This Privacy Statement applies to you if you live within the European Union. To adjust the region, please use the dropdown button located above.
This Privacy Statement applies to you if you live within the United Kingdom. To adjust the region, please use the dropdown button located above.
This Privacy Statement applies to you if you live within the United States. To adjust the region, please use the dropdown button located above.
The link to the Consent Tool (including cookies) can be found here: Cookie Banner
Privacy Statement for the use of the DAR Lean Platform of DAR TECH Limited ("DAR TECH")
in respect of Personal Data of EU Data Subjects
Table of Contents:
  1. Preamble and scope of this Privacy Statement
  2. Definitions
  3. Categories of Personal Data
  4. Areas in which DAR TECH acts as Controller and areas in which DAR TECH acts as Processor
  5. Purposes of Processing
  6. Legal Bases of Processing
  7. Transfer of Personal Data to Recipients
  8. Web Tools including the Cookies set by these tools
  9. Single Sign-on
  10. Specific Information for the DAR Lean App
  11. Transfer to third countries and international organizations
  12. Storage duration
  13. Automated decision making including profiling
  14. Rights of data subjects in connection with Personal Data
  15. Contact details of DAR TECH as Controller
  1. Preamble and scope of this Privacy Statement

    This Privacy Statement applies to the use of the following websites and/or applications offered and operated by DAR TECH Limited, Themistokli Dervi, 3, Julia House, CY-1066 Nicosia (in short, "DAR TECH"), including all videos, recordings, sounds, texts, graphics and other materials sent, received, stored or otherwise displayed via the following services:

    • the "DAR Lean" landing pages, accessible via the address https://www.darlean.com or https://www.darlean.eu;
    • the “DAR Lean” web platform, accessible via the address https://app.darlean.com;
    • the application "DAR Lean", which is available for download via the digital distribution platforms App Store (Apple) as well as Play Store (Google).
    • DAR TECH provides the following information in this regard:

    • with regard to which Processing operations DAR TECH shall be deemed to be the Controller or Processor;
    • which Personal Data DAR TECH processes;
    • the purposes for which DAR TECH processes Personal Data;
    • the legal bases due to which DAR TECH is entitled to process Personal Data;
    • to whom and to which entities DAR TECH transfers Personal Data;
    • how long DAR TECH stores Personal Data;
    • which external tools and plugins DAR TECH uses;
    • what rights data subjects have with regard to their Personal Data;
    • how DAR TECH can be reached in connection with data protection issues as well as the exercise of data subject rights.

    With this Privacy Statement, DAR TECH fulfils its information obligations under data protection law within the meaning of Articles 12 to 14 GDPR.

    The definitions used in this Privacy Statement refer exclusively to this Privacy Statement and do not affect the definitions in DAR TECH's Terms and Conditions (T&C).

  2. Definitions

    1. General Data Protection Regulation (GDPR)

      • General Data Protection Regulation or GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the Processing of Personal Data, on the free movement of such data and repealing Directive 95/46/EC in the latest valid version.
      • Personal Data means any information relating to an identified or identifiable natural person (“Data Subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
      • Processing means any operation or set of operations which is performed on personal data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
      • Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data; where the purposes and means of such Processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
      • Processor means a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.
      • Recipient means a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a third party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as Recipients; the Processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the Processing.
    2. General

      • Privacy Statement means this Privacy Statement of DAR TECH in accordance with Articles 12 to 14 GDPR.
      • Terms & Conditions means DAR TECH's Terms and Conditions.
      • Annex to the Terms & Conditions means DAR TECH’s Annex to the Terms and conditions pursuant to Article 28 GDPR which contains provisions relating to the Processing of Workspace Data by DAR TECH as Processor on behalf of the Contractual Partner as Controller.
      • DAR TECH means DAR TECH Limited, Themistokli Dervi, 3, Julia House, CY-1066 Nicosia.
      • DAR Lean Platform means the cloud-based internet platform operated by DAR TECH which allows a Team to organize and manage operational processes as well as teamwork, including, inter alia, productivity tools, processes, planning, HR management and reporting. The DAR Lean Platform consists of the following components:
        • DAR Lean Landing Page: the website operated by DAR TECH at the web addresses https://www.darlean.com and https://www.darlean.eu, which can be accessed by means of compatible web browsers and on which the DAR Lean Products are presented and promoted.
        • DAR Lean Web Platform: the web platform operated by DAR TECH at the web address https://www.darlean.com, which can be accessed by means of compatible web browsers and on which the individual modules are provided to the Users depending on the selected Subscription of the Contractual Partner.
        • DAR Lean App: the software application offered by DAR TECH, which is made available for download via the App Store offered by Apple Inc. and the Play Store offered by Google Inc. and which, depending on the Contractual Partner's selected Subscription, enables Users to use individual or all modules of the DAR Lean Platform on compatible end devices.
      • Workspace means a virtual Workspace within the DAR Lean Platform in which Users are provided with the possibility to use certain modules or tools.
      • Team means a plurality of Users who are inscribed to the same Workspace.
    3. Roles

      • Contractual Partner means any natural or legal person who concludes or has concluded a contract including the Terms & Conditions as well as the Annex to the Terms & Conditions with DAR TECH for the use of the DAR Lean Platform. The Contractual Partner is by default the owner of a Workspace.
      • Interested Party means any natural person who is not yet a User of the DAR Lean Platform but has received the invitation to use it.
      • User means any natural person, including a Contractual Partner, who uses the DAR Lean Platform. A User can be assigned one of the following roles:
        • Owner: A registered User who is or can act on behalf of the Contractual Partner and who is granted access to a Workspace, including, but not limited to set up such Workspace, grant and configure access to such Workspace and manage the rights and permissions of Users who are assigned to such Workspace. The Owner has full control over the Workspace and can develop, configure, and customise it to meet the organisational needs of the Contractual Partner. The Owner is, on behalf of the Contractual Partner, permitted to request the deletion of a Workspace or Workspace Data from DAR TECH.
        • Administrator: A registered User who has the same privileges as the Owner, except for the ability to request the deletion of a Workspace.
        • Member: A registered User who is an employee of a Contractual Partner and who is assigned to a Workspace belonging to the Contractual Partner. The Member is authorised to use the modules of the DAR Lean Platform within the limits set by an Owner or Administrator and the subscription model of the DAR Lean Platform chosen by the Contractual Partner.
        • Guest: A registered User who is an outsource employee, outside partner or any external member of the Contractual Partner and who is assigned to a Workspace belonging to the Contractual Partner. The Guest is authorised to use the modules of the DAR Lean Platform within the limits set by an Owner or Administrator and the subscription model of the DAR Lean Platform chosen by the Contractual Partner. As compared to a Member, the Guest usually has fewer permissions, such as read-only mode.
        • Visitor: A User who visits the DAR Lean Platform without being registered or logged in.
  3. Categories of Personal Data

    1. Data that DAR TECH as Controller collects from the User ("DAR TECH Data"):

      • Master Data: This includes Personal Data that is necessary for establishing a contractual relationship with the Contractual Partner and for billing, as well as for establishing a User account inter alia the name (including any academic titles), the job title, the employer, the address (street, postal code/city, country), the location of the registration, account data, other payment data or information, the tax number, a unique User ID and the affiliation to one or more Workspaces.
      • Sign-in Data: This includes the User's credentials required to log in to the DAR Lean Platform, such as, the email address, a password or an SSO token (E-Mail, other social network ID including, but not limited to Facebook, Google). The SSO services are described in Section 9.
      • Profile Data:This includes Personal Data that a User enters to create or update their profile, such as the name, the contact, social links (social network name), telephone number, e-mail- address, data on the employment contract and a description of such person.
      • Correspondence Data: This includes Personal Data that arise in correspondence between DAR TECH and a User, for example, when a User submits a support request to DAR TECH via the DAR Lean Platform, by e-mail or telephone, such as the User's e-mail address or telephone number and the message content.
      • Session Data: This includes the session ID assigned to a User while logging in to the DAR Lean Platform.
      • Connection Data: This includes Personal Data of a technical nature that is collected in connection with the use of the DAR Lean platform, such as the URL accessed by the User, the timestamp (date/time), browser type/browser version, the operating system used, the referrer URL and the IP address, the geolocation of the User, date and time of visits.

      In general, the Contractual Partner as well as the User is not required to provide Personal Data. However, this may possibly result in DAR TECH not being able to provide all services of the DAR Lean Platform. For example, the non-disclosure of Master Data may lead to the fact that no contractual relationship can be established between the Contractual Partner and DAR TECH. Likewise, the non-disclosure of Correspondence Data may result in DAR TECH not being able to answer inquiries/requests or give support.

    2. Data that DAR TECH as Processor processes on behalf of a Contractual Partner ("Workspace Data"):

      This includes all Personal Data that a User enters by using the various modules of the DAR Lean Platform within a Workspace, in particular:

      • Invitation Data: This includes Personal Data entered by the User for the purpose of inviting an Interested Party, such as in particular the e-mail address as well as the intended role.
      • Collaboration Data: This includes Personal Data that occurs as a result of multiple Users interacting with each other or within a Team, specifically Personal Data contained in project plans, functional personal tasks, meeting notes, Personal Data related to video conferencing (including video transmissions), or related User assignments/assignments.
      • Team Data: This includes Personal Data related to the Team (including human resources) of a Workspace, in particular listings of Users, roles, hierarchies, employee contract terms (if applicable), working time records, leave dates and types.
      • Work Data: This includes Personal Data related to tasks, in particular the assignment of Users to tasks, Personal Data related to processes, projects or budgets.
      • Media Data: This includes Personal Data contained in uploaded files, such as Word and PDF files, image, video and audio files.
  4. Areas in which DAR TECH acts as Controller and areas in which DAR TECH acts as Processor

    1. DAR TECH as Controller regarding DAR TECH Data

      DAR TECH Limited, Themistokli Dervi, 3, Julia House, CY-1066 Nicosia, Cyprus, is the sole data Controller for the Processing of DAR TECH data and for the purposes set forth in Section 5 in accordance with Article 4 No 7 GDPR.

    2. DAR TECH as Processor of the contracting party regarding Workspace Data

      DAR TECH Limited, Themistokli Dervi, 3, Julia House, CY-1066 Nicosia, Cyprus, processes Workspace Data on behalf of the Contractual Partner pursuant to Article 28 GDPR and in accordance with the Annex to the Terms & Conditions and is therefore a Processor pursuant to Article 4 No 8 GDPR. The Processing operations that DAR TECH performs on behalf of the Contractual Partner are, for example:

      • Sending an invitation email to an Interested Party based on a User's entry of Invitation Data.
      • Storage and provision of Collaboration Data, Team Data and Work Data according to the permissions set by a User in each case.

      Regarding the Processing of Workspace Data, the Contractual Partner shall be the independent and sole Controller in accordance with Article 4 No 7 GDPR; joint responsibility with DAR TECH is excluded.

  5. Purposes of Processing

    DAR TECH processes DAR TECH Data as Controller for the following purposes:

    • Provision of the DAR Lean Platform
      • Registration, creation of a User account: DAR TECH processes Master Data and Sign-in Data of the User in order to enable the User to register for the first time to the DAR Lean Platform and to set up a User account.
      • Sign-in and provision of the available modules of the DAR Lean Platform: DAR TECH processes Sign-in Data of the User as well as Session Data in order to enable the User to log-in to the DAR Lean Platform and use it accordingly. The SSO services are further described in Section 9.
      • Display of the DAR Lean Platform: DAR TECH processes certain Connection Data to enable the User to fully and properly display the DAR Lean Platform.
      • Optimized loading of the DAR Lean Platform: DAR TECH processes certain Connection Data to improve the performance of the DAR Lean Platform, for example because some components are loaded from external Content Deployment Networks (CDN).
      • Personalization of the DAR Lean Platform: DAR TECH processes certain Master Data as well as Profile Data to personalize the DAR Lean Platform for the respective User. Such personalization includes, inter alia, the subscriptions to Workspaces by the User.
      • Ordering of services, billing including debt collection: DAR TECH processes Master Data and, if necessary, Correspondence Data and Connection Data in order to be able to bill a Contractual Partner for services relating to the DAR Lean Platform and, if necessary, to pursue them (also in court).
    • Communication with the User
      • Communication (User Request/Support): DAR TECH processes Master Data as well as Correspondence Data in order to be able to contact and correspond with the User, inter alia to be able to answer enquiries and provide support, in particular by means of the contact form on the DAR Lean Platform or by e-mail.
      • Communication (Transactional): DAR TECH processes Master Data as well as Correspondence Data to send transactional messages (including e-mails) to the User or Contractual Partner. Transactional messages, include, inter alia, important messages related to the account, a Workspace or User credentials (e.g. notification about a password reset) or information about changes/amendments relating to contracts between the User and DAR TECH or this Privacy Statement.
      • Newsletter: DAR TECH processes certain Master Data to send the User a newsletter by e-mail based on the prior registration of the User. However, DAR TECH will only process this Personal Data for this purpose if the User has given their prior consent. This consent can be withdrawn at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.
    • Security and abuse prevention
      • IT Security: DAR TECH processes DAR TECH Data as well as - exclusively in justified cases and only to the extent absolutely necessary in accordance with the Terms & Conditions - Workspace Data (excluding special categories of data as described in Article 9 (1) GDPR) to ensure the security and operability of the DAR Lean Platform. This includes, in particular, Processing carried out in connection with technical and organizational measures to detect, prevent and track attacks on the DAR Lean Platform. If certain Workspace Data is found to affect IT security (e.g. because certain files contain viruses), DAR TECH reserves the right to delete such data in accordance with the Terms & Conditions as well as the Annex to the Terms & Conditions and to immediately inform the Contractual Partner. DAR TECH will, however, never transfer such data to third parties, unless explicitly required to do so by applicable Union or Member State law.
      • Prevention of fraud and abuse: DAR TECH processes DAR TECH Data as well as - exclusively in justified cases and only to the extent absolutely necessary in accordance with the Terms & Conditions - Workspace Data (excluding special categories of data as described in Article 9 (1) GDPR) to be able to detect, prevent and prosecute abuse of the DAR Lean Platform (in particular the use of the DAR Lean Platform by the User contrary to the Terms & Conditions, use of a User account by several persons, data and credit card fraud, upload of illegal content).
    • Fulfilment of legal obligations under Cypriot and European law
      • Information, Recording and Retention Obligations: DAR TECH processes all DAR TECH Data to comply with statutory disclosure, recording and retention obligations, in particular those under tax and commercial law.
      • Exercise of data subject rights: DAR TECH processes all DAR TECH Data in order to fulfil Users’ data subject rights pursuant to the GDPR (see Section 14 in detail) and to be able to respond to them.
    • Analysis and optimization of the DAR Lean Platform
      • Improvement of the DAR Lean Platform: DAR TECH processes certain Connection Data to be able to analyse and optimize the operation of the DAR Lean Platform, inter alia to find and understand bugs of the DAR Lean Platform. The services used for this purpose as well as the relevant data being processed by these services including the legal bases for Processing are further described in Section 8.
      • Analysis of the User structure: DAR TECH processes DAR TECH Data to be able to understand the geographical presence, gender, age and product patterns of Users who use the DAR Lean Platform, as well as to understand the usage habits and usage frequency as well as the satisfaction of tools provided within the DAR Lean Platform, in order to personalize the appearance of the DAR Lean Platform and to evaluate the useability and effectiveness of the modules within the DAR Lean Platform. The services used for this purpose as well as the relevant data being processed including the legal bases for Processing are described in Sections 6 to 8.
    • Further purposes
      • Purposes which require consent: DAR TECH may process Personal Data for additional purposes, which will be communicated to the User in this Privacy Statement as amended from time to time or otherwise as the occasion arises. Processing will only take place if the User has given prior consent to such Processing. Consent can be withdrawn easily at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.
      • Purposes stated elsewhere within this Privacy Statement: DAR TECH may also process Personal Data for purposes and on the basis of the legal bases set forth in Sections 6 to 8.
  6. Legal Bases of Processing

    Unless specified otherwise, DAR TECH processes DAR TECH Data for the purposes set forth in Section 5 based on one or more of the following legal bases:

    • Performance of a contract:DAR TECH processes DAR TECH Data on the basis of a contractual agreement concluded with the Contractual Partner regarding the use of the DAR Lean Platform or in order to take steps at the request of the Contractual Partner prior to entering into a contract, insofar as the Processing is necessary for this purpose (Article 6 (1) lit b GDPR).
    • Legal obligation: DAR TECH processes DAR TECH Data based on a legal obligation to which DAR TECH is subject to (Article 6 (1) lit c GDPR).
    • Legitimate interest: DAR TECH processes DAR TECH Data as well as - exclusively in justified cases and only to the extent absolutely necessary in accordance with the Terms & Conditions as well as the Annex to the Terms & Conditions – Workspace Data (excluding special categories of data as described in Article 9 (1) GDPR) based on its legitimate interest (Article 6 (1) lit f GDPR). Unless otherwise stated, the legitimate interests of DAR TECH are, in particular,
      • to establish and maintain a proper contract and User management;
      • to ensure the proper provision and functioning of the DAR Lean Platform;
      • to maintain the security and performance of the IT infrastructure used by DAR TECH;
      • to understand how the DAR Lean Platform is used, especially to identify usage habits and preferences;
      • to evaluate the performance of the DAR Lean Platform;
      • to personalize the DAR Lean Platform to the respective User preferences;
      • to find and eliminate bugs of the DAR Lean Platform; and
      • to be able to detect and stop any misuse of the DAR Lean Platform.
      • If referred to separately, DAR TECH also processes DAR TECH Data, based on a previously given and voluntary consent (Article 6 (1) lit a GDPR) by the User. The User is entitled to revoke this consent at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.

