Effective: August 1, 2026 | Last updated: August 1, 2026
support@dashapi.ai1. Scope and our role
This Privacy Policy explains how DashAPI, Inc. (a Delaware corporation) handles personal information in connection with the dashapi.ai website and the DashAPI platform (together, theService). LinkMe has its own policy — see theLinkMe Privacy Policy.
We act in two distinct roles, and the difference matters for your rights:
- As a controller — for information about our website visitors, prospects, account holders and billing contacts, and for how we secure, support and improve the Service. This policy describes that processing.
- As a processor — for the customer data an organisation puts into its DashAPI workspace, including data about that organisation's own customers, contacts and prospects. The organisation decides why and how that data is used; we act on its instructions under ourData Processing Addendum. If your data is in a customer's workspace, see clause 13.
We operate worldwide. We handle personal information in line with the EU and UK General Data Protection Regulation (GDPR), US federal and state privacy laws, and other privacy laws that apply to us.
2. Who we are and how to reach us
All privacy enquiries, rights requests and complaints are handled by email. We do not publish a postal address.
EU and UK enquiries. Individuals in the EEA and the UK may raise any matter relating to our processing of their personal data with us directly atsupport@dashapi.ai, and we will route it to our appointed representative where one is required.
3. Information we collect
3.1 Information you give us
- Account details — name, work email address, password credentials, job title, organisation name, and time zone.
- Organisation and team details — organisation name, workspace and team membership, roles and permissions.
- Billing details — billing contact, billing address for tax purposes, plan and invoice history. Card numbers go directly to our payment processor; we never receive or store them.
- Content you submit — records, documents, notes, tasks, messages, calendar and booking details, connector configurations, and anything else you put into your workspace.
- Support and sales correspondence — messages you send us, bug reports, feature requests, and lead forms including the pain points and context you choose to share.
3.2 Information we collect automatically
- Device and connection data — IP address, browser and device type, operating system, language.
- Usage and diagnostic data — pages and features used, session timing, requests to our API, error and performance logs.
- Marketing attribution — UTM parameters, referring page and campaign data captured when you arrive from a link or advert.
- Cookies and similar technologies — see clause 6 and our Cookie Policy.
3.3 Information from connected services
When you connect a third-party service — for example a Google or Microsoft calendar or mailbox, or a product connector — we receive data from it within the scopes you approve. This may include calendar events and availability, participant email addresses, message metadata and content, and records synced from other DashAPI products such as LinkMe. We use it only to provide the feature you enabled, and you can disconnect at any time.
3.4 Information from other sources
We may receive business contact information from data providers, public sources and partners — for example company, role and professional contact details — to keep records accurate, to qualify leads, and to power enrichment features you use. Where you use an enrichment feature, we send a limited identifier to a provider and receive matching records in return.
3.5 Data about other people
The Service is designed to hold information about your customers, prospects and contacts. Where you or your organisation put that information into a workspace, you are responsible for having a lawful basis to do so and for giving those individuals any required notice. We process it as a processor on your instructions.
3.6 What we do not want
Do not submit special-category data (such as health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade union membership or sexual orientation data), government identifiers, payment card numbers, or children's data to the Service unless a written agreement with us expressly covers it and you have met every additional legal requirement that applies.
4. How and why we use information
| Purpose | Examples | GDPR legal basis |
|---|---|---|
| Providing the Service | Creating and running accounts and workspaces, ingesting and normalising records, generating insights and reports, delivering bookings and notifications | Performance of a contract |
| Billing and administration | Processing subscriptions, invoicing, tax records, dunning | Performance of a contract; legal obligation |
| Support | Answering questions, investigating faults, restoring data | Performance of a contract; legitimate interests |
| Security and abuse prevention | Authentication, rate limiting, fraud detection, audit logging, incident investigation | Legitimate interests; legal obligation |
| Improving the Service | Aggregate and de-identified usage analysis, performance monitoring, prioritising features | Legitimate interests |
| Marketing and sales | Newsletters, product announcements, responding to lead forms, measuring campaigns | Consent where required; otherwise legitimate interests |
| Legal and compliance | Enforcing our terms, responding to lawful requests, establishing or defending legal claims | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have assessed that our interest in operating, securing and improving a business service does not override the rights and interests of the individuals concerned. You can object to that processing — see clause 11.
