Dalenda
Home
Privacy Policy

Privacy Policy

Dalenda — a trading name of JAIDO

Effective date: May 23, 2026Last updated: May 23, 2026

Preamble

Dalenda is a trade name operated by the company JAIDO (SAS, RCS Mulhouse 102 235 819). The data controller is the company JAIDO. All references to "JAIDO" in this document designate the legal entity that publishes the dalenda.ai website and is responsible for processing the data.

The purpose of this Privacy Policy (hereinafter the "Policy") is to inform users (hereinafter the "User" or "you") of the dalenda.ai website and the Dalenda services (hereinafter the "Services") about how their personal data is collected, processed, and protected.

JAIDO offers autonomous artificial intelligence agents designed to automate the processes of businesses and individuals. To provide these Services, JAIDO may need to access, with your explicit consent, certain of your third-party services, in particular: (i) Google services (Gmail, Google Drive, Google Calendar), (ii) Microsoft 365 services (Outlook, OneDrive, Outlook Calendar, Microsoft To Do), and (iii) the Sign in with Apple authentication service.

Data is hosted within French territory by OVH, Scaleway, and Outscale (SecNumCloud-qualified by ANSSI), with a distribution according to the sensitivity of the data processed (see section 10).

This Policy complies with the General Data Protection Regulation (GDPR - EU Regulation 2016/679), French Law No. 78-17 of January 6, 1978, as amended, known as the "Informatique et Libertés" Act, as well as the applicable requirements of the Google API Services User Data Policy (Limited Use), the Microsoft APIs Terms of Use, and the Apple Developer Program License Agreement / Sign in with Apple Guidelines.

1. Identity of the data controller

Corporate name: JAIDO

Trade name / Brand operated: Dalenda

Legal form: Simplified Joint-Stock Company (SAS)

Share capital: 1,000 euros

SIREN: 102 235 819

SIRET of the registered office: 10223581900012

Intra-EU VAT number: FR65102235819

APE / NAF code: 6201Z (Computer programming)

Registered office: 46 rue de Zillisheim, 68100 Mulhouse, France

President: its President in office

Website: https://www.dalenda.ai

Contact email address: contact@dalenda.ai

Data Protection Officer (DPO): dpo@dalenda.ai

2. Definitions

  • Personal data: any information relating to an identified or identifiable natural person.
  • Processing: any operation applied to personal data (collection, storage, consultation, modification, deletion, etc.).
  • User: any natural person using the Dalenda Services.
  • Google services: the Gmail, Google Drive, and Google Calendar services that JAIDO may access via the Google APIs.
  • Microsoft services: the Outlook (email), OneDrive (storage), Outlook Calendar, and Microsoft To Do services that JAIDO may access via Microsoft Graph API.
  • Apple services: the Sign in with Apple service allowing the User to authenticate to JAIDO via their Apple ID.
  • AI Agent: an automated JAIDO program performing tasks on behalf of the User.

3. Data collected

3.1 Data provided directly by the User

  • Identification data: last name, first name, email address, phone number.
  • Login data: credentials, password (stored in encrypted and salted form).
  • Billing data: postal address, bank details (processed via a secure payment provider).
  • Support data: content of exchanges with our customer service.

3.2 Data collected automatically

  • Technical data: IP address, browser type, operating system, pages visited, visit duration.
  • Cookies and trackers: see our Cookie Policy.
  • Application logs: usage logs of the AI agents.

3.3 Data obtained from Google services

With your explicit consent obtained via Google's OAuth 2.0 mechanism, JAIDO accesses the following data, only to the extent strictly necessary to perform the requested features. In accordance with the principle of minimization, Dalenda has selected ONLY non-sensitive or sensitive scopes, NO restricted scope, ensuring limited access compliant with the Google API Services User Data Policy (Limited Use) requirements.

a) Google Drive — surgical access via Google Picker

  • Scope limited to the files that the User explicitly designates via the Google Picker selector, as well as files created by Dalenda.
  • Creation, reading, modification, and deletion of designated files and folders.
  • RAG indexing of designated folders (recursive access to the content of selected folders).
  • Support for all formats: Google Docs/Sheets/Slides, PDF, images, videos, Office files, archives.
  • Management of sharing permissions for files within the scope.

Important limitation: Dalenda NEVER accesses your entire Google Drive. Only the files and folders that you explicitly designate are accessible.

