Privacy Policy

Last updated: 21 July 2026

1. Who we are (Data Controller)

DARIBA (“DARIBA”, “we”, “us”) operates the dariba.app service. For questions about this policy or to exercise your rights, contact us at privacy@dariba.app.

2. Scope

This policy explains how we process personal data when you create an account, complete a tax-structure assessment, purchase credits, or otherwise use DARIBA. It is designed to meet the requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection (nFADP), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and comparable US state privacy laws (VCDPA, CPA, CTDPA, UCPA), Brazil’s LGPD, Canada’s PIPEDA and the UAE PDPL, to the extent they apply.

3. Data we collect

  • Account data: email, hashed password, full name (optional), country (optional), authentication provider identifiers (Google/Apple).
  • Assessment data: answers you enter about tax residence, citizenship, income sources, activities, goals and other planning inputs.
  • Results & reports: generated scores, recommended structures, AI-generated summaries and PDF exports.
  • Billing data: credit purchases, transaction IDs, amounts and currency. Card details are handled directly by Stripe; we never see full card numbers.
  • Technical data: IP address, device/browser type, language, cookies and similar identifiers, and error/telemetry logs.
  • Communications: emails you send us and support conversations.
We do not intentionally collect special-category data (health, biometric, political opinions, etc.). Please do not submit such data in free-text fields.

4. Purposes and legal bases (GDPR Art. 6)

  • Provide the service (account, assessment, report generation) — performance of a contract.
  • Process payments and prevent fraud — contract and legitimate interests.
  • Security, logging and abuse prevention — legitimate interests and legal obligation.
  • Product analytics and improvement — legitimate interests (or consent where required).
  • Transactional emails (receipts, password resets) — contract.
  • Marketing emails — only with your consent; you can withdraw at any time.
  • Legal compliance — legal obligation.

5. Automated processing & AI

DARIBA uses automated scoring and large-language-model summaries to produce recommendations. Outputs are informational and educational only and are not a substitute for professional tax, legal or financial advice. No decision producing legal or similarly significant effects is made solely by automated means; you remain in control of any action you take on the results.

6. Sharing and processors

We share personal data only with vetted processors acting on our instructions:
  • Supabase — authentication, database and storage (EU region).
  • Stripe — payment processing.
  • Cloudflare — hosting, edge delivery and DDoS protection.
  • AI providers (via the Lovable AI Gateway) — generation of report summaries; prompts may be transmitted to the model provider for the sole purpose of returning a response and are not used to train third-party models.
  • Email delivery providers for transactional messages.
We do not sell personal data and do not “share” it for cross-context behavioural advertising as defined by the CCPA/CPRA.

7. International transfers

Where personal data is transferred outside the EEA/UK/Switzerland, we rely on adequacy decisions where available, and otherwise on the European Commission’s Standard Contractual Clauses (2021/914) together with appropriate supplementary measures.

8. Retention

Account and assessment data are retained for as long as your account is active and for up to 24 months after deletion for legal, accounting and dispute-resolution purposes. Billing records are retained for the period required by applicable tax law (typically up to 10 years). Server logs are retained for up to 90 days.

9. Your rights

Depending on your location you have the right to: access, rectify, erase, restrict or object to processing, data portability, and to withdraw consent at any time (GDPR/UK GDPR/FADP/LGPD). California and other US state residents have the right to know, delete, correct, limit use of sensitive data, and to opt out of sale/sharing and certain profiling — DARIBA does not sell or share personal data for cross-context behavioural advertising. To exercise any right, email privacy@dariba.app. You may also lodge a complaint with your local supervisory authority.

10. Cookies

We use strictly necessary cookies to keep you signed in and to secure the service. Optional analytics cookies, if enabled, are only set with your consent.

11. Security

Passwords are hashed, traffic is encrypted in transit (TLS), data is encrypted at rest, and access to production systems is restricted and logged. Row-Level Security is enforced on all user data tables.

12. Children

DARIBA is not directed to children under 16 and we do not knowingly collect their data.

13. Changes

We may update this policy; material changes will be notified in-app or by email. The “Last updated” date at the top reflects the current version.

14. Contact

Privacy contact: privacy@dariba.app.