  7. Transfer of Personal Data to Recipients

    1. Transfer to categories of recipients

      Personal Data will be transferred by DAR TECH for the purposes mentioned in Section 5 to one or more of the following categories of Recipients:

      • banks (e.g. in order to facilitate bank transfers);
      • tax advisors (e.g. in order to carry out proper accounting);
      • lawyers and collection agencies (e.g. to collect outstanding debts or exercise other legal rights);
      • courts and public authorities (e.g. to report and clarify legally relevant facts or to enforce claims);
      • external services as described in Sections 7.2 and 8;
      • Single Sign-on providers as described in Sections 7.2 and 9.

      The data is also transferred if DAR TECH is legally obliged to do so.

    2. Overview of transmission to external services

      DAR TECH also transfers Personal Data to the service providers listed below

      • DAR Solutions LLP., Almaty, Koktem microdistrict 2 – 22, Kazakhstan, based on a Processing agreement concluded with DAR TECH pursuant to Article 28 GDPR. DAR Solutions LLP processes DAR TECH Data on behalf of DAR TECH to provide technical assistance and development relating to the DAR Lean Platform and to provide support for Users. DAR Solutions LLP as well as DAR TECH are companies of the same group.
      • Web Tool Providers, as described in detail in Section 8:
        • Ynot Partners, Inc.,316 High Street, Palo Alto, CA 94301, USA, as operator of the "Userguiding.com" service, a User onboarding tool.
        • BITRIX24 LIMITED, Poseidonos, 1, LEDRA BUSINESS CENTRE, 'Egkomi 2406, Lefkosia, Cyprus, as operator of the service "Bitrix24.eu", a Content Delivery Network (CDN).
        • Stripe Payments Europe Limited 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland as operator of "Stripe", an online payment service.
        • Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland as operator of the services "Google Tag Manager" as well as "DialogFlow".
        • Volentio JSD Limited, Suite 2a1, Northside House, Mount Pleasant, Barnet, England, EN4 9EB, as operator of the service "jsDelivr", a Content Delivery Network (CDN) for open-source files, such as common frontend libraries like ReactJS.
        • Tilda Publishing Ltd., Regus Pembroke House, 28 - 32 Pembroke Street Upper, Dublin 2, Ireland, D02 NT28, as operator of the service “Tilda”.
        • Cloudflare, Inc, 101 Townsend St, San Francisco, CA 94107, USA, as operator of the service “Unpkg”.
      • Single Sign-on Providers as described in detail in Section 9:
        • Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (operator of the Service “Facebook Single Sign-on”).
        • Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (operator of the service "Google Single Sign-on”).
      • Hosting provider:
        • AMAZON WEB SERVICES EMEA SOCIÉTÉ À RESPONSABILITÉ LIMITÉE38 Avenue John F. Kennedy, L-1855 Luxembourg, Registration number: B186284 (operator of the service "AWS"): DAR TECH uses this service to provide the platform (hosting of the DAR Lean Platform). More detailed information can be found here: https://aws.amazon.com/de/compliance/gdpr-center/. The legal basis is the legitimate interest of DAR TECH (Article 6 (1) lit f GDPR), which lies in being able to fulfil the aforementioned purpose; also the fulfilment of contracts with Contractual Partners (Article 6 (1) lit b GDPR).
  8. Web Tools including the Cookies set by these tools

    1. Introduction and Technical Explanation

      DAR TECH utilises certain web tools as further described in Sections 8.2 to 8.9. Some of these web tools may utilize cookies. The link to the Consent Tool (including cookies) can be found here: Cookie-Banner.

      For detailed information about the Cookies set by the individual services listed below please refer to the https://darlean.com/en/cookies.

    2. Bitrix24.eu

      Bitrix24.eu is an external service provided by BITRIX24 LIMITED, Poseidonos, 1, LEDRA BUSINESS CENTRE, 'Egkomi 2406, Lefkosia, Cyprus.

      DAR TECH uses this service for the purpose of organizing communication with Users, thus to be able to answer User enquiries and provide support, as well as to enable proper presentation of the DAR Lean Platform and to optimize speed (for example by sideloading fonts). Among the data collected is the User name, the User phone number and the User e-mail-address.

      The legal basis is the legitimate interest of DAR TECH (Article 6 (1) lit f GDPR) to achieve the aforementioned purposes. The Service Provider makes its Privacy Policy available at the following location: https://www.bitrix24.eu/gdpr/.

    3. Stripe

      Stripe is an external service offered and operated by Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland.

      Stripe is an online payment service provider. If the Contractual Partner makes a payment via the DAR Lean Platform, the relevant payment data (name, address, data on bank details), the IP address and data on the contract concluded with DAR TECH are transmitted to the payment service provider who subsequently stores the data.

      DAR TECH uses this service to perform the billing (Processing regarding payment). The legal basis is the fulfilment of the contract (Article 6 (1) lit b GDPR) vis-à-vis the Contractual Partner; if cookies are used, additionally the prior consent of the Contractual Partner (Article 6 (1) lit a GDPR).

      The Service Provider makes its Privacy Policy available at the following location: https://stripe.com/en-cy/privacy.

    4. Google Tag Manager

      Google Tag Manager is an external service offered and operated by Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

      Google Tag Manager is a tag management system with which tracking codes and associated code fragments can be centrally integrated, managed and updated on the DAR Lean Platform. The service is provided by Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

      The Google Tag Manager serves as a mere system for passing through other tools, is hosted locally and does not transfer any Personal Data to Google. Information on Processing in connection with these other tools can be found under the respective tools in this Privacy Statement.

      The service provider makes its privacy policy available at the following location: https://policies.google.com/technologies/partner-sites?hl=de&hl=de

    5. DialogFlow

      DialogFlow is an external service offered and operated by Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

      DialogFlow is a natural language understanding platform used to design and integrate a conversational user interface into mobile apps, web applications, devices, bots, interactive voice response systems and related uses.

      DAR TECH uses DialogFlow to offer advice and to respond to Users’ requests by implementing the service into a chatbot solution. DialogFlow uses machine learning to understand inputs and respond accordingly. In general, DialogFlow does not request Personal Data from Users.

      Google Ireland Limited, Google LLC or Alphabet Inc. may anonymize the dialog created by the User and the DAR Lean Platform and subsequently use it to improve and train the DialogFlow product.

      The legal basis for Processing is the consent given by the User in accordance with Article 6 (1) (a) GDPR and Article 49 (1) (a) GDPR. See in detail Section 11. Consent can be withdrawn at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.

      Possible data Recipients are:

      • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (as Processor according to Article. 28 GDPR)
      • Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA
      • Alphabet Inc, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA

      The service provider makes its privacy policy available at the following location: https://cloud.google.com/dialogflow/docs/data-logging-terms?hl=en.

    6. jsDelivr

      jsDelivr is an external service offered and operated by Volentio JSD Limited, Suite 2a1, Northside House, Mount Pleasant, Barnet, England, EN4 9EB. It is a Content Delivery Network (CDN) for open-source files, such as common frontend libraries like ReactJS.

      DAR TECH uses this service to automatically keep certain libraries used for the DAR Lean Platform up to date by automatically including the latest distribution into it. This is necessary to safeguard IT Security and to optimize the loading time of the DAR Lean Platform. When the User accesses the DAR Lean Platform, certain Connection Data to the aforementioned service provider is transmitted.

      The legal basis for Processing is the legitimate interest of DAR TECH (Article 6 (1) lit f GDPR) which is to be able to fulfil the aforementioned purposes, especially to keep the DAR Lean Platform up to date and to avoid security flaws caused by outdated libraries.

      The service provider makes its privacy policy available at the following location: https://www.jsdelivr.com/terms/privacy-policy-jsdelivr-net.

    7. Matomo

      Matomo is an open source web analytics application to track online visits to websites and display reports on these visits for analytics. DAR TECH uses this service to statistically analyze the User structure and subsequently optimize the DAR Lean Platform. DAR TECH collects the following Personal Data: User IP address, Optional User ID, Date and time of the request, Title of the page being viewed (Page Title), URL of the page being viewed (Page URL), URL of the page that was viewed prior to the current page (Referrer URL), Screen resolution being used, Time in local user’s timezone, Files that were clicked and downloaded (Download), Links to an outside domain that were clicked (Outlink), Pages generation time (the time it takes for webpages to be generated by the webserver and then downloaded by the user: Page speed), Location of the user: country, region, city, approximate latitude and longitude, Main Language of the browser being used, User Agent of the browser being used, Random unique Visitor ID, Time of the first visit for this user, Time of the previous visit for this user, Number of visits for this user.

      The legal basis for Processing is the legitimate interest of DAR TECH pursuant to Article 6 (1) (f) GDPR to improve the DAR Lean Platform and to understand the user structure. If cookies are set, the legal basis for Processing is consent given by the User in accordance with Article 6 (1) (a) GDPR. Consent can be withdrawn at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.

      DAR TECH is using the Matomo Cloud service (“matomo.cloud”) , which is provided by InnoCraft Ltd, 7 Waterloo Quay, PO625, 6140 Wellington, New Zealand (“InnoCraft”), to store the aforementioned Personal Data. The European Commission has determined that New Zealand has an adequate level of data protection pursuant to Article 45 GDPR (Commission Implementing Decision 2013/65/EU pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of Personal Data by New Zealand). However, all Personal Data is stored on servers within the European Union. InnoCraft publishes its “Matomo Cloud Privacy Policy” under https://matomo.org/matomo-cloud-privacy-policy/. DAR TECH has concluded a data Processing agreement pursuant to Article 28 GDPR whose text can be accessed under https://matomo.org/matomo-cloud-dpa/.

    8. Tilda

      Tilda is an external service offered and operated by Tilda Publishing Ltd., Regus Pembroke House, 28 - 32 Pembroke Street Upper, Dublin 2, Ireland, D02 NT28.

      Tilda is a no-code website builder and content delivery network (CDN) service. Its purpose is to deliver web content – inter alia web pages, videos and/or audio files – to the User. The purpose of this service is to increase the performance of the DAR Lean Platform and to provide the User with visually appealing web pages. When the User visits the DAR Lean Platform, a connection to servers of the Service Provider is made and Connection Data is processed.

      The legal basis is the legitimate interest of DAR TECH (Article 6 (1) lit f GDPR) to achive the aforementioned purposes.

      The Service Provider makes its Privacy Policy available at the following location: https://tilda.cc/privacy/. DAR TECH has concluded a data Processing agreement pursuant whose text can be accessed under https://tilda.cc/dpa/. According to the Service Provider, Personal Data of Users within Europe or the USA is stored on servers within the European Union. The technical information of Tilda can be accessed under https://tilda.cc/lp/technical-information/.

    9. Unpkg

      Unpkg is an external service offered and operated by Cloudflare, Inc, 101 Townsend St, San Francisco, CA 94107, USA (“Cloudflare”).

      Unpkg is a global content delivery network (CDN) for JavaScript packages; it delivers such JavaScript packages to the User. The purpose of this service is to increase the performance of the DAR Lean Platform and to enable DAR TECH to include the most recent versions of such JavaScript packages into the DAR Lean Platform. This relieves DAR TECH from manually updating these packages; it furthermore also guarantees the security of the DAR Lean Platform. When the User visits the DAR Lean Platform, a connection to servers of the Service Provider is made and Connection Data is processed.

      The legal basis is the legitimate interest of DAR TECH (Article 6 (1) lit f GDPR) to achive the aforementioned purposes. Cloudflare outlines its GDPR compliance under https://www.cloudflare.com/trust-hub/gdpr/#gdprfaq. Its privacy policy is available under https://www.cloudflare.com/privacypolicy/.

      Cloudflare ensures and provides sufficient guarantees that European data protection law is complied with. Cloudflare is certified under the EU-US Privacy Framework. For the USA, the European Commission adopted its adequacy decision on July 10, 2023.

      The User can prevent the collection and Processing of Personal Data by Cloudflare by deactivating the execution of script code or by installing a script blocker in the web browser.

  9. Single Sign-on

    1. Facebook Single Sign-on

      Facebook Single Sign-on is an authentication (single sign-on) service operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (formerly Facebook, Inc).

      DAR TECH uses this service to allow users to log in to the platform using the Facebook login without having to create a specific user account (with individual email and password).

      The legal basis for Processing is the explicit consent given by the User in accordance with Article 6 (1) (a) GDPR and Article 49 (1) (a) GDPR. See in Detail Section 6 (Legal Basis) and Section 11 (Data Export). Such explicit consent is given by the User clicking on the "Facebook" button on the login page of the DAR Lean Platform. Consent can be withdrawn at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.

      The service provider makes its privacy policy available at the following location: https://www.facebook.com/privacy/policy/.

    2. Google Single Sign-On

      Google Single Sign-on is an authentication (single sign-on) service operated by Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

      DAR TECH uses this service to allow users to log in to the platform using the Google login without having to create a specific user account (with individual email and password).

      The legal basis for Processing is the explicit consent given by the User in accordance with Article 6 (1) (a) GDPR and, if applicable, Article 49 (1) (a) GDPR. See in Detail Section 6 (Legal Basis) and Section 11 (Data Export). Such explicit consent is given by the User clicking on the "Google" button on the login page of the DAR Lean Platform. Consent can be withdrawn at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.

      The service provider makes its privacy policy available at the following location: https://policies.google.com/privacy?hl=en.

  10. Specific Information for the DAR Lean App

    This section provides additional information on the Processing of Personal Data in connection with the use of the DAR Lean App.

    DAR TECH enables the User to download the DAR Lean App via various internet-based digital distribution platforms for application software. The download via these distribution platforms usually requires that the User has previously registered with the distribution platforms used. The distribution platforms on which the DAR Lean app is offered for download are:

    • App Store: This is a distribution platform for application software offered and operated by Apple Inc. or other legal entities of Apple. Apple's privacy policy is available at https://www.apple.com/legal/privacy.
    • Play Store: This is a distribution platform for application software offered and operated by Google LLC or another legal entity of Google. Google's privacy policy is available at https://policies.google.com/privacy.

    DAR TECH has neither knowledge nor influence of the way in which and the purposes for which these distribution platforms process the User's Personal Data.

  11. Transfer to third countries and international organisations

    Some of the Recipients listed above are located outside the European Union or process Personal Data outside of the European Union. DAR TECH may transfer Personal Data to service providers that carry out certain functions on its behalf. This may involve transferring Personal Data outside the European Economic Area (EEA) to countries which have laws that do not provide the same level of data protection as the EEA.