Google Drive scopes used: drive.file (creation/management of designated files), drive.metadata.readonly (metadata of files within the scope), drive.apps.readonly (informational list of Drive apps).

b) Google Calendar — full calendar management

  • Reading of existing events (title, date, time, participants, location, description).
  • Creation, modification, and deletion of appointment events.
  • Checking availability (free/busy) for automatic multi-participant scheduling.
  • Conflict detection before proposing time slots.
  • Creation of a dedicated 'Dalenda' calendar separate from the main calendar.
  • Management of calendar sharing permissions (ACL).
  • Reading of settings (time zone, language).

c) Gmail — Sending emails from the web platform

Dalenda can send emails on behalf of the User from the web platform, after explicit validation by the User (in particular sales follow-ups, customer support, scheduled prospecting sequences). Gmail scope used for the web platform: gmail.send (sending only, without access to the mailbox).

Important: Dalenda has NO access to your Gmail inbox from its web platform. We never read your incoming emails in the background.

d) Gmail — Gmail Add-on (optional add-on)

If the User installs the "Dalenda" add-on from Google Workspace Marketplace, additional features are available directly within the Gmail interface (side panel). In this context only: reading the content of the opened AND clicked Gmail message, AI-generated reply suggestion, content summary, creation of a draft reply, proposal of available calendar time slots.

Important: These scopes only allow access to emails in the context of interaction with the add-on, that is, only when the User themselves opens an email AND clicks the Dalenda icon. No background processing, no batch reading, no indexing of emails.

e) Google Identity

  • Authentication of the User via Sign-in with Google (creating/logging into a Dalenda account).
  • Retrieval of the primary email address of the Google account.
  • Retrieval of the last name, first name, and profile photo for personalizing the interface.

Identity scopes used: openid, userinfo.email, userinfo.profile. The complete and up-to-date list of OAuth scopes requested is presented to the User during the Google consent screen and is also available upon request at privacy@dalenda.ai.

3.4 Data obtained from Microsoft 365 services

With your explicit consent obtained via Microsoft's OAuth 2.0 mechanism (Microsoft Identity Platform), JAIDO accesses the following data via Microsoft Graph API, only to the extent strictly necessary to perform the requested features:

a) Outlook (Microsoft 365 Mail)

  • Reading of emails (subject, body, sender, recipients, date) for contextual analysis and automation.
  • Sending emails on behalf of the User (replies, sales follow-ups, customer support).
  • Management of folders, drafts, and categories.
  • Metadata of attachments (without systematic downloading of their content).

b) OneDrive (and OneDrive for Business)

  • Reading of files and folders explicitly designated by the User.
  • Creation, modification, and deletion of files generated by the agents (documents, reports, sales proposals).
  • Management of sharing permissions when the User requests it.

c) Outlook Calendar

  • Reading of existing events (title, date, time, participants, location, description).
  • Creation, modification, and deletion of events and appointments.
  • Checking availability for automatic scheduling.
  • Management of invitations and confirmations.

d) Microsoft To Do

  • Reading of task lists and existing tasks.
  • Creation, modification, and deletion of tasks for managing the schedule and actions to be taken.
  • Organization by lists and categories.

Microsoft Graph permissions requested: JAIDO requests only the Microsoft Graph permissions that are strictly necessary (principle of least privilege), as presented to the User during the Microsoft consent screen (for example Mail.ReadWrite, Mail.Send, Files.ReadWrite, Calendars.ReadWrite, Tasks.ReadWrite).

3.5 Data obtained from Apple (Sign in with Apple)

With your explicit consent obtained via the Sign in with Apple mechanism, JAIDO accesses exclusively the following data, strictly limited to authentication:

  • Anonymized unique identifier provided by Apple.
  • Email address (real or Apple private relay "Hide My Email" depending on your choice).
  • Name (only if you choose to share it during the first login).

Important: JAIDO does NOT access ANY iCloud data (iCloud Mail, iCloud Drive, iCloud Calendar, Reminders, Notes). Sign in with Apple is used solely for authentication and account creation purposes.

4. Compliance with Google's Limited Use policy

JAIDO's use and transfer of information received from the Google Workspace APIs to any other application will comply with the Google API Services User Data Policy, including the Limited Use requirements. More specifically, JAIDO undertakes to:

  • NOT use the Google Workspace data received via the Google APIs to develop, improve, or train generalized or non-personalized artificial intelligence models.
  • NOT transfer this data to third parties, except: (i) to a service provider acting as a processor; (ii) to comply with a legal obligation; or (iii) with your explicit and prior consent.
  • NOT use this data for advertising, direct marketing, resale, or analysis purposes unrelated to the Services provided.
  • NOT allow humans to read this data, except in the cases provided for (explicit consent, security, legal obligation, strictly necessary internal operations on anonymized data).

AI models: The data obtained from Gmail, Google Drive, and Google Calendar is in no case used to train JAIDO's artificial intelligence models or transmitted to third-party AI model providers for training purposes.

