Diil

Privacy Policy

Last updated:

This policy explains what personal data Diil processes, why, for how long, who helps us, and what rights you have. We have tried to write it the way we would want it explained to us: plainly, and without promising anything the product does not actually do.

Who we are

Diil is a visual website editor with a built-in CRM: leads, live chat, analytics, a blog and multilingual content. The service is operated by Diil (“Diil”, “we”, “us”).

Diil

Contact: contact form

This policy covers this website (including the developer documentation), the Diil CRM application, and the Diil widget (widget.js) that our customers install on their own websites.

Our role: controller and processor

Depending on whose data it is, we play one of two roles.

  • Controller. For the data of our account holders (site owners and their team members), people who contact us, and visitors of this website, we decide why and how the data is processed. This policy is our privacy notice for them.
  • Processor. When a customer connects their website to Diil, we process data about the visitors of that website — analytics, form submissions, chat conversations, site accounts — on the customer’s behalf and on their instructions. For that data the customer is the controller. They must have their own privacy notice and a valid legal basis, including consent where the law requires it. The terms on which we process this data are set out in the Terms of Use (section “Processing visitor data for you”).

If you visited a website that uses Diil and have a question about your data, please contact the owner of that website first: they decide what is collected there and can delete it. If you write to us instead, we will pass your request on to them.

Data we process as a controller

Your account

When you register, we store your email address, your name, a password hash (we use scrypt — we never store the password itself), how you registered (email or Google), and the IP address and browser user agent at sign-up. We also keep your plan, subscription, balance history and usage counters, because the service runs on them.

To confirm your email we send a six-digit code. Until you enter it, the pending registration (code, password hash, name and IP address) is kept for 10 minutes and then disappears on its own.

Sign in with Google

If you choose “Sign in with Google”, authentication goes through Google Firebase Authentication. We receive your email address and name from Google and store them together with the IP address and user agent, as with a regular registration. We do not receive your Google password.

Sign-in and security

After you sign in, the CRM keeps a session: a refresh_token cookie valid for 7 days and a short-lived access token in your browser’s storage (see the Cookie Policy). To slow down password guessing we count failed sign-in attempts per email address and per IP address; these counters expire after 15 minutes.

Team members and invitations

An account owner can invite colleagues. For an invitation we store the invitee’s email address, the access rights granted and who sent the invitation, and we email the invitation link. When you write a comment on a lead, your name is stored with it so the team knows who wrote it.

Audit log

Important actions in the CRM are recorded in an audit log: who did it (name and email), what was done and to what, plus the IP address and user agent. The log lets account owners see what happened in their workspace and helps us investigate security incidents.

Service emails

We send emails you need to use the service — registration codes and team invitations — through an email delivery (SMTP) provider.

Plans and payments

Paid plans are charged from a prepaid balance in your account. We keep the ledger of your balance, subscriptions and usage.

Card and other non-crypto payments are processed by our reseller and Merchant of Record, Creem (Armitage Labs OÜ), Estonia (see the Refund Policy). Creem collects your name, email address, billing country and address and payment details directly on its own checkout page and handles them under its own privacy policy. We never see or store full card numbers. From Creem we receive only what we need to credit the payment to your account and keep our records: the amount, currency, date and status of the payment, your email address and country, and a transaction reference.

If you pay in cryptocurrency, we receive the transaction details: amount, coin, network, transaction ID and the sending wallet address. For a refund we also use the wallet address you confirm to us.

Your content

Pages, blog posts, texts and files you add to Diil are stored to provide the service. Uploaded media and chat attachments are kept in object storage (Cloudflare R2). If you ask Diil to translate texts automatically, those texts are sent to Google Cloud Translation. If you connect your own Telegram bot for notifications, lead and chat contents are sent to that bot because you asked for it.

When you contact us

The contact form asks for your name, email address, an optional company or website, a topic and your message. Together with the language of the page, this is sent to our team’s chat in Telegram (through the Telegram Bot API) so we can reply to you by email; we do not keep a separate copy on our server. To stop spam, the form keeps short-lived counters of submissions per IP address and per email address in memory (up to one hour) and, where enabled, uses Cloudflare Turnstile to check that you are not a bot.

