Privacy Policy
What personal data Asrar Studio SARL collects when you use Dispatch, why, on which legal basis, how long we keep it, who we share it with and how to exercise your rights.
What changed in 1.1
Added a section on AI processing (model providers, no training on customer data, zero data retention where available); listed the fields we record as evidence of consent; added a retention table per data category; named our EU representative and our Data Protection Officer contact; clarified our processor role for customer content.
This Privacy Policy explains how Asrar Studio SARL (“Asrar”, “we”, “us”) handles personal data when you visit our websites, create an account or use Dispatch (the “Service”). We wrote it to be read, not skimmed past — if anything is unclear, write to privacy@asrar.example.
In short. We collect what we need to run Dispatch, keep your account secure and prove what you agreed to. We never sell your data and never use the content you put into Dispatch to train AI models. You can access, export, correct or delete your data at any time.
1. Who is responsible
Controller. Asrar Studio SARL, 00 Boulevard Placeholder, Floor 4, 20000 Casablanca, Morocco. Registration: RC Casablanca 000000 (placeholder).
Data Protection Officer. You can reach our DPO at dpo@asrar.example.
EU representative (Art. 27 GDPR). Asrar EU Representative (placeholder), 00 Rue Exemple, 75000 Paris, France.
Our two roles.
- For account, billing, website and security data we are the controller: we decide why and how it is processed, and this policy applies.
- For Customer Content — cards, inputs, attachments, comments, prompts and the artifacts agents produce inside a workspace — we act as a processor on behalf of the workspace owner (usually your employer or client). The workspace owner is the controller and decides how that content is used; our Data Processing Addendum governs that processing. If you have questions about content inside a workspace, contact the workspace owner first.
2. The data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password hash, profile picture, language, time zone | You, or your identity provider (Google) when you use it |
| Workspace data | Workspace name and slug, logo, roles, invitations, settings | You and your workspace members |
| Customer Content | Card titles and inputs, attachments, comments, prompts, templates, tool configurations, agent traces and artifacts | You and your workspace members |
| Consent records | See section 5 — which documents you accepted, when and how | Recorded by the Service |
| Usage data | Runs started, features used, token counts and estimated costs, pages visited in the app | Recorded by the Service |
| Device and log data | IP address, browser and operating system (user agent), timestamps, request identifiers, error logs, session list | Your browser and our servers |
| Communications | Support requests, emails you send us, email delivery status | You and our email provider |
| Billing data | Plan, invoices, billing contact, the last four digits and brand of a card | You and our payment processor (we never store full card numbers) |
| Cookie choices | Your cookie-banner decision and a random anonymous identifier | Your browser |
We do not knowingly collect special-category data (such as health data) and ask you not to submit it unless your workspace has a lawful basis to do so.
3. Why we use it and our legal bases
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and run your account and workspaces; provide the Service, including agent runs | Account, workspace, Customer Content, usage | Performance of a contract (6(1)(b)) |
| Send service emails: verification, sign-in links, password resets, invitations, approval requests, run notifications | Account, workspace | Performance of a contract |
| Keep the Service secure: detect abuse, fraud, spam and attacks; rate limiting; audit logs | Device and log data, usage | Legitimate interests (6(1)(f)) in protecting our users and systems |
| Keep evidence of the legal documents you accepted | Consent records | Legal obligation (6(1)(c)) and legitimate interests in proving compliance |
| Billing, invoicing, taxes and accounting | Billing data | Contract and legal obligation |
| Improve and fix the product using aggregated or pseudonymised usage statistics | Usage, device data | Legitimate interests (we never use Customer Content for this) |
| Analytics cookies | Pseudonymous usage | Consent (6(1)(a)) — only if you opt in |
| Product news and tips by email | Email address | Consent — only if you opt in at sign-up or in settings; you can unsubscribe at any time |
| Answer support requests | Communications, account | Contract or legitimate interests |
| Comply with the law and respond to lawful requests | Any relevant data | Legal obligation |
Where we rely on legitimate interests, we have balanced them against your rights; you can object at any time (section 10).
4. AI processing
Dispatch runs AI agents on the tasks you create. To do that:
- The inputs of a card, the relevant attachments (as extracted text), tool results (for example the text of a web page the agent fetched) and your instructions are sent to an AI model provider that generates the agent’s steps and output. Our current provider is listed on the subprocessors page.
- We use model providers under terms that prohibit training on our customers’ data and, where available, with zero data retention. We do not use Customer Content to train or fine-tune any model ourselves.
- Agents never perform side-effecting actions (sending an email, posting a message, calling a webhook) without a human approval, unless a workspace admin explicitly configured otherwise on the Pro plan.
