Legal

Privacy Policy

This policy explains which personal data we process when you visit our website, use the Dcision app and API or contact us, and the rights you have under the Brazilian LGPD, the European GDPR and other applicable laws.

1.Who we are

Dcision is operated by GR Digital, a company based in Brazil (“we”, “us”). We are the controller of the personal data described in this policy, except when we process data on behalf of our customers (see “Data you process with Dcision”).

Operator details: legal name GR Negócios Digitais; CNPJ 29.691.265/0001-65; registered office Av. Luiz Boiteux Piazza, 1302, Sala 13, Florianópolis/SC, 88056-682.

For privacy questions and requests, including those for our Encarregado (the data protection contact under the LGPD), write to privacy@dcision.io.

This policy covers https://dcision.io, https://app.dcision.io, https://api.dcision.io and https://docs.dcision.io.

2.Personal data we collect

  • Account data: e-mail address, name, preferred language and, if you sign in with Google, the URL of your profile picture; account creation and last sign-in dates. If you set a password, we store only a scrypt hash of it. E-mail sign-in codes are stored only as hashes, expire after 10 minutes and are deleted within a day.
  • Workspace and organization data: workspace name and settings; members and their roles; invitations (the invited e-mail address, the role, who sent it and when); the organization details you enter, such as legal name, tax ID, billing e-mail, country, address and website; decision schemas and their versions; and engine settings.
  • Keys and secrets: API keys are stored only as SHA-256 hashes with a short prefix for display. Your own engine keys (BYOK) and the secrets you store for destinations are encrypted with AES-256-GCM, and only their last four characters are shown; the webhook signing secret is also stored encrypted.
  • Execution logs: for each decision call, metadata such as decision, version, status, latency, engine and model, estimated cost, confidence, policy action and request ID. By default, the inputs (state) and outputs of each call are stored too; you can turn this off per decision.
  • Destinations: the result of each destination run with a decision (for example an LLM or agent reply) is stored with the execution; for each webhook, API call, workflow or asynchronous agent hand-off we also keep its status, attempts and timing, the target URL and headers with secrets masked, and up to 1 KB of the response. The full request, which contains the data you configured, is kept encrypted only until it is delivered or, if delivery fails, so that you can resend it.
  • Usage and billing data: hourly decision counts per workspace, plan and subscription status, and Stripe customer and subscription identifiers; the credit balance and its transactions, the brand, last four digits, expiry and Stripe fingerprint of the saved card, and who consented to automatic recharge and when. Card details are collected and processed by Stripe; we never see your full card number.
  • Communications: messages you send us and the information you enter in our forms, for example an expression of interest in the private sale (name, e-mail, company, investor type, country of residence, indicative amount, how you heard about us and your confirmations).
  • Website demo: the message and company size you type in the live demo on our home page are sent to our API and to the engine (TypeSafe) and may be stored with the resulting execution in our public demo workspace, for that workspace's log retention period. The answers — not your text — appear in the “latest executions” panel of the home page. Please do not type personal data in the demo.
  • Technical data: IP address, browser user agent and request metadata, processed to deliver the Service, protect it against abuse and enforce rate limits.

We do not ask for special categories of personal data, such as health or biometric data. Please do not send them to us, directly or inside decisions, unless it is strictly necessary and lawful.

3.Why we use personal data (legal bases)

  • To create and operate your account and workspaces, authenticate you, execute decisions and keep execution logs — performance of a contract (LGPD art. 7, V; GDPR art. 6(1)(b)).
  • To let workspace owners and admins invite members and manage their roles, including sending the invitation e-mail to the address they enter — performance of a contract with the workspace and legitimate interests (LGPD art. 7, V and IX; GDPR art. 6(1)(b) and (f)).
  • To run the destinations you configure, sending the data you set to the endpoints and services you choose — performance of a contract, on your instructions.
  • To bill, collect payments and keep financial records — performance of a contract and compliance with legal obligations (LGPD art. 7, II and V; GDPR art. 6(1)(b) and (c)).
  • To send service e-mails, such as sign-in codes, invitations, billing notices, quota alerts and security notices — performance of a contract.
  • To secure the Service, prevent fraud and abuse and enforce rate limits — legitimate interests (LGPD art. 7, IX; GDPR art. 6(1)(f)) and, where applicable, legal obligations.
  • To understand how the Service is used and improve it — legitimate interests, using aggregated metrics whenever possible.
  • To answer your messages and review an expression of interest in the private sale — steps taken at your request before entering into a contract (LGPD art. 7, V; GDPR art. 6(1)(b)) and, where required, your consent, which you can withdraw at any time. Identity verification (KYC) and anti-money-laundering checks, if they happen later, are based on legal obligations.
  • To comply with the law and to establish, exercise or defend legal claims — legal obligation and the regular exercise of rights (LGPD art. 7, II and VI; GDPR art. 6(1)(c) and (f)).

