Dayalogs
Product How it works Pricing Researchers Docs Blog
Sign in Register
Product How it works Pricing Researchers Docs Blog Sign in Register

Privacy Policy

What we collect, why we collect it, and what rights you have over it.

Privacy Terms Cookies

Last updated: 23 July 2026

1. Who we are

Sergio Peña Tapia, empresario individual (autónomo) ("Dayalogs", "we", "us", "our"), operates the Dayalogs survey platform available at dayalogs.com.

Registered address: Passeig de Manuel Girona 48, 6è 4a, 08034 Barcelona, Spain
NIF: 46240767A
Data protection contact: privacy@dayalogs.com

2. Our role depends on the data

2.1 Dayalogs as controller

Dayalogs is the data controller for account, team, billing, support, website analytics, security, API and MCP authorization data. We decide why and how this information is used to operate and protect the service.

2.2 Dayalogs as processor

When a customer creates surveys, imports audiences, sends campaigns, collects responses or uploads files, that customer normally decides the purpose and means of processing. The customer is the controller and Dayalogs acts as its processor, following the customer's instructions and the applicable Data Processing Agreement (DPA).

If you are a respondent, reviewer or campaign recipient, the organization that invited you is normally responsible for the survey and its content. Contact that organization first to exercise rights concerning its data. Dayalogs will assist it where required.

3. Data we process

3.1 Account, team and authentication data

  • Name, email address, organization, role and membership information
  • Password hash, verification state, authentication sessions and security events
  • Account settings, plan, entitlements and active workspace

3.2 Billing data

  • Plan selection, wallet balance, invoices and transaction history
  • Payment identifiers and limited card information supplied by Stripe, such as card brand and last four digits

Stripe processes full payment-card details. Dayalogs does not store full card numbers.

3.3 Survey and collaboration data

  • Survey definitions, versions, translations, themes, quotas and publication state
  • Review rounds, comments, decisions and reviewer contact details
  • Share links, LinkSets, embedded placements and associated variables or URL parameters
  • Audience contacts, tags, segments and customer-provided profile fields
  • Campaign content, recipients, queue state and delivery or engagement events

3.4 Respondent data

  • Answers, completion state, timestamps, selected language and survey version
  • Contact, link, URL and survey variables made available by the customer
  • Files uploaded in response to file-upload questions
  • Technical metadata needed to deliver, resume and protect a response

3.5 Response-quality signals

If the customer enables response confidence features, Dayalogs may process behavioral and technical signals such as response timing, pasted text, browser focus changes, honeypot interaction, client-integrity signals, repeated-answer patterns and pseudonymized identifiers derived from IP address or browser environment. These signals produce a review score; they are not proof that a respondent is human or fraudulent and do not automatically reject a response.

3.6 API, MCP and integration data

  • API key identifiers, hashed secrets, authorized OAuth applications and granted scopes
  • MCP client name, authorization records, expiry, revocation and last-used timestamps
  • Tool arguments and results needed to carry out requested actions
  • Connection, audit and security logs

Using Dayalogs through ChatGPT or another AI client sends the instructions and tool results needed for that request between Dayalogs and the AI provider selected by the user. That provider processes the data under its own terms and privacy policy. Dayalogs does not use customer survey content, responses or MCP tool data to train a general-purpose AI model.

3.7 Website, support and diagnostics

  • Support messages, feedback and correspondence
  • IP address, browser and device information, requested pages and operational logs
  • Analytics identifiers only after the visitor gives the required cookie consent
  • Diagnostic information sent to error-monitoring services; request bodies and default personal data collection are disabled in our current Sentry configuration

See our Cookie Policy for details and controls.

4. Why we use data and our legal bases

PurposeTypical dataLegal basis when Dayalogs is controller
Provide accounts, surveys, API and MCP integrationsAccount, authentication, product and integration dataPerformance of a contract
Process payments and keep accounting recordsAccount, billing and transaction dataPerformance of a contract and legal obligation
Secure the platform, prevent abuse and investigate incidentsAuthentication, technical, audit and quality signalsLegitimate interests and legal obligation where applicable
Send service messages and campaign email requested by customersAccount, recipient, campaign and delivery dataPerformance of a contract; customers determine the basis for their campaigns
Diagnose faults and improve reliabilityUsage, performance and diagnostic dataLegitimate interests
Measure website useCookie and analytics dataConsent where required
Send optional product newsEmail and preferencesConsent, which can be withdrawn at any time
Respond to support or legal requestsCorrespondence, account and relevant recordsContract, legitimate interests or legal obligation

When Dayalogs acts as a processor, the customer determines the legal basis for survey, audience, campaign, response and upload data. We do not sell personal data, share it with data brokers or use it for advertising profiles. We do not make solely automated decisions that produce legal or similarly significant effects for account users or respondents.