    Whenever DAR TECH transfers Personal Data to service providers outside of the EU, DAR TECH ensures a similar degree of protection is afforded to such Personal Data by ensuring that the countries have been deemed by the EU to provide an adequate level of protection for Personal Data, by implementing the following safeguards:

    Data recipient Service Third country Legal basis for data export
    Alphabet Inc DialogFlow USA Standard Contractual Clauses (SCC), Explicit consent (Article 49 (1) lit a GDPR)
    Google LLC DialogFlow, Google SSO USA Explicit consent (Article 49 (1) lit a GDPR), Standard Contractual Clauses (SCC) or by way of the EU-US Data Privacy Framework
    Meta Platforms Ireland Limited Facebook Single Sign-On USA Explicit consent (Article 49 (1) lit a GDPR)
    DAR Solutions LLP. Technical Assistance and Development, User Support Kazakhstan Standard Contractual Clauses (SCC)
    Volentio JSD Limited jsDelivr UK Adequacy Decision (EU) 2021/1772 or by way of Standard Contractual Clauses (SCC).
    InnoCraft Ltd Matomo.Cloud NZ Adequacy Decision (EU) 2013/65, as amended by Commission Implementing Decision (EU) 2016/2295.
    Cloudflare, Inc Unpkg USA EU-US Data Privacy Framework

    In general, DAR TECH transfers Personal Data only to countries for which the EU Commission has published adequacy decisions, or measures are taken by DAR TECH to ensure that all Recipients can guarantee an adequate level of data protection. For example, standard contractual clauses (pursuant to Implementing Decision (EU) 2021/914) will be concluded for this purpose. DAR TECH will make these standard contractual clauses available upon request.

    In July 2023 the European Commission adopted its adequacy decision for the EU-US Data Privacy Framework (DPF). The decision concludes that the United States ensures an adequate level of protection – comparable to that of the EU – for Personal Data transferred from the EU to US organisations under the new framework. On the basis of the new adequacy decision, Personal Data can flow safely from the EU to US companies participating in the DPF, without having to put in place additional data protection safeguards.

    If no adequacy decision exists, the organisations are not participating in the DPF, or if DAR TECH has not concluded standard contractual clauses with the respective service provider, DAR TECH will obtain the User's explicit consent prior to transmission. Explicit consent obtained for Processing for the respective Processing purpose pursuant to Article 6 (1) lit a GDPR shall also be deemed to be consent in accordance with Article 49 (1) lit a GDPR.

    Due to the U.S. Cloud Act there may be a right of access to data stored by organisations not registered with the DPF by the American government, even if the data is not stored in the USA. It might be possible that an authority or other government agency, in particular an intelligence service, could request access to certain User data from these Recipients without first obtaining a court order. It is also possible that, if such a request is fulfilled by the service provider, the User may lack legal protection against such access, such as a right to information or a right of complaint.

  12. Storage duration

    DAR TECH stores Personal Data for the period necessary to achieve the purposes set forth in this Privacy Statement and, in addition, for the duration of any statutory retention obligation. In particular, the following storage or retention periods apply, unless European or Cypriot law provides otherwise:

    • Master Data, Profile Data, and Sign-in Data of Users are stored for at least the duration of the existence of the User relationship with DAR TECH and then for a subsequent period of 3 years after the termination of the account.
    • Correspondence Data will be stored at least for the duration of the existence of the User relationship with DAR TECH, but no longer than 3 years after the termination of the account.
    • Session Data is stored for the duration of the visit to the DAR Lean Platform and deleted at the earliest after logout, but at the longest after 72 hours.
    • If the sole legal basis for Processing is consent, Personal Data is stored until such consent is withdrawn; after that, such Personal Data is deleted, as long as there are no other legitimate purposes for which this Personal Data is processed, such as legal retention periods. Depending on the purpose for which the consent was given, the Processing time within which DAR TECH complies with the request may be a maximum of 7 days after the withdrawal of consent.
  13. Automated decision making including profiling

    DAR TECH does not process Personal Data for the purpose of automated decision-making, including profiling.

  14. Rights of data subjects in connection with Personal Data

    1. Overview of rights of data subjects

      Data Subjects whose Personal Data is processed by DAR TECH are entitled – to:

      • request information as to whether and which Personal Data of the data subject DAR TECH is Processing and to receive further information on such Processing; also to receive copies of such data (Article 15 GDPR);
      • request the correction or completion of Personal Data (Article 16 GDPR);
      • request the deletion of Personal Data that is incorrect or processed in a way that does not comply with the law (Article 17 GDPR);
      • request DAR TECH to restrict the Processing of the Personal Data (Article 18 GDPR);
      • know the identity of third parties to whom the Personal Data is transferred (Article 19 GDPR);
      • request data portability, provided that the Processing is based on the legal grounds of consent or the performance or initiation of a contract and is carried out by means of automated processes (Article 20 GDPR);
      • object to the Processing of Personal Data under certain circumstances, whereby an objection to the Processing for purposes of direct marketing is possible at any time without stating reasons (Article 21 GDPR);
      • if the Processing is based on the legal basis of consent, to withdraw the consent, whereby such withdrawal shall not affect the lawfulness of the Processing carried out on the basis of the consent until the withdrawal (Article 7 (3) GDPR);
      • file a complaint with the competent supervisory authority (for Cyprus, the Commissioner for Personal Data Protection, Iasonos 1, 1082 Nicosia, Cyprus).
    2. Exercise of Rights

      Whenever DAR TECH acts as Controller relating to DAR TECH Data (e.g. correspondence between the User and DAR TECH), the rights as described in Section 14.1 will be satisfied directly by DAR TECH within the timelines set by applicable law.

      Whenever DAR TECH acts as processor relating to Workspace Data (e.g. when the User has written or was mentioned in meeting notes, or when a User requests the deletion of a file uploaded by him/her), DAR TECH will, after the receipt of such request, immediately transmit this request to the competent Contractual Partner as Controller of the Workspace the User is assigned to. Such a request is usually not directly answered by DAR TECH, but satisfied directly by the Contractual Partner, as DAR TECH is not a controller regarding this category of Personal Data. Only after having received a documented instruction of the Contractual Partner, DAR TECH may answer the request on behalf of the Contractual Partner as described in the Terms & Conditions as well as the Annex to the Terms & Conditions.

  15. Contact details of DAR TECH as Controller

    For inquiries regarding data protection or the exercise of Data Subject rights, please contact exclusively:

    DAR TECH Limited

    Themistokli Dervi, 3, Julia House

    CY-1066 Nicosia

    Cyprus

    E-mail: info-eu@darlean.com

  16. Changes to the Privacy Policy and your duty to inform DAR TECH of changes

    DAR TECH keeps this Privacy Statement under regular review. This version was last updated on June 10, 2024. Historic versions can be obtained by contacting DAR TECH using the contact details in Section 15. DAR TECH reserves the right to change and/or amend this Privacy Statement from time to time.

    It is important that the Personal Data DAR TECH holds about Users is accurate and current. Users should keep DAR TECH informed (using the respective functions on the Platform or the contact details in Section 15) if their Personal Data changes during their relationship with DAR TECH, for example a new address or email address.

  17. Changes to the Privacy Policy and your duty to inform DAR TECH of changes

    This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about individuals. DAR TECH does not control these third-party websites and is not responsible for their privacy statements. When a User leaves our website, DAR TECH encourages each User to read the privacy policy of every website visited.

Privacy Statementfor the use of the DAR Lean Platform of DAR TECH Limited ("DAR TECH") in respect of Personal Data of UK Data Subjects
Table of Contents:
  1. Preamble and scope of this Privacy Statement
  2. Definitions
  3. Categories of Personal Data
  4. Areas in which DAR TECH acts as Controller and areas in which DAR TECH acts as Processor
  5. Purposes of Processing
  6. Legal Bases of Processing
  7. Transfer of Personal Data to Recipients
  8. Web Tools including the Cookies set by these tools
  9. Single Sign-on
  10. Specific Information for the DAR Lean App
  11. Transfer to third countries and international organizations
  12. Storage duration
  13. Automated decision making including profiling
  14. Rights of data subjects in connection with Personal Data
  15. Contact details of DAR TECH as Controller
  1. Preamble and scope of this Privacy Statement

    This Privacy Statement applies to the use of the following websites and/or applications offered and operated by DAR TECH Limited, Themistokli Dervi, 3, Julia House, CY-1066 Nicosia (in short, "DAR TECH"), including all videos, recordings, sounds, texts, graphics and other materials sent, received, stored or otherwise displayed via the following services:

    • the "DAR Lean" landing page, accessible via the address https://darlean.com;
    • the “DAR Lean” web platform, accessible via the address https://app.darlean.com;
    • the application "DAR Lean", which is available for download via the digital distribution platforms App Store (Apple) as well as Play Store (Google).
    • DAR TECH provides the following information in this regard:

    • with regard to which Processing operations DAR TECH shall be deemed to be the Controller or Processor;
    • which Personal Data DAR TECH processes;
    • the purposes for which DAR TECH processes Personal Data;
    • the legal bases due to which DAR TECH is entitled to process Personal Data;
    • to whom and to which entities DAR TECH transfers Personal Data;
    • how long DAR TECH stores Personal Data;
    • which external tools and plugins DAR TECH uses;
    • what rights data subjects have with regard to their Personal Data;
    • how DAR TECH can be reached in connection with data protection issues as well as the exercise of data subject rights.

    With this Privacy Statement, DAR TECH fulfils its information obligations under data protection law within the meaning of Articles 12 to 14 of the UK GDPR and Articles 12 to 14 of the EU GDPR.

    The definitions used in this Privacy Statement refer exclusively to this Privacy Statement and do not affect the definitions in DAR TECH's Terms and Conditions (T&C).

  2. Definitions

    1. General Data Protection Regulation (GDPR)

      • UK General Data Protection Regulation or UK GDPR, for Processing UK Personal Data, means the General Data Protection Regulation, Regulation (EU) 2016/679, as it forms part of domestic law in the UK by virtue of section 3 of the European Union (Withdrawal) Act 2018 (including as further amended or modified by the laws of the UK from time to time).
      • EU General Data Protection Regulation or GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the Processing of Personal Data, on the free movement of such data and repealing Directive 95/46/EC in the latest valid version.
      • EEA means the European Economic Area.
      • EU means the European Union.
      • Member State means a member state of the European Union.
      • Personal Data means any information relating to an identified or identifiable natural person (“Data Subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
      • Processing means any operation or set of operations which is performed on personal data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
      • Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data; where the purposes and means of such Processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
      • Processor means a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.
      • Recipient means a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a third party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as Recipients; the Processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the Processing.
      • UK means the United Kingdom of Great Britain and Northern Ireland.
    2. General

      • Privacy Statement means this Privacy Statement of DAR TECH in accordance with Articles 12 to 14 of the UK GDPR and Articles 12 to 14 of the EU GDPR.
      • Terms & Conditions means DAR TECH's Terms and Conditions.
      • Annex to the Terms & Conditions means DAR TECH’s Annex to the Terms and conditions pursuant to Article 28 of the UK GDPR and Article 28 of the EU GDPR which contains provisions relating to the Processing of Workspace Data by DAR TECH as Processor on behalf of the Contractual Partner as Controller.
      • DAR TECH means DAR TECH Limited, Themistokli Dervi, 3, Julia House, CY-1066 Nicosia.
      • DAR Lean Platform means the cloud-based internet platform operated by DAR TECH which allows a Team to organise and manage operational processes as well as teamwork, including, inter alia, productivity tools, processes, planning, HR management and reporting. The DAR Lean Platform consists of the following components:
        • DAR Lean Landing Page: the website operated by DAR TECH at the web address https://www.darlean.com, which can be accessed by means of compatible web browsers and on which the DAR Lean Products are presented and promoted.
        • DAR Lean Web Platform: the web platform operated by DAR TECH at the web address https://app.darlean.com, which can be accessed by means of compatible web browsers and on which the individual modules are provided to the Users depending on the selected Subscription of the Contractual Partner.
        • DAR Lean App: the software application offered by DAR TECH, which is made available for download via the App Store offered by Apple Inc. and the Play Store offered by Google Inc. and which, depending on the Contractual Partner's selected Subscription, enables Users to use individual or all modules of the DAR Lean Platform on compatible end devices.
      • Workspace means a virtual Workspace within the DAR Lean Platform in which Users are provided with the possibility to use certain modules or tools.
      • Team means a plurality of Users who are inscribed to the same Workspace.
    3. Roles

      • Contractual Partner means any natural or legal person who concludes or has concluded a contract including the Terms & Conditions as well as the Annex to the Terms & Conditions with DAR TECH for the use of the DAR Lean Platform. The Contractual Partner is by default the owner of a Workspace.
      • Interested Party means any natural person who is not yet a User of the DAR Lean Platform but has received the invitation to use it.
      • User means any natural person, including a Contractual Partner, who uses the DAR Lean Platform. A User can be assigned one of the following roles:
        • Owner: A registered User who is or can act on behalf of the Contractual Partner and who is granted access to a Workspace, including, but not limited to set up such Workspace, grant and configure access to such Workspace and manage the rights and permissions of Users who are assigned to such Workspace. The Owner has full control over the Workspace and can develop, configure, and customise it to meet the organisational needs of the Contractual Partner. The Owner is, on behalf of the Contractual Partner, permitted to request the deletion of a Workspace or Workspace Data from DAR TECH.
        • Administrator: A registered User who has the same privileges as the Owner, except for the ability to request the deletion of a Workspace.
        • Member: A registered User who is an employee of a Contractual Partner and who is assigned to a Workspace belonging to the Contractual Partner. The Member is authorised to use the modules of the DAR Lean Platform within the limits set by an Owner or Administrator and the subscription model of the DAR Lean Platform chosen by the Contractual Partner.
        • Guest: A registered User who is an outsource employee, outside partner or any external member of the Contractual Partner and who is assigned to a Workspace belonging to the Contractual Partner. The Guest is authorised to use the modules of the DAR Lean Platform within the limits set by an Owner or Administrator and the subscription model of the DAR Lean Platform chosen by the Contractual Partner. As compared to a Member, the Guest usually has fewer permissions, such as read-only mode.
        • Visitor: A User who visits the DAR Lean Platform without being registered or logged in.
  3. Categories of Personal Data

    1. Data that DAR TECH as Controller collects from the User ("DAR TECH Data"):

      • Master Data: This includes Personal Data that is necessary for establishing a contractual relationship with the Contractual Partner and for billing, as well as for establishing a User account inter alia the name (including any academic titles), the job title, the employer, the address (street, postal code/city, country), the location of the registration, account data, other payment data or information, the tax number, a unique User ID and the affiliation to one or more Workspaces.
      • Sign-in Data: This includes the User's credentials required to log in to the DAR Lean Platform, such as, the email address, a password or an SSO token (E-Mail, other social network ID including, but not limited to Facebook, Google). The SSO services are described in Section 9.
      • Profile Data:This includes Personal Data that a User enters to create or update their profile, such as the name, the contact, social links (social network name), telephone number, e-mail- address, data on the employment contract and a description of such person.
      • Correspondence Data: This includes Personal Data that arise in correspondence between DAR TECH and a User, for example, when a User submits a support request to DAR TECH via the DAR Lean Platform, by e-mail or telephone, such as the User's e-mail address or telephone number and the message content.
      • Session Data: This includes the session ID assigned to a User while logging in to the DAR Lean Platform.
      • Connection Data: This includes Personal Data of a technical nature that is collected in connection with the use of the DAR Lean platform, such as the URL accessed by the User, the timestamp (date/time), browser type/browser version, the operating system used, the referrer URL and the IP address, the geolocation of the User, date and time of visits.

      In general, the Contractual Partner as well as the User is not required to provide Personal Data. However, this may possibly result in DAR TECH not being able to provide all services of the DAR Lean Platform. For example, the non-disclosure of Master Data may lead to the fact that no contractual relationship can be established between the Contractual Partner and DAR TECH. Likewise, the non-disclosure of Correspondence Data may result in DAR TECH not being able to answer inquiries/requests or give support.