We only send product news or marketing e-mails if you ask for them, and you can unsubscribe at any time.

4.Data you process with Dcision

When you send personal data to the API inside a decision state, you, our customer, are the controller, and we process that data as your processor (operator, under the LGPD) only to execute your decisions, following your instructions and our Terms of Use.

You choose what to send. Inputs and outputs are stored by default; you can turn storage off per decision. Send only the data a decision needs, and prefer pseudonymous identifiers.

You are responsible for the legal basis, for informing the people concerned and for answering their requests. If we receive a request about data we process for a customer, we will forward it to that customer and help as reasonably required. Enterprise customers can request a data processing agreement (DPA) at legal@dcision.io.

5.How decision engines process data

To execute a decision, the engine must receive the decision state and the compiled questions. By default, Dcision sends them directly to the Jev engine on TypeSafe's API, in the United States, using our platform credentials. The engine returns the result to us, and we return it to you.

If you connect your own keys (BYOK), the state is sent to the provider you selected (TypeSafe, OpenRouter or Vercel AI Gateway) under your own agreement with that provider, and that provider's privacy terms apply.

We do not use your inputs or outputs to train models. Engine providers process them under their own terms and policies.

6.Destinations

If you attach destinations to a decision — per-outcome actions such as webhooks, API calls, workflows, LLM or agent replies, fixed replies or functions in your code — we act on your instructions: when an execution matches, we send the data you configured to the endpoint or service you chose. Webhooks and workflows carry the outcome and only the parameters you map (the state is not included unless you map it); API calls carry the request you write; LLM and agent replies carry your instructions and an input that, by default, is the decision's state. LLM replies always use your own provider key, never our engine key.

Those endpoints and services — for example your own servers, a workflow tool, your agent or an LLM provider used with your own key — are recipients you choose, not our subprocessors, and their own terms and privacy policies apply.

The results of destinations, including LLM and agent replies, are stored with the execution for its log retention period, even when output storage is off; delivery records are deleted 30 days after a delivery ends. See “How long we keep data”.

7.Subprocessors and sharing

We share personal data only with service providers that help us run the Service, under contracts that limit their use of the data:

ProviderPurposeData involved
Contabo (via Dokploy)Hosting of the website, app, API and database, in the United States (New York)All data described in this policy
TypeSafeInference by the decision engine (Jev), in the United StatesDecision state, context and questions of each call
Cloudflare (R2)Encrypted daily backups of the databaseAll data stored in the database
StripePayments, subscriptions, credit purchases and invoicesBilling contact, organization details, payment and subscription data
HubMailTransactional e-mail (sign-in codes, invitations, billing, quota and security notices) and delivery of private-sale expressions of interest to our inboxE-mail address and message content
GoogleSign-in with Google (OAuth)Name, e-mail address and profile picture
DigitalOceanDNS for our domainsTechnical data only; no account or decision content

We may also disclose data when required by law or by a competent authority, to protect our rights and the safety of users, to professional advisers bound by confidentiality, or to a successor in a merger, acquisition or sale of assets. We do not sell personal data.

8.International transfers

GR Digital is based in Brazil, but our website, app, API and database are hosted in the United States (New York), and the decision engine (TypeSafe), Stripe and Google are based in or process data in the United States. Database backups are stored with Cloudflare. Your data is therefore processed outside your country, including in the United States.

When we transfer personal data internationally, we rely on mechanisms permitted by law, such as adequacy decisions where available, standard contractual clauses (including those approved by the European Commission and by the Brazilian ANPD), or the need of the transfer to perform our contract with you (LGPD art. 33; GDPR Chapter V).

