Dayalogs
Product How it works Pricing Researchers Docs Blog
Sign in Register
Product How it works Pricing Researchers Docs Blog Sign in Register

Privacy Policy

What we collect, why we collect it, and what rights you have over it.

Privacy Terms Cookies

Last updated: 17 June 2026

1. WHO WE ARE

Sergio Peña Tapia, empresario individual (autónomo) ("Dayalogs", "we", "us", "our"), operates the Dayalogs survey platform available at dayalogs.com.

Registered address: Passeig de Manuel Girona 48, 6è 4a, 08034 Barcelona, Spain NIF: 46240767A Data protection contact: privacy@dayalogs.com

2. TWO ROLES, TWO RESPONSIBILITIES

Dayalogs operates in two distinct capacities depending on whose data is involved.

2.1 Controller — your account and team data

When you create an account, manage a subscription, or contact us for support, Dayalogs is the data controller. We decide why and how your personal data is processed. This section of the policy primarily covers this role.

2.2 Processor — your respondents' data

When you use Dayalogs to distribute surveys and collect responses from your own audience, Dayalogs acts as a data processor on your behalf. You are the data controller for respondent data. We process it only according to your instructions and our Data Processing Agreement (DPA), which is incorporated into the Terms of Service for all paid plans. If you need a signed DPA, contact privacy@dayalogs.com.

3. DATA WE COLLECT (CONTROLLER)

3.1 Account and identity data

When you register or manage your account:

  • Name and email address
  • Organisation name (optional)
  • Password (stored as a hash — we never see the plaintext)
  • Profile photo (if uploaded)

3.2 Billing and payment data

When you activate a subscription or top up your wallet:

  • Plan selection and billing history
  • Wallet balance and transaction log
  • Payment is processed by [PLACEHOLDER: Stripe]. We receive a payment token and last-four digits only — we do not store full card numbers.

3.3 Usage and product data

When you use the platform:

  • Surveys created, published, and archived
  • Audience lists and campaign activity
  • API keys and MCP connection events
  • Feature usage, page visits, and session metadata
  • Error logs and performance diagnostics

3.4 Support and communications

If you contact us:

  • Email content and correspondence history
  • Feedback submitted through the product

3.5 Cookies and similar technologies

See the [Cookie Policy](legal-cookies.md) for full detail.

4. HOW WE USE YOUR DATA AND ON WHAT BASIS

PurposeData usedLegal basis
Providing the service (account, platform, API)Account, usageContract performance
Billing and subscription managementBilling, accountContract performance
Security and fraud preventionAccount, usage, logsLegitimate interests
Product improvement and analyticsUsage (aggregated or pseudonymised)Legitimate interests
Transactional emails (password reset, invoices, alerts)Account, billingContract performance
Marketing and product newsEmailConsent (you can unsubscribe at any time)
Legal obligations (tax records, court orders)Billing, accountLegal obligation

We do not sell your data. We do not use your data for automated profiling that produces legal or similarly significant effects.

5. WHO WE SHARE DATA WITH

We share data only with the following categories of recipients. All subprocessors are bound by data processing agreements.

RecipientPurposeLocation
[PLACEHOLDER: Stripe]Payment processing[PLACEHOLDER: US/EU]
[PLACEHOLDER: email provider, e.g. SendGrid]Transactional email[PLACEHOLDER]
[PLACEHOLDER: hosting/infrastructure, e.g. Hetzner/AWS]Platform hosting and storage[PLACEHOLDER: EU]
[PLACEHOLDER: analytics, e.g. Plausible]Product analytics[PLACEHOLDER: EU]
[PLACEHOLDER: error tracking, e.g. Sentry]Error monitoring[PLACEHOLDER]

We do not share data with advertisers or data brokers.

If we are required to disclose data by law, regulation, or a valid legal process, we will notify you unless legally prohibited from doing so.

6. INTERNATIONAL DATA TRANSFERS

If any subprocessor is located outside the European Economic Area (EEA), transfers are covered by Standard Contractual Clauses (SCCs) approved by the European Commission, or by an adequacy decision. Contact us for a copy of the applicable transfer mechanism.

7. DATA RETENTION

CategoryRetention
Account dataUntil account deletion + 30 days
Billing records and invoices7 years (legal obligation)
Survey and response dataUntil you delete it or your account is closed
Support correspondence3 years from last contact
Server and access logs90 days rolling

When retention expires or you delete your account, we anonymise or delete the relevant data within 30 days unless a longer retention period is required by law.

8. YOUR RIGHTS

Under the GDPR you have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you
  • Rectification — ask us to correct inaccurate or incomplete data
  • Erasure — ask us to delete your data in certain circumstances ("right to be forgotten")
  • Restriction — ask us to pause processing while a dispute is resolved
  • Portability — receive your data in a machine-readable format
  • Object — object to processing based on legitimate interests or for direct marketing
  • Withdraw consent — for any processing based on consent (e.g. marketing emails), you can withdraw at any time without affecting the lawfulness of prior processing

To exercise any right, email privacy@dayalogs.com. We will respond within one month. In complex or high-volume cases we may extend this by two further months with notice.

If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your national supervisory authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD) at aepd.es.

9. SECURITY

We apply technical and organisational measures appropriate to the risk, including:

  • HTTPS/TLS in transit
  • Encryption at rest for sensitive fields
  • Access controls and least-privilege principles
  • Regular security reviews

No system is completely secure. If you believe you have found a security vulnerability, report it to security@dayalogs.com and we will respond promptly.

10. CHILDREN

Dayalogs is a B2B product intended for use by organisations and professionals. We do not knowingly collect personal data from individuals under 16. If you believe a minor has provided us with personal data, contact us and we will delete it.

11. CHANGES TO THIS POLICY

If we make material changes, we will notify you by email and update the "Last updated" date above. Continued use of the service after the effective date constitutes acceptance.

12. CONTACT

Data protection enquiries: privacy@dayalogs.com General: hello@dayalogs.com Post: Sergio Peña Tapia, Passeig de Manuel Girona 48, 6è 4a, 08034 Barcelona, Spain

Dayalogs

Research, conversational again.

Legal
  • Terms of Use
  • Privacy Policy
  • Cookies Policy
  • Cookie preferences
Support
  • Blog
  • Documentation
  • Research Collaboration Program
  • Contact us

Payments powered by Stripe

© 2026 Dayalogs. All rights reserved.

Cookies

We use essential cookies to keep Dayalogs working. If you accept analytics, we can better understand which tools and workflows matter most and improve the product accordingly. Cookie Policy.