Live demo

The “Try the demo” button creates a temporary sandbox with sample data — no registration needed. Before it starts, Cloudflare Turnstile checks that the request comes from a person. The sandbox and everything in it are deleted completely after 60 minutes.

This website

This website sets no cookies and runs no analytics, advertising or tracking scripts. Fonts are served from our own server. Two preferences are kept in your browser’s local storage (theme and language), and the site checks whether you are signed in to the CRM so it can take you straight to your dashboard. Like any website, our server has to process your IP address to deliver the pages to you.

PurposeDataLegal basis (GDPR)
Creating and running your account, providing the service, billingAccount, plan, balance and usage data; your contentPerformance of a contract — Art. 6(1)(b)
Verifying your email, sending codes and invitationsEmail, name, code, invitation dataPerformance of a contract — Art. 6(1)(b)
Security: preventing account takeover, fraud and abuse; audit logIP address, user agent, failed sign-in counters, audit log entriesLegitimate interests in keeping the service and accounts secure — Art. 6(1)(f)
Answering your enquiryContact form dataYour consent, given with the checkbox on the form — Art. 6(1)(a); where the enquiry is about a contract with us — steps before entering into it, Art. 6(1)(b)
Protecting the demo and the contact form from botsTechnical data processed by Cloudflare Turnstile, IP-based rate limitsLegitimate interests in preventing abuse — Art. 6(1)(f)
Keeping records required by law (for example, accounting records once payments are live)Billing dataLegal obligation — Art. 6(1)(c)

Where we rely on legitimate interests, you can object at any time (see “Your rights”). Where we rely on consent, you can withdraw it at any time; this does not affect processing that already happened.

Data we process for our customers

When a website uses Diil, the following data about its visitors may be processed on the website owner’s behalf. Which of it is actually collected depends on the features the owner turns on.

  • Analytics. A random visitor ID, sessions, page addresses and titles, referrer, UTM tags, advertising click IDs (gclid, gbraid, wbraid, yclid, fbclid, msclkid), the values of advertising cookies already set on that website (_ga, _ga_*, _gcl_aw, _gcl_dc, _gcl_gb, _ym_uid, _fbp, _fbc), user agent and the device, browser and operating system derived from it, screen and window size, language, time zone, the IP address in truncated form (the last part of an IPv4 address is removed; IPv6 is shortened to /48), an approximate location (country, region, city) looked up in a local database without any external request, a bot flag, and events with their names, parameters and values.
  • Forms (leads). What the visitor enters — for example name, phone, email, message and other form fields — plus UTM tags, the page, country, visitor ID, truncated IP address and user agent. Fields that look like passwords, card numbers or tokens are filtered out and not stored.
  • Live chat. Messages, attachments (stored in the website owner’s storage on Cloudflare R2), the name and contact details the visitor chooses to give, and their language. The visitor’s IP address is not stored in the database; it is only used in short-lived rate-limit counters.
  • Site accounts. If the owner lets visitors sign in on their website: email address, whether it is verified, Google account ID (for Google sign-in), last sign-in time, one-time login codes (stored hashed for 10 minutes, together with the IP address) and sessions of up to 30 days. Login emails are sent through the owner’s own SMTP server, and Google sign-in uses the owner’s own Google client.

Consent mode and Global Privacy Control. A website owner can switch the widget into consent mode (data-consent="required"). Then no analytics are collected and no identifiers are stored until the visitor agrees; forms and chat, which the visitor starts themselves, keep working without analytics identifiers. If the visitor’s browser sends a Global Privacy Control signal, the widget never reads advertising cookies, whatever the settings.

The website owner can delete leads and chats at any time, and when a website is removed from Diil, its data is deleted with it.

Who helps us (sub-processors)

We use a small number of providers. Each only gets the data it needs for its task.