- No decision that produces legal or similarly significant effects on you is made solely by automated means. The Service helps you draft and analyse; people decide.
Our AI Policy explains how AI features work in more detail.
5. Evidence of consent
When you accept our Terms of Service, this Privacy Policy, the Acceptable Use & User Content Policy, a cookie choice or marketing emails, we record a consent entry containing: your user identifier and email address (or an anonymous identifier for cookie choices), the document and exact version accepted, a fingerprint (hash) of the document text, the exact wording you agreed to, the method (for example the sign-up checkbox or a re-acceptance prompt), the date and time, your IP address, browser user agent, language, time zone, approximate country when available and the page where you accepted. These entries are append-only: they are never edited, only followed by new entries (for example a withdrawal).
6. Who we share data with
We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising.
- Subprocessors that host and operate the Service for us — cloud hosting, database and object storage, transactional email, AI model providers and, if you use it, Google sign-in. They process data only on our instructions under written contracts. The current list, with purposes and locations, is on our subprocessors page. We give 30 days’ notice of changes.
- Services you connect. When a workspace connects Slack, Notion, Google Drive, an email provider, a webhook or a custom tool, we send the data you approve to that service. Its own privacy policy applies.
- Your workspace. Workspace owners and admins can see members’ names, emails and roles, and the content members contribute to the workspace.
- Legal and safety. We may disclose data if required by law or a valid legal order, or to protect the rights, safety and property of our users, the public or Asrar. We challenge requests that are overbroad and, where allowed, notify affected customers.
- Business transfers. If Asrar is involved in a merger, acquisition or sale of assets, data may be transferred subject to this policy, and we will notify you.
7. International transfers
We host the Service primarily in the European Union. Some subprocessors (for example our email and AI providers) process data in other countries, including the United States. When personal data leaves the European Economic Area, the United Kingdom, Switzerland or Morocco, we rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses (with the UK and Swiss addenda where relevant), together with supplementary measures such as encryption in transit and at rest. You can request a copy of the relevant safeguards from privacy@asrar.example.
8. How long we keep data
| Data | Retention |
|---|---|
| Account data | For the life of the account; deleted within 30 days after account deletion |
| Customer Content | As long as the workspace exists and within your plan’s history retention (30 days of run history on Free, unlimited on Pro); deleted within 30 days after a workspace is deleted |
| Demo sessions | Up to 30 minutes after the session ends, then deleted |
| Consent records | For the life of the account plus 5 years, to be able to prove consent |
| Security, access and audit logs | 12 to 24 months |
| Email delivery logs | 12 months |
| Billing records | 10 years, as required by accounting law |
| Backups | Rolling 35 days |
| Cookie choice | 12 months, then we ask again |
We may keep data longer where required by law or to establish, exercise or defend legal claims.
9. Security
We protect personal data with encryption in transit (TLS) and at rest, encrypted storage of integration secrets, private file storage with short-lived signed download links, strict tenant isolation, role-based access, rate limiting, audit logging, least-privilege access for our staff and regular backups. No system is perfectly secure; if a breach affects your personal data we will notify you and the competent authority as required by law. Report vulnerabilities to security@asrar.example.
10. Your rights
Depending on where you live (including under the GDPR, the UK GDPR and Moroccan Law No. 09-08), you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate data — most of it you can edit yourself in your account settings;
- erase your data (“right to be forgotten”) — you can delete your account from your settings;
- restrict or object to certain processing, including processing based on legitimate interests and all direct marketing;
- data portability — you can export your workspace data (JSON and files) from the product;
- withdraw consent at any time (cookie settings, marketing emails), without affecting processing that happened before;
- lodge a complaint with a supervisory authority — in Morocco the CNDP (Commission Nationale de contrôle de la protection des Données à caractère Personnel), or the authority of your EU/EEA country of residence.
To exercise your rights, email privacy@asrar.example. We answer within one month (extendable by two months for complex requests) and may need to verify your identity. For Customer Content, we will forward your request to the workspace owner, who is the controller.
California residents. We do not sell or share personal information as defined by the CCPA/CPRA. You may request to know, delete or correct your personal information and will not be discriminated against for exercising these rights.
11. Children
The Service is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact privacy@asrar.example and we will delete it.
12. Changes to this policy
We will notify you of material changes by email or in the product at least 30 days before they take effect, and publish every version with a summary of what changed on the version history page. Where required, we will ask you to accept the new version.
13. Contact
Privacy questions and requests: privacy@asrar.example · Data Protection Officer: dpo@asrar.example · Post: Asrar Studio SARL, 00 Boulevard Placeholder, Floor 4, 20000 Casablanca, Morocco.