    2. Data that DAR TECH as Processor processes on behalf of a Contractual Partner ("Workspace Data"):

      This includes all Personal Data that a User enters by using the various modules of the DAR Lean Platform within a Workspace, in particular:

      • Invitation Data: This includes Personal Data entered by the User for the purpose of inviting an Interested Party, such as in particular the e-mail address as well as the intended role.
      • Collaboration Data: This includes Personal Data that occurs as a result of multiple Users interacting with each other or within a Team, specifically Personal Data contained in project plans, functional personal tasks, meeting notes, Personal Data related to video conferencing (including video transmissions), or related User assignments/assignments.
      • Team Data: This includes Personal Data related to the Team (including human resources) of a Workspace, in particular listings of Users, roles, hierarchies, employee contract terms (if applicable), working time records, leave dates and types.
      • Work Data: This includes Personal Data related to tasks, in particular the assignment of Users to tasks, Personal Data related to processes, projects or budgets.
      • Media Data: This includes Personal Data contained in uploaded files, such as Word and PDF files, image, video and audio files.
  4. Areas in which DAR TECH acts as Controller and areas in which DAR TECH acts as Processor

    1. DAR TECH as Controller regarding DAR TECH Data

      DAR TECH Limited, Themistokli Dervi, 3, Julia House, CY-1066 Nicosia, Cyprus, is the sole data Controller for the Processing of DAR TECH data and for the purposes set forth in Section 5 in accordance with Article 4 (7) of the UK GDPR and Article 4 (7) of the EU GDPR.

    2. DAR TECH as Processor of the contracting party regarding Workspace Data

      DAR TECH Limited, Themistokli Dervi, 3, Julia House, CY-1066 Nicosia, Cyprus, processes Workspace Data on behalf of the Contractual Partner pursuant to Article 28 of the UK GDPR and Article 28 of the EU GDPR and in accordance with the Annex to the Terms & Conditions and is therefore a Processor pursuant to Article 4 (8) of the UK GDPR and Article 4 (8) of the EU GDPR. The Processing operations that DAR TECH performs on behalf of the Contractual Partner are, for example:

      • Sending an invitation email to an Interested Party based on a User's entry of Invitation Data.
      • Storage and provision of Collaboration Data, Team Data and Work Data according to the permissions set by a User in each case.

      Regarding the Processing of Workspace Data, the Contractual Partner shall be the independent and sole Controller in accordance with Article 4 (7) of the UK GDPR and Article 4 (7) of the EU GDPR; joint responsibility with DAR TECH is excluded.

  5. Purposes of Processing

    DAR TECH processes DAR TECH Data as Controller for the following purposes:

    • Provision of the DAR Lean Platform
      • Registration, creation of a User account: DAR TECH processes Master Data and Sign-in Data of the User in order to enable the User to register for the first time to the DAR Lean Platform and to set up a User account.
      • Sign-in and provision of the available modules of the DAR Lean Platform: DAR TECH processes Sign-in Data of the User as well as Session Data in order to enable the User to log-in to the DAR Lean Platform and use it accordingly. The SSO services are further described in Section 9.
      • Display of the DAR Lean Platform: DAR TECH processes certain Connection Data to enable the User to fully and properly display the DAR Lean Platform.
      • Optimised loading of the DAR Lean Platform: DAR TECH processes certain Connection Data to improve the performance of the DAR Lean Platform, for example because some components are loaded from external Content Deployment Networks (CDN).
      • Personalisation of the DAR Lean Platform: DAR TECH processes certain Master Data as well as Profile Data to personalise the DAR Lean Platform for the respective User. Such personalisation includes, inter alia, the subscriptions to Workspaces by the User.
      • Ordering of services, billing including debt collection: DAR TECH processes Master Data and, if necessary, Correspondence Data and Connection Data in order to be able to bill a Contractual Partner for services relating to the DAR Lean Platform and, if necessary, to pursue them (also in court).
    • Communication with the User
      • Communication (User Request/Support): DAR TECH processes Master Data as well as Correspondence Data in order to be able to contact and correspond with the User, inter alia to be able to answer enquiries and provide support, in particular by means of the contact form on the DAR Lean Platform or by e-mail.
      • Communication (Transactional): DAR TECH processes Master Data as well as Correspondence Data to send transactional messages (including e-mails) to the User or Contractual Partner. Transactional messages, include, inter alia, important messages related to the account, a Workspace or User credentials (e.g. notification about a password reset) or information about changes/amendments relating to contracts between the User and DAR TECH or this Privacy Statement.
      • Newsletter: DAR TECH processes certain Master Data to send the User a newsletter by e-mail based on the prior registration of the User. However, DAR TECH will only process this Personal Data for this purpose if the User has given their prior consent. This consent can be withdrawn at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.
    • Security and abuse prevention
      • IT Security: DAR TECH processes DAR TECH Data as well as - exclusively in justified cases and only to the extent absolutely necessary in accordance with the Terms & Conditions - Workspace Data (excluding special categories of data as described in Article 9 (1) of the UK GDPR and Article 9 (1) of the EU GDPR) to ensure the security and operability of the DAR Lean Platform. This includes, in particular, Processing carried out in connection with technical and organisational measures to detect, prevent and track attacks on the DAR Lean Platform. If certain Workspace Data is found to affect IT security (e.g. because certain files contain viruses), DAR TECH reserves the right to delete such data in accordance with the Terms & Conditions as well as the Annex to the Terms & Conditions and to immediately inform the Contractual Partner. DAR TECH will, however, never transfer such data to third parties, unless explicitly required to do so by applicable UK, Union or Member State law.
      • Prevention of fraud and abuse: DAR TECH processes DAR TECH Data as well as - exclusively in justified cases and only to the extent absolutely necessary in accordance with the Terms & Conditions - Workspace Data (excluding special categories of data as described in Article 9 (1) of the UK GDPR and Article 9 (1) of the EU GDPR) to be able to detect, prevent and prosecute abuse of the DAR Lean Platform (in particular the use of the DAR Lean Platform by the User contrary to the Terms & Conditions, use of a User account by several persons, data and credit card fraud, upload of illegal content).
    • Fulfilment of legal obligations under Cypriot and European law
      • Information, Recording and Retention Obligations: DAR TECH processes all DAR TECH Data to comply with statutory disclosure, recording and retention obligations, in particular those under tax and commercial law.
      • Exercise of data subject rights: DAR TECH processes all DAR TECH Data in order to fulfil Users’ data subject rights pursuant to the UK GDPR and the EU GDPR (see Section 14 in detail) and to be able to respond to them.
    • Analysis and optimisation of the DAR Lean Platform
      • Improvement of the DAR Lean Platform: DAR TECH processes certain Connection Data to be able to analyse and optimise the operation of the DAR Lean Platform, inter alia to find and understand bugs of the DAR Lean Platform. The services used for this purpose as well as the relevant data being processed by these services including the legal bases for Processing are further described in Section 8.
      • Analysis of the User structure: DAR TECH processes DAR TECH Data to be able to understand the geographical presence, gender, age and product patterns of Users who use the DAR Lean Platform, as well as to understand the usage habits and usage frequency as well as the satisfaction of tools provided within the DAR Lean Platform, in order to personalise the appearance of the DAR Lean Platform and to evaluate the useability and effectiveness of the modules within the DAR Lean Platform. The services used for this purpose as well as the relevant data being processed including the legal bases for Processing are described in Sections 6 to 8.
    • Further purposes
      • Purposes which require consent: DAR TECH may process Personal Data for additional purposes, which will be communicated to the User in this Privacy Statement as amended from time to time or otherwise as the occasion arises. Processing will only take place if the User has given prior consent to such Processing. Consent can be withdrawn easily at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.
      • Purposes stated elsewhere within this Privacy Statement: DAR TECH may also process Personal Data for purposes and on the basis of the legal bases set forth in Sections 6 to 8.
  6. Legal Bases of Processing

    Unless specified otherwise, DAR TECH processes DAR TECH Data for the purposes set forth in Section 5 based on one or more of the following legal bases:

    • Performance of a contract:DAR TECH processes DAR TECH Data on the basis of a contractual agreement concluded with the Contractual Partner regarding the use of the DAR Lean Platform or in order to take steps at the request of the Contractual Partner prior to entering into a contract, insofar as the Processing is necessary for this purpose (Article 6 (1) (b) of the UK GDPR and Article 6 (1) (b) of the EU GDPR).
    • Legal obligation: DAR TECH processes DAR TECH Data based on a legal obligation to which DAR TECH is subject to (Article 6 (1) (c) of the UK GDPR and Article 6 (1) (c) of the EU GDPR).
    • Legitimate interest: DAR TECH processes DAR TECH Data as well as - exclusively in justified cases and only to the extent absolutely necessary in accordance with the Terms & Conditions as well as the Annex to the Terms & Conditions – Workspace Data (excluding special categories of data as described in Article 9 (1) of the UK GDPR and Article 9 (1) of the EU GDPR) based on its legitimate interest (Article 6 (1) (f) of the UK GDPR and Article 6 (1) (f) of the EU GDPR). Unless otherwise stated, the legitimate interests of DAR TECH are, in particular,
      • to establish and maintain a proper contract and User management;
      • to ensure the proper provision and functioning of the DAR Lean Platform;
      • to maintain the security and performance of the IT infrastructure used by DAR TECH;
      • to understand how the DAR Lean Platform is used, especially to identify usage habits and preferences;
      • to evaluate the performance of the DAR Lean Platform;
      • to personalise the DAR Lean Platform to the respective User preferences;
      • to find and eliminate bugs of the DAR Lean Platform; and
      • to be able to detect and stop any misuse of the DAR Lean Platform.
      • If referred to separately, DAR TECH also processes DAR TECH Data, based on a previously given and voluntary consent (Article 6 (1) (a) of the UK GDPR and Article 6 (1) (a) of the EU GDPR) by the User. The User is entitled to revoke this consent at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.

  7. Transfer of Personal Data to Recipients

    1. Transfer to categories of recipients

      Personal Data will be transferred by DAR TECH for the purposes mentioned in Section 5 to one or more of the following categories of Recipients:

      • banks (e.g. in order to facilitate bank transfers);
      • tax advisors (e.g. in order to carry out proper accounting);
      • lawyers and collection agencies (e.g. to collect outstanding debts or exercise other legal rights);
      • courts and public authorities (e.g. to report and clarify legally relevant facts or to enforce claims);
      • external services as described in Sections 7.2 and 8;
      • Single Sign-on providers as described in Sections 7.2 and 9.

      The data is also transferred if DAR TECH is legally obliged to do so.

    2. Overview of transmission to external services

      DAR TECH also transfers Personal Data to the service providers listed below

      • DAR Solutions LLP., Almaty, Koktem microdistrict 2 – 22, Kazakhstan, based on a Processing agreement concluded with DAR TECH pursuant to Article 28 of the EU GDPR. DAR Solutions LLP processes DAR TECH Data on behalf of DAR TECH to provide technical assistance and development relating to the DAR Lean Platform and to provide support for Users. DAR Solutions LLP as well as DAR TECH are companies of the same group.
      • Web Tool Providers, as described in detail in Section 8:
        • Ynot Partners, Inc.,316 High Street, Palo Alto, CA 94301, USA, as operator of the "Userguiding.com" service, a User onboarding tool.
        • BITRIX24 LIMITED, Poseidonos, 1, LEDRA BUSINESS CENTRE, 'Egkomi 2406, Lefkosia, Cyprus, as operator of the service "Bitrix24.eu", a Content Delivery Network (CDN).
        • Stripe Payments Europe Limited 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland as operator of "Stripe", an online payment service.
        • Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland as operator of the services "Google Tag Manager" as well as "DialogFlow".
        • Volentio JSD Limited, Suite 2a1, Northside House, Mount Pleasant, Barnet, England, EN4 9EB, as operator of the service "jsDelivr", a Content Delivery Network (CDN) for open-source files, such as common frontend libraries like ReactJS.
        • Tilda Publishing Ltd., Regus Pembroke House, 28 - 32 Pembroke Street Upper, Dublin 2, Ireland, D02 NT28, as operator of the service “Tilda”.
        • Cloudflare, Inc, 101 Townsend St, San Francisco, CA 94107, USA, as operator of the service “Unpkg”.
      • Single Sign-on Providers as described in detail in Section 9:
        • Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (operator of the Service “Facebook Single Sign-on”).
        • Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (operator of the service "Google Single Sign-on”).
      • Hosting provider:
        • AMAZON WEB SERVICES EMEA SOCIÉTÉ À RESPONSABILITÉ LIMITÉE38 Avenue John F. Kennedy, L-1855 Luxembourg, Registration number: B186284 (operator of the service "AWS"): DAR TECH uses this service to provide the platform (hosting of the DAR Lean Platform). More detailed information can be found here: https://aws.amazon.com/de/compliance/gdpr-center/. The legal basis is the legitimate interest of DAR TECH (Article 6 (1) (f) of the UK GDPR and Article 6 (1) (f) of the EU GDPR), which lies in being able to fulfil the aforementioned purpose; also the fulfilment of contracts with Contractual Partners (Article 6 (1) (b) of the UK GDPR and Article 6 (1) (b) of the EU GDPR).
  8. Web Tools including the Cookies set by these tools

    1. Introduction and Technical Explanation

      DAR TECH utilises certain web tools as further described in Sections 8.2 to 8.9. Some of these web tools may utilise cookies. The link to the Consent Tool (including cookies) can be found here: Cookie-Banner.

      For detailed information about the Cookies set by the individual services listed below please refer to the https://darlean.com/cookies.

    2. Bitrix24.eu

      Bitrix24.eu is an external service provided by BITRIX24 LIMITED, Poseidonos, 1, LEDRA BUSINESS CENTRE, 'Egkomi 2406, Lefkosia, Cyprus.

      DAR TECH uses this service for the purpose of organizing communication with Users, thus to be able to answer User enquiries and provide support, as well as to enable proper presentation of the DAR Lean Platform and to optimise speed (for example by sideloading fonts). Among the data collected is the User name, the User phone number and the User e-mail-address.

      The legal basis is the legitimate interest of DAR TECH (Article 6 (1) (f) of the UK GDPR and Article 6 (1) (f) of the EU GDPR) to achieve the aforementioned purposes. The Service Provider makes its Privacy Policy available at the following location: https://www.bitrix24.eu/gdpr/.

    3. Stripe

      Stripe is an external service offered and operated by Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland.

      Stripe is an online payment service provider. If the Contractual Partner makes a payment via the DAR Lean Platform, the relevant payment data (name, address, data on bank details), the IP address and data on the contract concluded with DAR TECH are transmitted to the payment service provider who subsequently stores the data.

      DAR TECH uses this service to perform the billing (Processing regarding payment). The legal basis is the fulfilment of the contract (Article 6 (1) (b) of the UK GDPR and Article 6 (1) (b) of the EU GDPR) vis-à-vis the Contractual Partner; if cookies are used, additionally the prior consent of the Contractual Partner (Article 6 (1) (a) of the UK GDPR and Article 6 (1) (a) of the EU GDPR).

      The Service Provider makes its Privacy Policy available at the following location: https://stripe.com/gb/privacy.

    4. Google Tag Manager

      Google Tag Manager is an external service offered and operated by Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

      Google Tag Manager is a tag management system with which tracking codes and associated code fragments can be centrally integrated, managed and updated on the DAR Lean Platform. The service is provided by Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

      The Google Tag Manager serves as a mere system for passing through other tools, is hosted locally and does not transfer any Personal Data to Google. Information on Processing in connection with these other tools can be found under the respective tools in this Privacy Statement.

      The service provider makes its privacy policy available at the following location: https://policies.google.com/technologies/partner-sites?hl=de&hl=de

    5. DialogFlow

      DialogFlow is an external service offered and operated by Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

      DialogFlow is a natural language understanding platform used to design and integrate a conversational user interface into mobile apps, web applications, devices, bots, interactive voice response systems and related uses.

      DAR TECH uses DialogFlow to offer advice and to respond to Users’ requests by implementing the service into a chatbot solution. DialogFlow uses machine learning to understand inputs and respond accordingly. In general, DialogFlow does not request Personal Data from Users.

      Google Ireland Limited, Google LLC or Alphabet Inc. may anonymise the dialog created by the User and the DAR Lean Platform and subsequently use it to improve and train the DialogFlow product.

      The legal basis for Processing is the consent given by the User in accordance with Articles 6 (1) (a) and 49 (1) (a) of the UK GDPR and Article 6 (1) (a) and 49 (1) (a) of the EU GDPR. See in detail Section 11. Consent can be withdrawn at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.

      Possible data Recipients are:

      • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (as Processor according to Article. 28 of the UK GDPR and Article 28 of the EU GDPR)
      • Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA
      • Alphabet Inc, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA

      The service provider makes its privacy policy available at the following location: https://cloud.google.com/dialogflow/docs/data-logging-terms?hl=en.

