Privacy Policy
Effective date: August 26, 2025
This Privacy Policy explains how PromptSignal (operated by Dynamiq, “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you visit our websites, use our web app, or otherwise interact with our services (collectively, the Service). Our registered address is 1111B S Governors Ave STE 6798, Dover, DE 19904 US. For privacy questions, contact legal@dynamiq.ai.
PromptSignal is a B2B analytics platform. We provide tools that help organizations measure brand visibility, mentions, sentiment, and related metrics across LLM outputs and other sources. This policy is written to be clear and concise so you can quickly understand our practices.
1) Who is responsible for your data
- For website, marketing, and account data, Dynamiq acts as the data controller.
- For Customer Data that organizations upload or connect to the Service (e.g., prompts, outputs, datasets, identifiers, files), Dynamiq acts as a data processor under a separate Data Processing Addendum (DPA) available on request. In those cases, your organization is the controller.
2) What we collect
We collect the following categories of information:
- Account & Business Contact Data – name, work email, organization, role, authentication identifiers (e.g., magic link tokens, API keys), plan and billing metadata.
- Product & Usage Data – app interactions, configuration choices, feature usage, timestamps, diagnostic events, crash reports, and limited log data such as IP address, device/browser type, and referrer. We use this to operate, secure, and improve the Service.
- Customer Data (workspace content) – data you or your organization provide or connect (e.g., prompts, LLM outputs/results, brand/competitor lists, files, knowledge sources). This data may incidentally include personal data if you choose to submit it. You control what is uploaded.
- Support & Communications – messages you send us (support tickets, feedback, surveys), and related contact details.
- Cookies & Similar Technologies – essential cookies for sign‑in and security; optional analytics cookies with your consent where required. See Section 8.
We do not intentionally collect sensitive categories of personal data unless you provide them. The Service is for business users and is not directed to children (see Section 13).
3) Sources of information
- Directly from you or your organization (account creation, workspace setup, support requests).
- Automatically from your use of the Service (logs, telemetry, and analytics as described above).
- From integrated third‑party services you connect (e.g., data sources, storage, single sign‑on), strictly per your instructions.
- Publicly available sources or third‑party providers to help us enrich business contact records for B2B outreach where permitted by law.
4) How we use information (purposes & legal bases)
We use personal information to:
- Provide and secure the Service (create and manage accounts, authenticate users, prevent abuse, monitor availability and performance). Legal bases: contract performance; legitimate interests.
- Operate features (process Customer Data per your instructions, compute metrics, surface analytics and reports). Legal bases: contract performance; legitimate interests.
- Support and communicate (respond to inquiries, provide updates, send transactional emails). Legal bases: contract performance; legitimate interests.
- Improve and develop (debug, research, and enhance features; quality assurance; safety and security testing). Legal bases: legitimate interests.
- Marketing (B2B) (send product news or invites where permitted; you can opt out). Legal bases: consent where required; otherwise legitimate interests.
- Compliance (detect and prevent fraud or misuse, comply with legal obligations, enforce terms). Legal bases: legal obligations; legitimate interests.
Where we rely on consent (e.g., non‑essential cookies), you can withdraw consent at any time via our cookie banner or browser settings.
5) Sharing and disclosures
We may share information with:
- Service providers / subprocessors that host our infrastructure, deliver emails, provide analytics or support tooling, process payments, or otherwise help us run the Service. They are bound by confidentiality and data protection obligations.
- Your organization and authorized users within your workspace.
- Professional advisors (lawyers, accountants) under confidentiality.
- Authorities or third parties when required by law, to protect rights, safety, or prevent abuse.
- Business transfers if we are involved in a merger, acquisition, financing, or sale of assets.
We do not sell personal information and we do not share personal information for cross‑context behavioral advertising (as defined by applicable US state privacy laws).
We maintain a current list of subprocessors available on request.
6) International data transfers
We operate globally and may transfer data to countries with different data protection laws (including the United States). Where required, we use appropriate safeguards such as EU Standard Contractual Clauses (SCCs) and comparable UK addenda. If a recipient participates in the EU‑US Data Privacy Framework, we may rely on that certification where applicable.
7) Data retention
We retain personal information for as long as necessary to provide the Service, meet legal and accounting requirements, resolve disputes, and enforce agreements. In general:
- Account & billing records: retained for the duration of your subscription and for a reasonable period thereafter (e.g., tax/legal).
- Product & security logs: retained for a limited period, typically up to 12 months unless longer is needed for security investigations.
- Support records: retained for operational history and compliance, typically up to 24 months.
- Aggregated/De‑identified data: may be retained indefinitely for analytics and benchmarking.
We may delete or de‑identify Customer Data after account closure, subject to legal holds or backup constraints.
8) Cookies and similar technologies
We use:
- Strictly necessary cookies – required for login, security, and core functionality.
- Analytics cookies – help us understand usage and improve the Service. We only use these with your consent where required by law.
You can manage cookies via our banner (where shown) or your browser settings. Disabling certain cookies may affect functionality. We currently do not respond to browser Do‑Not‑Track signals. Where required, we honor Global Privacy Control (GPC) signals for opt‑out preferences.
9) Security
We implement reasonable administrative, technical, and physical safeguards to protect personal information (e.g., access controls, encryption in transit, backups, monitoring). However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10) Your rights
Depending on your location, you may have rights to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Delete personal data.
- Restrict or object to processing.
- Port personal data to another provider.
- Withdraw consent where processing is based on consent.
For California and certain US states, you may also have the right to opt out of sale/share, limit use of sensitive information, and appeal a decision. We do not sell or share personal information for cross‑context behavioral advertising.
To exercise rights, email legal@dynamiq.ai with “Privacy Request” in the subject and indicate your jurisdiction. We may need to verify your identity and, if applicable, your authorization to act on behalf of someone else. You will not be discriminated against for exercising your rights.
11) Customer Data handled as processor
When your organization is the controller and Dynamiq acts as a processor, we:
- Process Customer Data only on documented instructions (e.g., your in‑app settings and contracts).
- Implement appropriate security measures and require the same from our subprocessors.
- Assist with data subject requests and incident notifications as required by the DPA.
- Delete or return Customer Data at the end of the provision of services, subject to legal retention.
12) Third‑party links and integrations
The Service may link to or enable integrations with third‑party sites and services. Their privacy practices are governed by their own policies. Review those policies before enabling integrations or sharing data with them.
13) Children
The Service is intended for business users and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.
14) Changes to this policy
We may update this Privacy Policy from time to time. The updated version will be posted here with a new effective date. If we make material changes, we will provide additional notice (e.g., in‑app or email) as required by law.
15) Contact us
For questions or requests, contact legal@dynamiq.ai or write to: Dynamiq / PromptSignal, 1111B S Governors Ave STE 6798, Dover, DE 19904 US.