5. Compliance with Microsoft's terms of use (Microsoft Graph API)

JAIDO undertakes to strictly comply with the Microsoft APIs Terms of Use, the Microsoft Services Agreement, and the applicable data protection requirements. More specifically, JAIDO undertakes to:

  • NOT use the Microsoft 365 data received via Microsoft Graph API to train generalized or non-personalized AI models.
  • NOT transfer this data to third parties, except for exceptions equivalent to those described above.
  • NOT use this data for advertising, commercial profiling, resale, or analysis purposes unrelated to the Services.
  • Respect the rights of the tenant administrator when the User connects a professional Microsoft 365 account.
  • Respect the data residency settings defined by the tenant administrator.

Multi-Tenant Application: JAIDO is registered as a multi-tenant application on Microsoft Entra ID. The application publisher has been verified by Microsoft (Microsoft Publisher Verification).

6. Compliance with Apple requirements (Sign in with Apple)

JAIDO undertakes to comply with the Apple Developer Program License Agreement and the Sign in with Apple Guidelines:

  • Strictly limit the use of data obtained from Sign in with Apple to authentication and the creation/management of the Account.
  • Respect the Apple private relay ("Hide My Email") and not attempt any correlation aimed at de-anonymizing the real email address.
  • NOT share the unique Apple identifier with third parties for advertising or marketing purposes.
  • NOT use the data obtained from Sign in with Apple to train AI models.
  • Allow the deletion of the Account associated with an Apple identifier directly from the JAIDO interface.

7. Purposes of processing

7.1 Performance of the Services

  • Provision of the AI agents' features (lead qualification, customer support, content generation, etc.).
  • Connection and synchronization with your Google and Microsoft 365 services.
  • Authentication via Sign in with Apple where applicable.
  • Personalization of the agents' responses according to your professional context.

7.2 Management of the contractual relationship

  • Creation and management of your account.
  • Billing and collection.
  • Technical support and assistance.

7.3 Improvement of the Services

  • Analysis of application performance (on aggregated and anonymized data).
  • Detection and correction of bugs.

Important: This improvement purpose NEVER includes the use of data obtained from Gmail, Drive, Calendar, Outlook, OneDrive, Outlook Calendar, Microsoft To Do, or Sign in with Apple to train our AI models.

7.4 Security

  • Prevention of fraud and abuse.
  • Detection of suspicious activities.
  • Compliance with legal obligations.

7.5 Communications

  • Sending information relating to the Service (updates, security alerts).
  • Sending commercial information with your prior consent (newsletter, news).

8. Legal bases for processing

In accordance with article 6 of the GDPR, the processing operations are based on:

  • Performance of the contract (art. 6.1.b): for the provision of the subscribed Services.
  • Consent (art. 6.1.a): for access to Google, Microsoft 365, and Sign in with Apple services, as well as for non-essential cookies and marketing communications.
  • Legitimate interest (art. 6.1.f): for the security of the Service, fraud prevention, and performance improvement.
  • Legal obligation (art. 6.1.c): for the retention of accounting data and responding to requests from authorities.

9. Recipients of the data

  • Authorized JAIDO staff (technical, support, and sales teams), subject to a confidentiality obligation.
  • Our cloud hosting providers (processors within the meaning of article 28 of the GDPR): OVH SAS, Scaleway SAS, and Outscale SAS (3DS Outscale), all located in France. Outscale is SecNumCloud-qualified by ANSSI.
  • Our technical subcontractors acting on our behalf (payment providers, support tools, transactional mailing tools, etc.).
  • Administrative or judicial authorities when the law requires it.

The exhaustive list of our subcontractors is available upon request at privacy@dalenda.ai.

10. Data location and international transfers

10.1 Primary hosting in France

  • OVH SAS (Roubaix, France): standard hosting of the website and routine data.
  • Scaleway SAS (Paris, France): supplementary hosting for the Services and storage.
  • Outscale SAS (3DS Outscale) (Saint-Cloud, France): sovereign hosting SecNumCloud-qualified by ANSSI, reserved for Customers subject to strong regulatory requirements or processing particularly sensitive data.

The User may, upon request at privacy@dalenda.ai, request that their data be hosted exclusively on the Outscale SecNumCloud-qualified environment (an option potentially subject to a fee depending on the subscribed offer).

10.2 Transfers outside the European Union

Some of our third-party providers (in particular Google LLC, Microsoft Corporation, and Apple Inc.) may be located outside the EEA, primarily in the United States. JAIDO ensures that these transfers are governed by appropriate safeguards within the meaning of articles 44 to 49 of the GDPR (adequacy decisions, Standard Contractual Clauses, additional technical and organizational measures).

