacting privacy@dragonfl.ai.

7. Data Retention

Data CategoryRetention Period
User account dataUntil account deletion request or inactivity for 3 years
Session cookies8 hours (expire automatically)
Email verification tokens24 hours or until used
Lead / contact dataUntil deleted by organization admin or platform deletion
Call recordings & transcriptsUntil lead is deleted or on explicit request
AI research reports and notesUntil lead or organization is deleted
Chat conversation historyUntil deleted by user or organization deletion
Credit transaction logs7 years (financial records requirement)
Encrypted API & calendar credentialsUntil integration is disconnected or organization deleted

8. Security Measures

We implement the following technical and organizational measures to protect your data:

  • Encryption at rest: API keys, calendar credentials, and webhook headers are encrypted in the database using PostgreSQL pgcrypto with non-deterministic (random IV) encryption.
  • Encryption in transit: All communications use HTTPS/TLS. Secure and HttpOnly cookie flags are enforced.
  • Authentication: Auth0-managed authentication with email verification required. Session fingerprinting (user-agent + accept-language) to detect session hijacking.
  • CSRF protection: All state-changing requests validated with CSRF tokens using constant-time comparison.
  • Rate limiting: Login endpoint and API routes are rate-limited to prevent brute-force and abuse.
  • Role-based access control (RBAC): Fine-grained permissions ensure users can only access data within their organization scope.
  • Security headers: Content-Security-Policy, X-Frame-Options (DENY), X-Content-Type-Options, Referrer-Policy, and HSTS headers are applied in production.

9. Your Data Protection Rights

Depending on your location, you may have the following rights regarding your personal data:

Right of access (Art. 15 GDPR)

Request a copy of personal data we hold about you.

Right to rectification (Art. 16 GDPR)

Update your name, email, and phone via the Settings page. For other corrections, contact us.

Right to erasure / 'right to be forgotten' (Art. 17 GDPR)

Delete your account via Settings → Danger Zone. This permanently removes your user profile, session data, conversations, and notification settings from our systems and from Auth0.

Right to data portability (Art. 20 GDPR)

Request an export of your personal data in a machine-readable format by emailing us.

Right to restriction of processing (Art. 18 GDPR)

Request that we restrict processing of your data in certain circumstances.

Right to object (Art. 21 GDPR)

Object to processing based on legitimate interests. We will stop unless we have compelling legitimate grounds.

Right to withdraw consent

Where processing is based on consent, you may withdraw at any time without affecting prior processing.

CCPA rights (California residents)

Right to know, delete, opt-out of sale (we do not sell data), and non-discrimination. Submit requests to the email below.

To exercise any right, email privacy@dragonfl.ai. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, a member-state DPA in the EU).

10. Children's Privacy

The platform is intended for business use by adults. We do not knowingly collect personal data from individuals under the age of 16 (or the applicable age of digital consent in their jurisdiction). If you believe a minor has submitted data through our platform, contact us at privacy@dragonfl.ai and we will promptly delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page. For significant changes, we will notify active users by email or via an in-app notification before the changes take effect.

Continued use of the platform after the effective date of a revised policy constitutes your acceptance of the changes.

12. Contact Us

For any privacy-related questions, data subject requests, or to report a concern:

Dragonfl.ai – Privacy Team

Email: privacy@dragonfl.ai

© 2026 Dragonfl.ai. All rights reserved. Back to application