    6. jsDelivr

      jsDelivr is an external service offered and operated by Volentio JSD Limited, Suite 2a1, Northside House, Mount Pleasant, Barnet, England, EN4 9EB. It is a Content Delivery Network (CDN) for open-source files, such as common frontend libraries like ReactJS.

      DAR TECH uses this service to automatically keep certain libraries used for the DAR Lean Platform up to date by automatically including the latest distribution into it. This is necessary to safeguard IT Security and to optimize the loading time of the DAR Lean Platform. When the User accesses the DAR Lean Platform, certain Connection Data to the aforementioned service provider is transmitted.

      The legal basis for Processing is the legitimate interest of DAR TECH (Article 6 (1) (f) of the UK GDPR and Article 6 (1) (f) of the EU GDPR) which is to be able to fulfil the aforementioned purposes, especially to keep the DAR Lean Platform up to date and to avoid security flaws caused by outdated libraries.

      The service provider makes its privacy policy available at the following location: https://www.jsdelivr.com/terms/privacy-policy-jsdelivr-net.

    7. Matomo

      Matomo is an open source web analytics application to track online visits to websites and display reports on these visits for analytics. DAR TECH uses this service to statistically analyze the User structure and subsequently optimize the DAR Lean Platform. DAR TECH collects the following Personal Data: User IP address, Optional User ID, Date and time of the request, Title of the page being viewed (Page Title), URL of the page being viewed (Page URL), URL of the page that was viewed prior to the current page (Referrer URL), Screen resolution being used, Time in local user’s timezone, Files that were clicked and downloaded (Download), Links to an outside domain that were clicked (Outlink), Pages generation time (the time it takes for webpages to be generated by the webserver and then downloaded by the user: Page speed), Location of the user: country, region, city, approximate latitude and longitude, Main Language of the browser being used, User Agent of the browser being used, Random unique Visitor ID, Time of the first visit for this user, Time of the previous visit for this user, Number of visits for this user.

      The legal basis for Processing is the legitimate interest of DAR TECH pursuant to Article 6 (1) (f) of the UK GDPR and Article 6 (1) (a) of the EU GDPR to improve the DAR Lean Platform and to understand the user structure. If cookies are set, the legal basis for Processing is consent given by the User in accordance with Article 6 (1) (a) of the UK GDPR and Article 6 (1) (f) of the EU GDPR. Consent can be withdrawn at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.

      DAR TECH is using the Matomo Cloud service (“matomo.cloud”) , which is provided by InnoCraft Ltd, 7 Waterloo Quay, PO625, 6140 Wellington, New Zealand (“InnoCraft”), to store the aforementioned Personal Data. The European Commission has determined that New Zealand has an adequate level of data protection pursuant to Article 45 GDPR (Commission Implementing Decision 2013/65/EU pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of Personal Data by New Zealand). However, all Personal Data is stored on servers within the European Union. InnoCraft publishes its “Matomo Cloud Privacy Policy” under https://matomo.org/matomo-cloud-privacy-policy/. DAR TECH has concluded a data Processing agreement pursuant to Article 28 GDPR whose text can be accessed under https://matomo.org/matomo-cloud-dpa/.

    8. Tilda

      Tilda is an external service offered and operated by Tilda Publishing Ltd., Regus Pembroke House, 28 - 32 Pembroke Street Upper, Dublin 2, Ireland, D02 NT28.

      Tilda is a no-code website builder and content delivery network (CDN) service. Its purpose is to deliver web content – inter alia web pages, videos and/or audio files – to the User. The purpose of this service is to increase the performance of the DAR Lean Platform and to provide the User with visually appealing web pages. When the User visits the DAR Lean Platform, a connection to servers of the Service Provider is made and Connection Data is processed.

      The legal basis is the legitimate interest of DAR TECH (Article 6 (1) lit f EU GDPR and Article 6 (1) lit f UK GDPR) to achive the aforementioned purposes.

      The Service Provider makes its Privacy Policy available at the following location: https://tilda.cc/privacy/. DAR TECH has concluded a data Processing agreement pursuant whose text can be accessed under https://tilda.cc/dpa/. According to the Service Provider, Personal Data of Users within Europe or the USA is stored on servers within the European Union. The technical information of Tilda can be accessed under https://tilda.cc/lp/technical-information/.

    9. Unpkg

      Unpkg is an external service offered and operated by Cloudflare, Inc, 101 Townsend St, San Francisco, CA 94107, USA (“Cloudflare”).

      Unpkg is a global content delivery network (CDN) for JavaScript packages; it delivers such JavaScript packages to the User. The purpose of this service is to increase the performance of the DAR Lean Platform and to enable DAR TECH to include the most recent versions of such JavaScript packages into the DAR Lean Platform. This relieves DAR TECH from manually updating these packages; it furthermore also guarantees the security of the DAR Lean Platform. When the User visits the DAR Lean Platform, a connection to servers of the Service Provider is made and Connection Data is processed.

      The legal basis is the legitimate interest of DAR TECH (Article 6 (1) lit f EU GDPR and Article 6 (1) lit f UK GDPR) to achive the aforementioned purposes. Cloudflare outlines its GDPR compliance under https://www.cloudflare.com/trust-hub/gdpr/#gdprfaq. Its privacy policy is available under https://www.cloudflare.com/privacypolicy/.

      Cloudflare ensures and provides sufficient guarantees that European data protection law is complied with. Cloudflare is certified under the EU-US Privacy Framework. For the USA, the European Commission adopted its adequacy decision on July 10, 2023.

      The User can prevent the collection and Processing of Personal Data by Cloudflare by deactivating the execution of script code or by installing a script blocker in the web browser.

  9. Single Sign-on

    1. Facebook Single Sign-on

      Facebook Single Sign-on is an authentication (single sign-on) service operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (formerly Facebook, Inc).

      DAR TECH uses this service to allow users to log in to the platform using the Facebook login without having to create a specific user account (with individual email and password).

      The legal basis for Processing is the explicit consent given by the User in accordance with Articles 6 (1) (a) and 49 (1) (a) of the UK GDPR and Articles 6 (1) (a) and 49 (1) (a) of the EU GDPR. See in Detail Section 6 (Legal Basis) and Section 11 (Data Export). Such explicit consent is given by the User clicking on the "Facebook" button on the login page of the DAR Lean Platform. Consent can be withdrawn at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.

      The service provider makes its privacy policy available at the following location: https://www.facebook.com/privacy/policy/.

    2. Google Single Sign-On

      Google Single Sign-on is an authentication (single sign-on) service operated by Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

      DAR TECH uses this service to allow users to log in to the platform using the Google login without having to create a specific user account (with individual email and password).

      The legal basis for Processing is the explicit consent given by the User in accordance with Articles 6 (1) (a) and, if applicable, 49 (1) (a) of the UK GDPR and Articles 6 (1) (a) and 49 (1) (a) of the EU GDPR. See in Detail Section 6 (Legal Basis) and Section 11 (Data Export). Such explicit consent is given by the User clicking on the "Google" button on the login page of the DAR Lean Platform. Consent can be withdrawn at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.

      The service provider makes its privacy policy available at the following location: https://policies.google.com/privacy?hl=en.

  10. Specific Information for the DAR Lean App

    This section provides additional information on the Processing of Personal Data in connection with the use of the DAR Lean App.

    1. Provision of the DAR Lean App for Downloading

      DAR TECH enables the User to download the DAR Lean App via various internet-based digital distribution platforms for application software. The download via these distribution platforms usually requires that the User has previously registered with the distribution platforms used. The distribution platforms on which the DAR Lean app is offered for download are:

      • App Store: This is a distribution platform for application software offered and operated by Apple Inc. or other legal entities of Apple. Apple's privacy policy is available at https://www.apple.com/legal/privacy.
      • Play Store: This is a distribution platform for application software offered and operated by Google LLC or another legal entity of Google. Google's privacy policy is available at https://policies.google.com/privacy.

      DAR TECH has neither knowledge nor influence of the way in which and the purposes for which these distribution platforms process the User's Personal Data.

  11. Transfer to third countries and international organisations

    Some of the Recipients listed above are located outside the UK or process Personal Data outside of the UK. DAR TECH may transfer Personal Data to service providers that carry out certain functions on its behalf. This may involve transferring Personal Data outside the UK and the EEA to countries which have laws that do not provide the same level of data protection as the UK or the EEA.

    Whenever DAR TECH transfers Personal Data to service providers outside of the UK, DAR TECH ensures a similar degree of protection is afforded to such Personal Data by ensuring that the countries have been deemed by the UK to provide an adequate level of protection for Personal Data, namely, countries in the EEA (particularly Cyprus, Ireland, Luxembourg), or by implementing the following safeguards:

    Data recipient Service Third country Legal basis for data export
    Alphabet Inc DialogFlow USA Standard Contractual Clauses (SCC), Explicit consent (Article 49 (1) lit a GDPR)
    Google LLC DialogFlow, Google SSO USA Explicit consent (Article 49 (1) lit a GDPR), Standard Contractual Clauses (SCC) or by way of the EU-US Data Privacy Framework
    Meta Platforms Ireland Limited Facebook Single Sign-On USA Explicit consent (Article 49 (1) lit a GDPR)
    DAR Solutions LLP. Technical Assistance and Development, User Support Kazakhstan Standard Contractual Clauses (SCC)
    Volentio JSD Limited jsDelivr UK Adequacy Decision (EU) 2021/1772 or by way of Standard Contractual Clauses (SCC).
    InnoCraft Ltd Matomo.Cloud NZ Adequacy Decision (EU) 2013/65, as amended by Commission Implementing Decision (EU) 2016/2295.
    Cloudflare, Inc Unpkg USA EU-US Data Privacy Framework

    In general, DAR TECH transfers Personal Data only to countries for which the EU Commission has published adequacy decisions, or measures are taken by DAR TECH to ensure that all Recipients can guarantee an adequate level of data protection. For example, standard contractual clauses (pursuant to Implementing Decision (EU) 2021/914) will be concluded for this purpose. DAR TECH will make these standard contractual clauses available upon request.

    In July 2023 the European Commission adopted its adequacy decision for the EU-US Data Privacy Framework (DPF). The decision concludes that the United States ensures an adequate level of protection – comparable to that of the EU – for Personal Data transferred from the EU to US organisations under the new framework. On the basis of the new adequacy decision, Personal Data can flow safely from the EU to US companies participating in the DPF, without having to put in place additional data protection safeguards.

    If no adequacy decision exists, the organisations are not participating in the DPF, or if DAR TECH has not concluded standard contractual clauses with the respective service provider, DAR TECH will obtain the User's explicit consent prior to transmission. Explicit consent obtained for Processing for the respective Processing purpose pursuant to Article 6 (1) (a) of the UK GDPR and Article 6 (1) (a) of the EU GDPR shall also be deemed to be consent in accordance with Article 49 (1) (a) of the UK GDPR and Article 49 (1) (a) of the EU GDPR.

    Due to the U.S. Cloud Act there may be a right of access to data stored by organisations not registered with the DPF by the American government, even if the data is not stored in the USA. It might be possible that an authority or other government agency, in particular an intelligence service, could request access to certain User data from these Recipients without first obtaining a court order. It is also possible that, if such a request is fulfilled by the service provider, the User may lack legal protection against such access, such as a right to information or a right of complaint.

  12. Storage duration

    DAR TECH stores Personal Data for the period necessary to achieve the purposes set forth in this Privacy Statement and, in addition, for the duration of any statutory retention obligation. In particular, the following storage or retention periods apply, unless European or Cypriot law provides otherwise:

    • Master Data, Profile Data, and Sign-in Data of Users are stored for at least the duration of the existence of the User relationship with DAR TECH and then for a subsequent period of 3 years after the termination of the account.
    • Correspondence Data will be stored at least for the duration of the existence of the User relationship with DAR TECH, but no longer than 3 years after the termination of the account.
    • Session Data is stored for the duration of the visit to the DAR Lean Platform and deleted at the earliest after logout, but at the longest after 72 hours.
    • If the sole legal basis for Processing is consent, Personal Data is stored until such consent is withdrawn; after that, such Personal Data is deleted, as long as there are no other legitimate purposes for which this Personal Data is processed, such as legal retention periods. Depending on the purpose for which the consent was given, the Processing time within which DAR TECH complies with the request may be a maximum of 7 days after the withdrawal of consent.
  13. Automated decision making including profiling

    DAR TECH does not process Personal Data for the purpose of automated decision-making, including profiling.

  14. Rights of data subjects in connection with Personal Data

    1. Overview of rights of data subjects

      Data Subjects whose Personal Data is processed by DAR TECH are entitled – to:

      • request information as to whether and which Personal Data of the Data Subject DAR TECH is Processing and to receive further information on such Processing; also to receive copies of such data (Article 15 of the UK GDPR and Article 15 of the EU GDPR);
      • request the correction or completion of Personal Data (Article 16 of the UK GDPR and Article 16 of the EU GDPR);
      • request the deletion of Personal Data that is incorrect or processed in a way that does not comply with the law (Article 17 of the UK GDPR and Article 17 of the EU GDPR);
      • request DAR TECH to restrict the Processing of the Personal Data (Article 18 of the UK GDPR and Article 18 of the EU GDPR);
      • know the identity of third parties to whom the Personal Data is transferred (Article 19 of the UK GDPR and Article 19 of the EU GDPR);
      • request data portability, provided that the Processing is based on the legal grounds of consent or the performance or initiation of a contract and is carried out by means of automated processes (Article 20 of the UK GDPR and Article 20 of the EU GDPR);
      • object to the Processing of Personal Data under certain circumstances, whereby an objection to the Processing for purposes of direct marketing is possible at any time without stating reasons (Article 21 of the UK GDPR and Article 21 of the EU GDPR);
      • if the Processing is based on the legal basis of consent, to withdraw the consent, whereby such withdrawal shall not affect the lawfulness of the Processing carried out on the basis of the consent until the withdrawal (Article 7 (3) of the UK GDPR and Article 7 (3) of the EU GDPR);
      • file a complaint with the competent supervisory or regulatory authority: for the UK, the Information Commissioner's Office, Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF, or for Cyprus, the Commissioner for Personal Data Protection, Iasonos 1, 1082 Nicosia, Cyprus.
    2. Exercise of Rights

      Whenever DAR TECH acts as Controller relating to DAR TECH Data (e.g. correspondence between the User and DAR TECH), the rights as described in Section 14.1 will be satisfied directly by DAR TECH within the timelines set by applicable law.

      Whenever DAR TECH acts as processor relating to Workspace Data (e.g. when the User has written or was mentioned in meeting notes, or when a User requests the deletion of a file uploaded by him/her), DAR TECH will, after the receipt of such request, immediately transmit this request to the competent Contractual Partner as Controller of the Workspace the User is assigned to. Such a request is usually not directly answered by DAR TECH, but satisfied directly by the Contractual Partner, as DAR TECH is not a controller regarding this category of Personal Data. Only after having received a documented instruction of the Contractual Partner, DAR TECH may answer the request on behalf of the Contractual Partner as described in the Terms & Conditions as well as the Annex to the Terms & Conditions.

  15. Contact details of DAR TECH as Controller

    For enquiries regarding data protection or the exercise of Data Subject rights, please contact exclusively:

    DAR TECH Limited

    Themistokli Dervi, 3, Julia House

    CY-1066 Nicosia

    Cyprus

    E-mail: info-eu@darlean.com

  16. Changes to the Privacy Policy and your duty to inform DAR TECH of changes

    DAR TECH keeps this Privacy Statement under regular review. This version was last updated on June 10, 2024. Historic versions can be obtained by contacting DAR TECH using the contact details in Section 15. DAR TECH reserves the right to change and/or amend this Privacy Statement from time to time.

    It is important that the Personal Data DAR TECH holds about Users is accurate and current. Users should keep DAR TECH informed (using the respective functions on the Platform or the contact details in Section 15) if their Personal Data changes during their relationship with DAR TECH, for example a new address or email address.

  17. Changes to the Privacy Policy and your duty to inform DAR TECH of changes

    This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about individuals. DAR TECH does not control these third-party websites and is not responsible for their privacy statements. When a User leaves our website, DAR TECH encourages each User to read the privacy policy of every website visited.

