Privacy Policy
At Didit we build software that helps people organize work, not people’s lives. Protecting the information you entrust to us is therefore central to our product design, our business model, and our values. This Privacy Policy explains what data we collect through the Didit website, applications, and related services (together, the “Service”), how we use and safeguard that data, the limited circumstances in which we share it, and the choices available to you. It complements, and is interpreted consistently with, our User Terms of Service.
1 Scope and Roles
When you open a personal Didit workspace or sign in with a consumer e-mail address, Didit is the data “controller,” meaning we decide how and why your information is processed. If you use Didit under a paid subscription purchased by your company or another organization (the “Customer”), that organization controls the workspace and its contents; Didit processes the data only on the Customer’s instructions and in accordance with the contract between us.
This policy covers information Didit handles directly. If you connect third-party tools or share data with others, their privacy practices are governed by their own policies.
2 Information We Collect
When you create an account we ask for a display name, an e-mail address, and a password. You may later add optional profile details such as a photo or job title. As you work you may upload files, comments, task descriptions, or other content (“User Content”). Our servers also automatically record technical details—IP address, browser or device type, settings, the features you use, crash reports, and cookies or similar identifiers—to keep the Service running smoothly.
If you upgrade to a paid plan our payment processor (acting on our behalf) collects the billing name, address, and card or bank information needed to complete the transaction. Didit itself stores only a token, never full card data.
3 How We Use Information
We process personal information to deliver, administer, and secure the Service; to answer your questions and provide customer support; to monitor, debug, and improve performance; to develop new features and train internal quality models; and to comply with legal obligations. Where allowed by law we also use your contact details to send important operational notices and occasional product tips. You may opt out of non-essential e-mail at any time by following the unsubscribe link or contacting us.
User Content is processed only so that you and anyone you explicitly share it with can view, edit, or sync it across devices. We do not publish your private workspace data, and we do not use User Content to target advertising.
We never sell or rent personal information.
4 When We Share Information
We disclose information only as needed to operate our business or when required by law. Typical recipients are:
- Service providers that host infrastructure, deliver e-mail, process payments, or assist with analytics. They may access data solely to perform contracted tasks and must safeguard it.
- Customer administrators who manage an organization’s subscription: they may view workspace data and usage logs inside that domain.
- Legal or public authorities if we believe in good faith that disclosure is necessary to comply with a valid subpoena, court order, or similar process, or to prevent serious harm.
- Successor entities in the event of a merger, acquisition, or asset sale. Any new owner will honour the commitments in this policy unless it notifies you and offers a choice.
Didit may also share aggregated or de-identified statistics—never data that can reasonably identify you—to help us explain product performance or market trends.
5 Cookies and Analytics
Didit uses essential and analytics cookies to keep you signed in, remember preferences, and understand how the Service is used. For details — and for options to manage your settings — see our separate [Cookies Notice].
6 Security
All traffic between your device and Didit is encrypted in transit using TLS. Passwords are salted and hashed; we never store them in plain text. Systems are segmented, access is role-based, and staff receive regular security training. No Internet service can guarantee absolute protection, but we continually test and refine our safeguards to reduce risk.
7 Data Retention
Account data is kept for as long as your workspace remains active and for a reasonable period thereafter to resolve disputes or enforce our terms. If you delete a workspace we queue its associated User Content and personal information for irreversible removal within 30 days, unless a longer period is required by law or compelled by the Customer that controls the workspace. Basic server logs containing IP addresses are retained for up to 90 days, and the last successful IP used to sign in is kept for up to 12 months to aid abuse prevention.
8 Your Choices and Rights
You may review and update profile details at any time from your account settings, download an archive of your workspace data, or permanently delete your account. Nevada residents may direct us not to sell “covered information” (Nevada Revised Statutes 603A) by e-mailing privacy@didit.co; Didit does not sell data today, but we honour opt-out requests as the statute requires.
Residents of other jurisdictions may have additional rights—such as access, correction, or deletion—that apply once Didit is subject to those local laws. We will respect valid requests regardless of where you live to the extent technically feasible and not overridden by our contractual obligations or legal duties.
9 Children’s Privacy
The Service is directed to users who are at least 13 years old. We do not knowingly collect personal information from children under 13, or under 16 where local law sets that higher threshold. If we learn that we have done so inadvertently we will delete the information as quickly as possible.
10 International Data Transfers
Didit is headquartered in Nevada, USA. If you access the Service from outside the United States you understand that your information will be transferred to, stored in, and processed on U.S. servers. Should we later serve regions that impose cross-border-transfer rules, we will adopt appropriate safeguards such as Standard Contractual Clauses or successor frameworks and update this notice.
11 Changes to This Policy
We may revise this Privacy Policy to reflect new features, legal requirements, or security improvements. Significant changes will be announced through the Service or by e-mail before they take effect. The date at the top shows when the latest version became effective. Continued use of the Service after a revision means you accept the updated terms.
12 Contact
Questions or concerns? Please write to legal@didit.co. We will respond as promptly as possible, and always within any time-frame required by applicable law.
Effective July 11, 2025