Privacy Policy
Last updated: July 17, 2026
We Are Singular, Lda, incorporated in Portugal (NIPC: PT513858512), operates Daaam. Contact us at [email protected]. Our designated project data-protection contact is Bruno Afonso at [email protected].
This policy describes the Service as it operates today. We will update it before introducing materially different processing, including payment processing, product analytics, or a new monitoring provider.
When Daaam is a controller or processor
We Are Singular is the controller for the account, profile, waitlist, security, and operational data that we decide how to use to operate Daaam.
For files, metadata, comments, and other personal data that a customer places in a Workspace, We Are Singular generally acts as a processor on the Workspace customer’s instructions. The customer or organisation that controls the Workspace is responsible for having a lawful basis to upload, organise, share, and otherwise use that data. If you use Daaam on behalf of an organisation, that organisation may be the controller of your Workspace activity and content.
For a Data Processing Agreement, contact [email protected].
Data we process
Website and waitlist data
- Waitlist email: The landing-page waitlist sends the email address you submit directly to Loops so we can manage the waitlist and related communications.
- Waitlist rate-limit timestamp: The landing page stores a timestamp in your browser under
loops-waitlist-last-submit-at. It does not contain your email address and is used only to prevent repeat submissions within one minute. - Basic request data: Our hosting and edge providers receive network and request information needed to deliver and protect the site, such as IP address, browser information, requested URL, time, and response status.
Account, profile, and authentication data
- Email address, user and session identifiers, display name, job title, profile-image URL, and fallback-avatar seed
- Password and session operations handled by Supabase Auth; Daaam does not store your plaintext password
- Workspace memberships, roles, permissions, invitations, API-key metadata, and registered webhook configuration
Workspace content and metadata
- Uploaded images, videos, documents, edits, watermarks, and generated renditions
- Filenames, descriptions, alternative text, folders, boards, tags, workflow states, comments, favourites, and share-link configuration
- Technical file information such as MIME type, size, dimensions, colour data, and processing state
- Embedded EXIF, IPTC, XMP, document, image, and video metadata. Depending on the source file, this may contain names, copyright details, dates, camera or software information, and location data
- ZIP job information and the temporary archives generated for requested downloads
You are responsible for reviewing source-file metadata and for having permission to upload personal data relating to other people.
Activity, security, and support data
- Workspace audit events, including the acting user, action, affected resource identifiers, event details, IP address, user agent, and time
- Request logs, including method, path, status, duration, user identifier, and Workspace identifier
- Upload, queue, processing, delivery, and error information needed to operate and troubleshoot the Service
- Messages and files you choose to provide when requesting support
Workspace owners and admins can access Workspace audit information, including recorded IP addresses.
Avatar-request data
Daaam currently uses the hosted DiceBear API to render fallback avatars. The URL seed may be based on a user’s name, email address, or user identifier. When an avatar is loaded, DiceBear and its delivery providers receive that seed in the request URL together with ordinary network data such as the requesting IP address and browser headers.
The landing-page blog uses Gravatar for Daaam author avatars. The browser request contains a one-way SHA-256 hash of the Daaam author’s email address, not the visitor’s email address. Automattic and its delivery providers still receive ordinary request data such as the visitor’s IP address and browser headers.
Billing and analytics data
Daaam does not currently offer paid plans, accept payments, use a billing provider, run product analytics, or use a separate infrastructure-monitoring service. We therefore do not currently collect payment-card or billing data for the Service. If billing, analytics, or monitoring is introduced, we will update this policy and the Terms before that processing begins.
Why we process data
| Purpose | Typical GDPR basis |
|---|---|
| Create accounts; authenticate users; provide Workspaces and features | Performance of a contract (Art. 6(1)(b)) |
| Store, transform, organise, search, and deliver Workspace content | Customer instructions; contract (Art. 6(1)(b)) |
| Send invitations, security notices, and other service messages | Contract and legitimate interests (Art. 6(1)(b), Art. 6(1)(f)) |
| Operate logs, audit trails, abuse controls, and service recovery | Legitimate interests in security and reliability (Art. 6(1)(f)) |
| Manage the waitlist and optional waitlist communications | Consent (Art. 6(1)(a)); you may withdraw it at any time |
| Respond to rights requests, binding orders, and other legal obligations | Legal obligation (Art. 6(1)(c)); legal claims where applicable |
We do not rely on a billing or tax-retention purpose today because the Service does not currently process payments.
How we use Workspace content
- Service delivery only: We process content to store, transform, organise, search, watermark, preview, share, and deliver it, and to secure and support those operations.
- No AI training: We do not use Workspace content to train our own or another party’s artificial-intelligence or machine-learning models.
- No sale: We do not sell or monetise Workspace content or its metadata.
- Automated processing: Normal media transformations are automated. Authorised personnel may access content only where reasonably necessary for support requested by a customer, security or incident response, service recovery, or a binding legal obligation.
- Provider access: The infrastructure providers listed below process content only as needed to provide their part of the Service, subject to their applicable terms.
Sharing and disclosures
We disclose data only in these situations:
- To other members of the Workspace according to the Workspace’s roles and permissions
- To people who receive a share link, including a public or password-protected share
- To the infrastructure and communications providers listed below
- To a webhook endpoint, WordPress site, API client, or other integration that a Workspace owner or authorised API-key holder configures
- To professional advisers, authorities, or another party where required by binding law or reasonably necessary to establish, exercise, or defend legal claims
- As part of a corporate transaction, with appropriate confidentiality and notice where required
Customer-configured webhook endpoints, WordPress sites, API clients, and share recipients are not Daaam sub-processors. They are recipients selected by the customer. A webhook may receive asset and folder identifiers, version identifiers, name, alternative text, description, and tags. Customers are responsible for the destination, its security, and its own privacy terms.