Privacy Statementfor the use of the DAR Lean Platform of of DARLEAN US CORP. ("DARLEAN US")
Last updated: December 1, 2024
Table of Contents:
  1. Preamble and scope of this Privacy Statement
  2. Definitions
  3. Categories of Personal Data
  4. Areas in which DARLEAN US acts as Controller and areas in which DARLEAN US acts as Processor
  5. Purposes of Processing
  6. Legal Bases of Processing
  7. Transfer of Personal Data to Recipients
  8. Web Tools including the Cookies set by these tools
  9. Single Sign-on
  10. Specific Information for the DAR Lean App
  11. Storage duration
  12. Automated decision making including profiling
  13. Rights of data subjects in connection with Personal Data
  14. Contact details of DARLEAN US as Controller
  15. Changes to this Privacy Statement and your duty to inform DARLEAN US of changes
  16. Third-party Links
  1. Preamble and scope of this Privacy Statement

    This Privacy Statement applies to the use of the following websites and/or applications offered and operated by DARLEAN US CORP., 850 New Burton Road, Suite 201, Dover, DE 19904 (in short, "DARLEAN US"), including all videos, recordings, sounds, texts, graphics and other materials sent, received, stored or otherwise displayed via the following services:

    • the "DAR Lean" landing pages, accessible via the address https://www.darlean.com;
    • the “DAR Lean” web platform, accessible via the address https://app.darlean.com;
    • the application "DAR Lean", which is available for download via the digital distribution platforms App Store (Apple) as well as Play Store (Google).
    • DARLEAN US provides the following information in this regard:

    • with regard to which Processing operations DARLEAN US shall be deemed to be the Controller or Processor;
    • which Personal Data DARLEAN US processes;
    • the purposes for which DARLEAN US processes Personal Data;
    • the legal bases on which DARLEAN US relies to process Personal Data;
    • to whom and to which entities DARLEAN US transfers Personal Data;
    • how long DARLEAN US stores Personal Data;
    • which external tools and plugins DARLEAN US uses;
    • what rights data subjects have with regard to their Personal Data;
    • how DARLEAN US can be reached in connection with data protection issues as well as the exercise of data subject rights.

    With this Privacy Statement, DARLEAN US fulfils its information obligations under data protection law within the meaning of Articles 12 to 14 GDPR.

    The definitions used in this Privacy Statement refer exclusively to this Privacy Statement and do not affect the definitions in DARLEAN US's Terms and Conditions (T&C).

  2. Definitions

    1. General

      • Personal Data means, unless explicitly stated otherwise by applicable Privacy Laws, any information relating to an identified or identifiable natural person (“Data Subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
      • Processing means, unless explicitly stated otherwise by applicable Privacy Laws, any operation or set of operations which is performed on personal data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
      • Controller means, unless explicitly stated otherwise by applicable Privacy Laws, the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data; where the purposes and means of such Processing are determined by EU or Member State law, the controller or the specific criteria for its nomination may be provided for by EU or Member State law.
      • Processor means, unless explicitly stated otherwise by applicable Privacy Laws, a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.
      • Recipient means, unless explicitly stated otherwise by applicable Privacy Laws, a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a third party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with EU or Member State law shall not be regarded as Recipients; the Processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the Processing.
      • Special Categories of Personal Data means, unless explicitly stated otherwise by applicable Privacy Laws, personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation.
      • Privacy Laws means, the applicable data protection laws in connection with this Privacy Statement, the Terms & Conditions, and the Annex to the Terms & Conditions, including inter alia the following as applicable and as amended from time to time:
        • General Data Protection Regulation, Regulation (EU) 2016/679, as it forms part of domestic law in the UK by virtue of section 3 of the European Union (Withdrawal) Act 2018 (UK GDPR);
        • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (EU GDPR).
      • Privacy Statement means this Privacy Statement of DARLEAN US.
      • Terms & Conditions means DARLEAN US's Terms and Conditions.
      • Annex to the Terms & Conditions means DARLEAN US’s Annex to the Terms and conditions which contains provisions relating to the Processing of Workspace Data by DARLEAN US as Processor on behalf of the Contractual Partner as Controller.
      • DARLEAN US means DARLEAN US CORP., 850 New Burton Road, Suite 201, Dover, DE 19904.
      • DAR Lean Platform means the cloud-based internet platform operated by DARLEAN US which allows a Team to organize and manage operational processes as well as teamwork, including, inter alia, productivity tools, processes, planning, HR management and reporting. The DAR Lean Platform consists of the following components:
        • DAR Lean Landing Page: the website operated by DAR TECH at the web addresses https://www.darlean.com, which can be accessed by means of compatible web browsers and on which the DAR Lean Products are presented and promoted.
        • DAR Lean Web Platform: the web platform operated by DAR TECH at the web address https://app.darlean.com, which can be accessed by means of compatible web browsers and on which the individual modules are provided to the Users depending on the selected Subscription of the Contractual Partner.
        • DAR Lean App: the software application offered by DAR TECH, which is made available for download via the App Store offered by Apple Inc. and the Play Store offered by Google Inc. and which, depending on the Contractual Partner's selected Subscription, enables Users to use individual or all modules of the DAR Lean Platform on compatible end devices.
      • Workspace means a virtual Workspace within the DAR Lean Platform in which Users are provided with the possibility to use certain modules or tools.
      • Team means a plurality of Users who are subscribed to the same Workspace.
    2. Roles

      • Contractual Partner means any natural or legal person who concludes or has concluded a contract including the Terms & Conditions as well as the Annex to the Terms & Conditions with DARLEAN US for the use of the DAR Lean Platform. The Contractual Partner is by default the owner of a Workspace.
      • Interested Party means any natural person who is not yet a User of the DAR Lean Platform but has received the invitation to use it.
      • User means any natural person, including a Contractual Partner, who uses the DAR Lean Platform. A User can be assigned one of the following roles:
        • Owner: A registered User who is or can act on behalf of the Contractual Partner and who is granted access to a Workspace, including, but not limited to set up such Workspace, grant and configure access to such Workspace and manage the rights and permissions of Users who are assigned to such Workspace. The Owner has full control over the Workspace and can develop, configure, and customise it to meet the organisational needs of the Contractual Partner. The Owner is, on behalf of the Contractual Partner, permitted to request the deletion of a Workspace or Workspace Data from DARLEAN US.
        • Administrator:A registered User who has the same privileges as the Owner, except for the ability to request the deletion of a Workspace.
        • Member:A registered User who is an employee of a Contractual Partner and who is assigned to a Workspace belonging to the Contractual Partner. The Member is authorised to use the modules of the DAR Lean Platform within the limits set by an Owner or Administrator and the subscription model of the DAR Lean Platform chosen by the Contractual Partner.
        • Guest: A registered User who is an outsource employee, outside partner or any external member of the Contractual Partner and who is assigned to a Workspace belonging to the Contractual Partner. The Guest is authorised to use the modules of the DAR Lean Platform within the limits set by an Owner or Administrator and the subscription model of the DAR Lean Platform chosen by the Contractual Partner. As compared to a Member, the Guest usually has fewer permissions, such as read-only mode.
        • Visitor: A User who visits the DAR Lean Platform without being registered or logged in.
  3. Categories of Personal Data

    1. Data that DARLEAN US as Controller collects from the User ("DARLEAN US Data"):

      • Master Data: This includes Personal Data that is necessary for establishing a contractual relationship with the Contractual Partner and for billing, as well as for establishing a User account inter alia the name (including any academic titles), the job title, the employer, the address (street, postal code/city, country), the location of the registration, account data, other payment data or information, the tax number, a unique User ID and the affiliation to one or more Workspaces.
      • Sign-in Data: This includes the User's credentials required to log in to the DAR Lean Platform, such as, the email address, a password or an SSO token (E-Mail, other social network ID including, but not limited to Facebook, Google). The SSO services are described in Section 9.
      • Profile Data:This includes Personal Data that a User enters to create or update their profile, such as the name, the contact, social links (social network name), telephone number, e-mail- address, data on the employment contract and a description of such person.
      • Correspondence Data: This includes Personal Data that arise in correspondence between DARLEAN US and a User, for example, when a User submits a support request to DARLEAN US via the DAR Lean Platform, by e-mail or telephone, such as the User's e-mail address or telephone number and the message content.
      • Session Data: This includes the session ID assigned to a User while logging in to the DAR Lean Platform.
      • Connection Data: This includes Personal Data of a technical nature that is collected in connection with the use of the DAR Lean platform, such as the URL accessed by the User, the timestamp (date/time), browser type/browser version, the operating system used, the referrer URL and the IP address, the geolocation of the User, date and time of visits.

      In general, the Contractual Partner as well as the User is not required to provide Personal Data. However, this may possibly result in DARLEAN US not being able to provide all services of the DAR Lean Platform. For example, the non-disclosure of Master Data may lead to the fact that no contractual relationship can be established between the Contractual Partner and DARLEAN US. Likewise, the non-disclosure of Correspondence Data may result in DARLEAN US not being able to answer enquiries/requests or give support.

    2. Data that DARLEAN US as Processor processes on behalf of a Contractual Partner ("Workspace Data"):

      This includes all Personal Data that a User enters by using the various modules of the DAR Lean Platform within a Workspace, in particular:

      • Invitation Data: This includes Personal Data entered by the User for the purpose of inviting an Interested Party, such as in particular the e-mail address as well as the intended role.
      • Collaboration Data: This includes Personal Data that occurs as a result of multiple Users interacting with each other or within a Team, specifically Personal Data contained in project plans, functional personal tasks, meeting notes, Personal Data related to video conferencing (including video transmissions), or related User assignments/assignments.
      • Team Data: This includes Personal Data related to the Team (including human resources) of a Workspace, in particular listings of Users, roles, hierarchies, employee contract terms (if applicable), working time records, leave dates and types.
      • Work Data: This includes Personal Data related to tasks, in particular the assignment of Users to tasks, Personal Data related to processes, projects or budgets.
      • Media Data: This includes Personal Data contained in uploaded files, such as Word and PDF files, image, video and audio files.
  4. Areas in which DARLEAN US acts as Controller and areas in which DARLEAN US acts as Processor

    1. DARLEAN US as Controller regarding DARLEAN US Data

      DARLEAN US, is the data Controller for the Processing of DARLEAN US Data and for the purposes set forth in Section 5.

    2. DARLEAN US as Processor of the contracting party regarding Workspace Data

      DARLEAN US, processes Workspace Data on behalf of the Contractual Partner and in accordance with the Annex to the Terms & Conditions and is therefore a Processor. The Processing operations that DARLEAN US performs on behalf of the Contractual Partner are, for example:

      • Sending an invitation email to an Interested Party based on a User's entry of Invitation Data.
      • Storage and provision of Collaboration Data, Team Data and Work Data according to the permissions set by a User in each case.

      Regarding the Processing of Workspace Data, the Contractual Partner shall be the independent and sole Controller; joint responsibility with DARLEAN US is excluded.

  5. Purposes of Processing

    DARLEAN US processes DARLEAN US Data as Controller for the following purposes:

    • Provision of the DAR Lean Platform
      • Registration, creation of a User account: DARLEAN US processes Master Data and Sign-in Data of the User in order to enable the User to register for the first time to the DAR Lean Platform and to set up a User account.
      • Sign-in and provision of the available modules of the DAR Lean Platform: DARLEAN US processes Sign-in Data of the User as well as Session Data in order to enable the User to log-in to the DAR Lean Platform and use it accordingly. The SSO services are further described in Section 9.
      • Display of the DAR Lean Platform: DARLEAN US processes certain Connection Data to enable the User to fully and properly display the DAR Lean Platform.
      • Optimized loading of the DAR Lean Platform:DARLEAN US processes certain Connection Data to improve the performance of the DAR Lean Platform, for example because some components are loaded from external Content Deployment Networks (CDN).
      • Personalization of the DAR Lean Platform: DARLEAN US processes certain Master Data as well as Profile Data to personalize the DAR Lean Platform for the respective User. Such personalization includes, inter alia, the subscriptions to Workspaces by the User.
      • Ordering of services, billing including debt collection: DARLEAN US processes Master Data and, if necessary, Correspondence Data and Connection Data in order to be able to bill a Contractual Partner for services relating to the DAR Lean Platform and, if necessary, to pursue them (also in court).
    • Communication with the User
      • Communication (User Request/Support): DARLEAN US processes Master Data as well as Correspondence Data in order to be able to contact and correspond with the User, inter alia to be able to answer enquiries and provide support, in particular by means of the contact form on the DAR Lean Platform or by e-mail.
      • Communication (Transactional): DARLEAN US processes Master Data as well as Correspondence Data to send transactional messages (including e-mails) to the User or Contractual Partner. Transactional messages, include, inter alia, important messages related to the account, a Workspace or User credentials (e.g. notification about a password reset) or information about changes/amendments relating to contracts between the User and DARLEAN US or this Privacy Statement.
      • Newsletter: DARLEAN US processes certain Master Data to send the User a newsletter by e-mail based on the prior registration of the User. However, DARLEAN US will only process this Personal Data for this purpose if the User has given their prior consent. This consent can be withdrawn at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.
    • Security and abuse prevention
      • IT Security: DARLEAN US processes DARLEAN US Data as well as - exclusively in justified cases and only to the extent absolutely necessary in accordance with the Terms & Conditions - Workspace Data (excluding Special Categories of Personal Data) to ensure the security and operability of the DAR Lean Platform. This includes, in particular, Processing carried out in connection with technical and organizational measures to detect, prevent and track attacks on the DAR Lean Platform. If certain Workspace Data is found to affect IT security (e.g. because certain files contain viruses), DARLEAN US reserves the right to delete such data in accordance with the Terms & Conditions as well as the Annex to the Terms & Conditions and to immediately inform the Contractual Partner. DARLEAN US will, however, never transfer such data to third parties, unless explicitly required to do so by applicable law.
      • Prevention of fraud and abuse: DARLEAN US processes DARLEAN US Data as well as - exclusively in justified cases and only to the extent absolutely necessary in accordance with the Terms & Conditions - Workspace Data (excluding Special Categories of Personal Data of data to be able to detect, prevent and prosecute abuse of the DAR Lean Platform (in particular the use of the DAR Lean Platform by the User contrary to the Terms & Conditions, use of a User account by several persons, data and credit card fraud, upload of illegal content).
    • Fulfilment of legal obligations under Cypriot and European law
      • Information, Recording and Retention Obligations: DARLEAN US processes all DARLEAN US Data to comply with statutory disclosure, recording and retention obligations, in particular those under tax and commercial law.
      • Exercise of data subject rights: DARLEAN US processes all DARLEAN US Data in order to fulfil Users’ data subject rights pursuant to applicable Privacy Laws (see Section 13 in detail) and to be able to respond to them.
    • Analysis and optimization of the DAR Lean Platform
      • Improvement of the DAR Lean Platform: DARLEAN US processes certain Connection Data to be able to analyse and optimize the operation of the DAR Lean Platform, inter alia to find and understand bugs of the DAR Lean Platform. The services used for this purpose as well as the relevant data being processed by these services including the legal bases for Processing are further described in Sections 6 to 8.
      • Analysis of the User structure: DARLEAN US processes DARLEAN US Data to be able to understand the geographical presence, gender, age and product patterns of Users who use the DAR Lean Platform, as well as to understand the usage habits and usage frequency as well as the satisfaction of tools provided within the DAR Lean Platform, in order to personalize the appearance of the DAR Lean Platform and to evaluate the useability and effectiveness of the modules within the DAR Lean Platform. The services used for this purpose as well as the relevant data being processed including the legal bases for Processing are described in Sections 6 to 8.
    • Further purposes
      • Purposes which require consent: DARLEAN US may process Personal Data for additional purposes, which will be communicated to the User in this Privacy Statement as amended from time to time or otherwise as the occasion arises. Processing will only take place if the User has given prior consent to such Processing. Consent can be withdrawn easily at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.
      • Purposes stated elsewhere within this Privacy Statement: DARLEAN US may also process Personal Data for purposes and on the basis of the legal bases set forth in Sections 6 to 8.
    • Deidentified Data
      • To the extent required by any binding obligation to which DARLEAN US is subject, DARLEAN US hereby publicly commits to process Deidentified Data in its possession only in a de-identified fashion and not attempt to re-identify such Deidentified Data.
      • “Deidentified Data” means data that cannot reasonably be used to infer information about, and that cannot reasonably be linked to, an identified or identifiable individual.
  6. Legal Bases of Processing

    Unless specified otherwise, DARLEAN US processes DARLEAN US Data for the purposes set forth in Section 5 based on one or more of the following legal bases:

    • Performance of a contract:DARLEAN US processes DARLEAN US Data on the basis of a contractual agreement concluded with the Contractual Partner regarding the use of the DAR Lean Platform or in order to take steps at the request of the Contractual Partner prior to entering into a contract, insofar as the Processing is necessary for this purpose.
    • Legal obligation: DARLEAN US processes DARLEAN US Data based on a legal obligation to which DARLEAN US is subject to.
    • Legitimate interest: DARLEAN US processes DARLEAN US Data as well as - exclusively in justified cases and only to the extent absolutely necessary in accordance with the Terms & Conditions as well as the Annex to the Terms & Conditions – Workspace Data (excluding Special Categories of Personal Data) based on its legitimate interest. Unless otherwise stated, the legitimate interests of DARLEAN US are, in particular,
      • to establish and maintain a proper contract and User management;
      • to ensure the proper provision and functioning of the DAR Lean Platform;
      • to maintain the security and performance of the IT infrastructure used by DARLEAN US;
      • to understand how the DAR Lean Platform is used, especially to identify usage habits and preferences;
      • to evaluate the performance of the DAR Lean Platform;
      • to personalize the DAR Lean Platform to the respective User preferences;
      • to find and eliminate bugs of the DAR Lean Platform; and
      • to be able to detect and stop any misuse of the DAR Lean Platform.
      • If referred to separately, DARLEAN US also processes DARLEAN US Data, based on a previously given and voluntary consent by the User. The User is entitled to revoke this consent at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.

