Legal
Privacy notice
How personal data is handled by this website and by the DUN-AI platform.
This document is a working draft prepared by the product team. It has not been reviewed or approved by qualified legal counsel in any jurisdiction, and it is not in force. It must be reviewed, completed and adopted before this site is published to a live domain or any customer relationship is entered into. Bracketed text marks information that only the operating entity can supply.
This website
This website loads no third-party scripts, fonts, images, analytics or advertising technology. It sets no cookies for measurement or marketing, and it does not profile visitors. There is no consent banner because there is nothing to consent to.
Server logs may record the fact of a request, including an address and a timestamp, for security and operational purposes. They are not used to build a profile of an individual.
The platform
DUN-AI is used by organisations to assess their own investment decisions. Most of what it holds is organisational information, not personal data, but some personal data is unavoidable.
| Category | Why it is held |
|---|---|
| Account details | Name, work email address and organisational role, so access can be granted and decisions attributed to an accountable person. |
| Authentication data | A one-way hash of the password and session records. The password itself is never stored in any recoverable form. |
| Activity records | Who did what and when, held in a tamper-evident audit log. This is essential to the product: a decision that cannot be attributed cannot be governed. |
| Assessment content | Answers, evidence descriptions and comments supplied by users. These may incidentally contain personal data depending on what a user writes. |
The questions ask about processes, systems, volumes and controls. There is no need to supply records about customers, patients or citizens, and doing so is discouraged. Questions that touch sensitive territory explain why they are being asked.
Roles, basis and retention
Controller and processor
For account and platform-operation data, [operating entity] acts as controller. For the content an organisation places into its own assessments, [operating entity] acts as processor on that organisation’s instructions, under a written agreement.
Lawful basis
Contract, for providing the service to an account holder; legitimate interests, for security, audit integrity and service operation, balanced against the individual’s interests; and legal obligation where record retention is required.
Retention
Assessment and decision records are retained for the period the customer organisation specifies, because their purpose is to remain available for later scrutiny. Audit records cannot be selectively deleted without breaking the integrity chain that makes them worth keeping; deletion is therefore performed at the level of a whole tenant. [Retention periods to be confirmed.]
Location and transfers
Data is held in the deployment region the customer selects. There is no automatic movement of data between regional deployments. [Hosting locations and any transfer mechanisms to be confirmed.]
Sub-processors and AI assistance
[A current list of sub-processors is to be published here.] Optional AI assistance for narrative phrasing is disabled unless the operator supplies a provider credential. Where it is enabled, the provider becomes a sub-processor and must be listed. Answers classified as confidential are not sent to an external provider, and no language model is permitted to determine any assessment outcome.
Your rights
Depending on where you are, you may have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to a supervisory authority.
If your organisation holds a DUN-AI account, please raise a request with your own administrator first: for assessment content, they are the controller and we act on their instructions. For account data, contact us directly.