We do not sell personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under US state privacy laws.
5. AI processing
The Service uses third-party large language models to summarise, classify, extract, enrich and generate content, and to run agents you configure. When you use an AI feature, the content needed to answer the request — which may include personal information in your workspace — is sent to the model provider listed on our Sub-processors page.
- We contract with model providers on terms that prohibit training their models on your content.
- We do not use customer content to train our own general-purpose models.
- AI output is probabilistic and may be inaccurate. It should be reviewed before being relied on.
- We do not use AI to make decisions that produce legal or similarly significant effects about an individual without human involvement. If we ever introduce such processing, we will update this policy first.
8. International transfers
We operate worldwide and our infrastructure and sub-processors are primarily in the United States. Personal information may therefore be transferred to, stored in and processed in countries other than your own, including countries whose data protection laws differ from those of your jurisdiction.
Where we transfer personal data out of the EEA, the UK or Switzerland, we rely on appropriate safeguards, principally the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, and we carry out transfer risk assessments where required. You can request details of the safeguards that apply to a specific transfer by emailingsupport@dashapi.ai.
9. How long we keep information
| Category | Retention |
|---|---|
| Workspace content and customer records | For the life of the account. After termination, available for export for 30 days, then deleted from live systems; backup copies age out on our normal backup rotation. |
| Account and profile data | For the life of the account, then deleted within 90 days unless retention is required by law. |
| Billing and tax records | Up to 7 years, as required by tax and accounting law. |
| Security, audit and access logs | Typically 12 months, longer where needed for an open investigation. |
| Support and sales correspondence | Up to 3 years from the last interaction. |
| Marketing contact records | Until you unsubscribe or object, plus a suppression record so we do not contact you again. |
Where an organisation is our customer, it may set shorter retention periods for its workspace. We may keep aggregated, de-identified data indefinitely; it is no longer personal information.
10. Security
We use administrative, technical and physical safeguards appropriate to the risk, including encryption in transit and at rest, tenant scoping and role-based access control, least-privilege access for our staff, audit logging, and regular dependency and vulnerability scanning. OurSecurity Overview describes these in more detail and explains how to report a vulnerability.
No system is completely secure. We cannot guarantee absolute security, and you are responsible for protecting your credentials and API tokens and for configuring access in your organisation correctly.
11. Your rights
Depending on where you live, you may have the right to: access the personal information we hold about you; have it corrected; have it deleted; restrict or object to processing, including profiling and direct marketing; receive it in a portable, machine-readable format; and withdraw consent at any time without affecting processing already carried out.
To exercise a right, email support@dashapi.ai. We will verify your identity before acting, and respond within the time required by applicable law — within one month under the GDPR and UK GDPR, extendable by two further months for complex requests, and within 45 days under most US state laws, extendable once where permitted. We do not charge a fee unless a request is manifestly unfounded or excessive.
If your data sits in a customer's workspace, we will forward your request to that customer, who is the controller — see clause 13.
You may also complain to a supervisory authority. In the EEA that is the authority in your country of residence or work; in the UK it is the Information Commissioner's Office. We would appreciate the chance to address your concern first.
12. US state privacy rights
Residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia have rights under their state privacy laws. Not all states grant identical rights.
