Privacy Policy
Last updated: February 15, 2026
This Privacy Policy describes how Delphi ("Delphi", "we", "us", or "our") collects, uses, and discloses information when you use our platform and services ("Services"). This policy applies to our enterprise customers ("Customers") and users of our website.
1. Information We Collect
1.1 Customer Data
When Customers use our Services, they may submit documents, text, and other content for analysis ("Customer Data"). Customer Data is processed solely to provide the Services and is governed by our Terms of Service and any applicable Data Processing Agreement.
1.2 Account Information
We collect information provided during account creation and administration, including names, email addresses, job titles, and organization details.
1.3 Usage Information
We automatically collect information about how the Services are accessed and used, including log data, device information, and feature usage patterns. This information is used to operate, maintain, and improve the Services.
1.4 Website Visitors
When you visit our website, we may collect information such as IP address, browser type, referring URL, and pages viewed. We use this information to analyze trends and administer the website.
2. How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the Services
- Process and complete transactions
- Send administrative communications
- Respond to inquiries and provide customer support
- Monitor and analyze usage patterns to improve the Services
- Detect, prevent, and address security issues
- Comply with legal obligations
We do not use Customer Data to train machine learning or AI models.
3. How We Share Information
We do not sell personal information. We may share information in the following circumstances:
3.1 Service Providers
We engage third-party service providers to perform functions on our behalf, such as hosting, analytics, and customer support. These providers are contractually obligated to use information only as necessary to provide services to us. A list of our subprocessors is available on our Security page.
3.2 AI Model Providers
To provide the Services, Customer Data may be processed by third-party AI model providers. These providers are bound by contractual obligations regarding data protection and are prohibited from using Customer Data to train their models.
3.3 Legal Requirements
We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Delphi, our Customers, or others.
3.4 Business Transfers
In connection with a merger, acquisition, or sale of assets, information may be transferred to the acquiring entity.
4. Data Retention
We retain Customer Data for the duration of the Customer's subscription and for thirty (30) days thereafter to allow for data export. After this period, Customer Data is deleted in accordance with our data retention procedures.
Account information and usage data may be retained for longer periods as necessary to comply with legal obligations, resolve disputes, and enforce agreements.
5. Data Security
We implement appropriate technical and organizational measures to protect information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data at rest (AES-256) and in transit (TLS 1.3)
- Isolated tenant environments
- Access controls and authentication
- Regular security assessments and penetration testing
- Employee security training
For more information, see our Security page.
6. Data Residency and International Transfers
Customer Data is stored and processed within the GCC region. We do not transfer Customer Data outside of the designated region without Customer consent.
For website visitors and account information, data may be processed in jurisdictions where our service providers operate. Where required, we implement appropriate safeguards for international data transfers.
7. Your Rights
Depending on your jurisdiction, you may have certain rights regarding your personal information, including:
- Access to personal information we hold about you
- Correction of inaccurate or incomplete information
- Deletion of personal information
- Restriction of processing
- Data portability
- Objection to processing
For enterprise Customers, requests related to Customer Data should be directed to your organization's administrator. Individual data subject requests can be submitted to privacy@askdelphi.io.
8. PDPL Compliance
For individuals in the United Arab Emirates, we process personal data in compliance with the UAE Personal Data Protection Law (PDPL). This includes:
- Processing data only for specified, legitimate purposes
- Maintaining transparency about data processing activities
- Implementing appropriate security measures
- Respecting data subject rights
- Storing data within the UAE/GCC as required
9. Cookies and Tracking
Our website uses cookies and similar technologies to operate and improve the site. We use:
- Essential cookies required for site functionality
- Analytics cookies to understand how visitors use our site
You can control cookies through your browser settings. Disabling certain cookies may affect site functionality.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify Customers of material changes by email or through the Services. Continued use of the Services after changes become effective constitutes acceptance of the revised policy.
11. Data Processing Agreement
Enterprise Customers may request a Data Processing Agreement (DPA) that governs our processing of Customer Data. To request a DPA or for questions about data processing, contact legal@askdelphi.io.
Contact
For questions about this Privacy Policy or our data practices, contact us at:
Delphi
United Arab Emirates