  7. Transfer of Personal Data to Recipients

    1. Transfer to categories of recipients

      Personal Data will be transferred by DAR TECH for the purposes mentioned in Section 5 to one or more of the following categories of Recipients:

      • banks (e.g. in order to facilitate bank transfers);
      • tax advisors (e.g. in order to carry out proper accounting);
      • lawyers and collection agencies (e.g. to collect outstanding debts or exercise other legal rights);
      • courts and public authorities (e.g. to report and clarify legally relevant facts or to enforce claims);
      • external services as described in Sections 7.2 and 8;
      • Single Sign-on providers as described in Sections 7.2 and 9.

      The data is also transferred if DARLEAN US is legally obliged to do so.

    2. Overview of transmission to external services

      DARLEAN US may transfers Personal Data to the affiliates and service providers listed below.

      • DAR Solutions LLP., Almaty, Koktem microdistrict 2 – 22, Kazakhstan. DAR Solutions LLP processes DARLEAN US Data on behalf of DARLEAN US to provide technical assistance and development relating to the DAR Lean Platform and to provide support for Users. DAR Solutions LLP as well as DARLEAN US are companies of the same group.
      • DAR TECH Limited, Kyriakou Matsi 46, Apt 101, 1082, Nicosia, Cyprus, European Union. DAR TECH Limited provides additional technical and analytical support relating to the DAR Lean Platform. DAR TECH Limited as well as DAR FT UK LIMITED are companies of the same group.
      • Any cross-border data transfer is conducted solely to ensure the functionality and performance of the DAR Lean Platform and its Services. DARLEAN US may choose not to transfer such data to its affiliates if it is not deemed necessary. Cross-border data transfer is a right, not an obligation, of DARLEAN US.

      • Web Tool Providers, as described in detail in Section 8:
        • HubSpot, Inc., Two Canal Park Cambridge, MA 02141 USA, as operator of the service "Hubspot", a Content Delivery Network (CDN).
        • Stripe Payments Company, 354 Oyster Point Boulevard, South San Francisco, California, 94080, as operator of "Stripe", an online payment service.
        • Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, as operator of the services "Google Tag Manager” as well as "DialogFlow").
        • Volentio JSD Limited, Suite 2a1, Northside House, Mount Pleasant, Barnet, England, EN4 9EB, as operator of the service "jsDelivr", a Content Delivery Network (CDN) for open-source files, such as common frontend libraries like ReactJS.
        • Tilda Platform Cloud Services Co. LLC, License 1110180, P.O. Box number 450767, Dubai, UAE, as operator of the service “Tilda”.
        • Cloudflare, Inc, 101 Townsend St, San Francisco, CA 94107, USA, as operator of the service “Unpkg”.
      • Single Sign-on Providers as described in detail in Section 9:
        • Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (operator of the Service “Facebook Single Sign-on”).
        • Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (operator of the service "Google Single Sign-on”).
      • Hosting provider:
        • Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210, U.S.A. (operator of the service "AWS"): DARLEAN US uses this service to provide the platform (hosting of the DAR Lean Platform). The legal basis is the legitimate interest of DARLEAN US, which lies in being able to fulfil the aforementioned purpose; also the fulfilment of contracts with Contractual Partners.
  8. Web Tools including the Cookies set by these tools

    1. Introduction and Technical Explanation

      DARLEAN US utilises certain web tools as further described in Sections 8.2 to 8.9. Some of these web tools may utilize cookies. The link to the Consent Tool (including cookies) can be found here: Cookie-Banner.

      For detailed information about the Cookies set by the individual services listed below please refer to the https://darlean.com/cookies.

      Please note that through certain of the web tools and other services DARLEAN US uses, external parties (including without limitation third-party analytics service providers) may directly collect information about a Users’ or Interested Party’s online activities over time and across different websites.

    2. Hubspot

      Hubspot is an external service provided by Hubspot Inc., Two Canal Park Cambridge, MA 02141 USA.

      DARLEAN US uses this service for the purpose of organizing communication with Users, thus to be able to answer User enquiries and provide support, as well as to enable proper presentation of the DAR Lean Platform and to optimize speed (for example by sideloading fonts). Among the data collected is the User name, the User phone number and the User e-mail-address.

      The legal basis is the legitimate interest of DARLEAN US to achieve the aforementioned purposes.

      The Service Provider makes its Privacy Policy available at the following location: https://legal.hubspot.com/privacy-policy.

    3. Stripe

      Stripe is an external service offered and operated by Stripe Payments Company, 354 Oyster Point Boulevard, South San Francisco, California, 94080.

      Stripe is an online payment service provider. If the Contractual Partner makes a payment via the DAR Lean Platform, the relevant payment data (name, address, data on bank details), the IP address and data on the contract concluded with DARLEAN US are transmitted to the payment service provider who subsequently stores the data.

      DARLEAN US uses this service to perform the billing (Processing regarding payment). The legal basis is the fulfilment of the contract vis-à-vis the Contractual Partner; if cookies are used, additionally the prior consent of the Contractual Partner.

      In particular, we would like you to be aware that, when you make a payment via the DAR LEAN Platform and interact with Stripe, Stripe may place cookies on your computer or mobile device in connection with the provision of its services, including for fraud prevention purposes. Please see https://stripe.com/cookie-settings for more information.

      The Service Provider makes its Privacy Policy available at the following location: https://stripe.com/en-cy/privacy.

    4. Google Tag Manager

      Google Tag Manager is an external service offered and operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

      Google Tag Manager is a tag management system with which tracking codes and associated code fragments can be centrally integrated, managed and updated on the DAR Lean Platform.

      The Google Tag Manager serves as a mere system for passing through other tools, is hosted locally and does not transfer any Personal Data to Google. Information on Processing in connection with these other tools can be found under the respective tools in this Privacy Statement.

      The service provider makes its privacy policy available at the following location: https://policies.google.com/privacy.

    5. DialogFlow

      DialogFlow is an external service offered and operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

      DialogFlow is a natural language understanding platform used to design and integrate a conversational user interface into mobile apps, web applications, devices, bots, interactive voice response systems and related uses.

      DARLEAN US uses DialogFlow to offer advice and to respond to Users’ requests by implementing the service into a chatbot solution. DialogFlow uses machine learning to understand inputs and respond accordingly. In general, DialogFlow does not request Personal Data from Users.

      Google Ireland Limited, Google LLC or Alphabet Inc. may anonymize the dialog created by the User and the DAR Lean Platform and subsequently use it to improve and train the DialogFlow product.

      The legal basis for Processing is the consent given by the User. Consent can be withdrawn at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.

      Possible data Recipients are:

      • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
      • Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA
      • Alphabet Inc, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA

      The service provider makes its privacy policy available at the following location: https://cloud.google.com/dialogflow/docs/data-logging-terms?hl=en.

    6. jsDelivr

      jsDelivr is an external service offered and operated by Volentio JSD Limited, Suite 2a1, Northside House, Mount Pleasant, Barnet, England, EN4 9EB. It is a Content Delivery Network (CDN) for open-source files, such as common frontend libraries like ReactJS.

      DAR TECH uses this service to automatically keep certain libraries used for the DAR Lean Platform up to date by automatically including the latest distribution into it. This is necessary to safeguard IT Security and to optimize the loading time of the DAR Lean Platform. When the User accesses the DAR Lean Platform, certain Connection Data to the aforementioned service provider is transmitted.

      The legal basis for Processing is the legitimate interest of DARLEAN US which is to be able to fulfil the aforementioned purposes, especially to keep the DAR Lean Platform up to date and to avoid security flaws caused by outdated libraries.

      The service provider makes its privacy policy available at the following location: https://www.jsdelivr.com/terms/privacy-policy-jsdelivr-net.

    7. Matomo

      Matomo is an open source web analytics application to track online visits to websites and display reports on these visits for analytics. DARLEAN US uses this service to statistically analyze the User structure and subsequently optimize the DAR Lean Platform. DARLEAN US collects the following Personal Data: User IP address, Optional User ID, Date and time of the request, Title of the page being viewed (Page Title), URL of the page being viewed (Page URL), URL of the page that was viewed prior to the current page (Referrer URL), Screen resolution being used, Time in local user’s timezone, Files that were clicked and downloaded (Download), Links to an outside domain that were clicked (Outlink), Pages generation time (the time it takes for webpages to be generated by the webserver and then downloaded by the user: Page speed), Location of the user: country, region, city, approximate latitude and longitude, Main Language of the browser being used, User Agent of the browser being used, Random unique Visitor ID, Time of the first visit for this user, Time of the previous visit for this user, Number of visits for this user.

      The legal basis for Processing is the legitimate interest of DARLEAN US to improve the DAR Lean Platform and to understand the user structure. If cookies are set, the legal basis for Processing is consent given by the User. Consent can be withdrawn at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.

      DARLEAN US is using the Matomo Cloud service (“matomo.cloud”), which is provided by InnoCraft Ltd, 7 Waterloo Quay, PO625, 6140 Wellington, New Zealand (“InnoCraft”), to store the aforementioned personal data. InnoCraft publishes its “Matomo Cloud Privacy Policy” under https://matomo.org/matomo-cloud-privacy-policy/.

    8. Tilda

      Tilda is an external service offered and operated by Tilda Platform Cloud Services Co. LLC, License 1110180, P.O. Box number 450767, Dubai, UAE.

      Tilda is a no-code website builder and content delivery network (CDN) service. Its purpose is to deliver web content – inter alia web pages, videos and/or audio files – to the User. The purpose of this service is to increase the performance of the DAR Lean Platform and to provide the User with visually appealing web pages. When the User visits the DAR Lean Platform, a connection to servers of the Service Provider is made and Connection Data is processed.

      The legal basis is the legitimate interest of DAR TECH (Article 6 (1) lit f GDPR) to achive the aforementioned purposes.The legal basis is the legitimate interest of DARLEAN US to achive the aforementioned purposes.

      The Service Provider makes its Privacy Policy available at the following location: https://tilda.cc/privacy/. The technical information of Tilda can be accessed under https://tilda.cc/lp/technical-information/.

    9. Unpkg

      Unpkg is an external service offered and operated by Cloudflare, Inc, 101 Townsend St, San Francisco, CA 94107, USA (“Cloudflare”).

      Unpkg is a global content delivery network (CDN) for JavaScript packages; it delivers such JavaScript packages to the User. The purpose of this service is to increase the performance of the DAR Lean Platform and to enable DARLEAN US to include the most recent versions of such JavaScript packages into the DAR Lean Platform. This relieves DARLEAN US from manually updating these packages; it furthermore also guarantees the security of the DAR Lean Platform. When the User visits the DAR Lean Platform, a connection to servers of the Service Provider is made and Connection Data is processed.

      The legal basis is the legitimate interest of DARLEAN US to achive the aforementioned purposes. Cloudflare outlines its compliance under Privacy Laws under https://www.cloudflare.com/privacypolicy/. The User can prevent the collection and processing of Personal Data by Cloudflare by deactivating the execution of script code or by installing a script blocker in the web browser.

  9. Single Sign-on

    1. Facebook Single Sign-on

      Facebook Single Sign-on is an authentication (single sign-on) service operated by Meta Platforms Inc, 1 Meta Way Menlo Park, CA 94025-1444 (formerly Facebook, Inc).

      DARLEAN US uses this service to allow users to log in to the platform using the Facebook login without having to create a specific user account (with individual email and password).

      The legal basis for Processing is the explicit consent given by the User. Such explicit consent is given by the User clicking on the "Facebook" button on the login page of the DAR Lean Platform. Consent can be withdrawn at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.

      The service provider makes its privacy policy available at the following location: https://www.facebook.com/privacy/policy/.

    2. Google Single Sign-On

      Google Single Sign-on is an authentication (single sign-on) service operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

      DARLEAN US uses this service to allow users to log in to the platform using the Google login without having to create a specific user account (with individual email and password).

      The legal basis for Processing is the explicit consent given by the User. Such explicit consent is given by the User clicking on the "Google" button on the login page of the DAR Lean Platform. Consent can be withdrawn at any time without giving reasons. The withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal.

      The service provider makes its privacy policy available at the following location: https://policies.google.com/privacy?hl=en.

  10. Specific Information for the DAR Lean App

    This section provides additional information on the Processing of Personal Data in connection with the use of the DAR Lean App.

    DARLEAN US enables the User to download the DAR Lean App via various internet-based digital distribution platforms for application software. The download via these distribution platforms usually requires that the User has previously registered with the distribution platforms used. The distribution platforms on which the DAR Lean app is offered for download are:

    • App Store: This is a distribution platform for application software offered and operated by Apple Inc. or other legal entities of Apple. Apple's privacy policy is available at https://www.apple.com/legal/privacy.
    • Play Store: This is a distribution platform for application software offered and operated by Google LLC or another legal entity of Google. Google's privacy policy is available at https://policies.google.com/privacy.

    DARLEAN US has neither knowledge nor influence of the way in which and the purposes for which these distribution platforms process the User's Personal Data.

  11. Storage duration

    DARLEAN US stores Personal Data for the period necessary to achieve the purposes set forth in this Privacy Statement and, in addition, for the duration of any statutory retention obligation. In particular, the following storage or retention periods apply, unless applicable law, especially applicable Privacy Law, provides otherwise:

    • Master Data, Profile Data, and Sign-in Data of Users are stored for at least the duration of the existence of the User relationship with DARLEAN US and then for a subsequent period of 3 years after the termination of the account.
    • Correspondence Data will be stored at least for the duration of the existence of the User relationship with DARLEAN US, but no longer than 3 years after the termination of the account.
    • Session Data is stored for the duration of the visit to the DAR Lean Platform and deleted at the earliest after logout, but at the longest after 72 hours.
    • If the sole legal basis for Processing is consent, Personal Data is stored until such consent is withdrawn; after that, such Personal Data is deleted, as long as there are no other legitimate purposes for which this Personal Data is processed, such as legal retention periods. Depending on the purpose for which the consent was given, the Processing time within which DARLEAN US complies with the request may be a maximum of 7 days after the withdrawal of consent.
  12. Automated decision making including profiling

    DARLEAN US does not process Personal Data for the purpose of automated decision-making, including profiling.

