This policy explains what we collect about you as a Dragly customer, and how we handle the data you collect through Dragly.
Your name, work email, workspace details, billing information, and product telemetry — which screens you use and which features you run. We use it to operate your account, bill you, support you, and decide what to build next. We do not sell it.
Records you scrape or enrich are stored in your workspace and are yours. We process them on your instruction only. We do not use one customer's collected data to enrich another customer's results.
Raw scraped records are held for 24 months, enriched attributes for 36 months, then automatically purged. Suppression entries are kept indefinitely — that is what stops an erased person being re-collected. Audit records are retained for 7 years and cannot be edited or deleted.
You can request access, correction, export, or erasure of your personal data at any time. Write to privacy@dragly.io and we will respond within 30 days. Where you are the controller of collected data, we will help you meet the same obligations to your own subjects.
We use a small set of vendors for hosting, email delivery, and payments (Razorpay, PayPal, Stripe). Each is bound by a data-processing agreement. The current list is available on request and we give notice before adding a new one.
Data is encrypted in transit and at rest. Admin access is restricted by role, requires two-factor authentication, and every privileged action is written to an immutable audit log with a stated reason.
We host in the EU and the US. Where data moves between regions we rely on standard contractual clauses. You can request EU-only residency on Scale and Enterprise plans.
Questions, or want to reach our Data Protection Officer? privacy@dragly.io — we read every message.