9.How long we keep data

  • Execution logs, including stored inputs and outputs: 7 days on Genesis, 14 days on Developer and 30 days on Growth, or the contractual period on Enterprise. You can set a shorter period in the workspace settings; a daily job deletes older logs.
  • Idempotency records, which keep a copy of an API response so that a retried request is not executed twice: replayed for 24 hours and deleted by a daily job within about two days.
  • E-mail sign-in codes: they expire after 10 minutes and are deleted within a day.
  • Hourly usage counts (without inputs or outputs): up to 400 days, for billing and quota enforcement.
  • Destination deliveries: deleted 30 days after the delivery ends; the encrypted copy of the request is deleted as soon as it is delivered. Destination results stored with an execution follow the execution logs.
  • Invitations: kept while the workspace exists; the invitation link expires after 7 days.
  • Account and workspace data: while your account is active. After you ask us to delete your account, we delete or anonymize it within 30 days, except for data we must keep by law.
  • Database backups: encrypted, made daily and kept for up to 14 days, so deleted data can remain in backups for up to 14 days after it is deleted from the database.
  • Billing records and invoices: for the period required by tax and accounting law.
  • Expressions of interest in the private sale and related messages: while the private sale is open, and then deleted, unless you become an investor or the law requires us to keep them.

10.Security

We protect data with encryption in transit (TLS), hashing of API keys, sign-in codes and passwords (scrypt), AES-256-GCM encryption of your own engine keys and destination secrets, encrypted backups, least-privilege access controls with workspace roles, workspace isolation on every request, signed webhooks, and session tokens kept in httpOnly cookies that browser JavaScript cannot read. Changing your password signs out your other sessions.

No system is completely secure. If a personal data breach is likely to put you at risk, we will notify you and the competent authorities as required by law, such as the ANPD in Brazil.

Please report vulnerabilities to security@dcision.io (see also https://dcision.io/.well-known/security.txt).

11.Your rights

Depending on where you live, you have the right to:

  • confirm whether we process your data, and access it;
  • correct incomplete, inaccurate or outdated data;
  • have unnecessary or excessive data, or data processed unlawfully, anonymized, blocked or deleted;
  • receive your data in a portable format;
  • know with which entities we share your data;
  • be informed about the possibility of not giving consent and its consequences, and withdraw consent at any time;
  • object to processing based on legitimate interests, and ask us to restrict processing;
  • ask for a review of decisions taken solely on the basis of automated processing.

To exercise your rights, write to privacy@dcision.io from the e-mail address of your account. We may ask for information to confirm your identity, and we will answer within the deadlines set by law.

You can also lodge a complaint with a data protection authority: in Brazil, the Autoridade Nacional de Proteção de Dados (ANPD); in the European Economic Area, the supervisory authority of the country where you live or work.

We do not take decisions about you based solely on automated processing that produce legal or similarly significant effects. Automated protections, such as rate limits, may temporarily limit access to the Service. If your data reached us through one of our customers (for example inside a decision state), please contact that customer first; we will help them answer you.

12.Cookies

Our website (https://dcision.io) does not set cookies and does not use analytics, advertising or tracking technologies.

The app (https://app.dcision.io) uses only strictly necessary cookies:

CookiePurposeDuration
__Secure-authjs.session-tokenKeeps you signed in (httpOnly)30 days
__Host-authjs.csrf-token, __Secure-authjs.callback-urlProtect the sign-in flowSession
__Secure-authjs.pkce.code_verifier, __Secure-authjs.stateProtect sign-in with Google15 minutes
dcision-themeRemembers your light or dark theme1 year
dcision-wsRemembers your active workspace (httpOnly)1 year

Because these cookies are essential to provide the Service you request, they do not require consent. You can block them in your browser, but then you will not be able to sign in.

13.Children

The Service is intended for professionals and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a minor has given us personal data, contact privacy@dcision.io and we will delete it.

14.Changes to this policy

We may update this policy. We will notify you of material changes by e-mail or in the app before they take effect. The date at the top of this page shows the current version.

15.Contact

Dcision is operated by GR Digital (GR Negócios Digitais, CNPJ 29.691.265/0001-65), Av. Luiz Boiteux Piazza, 1302, Sala 13, Florianópolis/SC, 88056-682, Brazil. This policy is available in several languages; if versions conflict, the English version prevails, except where the law requires otherwise.