5. Recipients and service providers

We disclose data only as needed to provide the service, follow customer instructions, protect Dayalogs or comply with law. Current categories include:

RecipientPurposeData involved
Amazon Web Services (AWS)Hosting, database infrastructure, object storage, email delivery and delivery-event queuesPlatform data, uploaded files, email and operational events
StripePayments, subscriptions, invoices and fraud preventionAccount, billing and payment data
Google AnalyticsWebsite analytics after consentCookie identifiers and website usage data
SentryError and performance monitoring when configuredLimited diagnostic and technical data
AI or agent providers chosen by the userExecute MCP/API-assisted workflowsRequested tool inputs and outputs
Professional advisers and public authoritiesLegal, accounting, security and regulatory obligationsOnly records relevant to the request or obligation

Providers receive only the data required for their role and are subject to contractual or legal confidentiality and data-protection duties. We do not share data with advertisers.

6. International transfers

We prefer European infrastructure where practical, including AWS resources configured in the EU (Frankfurt) region. Some providers or support teams may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, the European Commission's Standard Contractual Clauses or another lawful safeguard. Contact us for information about the safeguard relevant to a particular transfer.

7. Retention

CategoryTypical retention
Account and workspace dataFor the account lifetime; deletion from active systems normally within 30 days after closure
Survey, audience, response, review and uploaded-file dataUntil the customer deletes it or closes the account; active-system deletion normally within 30 days
BackupsRotated and deleted within 90 days
API keys and OAuth/MCP authorizationsUntil expiry, revocation or deletion; secrets are stored hashed where applicable
Security and access logsNormally 90 days, longer only for an active security investigation or legal obligation
Operational job and delivery logsNormally 30 days; campaign outcome records remain with the campaign until deleted
Error-monitoring diagnosticsNormally up to 90 days
Support correspondenceNormally 3 years after the last contact
Invoices and legally required accounting recordsFor the period required by applicable tax and commercial law
Email suppression recordsAs long as reasonably necessary to prevent harmful, unwanted or repeatedly failing email

Deletion may be delayed where we must preserve evidence, comply with law, resolve a dispute or prevent repeated email abuse. We then restrict the data to that purpose.

8. Your controls

Depending on your role and plan, Dayalogs provides controls to:

  • Update account and organization information
  • Export or delete responses, audiences and surveys
  • Remove uploaded files and revoke share links or embedded placements
  • Revoke API keys and MCP/OAuth authorizations
  • Manage campaign recipients, unsubscribe choices and email deliverability
  • Change cookie consent through the cookie preferences control

Account administrators control workspace data and access. Revoking an integration stops future access but does not automatically delete records already created through it.

9. Your data-protection rights

Where the GDPR applies, you may have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent. To exercise rights concerning a Dayalogs account or our own processing, email privacy@dayalogs.com. We may need to verify your identity and will normally respond within one month.

For survey responses, campaign messages or audience records controlled by a Dayalogs customer, contact that customer first. We will support verified requests received from the customer.

You may complain to your local supervisory authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD).

10. Security

We use measures appropriate to the risk, including HTTPS/TLS, access controls, least-privilege permissions, credential hashing, origin restrictions for embeds, scoped API/MCP authorization, backups and operational monitoring. No service can guarantee absolute security. Report suspected vulnerabilities to security@dayalogs.com.

11. Children

Dayalogs is intended for organizations and professionals, not for children to create accounts independently. Customers are responsible for ensuring that surveys directed to minors have an appropriate legal basis, notices and consent process. If you believe a child has provided data unlawfully, contact us.

12. Changes and contact

We may update this policy when the product, providers or law changes. We will change the date above and provide additional notice for material changes where appropriate.

Privacy: privacy@dayalogs.com
Security: security@dayalogs.com
General: hello@dayalogs.com
Post: Sergio Peña Tapia, Passeig de Manuel Girona 48, 6è 4a, 08034 Barcelona, Spain

Dayalogs

Research, conversational again.

Legal
  • Terms of Use
  • Privacy Policy
  • Cookies Policy
  • Cookie preferences
Support
  • Blog
  • Documentation
  • Research Collaboration Program
  • Contact us

Payments powered by Stripe

© 2026 Dayalogs. All rights reserved.

Cookies

We use essential cookies to keep Dayalogs working. If you accept analytics, we can better understand which tools and workflows matter most and improve the product accordingly. Cookie Policy.