GDPR & Data Processing
Last updated: July 17, 2026
This page gives individual users a practical route for exercising data-protection rights and gives Workspace customers a technical summary of Daaam’s current processing. It should be read with our Privacy Policy.
Your rights under GDPR
Subject to the conditions and exceptions in applicable law, you have:
- Access (Art. 15) — ask whether we process your personal data and request a copy
- Rectification (Art. 16) — correct profile information using available profile controls or ask us to correct it
- Erasure (Art. 17) — request deletion using the manual procedure below
- Restriction (Art. 18) — ask us to limit processing in specified circumstances
- Portability (Art. 20) — request personal data you provided in a structured, commonly used, machine-readable format where the right applies
- Objection (Art. 21) — object to processing based on legitimate interests or to direct marketing
- Withdrawal of consent (Art. 7(3)) — withdraw consent at any time where consent is the basis for processing
- Rights relating to automated decisions (Art. 22) — Daaam does not currently make decisions that produce legal or similarly significant effects based solely on automated processing
Send requests to [email protected] or our data-protection contact, Bruno Afonso. Electronic requests are accepted. We may request only the additional information reasonably needed to verify your identity and authority.
We respond without undue delay and normally within one month after receipt and any necessary verification. For a complex request or multiple requests, that period may be extended by up to two additional months; if so, we will explain the extension within the first month.
Account deletion procedure
Daaam does not currently provide a self-service account-deletion control. Account and Workspace deletion is a manual, verified request process:
- Send the request. Email [email protected] from the address associated with the account. State whether you want to delete only your user account, one or more Workspaces, your waitlist record, or all data within your authority.
- Verify the requester. We verify control of the account email and may ask for limited additional information if needed to prevent an unauthorised deletion.
- Resolve Workspace control. If you are the only owner of a Workspace, tell us whether the Workspace should be deleted or transferred to another verified owner. If the Workspace belongs to an organisation or has other owners, Workspace content normally remains under that controller’s control; we may need to coordinate with an authorised owner before deleting shared content.
- Remove the account. For an approved account request, we revoke active sessions and credentials and remove the Supabase Auth identity, profile, avatar reference, memberships, invitations, favourites, comments, and other user-specific records that can be deleted. We revoke or reassign user-created API credentials and integration configuration where needed to complete the deletion safely.
- Delete or detach Workspace data. For a Workspace approved for deletion, we remove its database records and media objects from live storage. For a retained shared Workspace, content uploaded for that Workspace may remain; user and audit references are detached, deleted, or anonymised where required so the remaining Workspace can continue without retaining unnecessary account-level personal data.
- Notify relevant providers. Where applicable to the request, we remove the waitlist contact from Loops and instruct service providers to delete processor-held data that is not removed through normal account or Workspace deletion.
- Confirm the result. We email the requester with what was deleted, what was retained, the reason for any retention, and the expected expiry of any remaining copy.
Moving an asset to Trash is not account deletion and does not currently start an automatic 30-day purge. An authorised Workspace user must permanently delete the asset, empty Trash, or include the Workspace in an approved deletion request.
Data that may remain after a request
- Data controlled by a retained organisation or shared Workspace may remain under that controller’s instructions.
- We may retain the minimum data required by binding law or needed to establish, exercise, or defend legal claims.
- Security or audit evidence may be retained where erasure would impair another person’s rights or an active investigation; unnecessary personal fields will be removed or restricted.
- Residual copies may remain temporarily in isolated provider backups until the applicable backup cycle expires. They are not used for ordinary service operations. If a backup is restored, completed deletion requests must be reapplied.
There is no current billing or tax record to preserve for the Service because Daaam does not accept payments. We do not promise a seven-day backup-erasure window because the current provider and operational backup schedules are not one consolidated seven-day cycle.
Service providers and international processing
The following table describes services wired into the current product. Suggested or planned providers are not included until their processing is active.
| Provider | Data and purpose | Location and first-party documentation |
|---|---|---|
| Supabase | Account/profile data, authentication, relational Workspace data, audit events, and Realtime | Primary Daaam project: EU West (Ireland). Regions · DPA |
| Backblaze B2 | Original media, generated renditions, and temporary download archives | Daaam production endpoint: EU Central. Data regions · EEA/EU DPA |
| Cloudflare | App/edge delivery, CDN cache, queues, DNS, rate limiting, request data, and transactional email | Global network. Customer DPA · Sub-processors |
| Modal | Media and ZIP processing, generated renditions, watermarking, and image-proxy delivery | Processing location depends on the active runtime configuration. DPA · Security and privacy |
| Loops (Astrodon Corp.) | Waitlist email collection and waitlist communications | Processing under Loops’ service infrastructure and sub-processors. Privacy Policy |
| DiceBear (Florian Körner) | Hosted fallback-avatar request containing a seed plus ordinary request metadata | DiceBear is based in Germany and uses hosting/CDN providers described in its Privacy Policy. |
| Automattic (Gravatar) | Landing-blog author avatar; receives a hash of Daaam’s author email and visitor request metadata | Privacy Policy |
The primary relational database and production object-storage endpoint are in EU regions. Cloudflare’s global edge, provider support systems and sub-processors, Modal, Loops, and customer-selected destinations may process data outside the EEA. Data sent to a webhook, WordPress site, API client, or share recipient selected by a customer goes to the location chosen by that customer.
Where an international transfer subject to GDPR requires a transfer mechanism, We Are Singular uses the mechanism applicable to that provider and transfer, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, together with supplementary measures where required. Contact our data-protection contact for the current provider and transfer details.
Customer-controlled disclosures
Workspace owners and authorised API-key holders can cause data to leave Daaam by:
- inviting members or granting access to folders and boards
- creating public, expiring, or password-protected share links
- registering a webhook that receives selected asset metadata
- connecting a WordPress site or another API client
- downloading or exporting files and metadata
These recipients are selected by the customer and are not Daaam sub-processors. The Workspace customer is responsible for configuring permissions, telling affected people about those disclosures, and assessing any transfer to the selected destination.
Breach notification
If a personal-data breach occurs, we will assess its scope and risk, contain and document it, and:
- Notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it when GDPR Art. 33 requires notification
- Notify affected people without undue delay when GDPR Art. 34 requires communication because the breach is likely to result in a high risk to their rights and freedoms
- Provide processor notifications to affected B2B customers as required by the applicable DPA
Data Processing Agreements
Workspace customers that need a DPA should contact [email protected]. The DPA must identify the customer’s role, processing instructions, data categories, security requirements, assistance with data-subject requests, deletion/return terms, and any applicable international-transfer mechanism.
Data-protection contact
The designated data-protection contact and project data officer for Daaam is:
Bruno Afonso — [email protected]
You may contact Bruno about this policy, provider processing, rights requests, or complaints. Operational requests can also be sent to [email protected].
Data Protection Impact Assessments
Before introducing processing likely to result in a high risk to individuals, we will assess whether a Data Protection Impact Assessment is required and complete it before that processing begins. The current Service does not perform automated individual decision-making, face recognition, or AI training on Workspace content.
Complaints
Our lead supervisory authority in Portugal is the CNPD (Comissão Nacional de Proteção de Dados). You may complain to the CNPD or, where applicable, to the supervisory authority in the EU/EEA country where you live or work. We encourage you to contact us first so we can investigate, but doing so does not limit your right to complain directly to an authority.