What we collect, why we collect it, and what rights you have over it.
Last updated: 23 July 2026
Sergio Peña Tapia, empresario individual (autónomo) ("Dayalogs", "we", "us", "our"), operates the Dayalogs survey platform available at dayalogs.com.
Registered address: Passeig de Manuel Girona 48, 6è 4a, 08034 Barcelona, Spain
NIF: 46240767A
Data protection contact: privacy@dayalogs.com
Dayalogs is the data controller for account, team, billing, support, website analytics, security, API and MCP authorization data. We decide why and how this information is used to operate and protect the service.
When a customer creates surveys, imports audiences, sends campaigns, collects responses or uploads files, that customer normally decides the purpose and means of processing. The customer is the controller and Dayalogs acts as its processor, following the customer's instructions and the applicable Data Processing Agreement (DPA).
If you are a respondent, reviewer or campaign recipient, the organization that invited you is normally responsible for the survey and its content. Contact that organization first to exercise rights concerning its data. Dayalogs will assist it where required.
Stripe processes full payment-card details. Dayalogs does not store full card numbers.
If the customer enables response confidence features, Dayalogs may process behavioral and technical signals such as response timing, pasted text, browser focus changes, honeypot interaction, client-integrity signals, repeated-answer patterns and pseudonymized identifiers derived from IP address or browser environment. These signals produce a review score; they are not proof that a respondent is human or fraudulent and do not automatically reject a response.
Using Dayalogs through ChatGPT or another AI client sends the instructions and tool results needed for that request between Dayalogs and the AI provider selected by the user. That provider processes the data under its own terms and privacy policy. Dayalogs does not use customer survey content, responses or MCP tool data to train a general-purpose AI model.
See our Cookie Policy for details and controls.
| Purpose | Typical data | Legal basis when Dayalogs is controller |
|---|---|---|
| Provide accounts, surveys, API and MCP integrations | Account, authentication, product and integration data | Performance of a contract |
| Process payments and keep accounting records | Account, billing and transaction data | Performance of a contract and legal obligation |
| Secure the platform, prevent abuse and investigate incidents | Authentication, technical, audit and quality signals | Legitimate interests and legal obligation where applicable |
| Send service messages and campaign email requested by customers | Account, recipient, campaign and delivery data | Performance of a contract; customers determine the basis for their campaigns |
| Diagnose faults and improve reliability | Usage, performance and diagnostic data | Legitimate interests |
| Measure website use | Cookie and analytics data | Consent where required |
| Send optional product news | Email and preferences | Consent, which can be withdrawn at any time |
| Respond to support or legal requests | Correspondence, account and relevant records | Contract, legitimate interests or legal obligation |
When Dayalogs acts as a processor, the customer determines the legal basis for survey, audience, campaign, response and upload data. We do not sell personal data, share it with data brokers or use it for advertising profiles. We do not make solely automated decisions that produce legal or similarly significant effects for account users or respondents.
We disclose data only as needed to provide the service, follow customer instructions, protect Dayalogs or comply with law. Current categories include:
| Recipient | Purpose | Data involved |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, database infrastructure, object storage, email delivery and delivery-event queues | Platform data, uploaded files, email and operational events |
| Stripe | Payments, subscriptions, invoices and fraud prevention | Account, billing and payment data |
| Google Analytics | Website analytics after consent | Cookie identifiers and website usage data |
| Sentry | Error and performance monitoring when configured | Limited diagnostic and technical data |
| AI or agent providers chosen by the user | Execute MCP/API-assisted workflows | Requested tool inputs and outputs |
| Professional advisers and public authorities | Legal, accounting, security and regulatory obligations | Only records relevant to the request or obligation |
Providers receive only the data required for their role and are subject to contractual or legal confidentiality and data-protection duties. We do not share data with advertisers.
We prefer European infrastructure where practical, including AWS resources configured in the EU (Frankfurt) region. Some providers or support teams may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, the European Commission's Standard Contractual Clauses or another lawful safeguard. Contact us for information about the safeguard relevant to a particular transfer.
| Category | Typical retention |
|---|---|
| Account and workspace data | For the account lifetime; deletion from active systems normally within 30 days after closure |
| Survey, audience, response, review and uploaded-file data | Until the customer deletes it or closes the account; active-system deletion normally within 30 days |
| Backups | Rotated and deleted within 90 days |
| API keys and OAuth/MCP authorizations | Until expiry, revocation or deletion; secrets are stored hashed where applicable |
| Security and access logs | Normally 90 days, longer only for an active security investigation or legal obligation |
| Operational job and delivery logs | Normally 30 days; campaign outcome records remain with the campaign until deleted |
| Error-monitoring diagnostics | Normally up to 90 days |
| Support correspondence | Normally 3 years after the last contact |
| Invoices and legally required accounting records | For the period required by applicable tax and commercial law |
| Email suppression records | As long as reasonably necessary to prevent harmful, unwanted or repeatedly failing email |
Deletion may be delayed where we must preserve evidence, comply with law, resolve a dispute or prevent repeated email abuse. We then restrict the data to that purpose.
Depending on your role and plan, Dayalogs provides controls to:
Account administrators control workspace data and access. Revoking an integration stops future access but does not automatically delete records already created through it.
Where the GDPR applies, you may have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent. To exercise rights concerning a Dayalogs account or our own processing, email privacy@dayalogs.com. We may need to verify your identity and will normally respond within one month.
For survey responses, campaign messages or audience records controlled by a Dayalogs customer, contact that customer first. We will support verified requests received from the customer.
You may complain to your local supervisory authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD).
We use measures appropriate to the risk, including HTTPS/TLS, access controls, least-privilege permissions, credential hashing, origin restrictions for embeds, scoped API/MCP authorization, backups and operational monitoring. No service can guarantee absolute security. Report suspected vulnerabilities to security@dayalogs.com.
Dayalogs is intended for organizations and professionals, not for children to create accounts independently. Customers are responsible for ensuring that surveys directed to minors have an appropriate legal basis, notices and consent process. If you believe a child has provided data unlawfully, contact us.
We may update this policy when the product, providers or law changes. We will change the date above and provide additional notice for material changes where appropriate.
Privacy: privacy@dayalogs.com
Security: security@dayalogs.com
General: hello@dayalogs.com
Post: Sergio Peña Tapia, Passeig de Manuel Girona 48, 6è 4a, 08034 Barcelona, Spain