Dobuli legal
Privacy Policy
This notice explains how Dobuli handles personal data when people use the service or contact us.
Effective date: 13 August 2026
About this notice
This Privacy Policy describes how the company operating Dobuli collects and uses personal data through its website, account area, website-building tools, support channels, and related services. It is written for Dobuli account holders, prospective users, website visitors, and people who communicate with us.
Dobuli has not launched publicly. This notice is a working draft and must be updated to match the final company identity, service providers, data locations, retention schedule, cookies, and product behaviour before production use.
Who controls your personal data
For account administration, service operation, billing, security, product communications, and our own website, the intended data controller is:
- Controller
- [Legal entity name]
- Registry code
- [Registry code]
- Address
- [Registered address]
- Privacy contact
- [Privacy email]
When a Dobuli customer uses the service to collect personal data from visitors to their own website—for example through a contact or booking feature—the customer is normally the controller and Dobuli is normally its processor. In that situation, contact the website owner first about the processing. Processor terms and a data processing agreement will be confirmed before those features are offered.
Personal data we collect
- Account and identity data: name, email address, authentication method, account identifiers, and profile details.
- Organisation data: business name, role, team membership, permissions, and workspace settings where enabled.
- Content and instructions: prompts, website briefs, uploaded files, generated or edited content, site configuration, domain settings, and publishing history.
- Website-visitor data: form, booking, analytics, or communication data a customer asks Dobuli to process where those features are enabled.
- Usage and device data: IP address, browser and device information, timestamps, pages and features used, diagnostic events, security logs, and cookie or local-storage identifiers.
- Communication data: support requests, feedback, survey responses, and other messages you send us.
- Transaction data: plan, invoice, tax, billing-status, and limited payment details if paid services are offered. Full card details would normally be handled by the selected payment provider.
We collect this data from you, your organisation, your device, the features you use, and service providers acting for us. If you connect a third-party service, we receive the data that you authorise that service to share.
How and why we use personal data
| Purpose | Typical data | Legal basis |
|---|---|---|
| Create accounts and provide requested features | Account, organisation, content, and usage data | Performance of a contract or steps requested before a contract |
| Secure Dobuli and prevent misuse | Account, device, usage, and security-log data | Legitimate interests and, where relevant, legal obligations |
| Provide support and service messages | Account, communication, and diagnostic data | Contract and legitimate interests |
| Operate billing where paid plans are offered | Account and transaction data | Contract and legal obligations |
| Improve and understand the service | Usage, feedback, and aggregated data | Legitimate interests or consent where required |
| Send optional marketing | Contact details and communication preferences | Consent or another basis permitted by applicable law |
| Meet legal duties and defend legal claims | Relevant account, transaction, content, and log data | Legal obligations and legitimate interests |
Where we rely on legitimate interests, we assess the need for the processing, its impact on people, and safeguards. Where consent is the basis, you may withdraw it at any time without affecting processing that happened before withdrawal.
AI and automated processing
Where AI features are enabled, Dobuli may send prompts, source content, and necessary technical context to selected AI providers to generate or transform content. The final policy must identify those providers, their locations and retention practices, and whether inputs or outputs may be used to improve models. [AI provider and training-use details to be confirmed]
Do not include sensitive or unnecessary personal data in prompts or uploads. Dobuli does not intend to make decisions that produce legal or similarly significant effects about you solely through automated processing. If that changes, we will provide the information, safeguards, and human-review options required by law before the feature is used.
Cookies and local storage
Dobuli may use cookies or browser storage that are necessary for authentication, security, preferences, and preserving a website brief between steps. Optional analytics, advertising, or similar technologies will be used only with the notice and choice required in the relevant location. A final cookie list, purposes, providers, and lifetimes must be added before launch. [Cookie inventory and consent configuration to be confirmed]
Sharing and international transfers
We may disclose personal data only as needed to:
- hosting, infrastructure, authentication, email, support, analytics, payment, and AI providers acting for us;
- members and administrators of your organisation, according to their permissions;
- professional advisers, auditors, insurers, and transaction counterparties under appropriate confidentiality duties;
- authorities or other parties when required by law or necessary to protect rights and safety; and
- a successor in a merger, acquisition, financing, or sale, subject to lawful safeguards.
Some providers may process data outside the European Economic Area. Before launch, Dobuli must confirm data locations and, where required, use an adequacy decision, standard contractual clauses, or another lawful transfer mechanism together with supplementary safeguards. [Subprocessor list and transfer mechanisms to be confirmed]
We do not sell personal data.
Retention and deletion
We keep personal data only for as long as needed for the purposes above, taking account of your account status, contractual needs, security, disputes, and legal record-keeping duties. Dobuli's final retention schedule must be implemented and published before launch.
- Account records
- [Account retention period to be confirmed]
- Website content
- [Site content and export period to be confirmed]
- Security logs
- [Security-log retention period to be confirmed]
- Support records
- [Support-record retention period to be confirmed]
- Backups
- [Backup deletion cycle to be confirmed]
Data may remain longer where law requires it, a dispute must be resolved, or deletion from a secured backup occurs on the next scheduled cycle. Where possible, we anonymise data that is no longer needed in identifiable form.
Security
We use technical and organisational measures intended to protect personal data against unauthorised access, loss, alteration, or disclosure. No online service can guarantee absolute security. Before launch, Dobuli must complete its access-control, incident-response, backup, vendor-review, and breach-notification procedures.
Your privacy rights
Subject to applicable law, you may have the right to:
- obtain information about processing and a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion or restriction of processing;
- receive portable data you provided to us;
- object to processing based on legitimate interests or direct marketing;
- withdraw consent at any time where processing relies on consent; and
- complain to the Estonian Data Protection Inspectorate or another competent supervisory authority.
Send a request to [Privacy email]. We may need to verify your identity and clarify the request. If your request concerns data controlled by a Dobuli customer through its website, contact that customer; we will assist it where required by our processor obligations.
Organisation administrators
If an organisation gives you access to Dobuli, its administrators may manage your account, view or export organisation content, control permissions, and receive information about your use of that workspace. Your organisation is responsible for explaining its own processing to you.
Children
Dobuli is not intended for children to use independently. We do not knowingly seek personal data from a child who cannot lawfully consent or contract without a parent or guardian. If you believe a child has provided data improperly, contact us so we can investigate and take appropriate action.
Changes to this policy
We may update this policy when Dobuli, our providers, or legal requirements change. We will publish the new version and effective date. If a change materially affects how we use personal data, we will provide any additional notice or choice required by law.
Contact
For questions, rights requests, or privacy complaints, contact:
- Controller
- [Legal entity name]
- [Privacy email]
- Address
- [Registered address]
- Data protection officer
- [DPO contact, if appointed]