Current service providers
| Provider | Current purpose | Processing notes |
|---|---|---|
| Supabase | PostgreSQL database, authentication, and Realtime | Primary project region is EU West (Ireland); provider support and sub-processing may be elsewhere |
| Backblaze B2 | Original files, generated media, and temporary download storage | Production object-storage endpoint is in Backblaze’s EU Central region |
| Cloudflare | Application and edge delivery, CDN/cache, queues, DNS, rate limiting, and email | Operates a global network and may process request, cache, queue, and email data internationally |
| Modal | Media transformation, image delivery, watermarking, and ZIP processing | Receives files, file metadata, storage credentials, and job identifiers needed for processing |
| Loops (Astrodon Corp.) | Landing-page waitlist collection and waitlist communications | Receives the email address submitted to the waitlist |
| DiceBear (Florian Körner) | Hosted fallback-avatar rendering | Receives the avatar seed in the URL and ordinary request metadata |
| Automattic (Gravatar) | Landing-blog author avatars | Receives a hash of Daaam’s author email and ordinary visitor request metadata |
See GDPR & Data Processing for first-party provider documentation and international-processing details.
Storage delivery and security boundaries
We use HTTPS for application, API, upload, processing, and delivery traffic. We apply role-based access controls, Workspace-scoped database access, signed upload operations, restricted infrastructure credentials, and credential redaction in application logs.
The current production object-storage bucket supports public reads so media can be delivered through Daaam’s proxy and CDN. Object keys are designed to be difficult to guess, but a person who obtains a valid direct object URL may be able to retrieve that object without the Daaam Workspace permission check. A copied direct object URL should therefore be treated as a bearer link, not as an access-control boundary. Share links can also be forwarded by their recipients. Use share passwords and expiry controls where appropriate, and do not upload material whose risk profile requires end-to-end encryption or a private object-store access guarantee that Daaam does not currently provide.
No online service can guarantee absolute security. Contact [email protected] if you believe data or credentials have been exposed.
Retention
- Account and profile data: Retained while the account is active and then handled through the manual deletion procedure described on our GDPR page
- Workspace data and content: Retained while the Workspace exists. Moving an asset to Trash hides it but does not start an automatic 30-day deletion; it remains until an authorised user restores or permanently deletes it
- Abandoned uploads and temporary jobs: Incomplete upload reservations and generated download jobs are subject to operational cleanup. A completed ZIP download is offered for 24 hours; related temporary records and files may remain briefly while cleanup and provider lifecycle rules run
- Workspace audit data: Retained with the Workspace. If an account is removed from a shared Workspace, the event may remain for accountability, but we will remove or anonymise personal fields where required by an approved deletion request
- Authentication data: Access and refresh sessions have configured lifetimes of up to 7 and 30 days respectively, and may end earlier on sign-out, revocation, or account deletion
- Waitlist data: Retained until you unsubscribe, request deletion, or the waitlist purpose ends, subject to limited provider, legal, and suppression records
- Operational logs: Retained for the period reasonably needed for security, reliability, troubleshooting, and legal claims. We do not currently publish a single fixed retention period because the period depends on the log and hosting system
- Backups: Deletion is applied to live systems first. Residual provider backup copies, if present, remain isolated from normal use until the applicable provider or operational backup cycle expires. If a backup is restored, completed deletion requests must be reapplied
- Billing and tax records: None are created by the current Service. If payment processing is introduced, the applicable records and retention periods will be disclosed before billing begins
International processing
The primary Supabase database is configured in Ireland and the production Backblaze object-storage endpoint is in the EU Central region. That does not mean every processing operation stays in the EEA. Cloudflare operates a global edge network, and Modal, Loops, provider support systems, provider sub-processors, avatar delivery infrastructure, and customer-selected integrations may process data in other jurisdictions.
Where GDPR rules apply to an international transfer for which We Are Singular is responsible, we use an applicable transfer mechanism and supplementary measures where required. Provider locations and sub-processors can change; contact our data-protection contact for the current contractual details. A customer that selects an external webhook, WordPress/API destination, or share recipient is responsible for the transfer it instructs us to make.
Your rights
Subject to the conditions and exceptions in applicable law, you may request access, rectification, erasure, restriction, portability, or objection, and may withdraw consent. These rights apply to all our users where doing so is practical, even when the GDPR does not directly apply.
Email [email protected] or contact Bruno Afonso. We normally respond within one month after receiving and, where necessary, verifying a request. See our GDPR page for the complete request and deletion procedure.
Law-enforcement and illegal-content requests
We may preserve or disclose data where required by binding Portuguese or EU law, a valid court order, or another lawful request from a competent authority. We review requests and limit disclosure to data we hold that is legally required.
If we become aware of apparently illegal or seriously harmful content, we may restrict access, preserve relevant evidence, and report it where required or permitted by applicable law. This statement does not claim that Daaam currently performs general automated content scanning.
Supervisory authority
You may lodge a complaint with the CNPD (Comissão Nacional de Proteção de Dados) or, where applicable, the data protection authority in your EU/EEA country of residence or work.
Cookies and browser storage
We use strictly necessary authentication and protected-share cookies and a waitlist rate-limit timestamp in browser storage. We do not currently use product-analytics, advertising, or behavioural-tracking cookies. See our Cookie Policy.
Children
Daaam is not directed at individuals under 16, and accounts may not be created by anyone under 16. Contact us if you believe a child has provided personal data contrary to this policy.
Changes to this policy
We will update the date at the top when this policy changes. Where a change materially affects how we process personal data, we will provide any advance notice or renewed choice required by applicable law before the change takes effect.