11. Retention period

  • Account data: for the entire duration of the contractual relationship, then archived for 3 years after the last interaction.
  • Google, Microsoft, and Apple data: only for as long as necessary to perform the requested task. No permanent copy is kept. OAuth access tokens are deleted as soon as consent is revoked.
  • Billing data: 10 years from the close of the accounting year (legal obligation).
  • Technical logs: 13 months maximum.
  • Prospecting data: 3 years from the last contact.

12. Your rights

In accordance with the GDPR, you have the following rights:

  • Right of access (art. 15).
  • Right to rectification (art. 16).
  • Right to erasure (art. 17).
  • Right to restriction (art. 18).
  • Right to portability (art. 20).
  • Right to object (art. 21).
  • Right to withdraw your consent at any time.
  • Right to set guidelines regarding the fate of your data after your death.
  • Right to lodge a complaint with the CNIL (www.cnil.fr).

To exercise your rights: send your request to privacy@dalenda.ai or by post to JAIDO – 46 rue de Zillisheim, 68100 Mulhouse, France. We undertake to respond within one month, which may be extended by two months in the event of complexity.

13. Security measures

13.1 Technical measures

  • Hosting of data within French territory (OVH, Scaleway, Outscale SecNumCloud-qualified, depending on sensitivity).
  • Encryption of data in transit (TLS 1.3) and at rest (AES-256).
  • Encrypted storage of OAuth tokens in a secure vault.
  • Strong authentication (MFA) for administrator access.
  • Segregation of environments (production, development, test).
  • Regular encrypted backups within French territory.
  • Regular penetration testing and security audits.
  • Automated detection of incidents and anomalies.

13.2 Organizational measures

  • Access control policy based on the principle of least privilege.
  • Regular staff awareness and training.
  • Confidentiality commitments signed by all employees and subcontractors.
  • Data breach management procedure compliant with the GDPR (notification to the CNIL within 72 hours where applicable).
  • Periodic internal audit procedure.

14. Cookies and trackers

The dalenda.ai website uses cookies and trackers to ensure its operation, measure its audience, and personalize your experience. You can configure your preferences at any time via the cookie management banner. For more information, see our dedicated Cookie Policy.

15. Protection of minors

The Dalenda Services are strictly reserved for natural persons of legal age, at least 18 years old. JAIDO does not knowingly collect personal data concerning minors and does not authorize the creation of an Account by a minor, nor the creation of an Account by an adult on behalf of a minor. If you become aware that a minor has provided personal data to JAIDO, please contact us without delay at privacy@dalenda.ai.

16. How to revoke access to third-party services

16.1 Google (Gmail, Drive, Calendar)

  • Via your Google account: myaccount.google.com/permissions, select "Jaido" and click "Remove access".
  • Via your JAIDO account: settings > Integrations > "Disconnect".

16.2 Microsoft 365 (Outlook, OneDrive, Calendar, To Do)

  • Via your personal Microsoft account: account.live.com/consent/Manage.
  • For professional accounts: via myaccount.microsoft.com or the Microsoft Entra ID tenant administrator.
  • Via your JAIDO account: settings > Integrations > "Disconnect".

16.3 Apple (Sign in with Apple)

  • Via your Apple ID: appleid.apple.com/account/manage, "Apps using your Apple ID" section.
  • Via your JAIDO account: settings > Account > "Remove Apple sign-in".

Complete deletion of the JAIDO Account: You can request the complete deletion of your Account and all associated data by sending an email to privacy@dalenda.ai or directly from your Account (settings > Account > "Delete my account").

17. Modifications to the Policy

JAIDO reserves the right to modify this Policy at any time in order to adapt it to legislative, regulatory, case-law, or technical developments. Any substantial modification will be notified to you by email and/or via a notification on the platform, at least 30 days before it takes effect.

18. Contact

By email: privacy@dalenda.ai

DPO: dpo@dalenda.ai

Website: https://www.dalenda.ai

Postal address: JAIDO – 46 rue de Zillisheim, 68100 Mulhouse, France

Supervisory authority (France): Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07 — www.cnil.fr

Dalenda

Contact : support@dalenda.ai

FacebookXInstagram

Segwi l-midja soċjali tagħna biex tibqa' aġġornat bl-aħħar aħbarijiet tagħna

support@dalenda.ai

Links mgħaġġla

PrezzijietImportazzjoni tal-memorjaSigurtà u aċċessAffiljazzjoni

Avviżi legali

Politika ta' privatezzaTermini u kundizzjonijietPolitika tal-cookiesKonformità mal-GDPR

© 2026 Dalenda. Id-drittijiet kollha riżervati