ProviderWhat forWhere
OVHcloudServer hosting. Our database (PostgreSQL) and cache (Redis) run on our own server there.European Union
CloudflareR2 object storage for uploaded media and chat attachments; Turnstile bot checks (demo button and, where enabled, the contact form)Global network
GoogleFirebase Authentication for “Sign in with Google”; Cloud Translation for texts you choose to translateGlobal network
Email delivery (SMTP) providerSending service emails: registration codes and invitationsDepends on the provider
TelegramDelivering contact form requests to our team’s chatGlobal network
Creem (Armitage Labs OÜ)Payment processing and invoicing as Merchant of Record for card payments. Creem receives your name, email, billing country and address and payment details directly — we never see full card numbers. As the seller, Creem handles this data under its own privacy policy.European Union (Estonia)

Some data goes to third parties only because a customer chooses so: to the customer’s own Telegram bot, SMTP server or Google client, if they connect them. Those services work under the customer’s own agreements with them.

We do not sell personal data and do not share it with advertisers. We may disclose data if the law requires it, for example in response to a binding request from a public authority.

International transfers

Our servers are in the European Union. Some providers listed above operate worldwide, so data may be processed outside the European Economic Area. Where that happens, we rely on an adequacy decision of the European Commission or on the Standard Contractual Clauses approved by it, as applicable, together with the provider’s additional safeguards.

How long we keep data

DataHow long
Pending registration (code, password hash, name, IP)10 minutes
Failed sign-in counters15 minutes
CRM session (refresh_token)7 days, or until you sign out
Account data, content, audit logWhile the account exists. After the account is deleted — deleted, including from backups within 30 days
Data of an account whose plan has expiredKept, so you can continue where you left off; it is not deleted automatically
Demo sandbox60 minutes, then deleted completely
Contact form requests (our Telegram chat)As long as needed to handle your request and our follow-up correspondence; on request we delete them earlier
Contact form rate-limit countersUp to one hour, in memory only
Visitor page views and events (for customers)13 months (395 days) by default, then deleted automatically
Leads and chats (for customers)Until the customer deletes them or removes the website
Site account login codes and sessions (for customers)10 minutes and up to 30 days respectively

How we protect data

  • Passwords are stored only as scrypt hashes.
  • Data travels over encrypted connections (TLS).
  • Access within a workspace is controlled by roles and access rights set by the account owner.
  • Important actions are recorded in an audit log.
  • Sign-in attempts, forms and chat are rate-limited against guessing and abuse.
  • Visitor IP addresses for analytics are stored truncated, and sensitive form fields are dropped.

No system is perfectly secure. If a personal data breach happens that is likely to put you at risk, we will inform you and, where required, the supervisory authority.

Your rights

Depending on where you live, you have the right to:

  • access your data and get a copy of it;
  • rectify data that is wrong or incomplete;
  • erase your data (“right to be forgotten”);
  • restrict processing in certain cases;
  • data portability — receive the data you gave us in a machine-readable format;
  • object to processing based on legitimate interests;
  • withdraw consent at any time, where processing is based on consent;
  • lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work or where you think your rights were infringed.

To exercise a right, write to us through our contact form and choose the topic “Privacy request”. We will reply within one month; if a request is complex, we may extend this by up to two more months and will tell you why. We may ask you to confirm your identity first, for example by writing from the email address of the account.

Account deletion is available in the CRM settings; if your account does not show this option yet, send us a request and we will delete the account for you.

If you are a visitor of a website that uses Diil, the website owner is responsible for your request (see “Our role”). We will help them answer it.

Children

Diil is a service for businesses and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us personal data, let us know and we will delete it.

Automated decision-making

We do not make decisions based solely on automated processing that have legal or similarly significant effects on you. Automatic spam and bot checks only filter out abusive traffic and submissions.

Changes to this policy

We will update this policy when the service or the law changes. The date at the top shows the latest version. If a change is significant, we will tell account holders in advance by email or in the CRM.

Contact

Questions about this policy or your data? Write to us through our contact form.