  13. Rights of data subjects in connection with Personal Data

    1. Overview of rights of data subjects

      Data Subjects whose Personal Data is processed by DARLEAN US may be – under the conditions and prerequisites set out by applicable Privacy Law – entitled to:

      • request information as to whether and which Personal Data of the Data Subject DARLEAN US is Processing and to receive further information on such Processing; also to receive copies of such data;
      • request the correction or completion of Personal Data;
      • request the deletion of Personal Data that is incorrect or processed in a way that does not comply with the law;
      • request DARLEAN US to restrict the Processing of the Personal Data;
      • know the identity of third parties to whom the Personal Data is transferred;
      • request data portability, provided that the Processing is based on the legal grounds of consent or the performance or initiation of a contract and is carried out by means of automated processes;
      • object to the Processing of Personal Data under certain circumstances, whereby an objection to the Processing for purposes of direct marketing is possible at any time without stating reasons;
      • if the Processing is based on the legal basis of consent, to withdraw the consent, whereby such withdrawal shall not affect the lawfulness of the Processing carried out on the basis of the consent until the withdrawal;
      • file a complaint with the competent supervisory authority.
    2. Exercise of Rights

      Whenever DARLEAN US acts as Controller relating to DARLEAN US Data (e.g. correspondence between the User and DARLEAN US), the rights as described in Section 13.1 will be satisfied directly by DARLEAN US within the timelines set by applicable law.

      Whenever DARLEAN US acts as Processor relating to Workspace Data (e.g. when the User has written or was mentioned in meeting notes, or when a User requests the deletion of a file uploaded by him/her), DARLEAN US will, after the receipt of such request, immediately transmit this request to the competent Contractual Partner as Controller of the Workspace the User is assigned to. Such a request is usually not directly answered by DARLEAN US, but satisfied directly by the Contractual Partner, as DARLEAN US is not a Controller regarding this category of Personal Data. Only after having received a documented instruction of the Contractual Partner, DARLEAN US may answer the request on behalf of the Contractual Partner as described in the Terms & Conditions as well as the Annex to the Terms & Conditions.

    3. Do Not Track Requests

      The term “Do Not Track” refers to a HTTP header offered by certain web browsers to request that websites refrain from tracking the user. DARLEAN US takes no action in response to automated Do Not Track requests. However, if you wish to stop such tracking, please contact us in accordance with Section 14.

  14. Contact details of DARLEAN US as Controller

    For inquiries regarding data protection or the exercise of Data Subject rights, please contact exclusively:

    DARLEAN US CORP.

    850 New Burton Road,

    Suite 201, Dover,

    DE 19904,

    USA

    E-mail: support@darlean.com

  15. Changes to the Privacy Policy and your duty to inform DAR TECH of changes

    DARLEAN US keeps this Privacy Statement under regular review. This version was last updated on and is valid from December 1, 2024.

    DARLEAN US will not make changes that result in significant additional uses or disclosures of your personal data without allowing you to “opt in” to such changes. DARLEAN US may also make non-significant changes to this Privacy Statement that generally will not significantly affect our use of your personal data, for which your opt-in is not required. DARLEAN US encourages you to check this page periodically for any changes. If any non-significant changes to this Privacy Statement are unacceptable to you, you must immediately contact us and, until the issue is resolved, stop using the DAR Lean Platform.

    Historic versions can be obtained by contacting DARLEAN US using the contact details in Section 14. DARLEAN US reserves the right to change and/or amend this Privacy Statement from time to time.

    It is important that the Personal Data DARLEAN US holds about Users is accurate and current. Users should keep DARLEAN US informed (using the respective functions on the Platform or the contact details in Section 14) if their Personal Data changes during their relationship with DARLEAN US, for example a new address or email address.

  16. Third-party Links

    This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about individuals. DARLEAN US does not control these third-party websites and is not responsible for their privacy statements. When a User leaves our website, DARLEAN US encourages each User to read the privacy policy of every website visited.

Privacy Policy
Scope of this Privacy Policy
What Information do we Collect?
Personally Identifiable Information
Non-Personally Identifiable Information
Why do we Need your Personal Data?
Information we collect automatically when you use the Services:
Darvis AI Additional Terms
Which models are you using and which version?
Is my data used to train any AI models?
What is in-context learning?
Do you detect and defend against prompt injection?
Who owns the data input into Darvis?
Your privacy is extremely important to us. To better protect you, we provide this notice explaining our online information practices and the choices you can make about the way your information is collected and used.
If you do not agree to our use of your personal data in line with this policy, please do not use the Darlean Services.
Please be aware that this Privacy Policy does not govern all the information Darlean may process.
Any capitalized words we use in this Privacy Policy that we haven't defined here will have the same meaning that they're given in our Terms of Use.
Our commitments to employees are governed by our internal employment policies.
In all instances we are committed to transparency with our customers, employees, and to protecting your data privacy.
You will be required to establish an account in order to take advantage of certain features of the Darlean Service. If you wish to establish an account you will be required to provide us with information (including personally identifiable information and non-personally identifiable information). In addition, we may obtain your personally identifiable information from you if you identify yourself to us by sending us an e-mail with questions or comments.
Depending on your use of the Darlean Service, we collect two types of information:
personally identifiable information and non-personally identifiable information.
Personally identifiable information identifies you or can be used to identify or contact you. Examples of personally identifiable information may include your name, IP address, company name, job title, address, e-mail address, telephone number, and billing and credit card information.
Non-personally identifiable information is information, any single item of which, by itself, cannot be used to identify or contact you, which may include demographic information (such as age, profession, company industry, gender, current location, or zip code), IP addresses, browser types, domain names, and statistical data involving the use of the Darlean Service. Certain non-personally identifiable information may be considered a part of your personally identifiable information if it were combined with other identifiers (for example, combining your zip code with your street address) in a way that enables you to be identified. But the same pieces of information may be considered non-personally identifiable information when they are taken alone or combined only with other non-personally identifiable information (for example, your account preferences).
We do not sell any data, including your personal data. We will only collect and process your personal data in accordance with applicable data protection and privacy laws. We need to collect and process certain personal data in order to provide you with access to Darlean. If you registered with us, you will have been asked to check a tick box indicating your agreement to provide this data in order to access our services. This consent provides us with the legal basis we require under applicable law to process your data. You maintain the right to withdraw such consent at any time.

Information we collect automatically when you use the Services:
We collect information about you when you use our Services, such as browsing our websites and taking certain actions within the Services, including:
Information we collect automatically when you use the Services:
We collect information about you when you use our Services, such as browsing our websites and taking certain actions within the Services, including:

Your use of the Services: We keep track of certain information about you when you visit and interact with any of our Services. This information includes the features you use; the tasks, projects, teams and other links you click on; the type, size and filenames of attachments you upload to the Services; frequently used search terms; and how you interact with others on the Darlean. We also collect information about the teams and people you work with and how you interact with them, like who you collaborate and communicate with most frequently.

Device and Connection Information: We collect information about your computer, phone, tablet, or other devices you use to access the Services. This device information includes your connection type and settings when you install, access, update, or use our Services. We also collect information through your device about your operating system, browser type, IP address, URLs of referring/exit pages, device identifiers, and crash data. We use your IP address and/or country preference in order to approximate your location to provide you with a better Service experience. How much of this information we collect depends on the type and settings of the device you use to access the Services.

Log files: We collect non-personally identifiable information through our Internet log files, which record data such as user IP addresses, browser types, domain names, and other anonymous statistical data involving the use of the Darlean Service. This information may be used to analyze trends, to administer the Darlean, to monitor the use of the Darlean Service, and to gather general demographic information. We may link this information to personally identifiable information for these and other purposes, such as personalizing your experience on the Darlean Service, and evaluating the Darlean Service in general.
Information we receive from other sources
We receive information about you from other Service users, from third party services, and from our business and channel partners.

  • Other users of the Services: Other users of our Services may provide information about you when they submit content through the Services. For example, you may be mentioned by someone else on a task, or a team member may upload content about you to Darlean. We also receive your email address from other Service users when they provide it in order to invite you to the Services. Similarly, an administrator may provide your contact information when they designate you as another administrator for a task, team or an Enterprise or Unlimited Account.

  • Other services you link to your account: We receive information about you when you or your administrator enable third-party apps or integrate or link a third-party service with our Services. For example, you or your administrator may also integrate our Services with other services you use, such as to allow you to access, store, share and edit certain content from a third-party through our Services. For example, you may authorize our Services to access and display files from a third-party document-sharing service within the Services interface. The information we receive when you link or integrate our Services with a third-party service depends on the settings, permissions and privacy policy controlled by that third-party service. You should always check the privacy settings and notices in these third-party services to understand what data may be disclosed to us or shared with our Services.

  • Other partners: We may receive information about you and your activities on and off the Services from third-party partners, such as advertising and market research partners who provide us with information about your interest in, and engagement with, our Services and online advertisements, or in cases where you give such third parties permission to share information with us or where the information is publicly available online or through your device or browser data
These Darvis AI apply to your access and use of any Darvis AI feature(s), and form a part of the Terms Of Use or the Master Services Agreement, as applicable, between you and Darvis (the “Agreement”). Any capitalized terms used but not otherwise defined herein have the meaning set forth in the Agreement. References to “Customer Data” in these Darvis AI Terms shall also mean User Content for purposes of the Terms of Use. If you do not want to use Darvis AI or disagree with these Darvis AI Terms, you may also disable Darvis AI in your Workspace.

“Darvis AI” means any tools, features or functionality made available to you via the Darvis AI DarleanApp or Darlean platform (e.g., AI authorship and editing features) that utilize data models trained by machine learning and artificial intelligence, including but not limited to, tools for generating short-form or long-form content through prompting, editing of or extraction of information from existing content via prompting, and translation of existing or newly generated content.

Improving Darvis AI. Your access to or use of Darvis AI does not grant Darvis any right or license to use or share your Customer Data in a manner that is inconsistent with the Agreement unless otherwise agreed to by you.

Input and Output. You may provide input to be processed by Darvis AI (“Input”), and receive output generated by Darvis AI based on any Input (“Output”). When using Darvis AI, Input and Output are your Customer Data for purposes of the Agreement. You are solely responsible for the creation, development, content, operation, maintenance, use, and dissemination of your Customer Data. You are solely responsible for ensuring that your Input, access to and use of Darvis AI, and Output will not  violate any applicable law or regulation;  violate these Darvis AI Terms, the Agreement, or any content and use policies we may implement from time to time; or  infringe upon, violate, or misappropriate any of Darvis rights or the rights of any third party. You acknowledge that due to the nature of machine learning and Darvis AI more generally, Output may not be unique and Darvis AI may generate the same or similar output to Darvis or other third parties. You will not provide Input or attempt to generate Output through Darvis AI that consists of any sensitive or regulated information unless you have a separate agreement with us that expressly allows for your processing of such data through Darvis AI, including Protected Health Information as defined by HIPAA or similar statutes, or health, genetic, biometric record or data in general;  government-issued identification numbers of any kind; or  personal financial or bank account information.

Healthcare Use. You may not use Darvis AI in connection with any healthcare activities unless you have an active Business Associate Agreement with Darlean and Darlean has confirmed that: (a) your account is set up for healthcare AI use and (b) Zero Data Retention or access to otherwise-HIPAA compliant workflows or endpoints are enabled for any PHI data you process through Darvis AI. To the extent that you use Darvis AI or use or disclose Output, or permit Darvis AI or Output to be used or disclosed, in connection with any healthcare activities (including without limitation the practice of medicine, billing, coding, claims processing, or clinical research), you will: (i) test the Input and Output for accuracy in your use cases; (ii) ensure that your employees, agents, and contractors understand and comply with these terms, the BAA between you and Darlean, HIPAA, and all other applicable laws and regulations, including by providing appropriate training; (iii) ensure that only duly trained and qualified individuals who maintain licenses, certifications or other authorizations required to perform such healthcare activities will use Darvis AI or use or disclose the Outputs in connection with such healthcare activities; (iv) not use Darvis AI or Outputs to give medical advice, diagnose any medical condition, or create any treatment plans or programs; (v) not represent to any party, including a patient, that Darvis AI was performed by a human or that Output was human-generated; and (vi) only process PHI, submit PHI for Input, or retrieve Output that includes or is based on PHI, through a Zero Data Retention or otherwise HIPAA compliant workflow or AI endpoint. For the purposes of these Darvis AI Terms, “Zero Data Retention” refers to workflows or AI endpoints in which no Input is retained by the model or endpoint after processing.

Darvis AI Use Restrictions. You may not use Darvis AI or any Output (i) to develop data sets, foundation models, or other large scale models that may compete with Darlean or Darvis AI; (ii) to mislead any person or imply that Output from generated using Darvis AI is unique or solely human generated; (iii) to generate spam or misleading content; (iv) in a manner that violates any law, regulation, technical documentation, usage guidelines, policies, or other terms, whether made available or communicated to you by Darvis or any other third party; (v) to modify or create derivative works of Darlean or Darvis AI; (vi) to reverse assemble, reverse compile, decompile, translate, engage in model extraction or stealing attacks, or otherwise attempt to discover the source code or underlying components of models, algorithms, and systems of Darlean or Darvis AI (except to the extent such restrictions are contrary to applicable law); (vii) to extract data from Darlean or Darvis AI other than as permitted through the API; or (viii) to buy, sell, or transfer API keys from, to, or with a third party without Darlean’s prior written consent. Additionally, your use of Darvis AI is subject to fair usage restrictions that we may determine in our sole discretion. You acknowledge and agree that if you exceed what we determine to be fair usage: (a) you may be required to purchase additional usage rights to continue accessing and using Darvis AI; and (b) Darlean may disable or degrade performance of Darvis AI.

Third Party Policies. Darvis AI incorporates AI models from third party providers, which are made available to you through the Darvis AI interface. Darlean may, in its sole discretion, add, remove, limit, or otherwise modify the third party providers included in the Darvis AI services at any time. If you choose to use Darvis AI, you must do so in a manner that is fully compliant with the policies of any third party provider you use. These policies are not set or controlled by Darlean and it is your responsibility to familiarize yourself with them.
Darvis AI is built with ChatGPT-4o. Our AI features use a combination of ChatGPT and Gemini models. 
For example:

  • Darvis chat use ChatGPT-4o.
  • When generating and editing images, Gemini 2.5 Flash Image (Nano Banana) is used.

The ChatGPT and Gemini models integrated with Darvis are the only models that can access your Workspace data using in-context learning.
For example, you open the external ChatGPT-4.0 model from Darvis and ask: "Summarize the Accounting team's progress on the Q4 2026 audit." ChatGPT can't answer you because it can't access your Workspace data.
Darvis is not trained on data from your Workspace. We've secured licensing with our partners to ensure they do not access your data for training purposes. We also have zero data retention agreements with all of the large language model (LLM) organizations we partner with. The agreements require our partners not to retain any data from your Workspace after your data is input and processed through the LLM.
Additionally, we use in-context learning (ICL) to ensure that our models are not learning from data.
In-context learning (ICL) is a technique that allows large language models (LLMs) to generate appropriate responses when given context or examples within a prompt. This shows the model what to do without retraining or fine-tuning the model.

For example, when asked a question like "What is our PTO policy?" Darvis understands that it should search for PTO-related content in your Workspace. Darvis analyzes the content and provides the most appropriate response.

This allows Darvis to assist you while never storing information from your Workspace.
Yes, we separate user inputs from system prompts to ensure the large language model (LLM) recognizes that system prompt data is not meant as instructions. We conduct regular internal and external vulnerability testing across the platform with a focus on AI, following Open Worldwide Application Security Project (OWASP) guidelines.
Darvis customers retain any ownership they have of their data, regardless of whether it is processed through a large language model (LLM) or not. Any data provided by a Darvis customer that is sent to Darvis AI providers is covered by Darvis contract with that AI provider. Darvis contracts with AI providers prohibit Darvis customer data from being used to train any AI model or from being retained by that model after processing.
Darvis AI undergoes regular internal and external penetration testing to ensure security. We have an automated eval testing framework to ensure the behavior of Darvis AI remains consistent.
Darvis AI undergoes regular internal and external penetration testing to ensure security. We have an automated eval testing framework to ensure the behavior of Darvis AI remains consistent.
Darvis AI has two main feature types:

  • Manual AI usage: For example, using our feature, Project report.
  • Project Report has access to the same information as the person using it. AI can't reveal anything that person can't otherwise access.
  • Automatic AI usage: This usage is configured by someone in your Workspace that happens automatically or autonomously. For example, Daily reports.
  • Darvis Daily report respond based on their instructions and the knowledge they're given access to when configured. They respond in Chat  as configured.
How do you ensure Darvis AI is secure and consistent?
How do you ensure Darvis AI is secure and consistent?
Does Darvis AI respect the user's role and permissions when responding?