12.1 Categories we collect
| Category | Source | Purpose | Disclosed to |
|---|---|---|---|
| Identifiers — name, work email, phone, account ID, IP address | You; your organisation; connected services; data providers | Providing the Service, support, security, billing, marketing | Hosting, AI, analytics, payment and support sub-processors |
| Commercial information — plan, subscription and transaction history | You; payment processor | Billing, account management, tax records | Payment processor; accounting and tax advisers |
| Professional or employment information — job title, employer, role | You; your organisation; data providers | Providing the Service, enrichment, sales qualification | Hosting and AI sub-processors |
| Internet and network activity — feature usage, page views, API requests, logs | Automatic collection | Operating and improving the Service, security, analytics | Hosting, analytics and monitoring sub-processors |
| Geolocation — approximate location from IP address | Automatic collection | Security, fraud prevention, localisation | Hosting and security sub-processors |
| Content you submit — records, documents, notes, messages, calendar data | You; your organisation; connected services | Providing the Service on your instructions | Hosting, storage and AI sub-processors |
12.2 Sale, sharing, targeted advertising and profiling
We do not sell personal information, do not share it for cross-context behavioural advertising, and do not use it for profiling that produces legal or similarly significant effects. We therefore have no opt-out of sale or sharing to offer, but we honour Global Privacy Control and similar browser signals as an opt-out request on our website.
12.3 Sensitive personal information
We do not seek sensitive personal information, and we use any that reaches us only for the permitted purposes of providing the Service, security and legal compliance — never to infer characteristics. Because of that, we do not offer a "limit the use of my sensitive personal information" control.
12.4 Exercising your rights and appeals
Email support@dashapi.ai to make a request, including a request through an authorised agent — we may require written authorisation and verification of your identity. We will not discriminate against you for exercising a right. If we decline a request, residents of states that provide an appeal right (including Colorado, Connecticut, Delaware, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas and Virginia) may appeal by replying to our decision. We will respond to an appeal within 45 days, extendable by 60 days where reasonably necessary, and will tell you how to contact your state attorney general if you remain dissatisfied.
13. People whose data is in a customer workspace
You may appear in DashAPI without having an account — for example because a customer records you as a contact, books a meeting with you, or enriches a record about you.
In that case the customer is the controller of your data and we are its processor. If you ask us to access, correct or delete that data, we will forward your request to the relevant customer and support them in responding, but we cannot act on it independently. Where you tell us who the organisation is, we will confirm that we have passed it on.
Enrichment opt-out. If you do not want us to enrich records about you from third-party data providers, email support@dashapi.ai with the email address or domain to suppress. We will stop enriching your information and keep the minimum identifier needed to honour the suppression, used for no other purpose. Opting out with us does not remove your information from the third-party providers themselves, who are independent controllers — contact them directly as well.
14. Children's privacy
The Service is a business tool intended for people aged 18 and over. We do not knowingly collect personal information from children. If you believe a child's information has reached us, emailsupport@dashapi.ai and we will delete it.
15. Marketing communications
We may send product news, research and offers where you have opted in or where we have a legitimate interest in contacting you in a business capacity and local law permits it. Every marketing email has an unsubscribe link, and you can also email support@dashapi.ai. Opting out of marketing does not stop transactional messages about your account, billing, security or the operation of the Service.
16. Data breach notification
If we become aware of a personal data breach, we will investigate, contain it, and assess the risk. Where required by law we will notify the relevant supervisory authority — within 72 hours under the GDPR and UK GDPR where feasible — and notify affected individuals or customers without undue delay where the breach is likely to result in a high risk to them. Where we act as a processor, we will notify the affected customer without undue delay so it can meet its own obligations.
17. Changes to this policy
We may update this policy to reflect changes in our practices, technology or legal obligations. We will post the updated policy with a new "last updated" date, and for material changes we will notify account holders by email or in-product notice before the change takes effect. We will not use personal information we already hold in a materially different way without a lawful basis to do so.
18. Complaints and contact
For any question, request or complaint about privacy, contact us. We aim to acknowledge within 5 business days and to resolve complaints within 30 days, telling you if we need longer.
Other legal documents
- Terms of ServiceThe contract for using the DashAPI platform.
- Acceptable Use PolicyWhat you may and may not do with the platform.
- Data Processing AddendumGDPR/UK GDPR terms for customer personal data.
- Sub-processorsThird parties that process data on our behalf.
- Security OverviewHow we protect data, and how to report a flaw.
- Cookie PolicyCookies and similar technologies on our sites.
- Website Terms of UseRules for browsing dashapi.ai itself.