Introduction
This Privacy Policy describes how DIBIZ.Link (“We”, “Us”, “Our”, “DIBIZ”, “the Company”) collects, uses, stores and discloses information when You use the DIBIZ.Link application and related services (the “Service”).
DIBIZ.Link is built on a local-first architecture. The great majority of the business, contact, ledger, document and messaging data You create in the Service is generated and stored in an encrypted database on Your own device. Where You choose to enable Backup, an encrypted copy of that data is transferred directly from Your device to a personal cloud storage account that You control — such as Google Drive, Microsoft OneDrive, Apple iCloud, or another cloud storage provider You choose to connect. We do not hold a copy of, and cannot decrypt, the contents of Your Backup.
Some parts of the Service still depend on servers that DIBIZ operates or engages, for example to create and authenticate Your Account, to relay messages between Your devices in real time, to deliver push notifications, to process Electronic Signing requests and, for organizations on a paid/Full-Tier subscription plan, to store certain ledger and document metadata. This Policy explains, as precisely as possible, what stays on Your device or Your own cloud account, and what is processed on Our servers or those of Our service providers.
By using the Service, You acknowledge that Your personal data will be processed as described in this Privacy Policy and in accordance with the applicable legal bases described in “Legal Basis for Processing (EEA/UK Users)” below.
Beta Release
During the initial beta release period, DIBIZ.Link may be provided as a beta or early-access version. Certain features may be incomplete, experimental, subject to change, temporarily unavailable, or withdrawn as We test, improve, and validate the Service.
During the beta period, availability, performance, functionality, and user experience may differ from those of a generally available release. Users should maintain appropriate backups of important data and should not rely on beta functionality as the sole means of preserving or accessing important business information.
The beta status does not change the privacy, security, data-protection, or data-handling practices described in this Privacy Policy. When DIBIZ.Link transitions from beta to general availability, this Policy may be updated where necessary to reflect material changes in processing or the Service.
During the limited Beta Release period, certain Service features may change, be added, suspended, or removed as We test and improve the platform. Any such changes will not alter the data-processing practices described in this Privacy Policy without the updates and notices required by applicable law.
Interpretation and Definitions
Interpretation
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
- You means the individual accessing or using the Service, or the company or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
- Company (referred to as either “the Company”, “We”, “Us” or “Our” in this Policy) refers to DIBIZ Pte Ltd, Singapore and its subsidiaries in other countries.
- Affiliate means an entity that controls, is controlled by, or is under common control with a party, where “control” means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
- Account means the unique account created for You, and administered through Our authentication service, to sign in to and access the Service.
- Website refers to DIBIZ.Link, accessible from https://dibizlink.com/.
- Service refers to the DIBIZ.Link mobile and desktop applications, including their core functionalities, local data storage, optional cloud backup, messaging, ledger/document management, Electronic Signing, and any updates, enhancements or new features.
- Local Storage refers to the encrypted, on-device database and file storage that the Service uses by default to store Your data.
- Backup refers to the optional, encrypted copy of Your Local Storage that You may choose to store in a personal cloud storage account (such as Google Drive, Microsoft OneDrive, Apple iCloud, or another cloud storage provider You choose to connect) that You control.
- Full-Tier Organization refers to an organization on a paid subscription plan that has server-processed features enabled, such as centralized ledger records, as described below. Organizations that are not on such a plan are referred to as operating on a Free Tier.
- Electronic Signing is a feature provided directly by DIBIZ.Link that allows You to electronically sign documents through the Service.
- Country refers to the jurisdiction in which You reside or from which You access Our Service.
- Service Provider means any natural or legal person who processes data on behalf of the Company, including Google, Microsoft and Apple (for Backup infrastructure), Google/Firebase (for push notifications), Hedera (for independent verification recording of completed signings), Cloudflare (for Free-Tier document transfer storage), Microsoft Azure (for Full-Tier document storage), and Our AI service provider (currently Google Cloud Vertex AI; We may engage a different AI service provider in the future, in which case this Policy will be updated) (for optional AI-assisted document parsing). DIBIZ.Link’s Electronic Signing functionality itself is provided by DIBIZ.Link and not by a third-party electronic-signing provider.
- Personal Data is any information that relates to an identified or identifiable individual.
- Official Data refers to company-related information provided by a user, such as organization name, email, address, and organisation type.
- Cookies are small files that are placed on Your computer, mobile device or any other device by the Website, containing details of Your browsing history on that Website among its many uses.
- Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a session).
Collecting and Using Your Personal/Official Data
Account and Profile Data
While using Our Service, We may ask You to provide certain official/personally identifiable information needed to create and manage Your Account, including but not limited to:
- Company name
- Business registration number
- Business address
- Industry type
- Email address
- First name and last name
- Address, State, Province, ZIP/Postal code, City
- Contact numbers
This account/profile information is processed by Our authentication service in order to create and manage Your Account and Your sign-in sessions, and is stored on Our servers, located in India, for as long as Your Account remains active.
Where Your Local Storage and Backups Are Kept
Beyond the account information above, the substantive content You create and use in the Service — including Your organization’s contacts, partnerships, ledger entries and documents, messages, and email — is generated and stored in an encrypted local database on Your device (secured using SQLCipher/AES-based encryption), using encryption keys derived on Your device. By default, none of this content is transmitted to or stored on DIBIZ’s servers.
If You choose to enable Backup, an encrypted copy of this local database, and separately encrypted copies of Your file attachments, are uploaded directly from Your device to a personal cloud storage account that You control:
- Google Drive — stored in a hidden, app-only folder that is not visible in Your regular Drive
- Microsoft OneDrive — stored in an app-only folder
- Apple iCloud — stored in Your private iCloud container for the Service
- Any other cloud storage provider You choose to connect — stored under that provider’s own equivalent app-restricted storage area, where supported
These uploads travel directly between Your device and the relevant cloud storage provider’s servers — they do not pass through, and are not stored on, any DIBIZ server. The database backup and Your file attachments are encrypted (using SQLCipher and AES-256-GCM respectively) with keys derived on Your device before they ever leave Your device, using different derived keys than those protecting Your live on-device data. DIBIZ does not hold a copy of, and cannot decrypt, the contents of Your Backup.
To let You recover Your Account and Backup on a new device, We store limited backup metadata on Our servers — specifically: Your account identifier; the authentication and key-derivation method and version You are using; a truncated cryptographic fingerprint of Your recovery Secret Key (never the key itself); whether You have set a recovery passphrase; timestamps for when Your Emergency Kit was issued and acknowledged; which cloud provider You have connected (stored only as a convenience hint); and basic records of the devices (type, platform, label) linked to Your account, up to a maximum number of devices. None of this metadata, alone or together, can be used to decrypt Your Local Storage or Backup.
DIBIZ does not hold, and has no technical ability to reset, recover, or bypass, a lost Secret Key, Emergency Kit, or recovery passphrase. If You lose access to all of Your devices and Your recovery credentials, Your Local Storage and Backup may become permanently and irrecoverably inaccessible — please see the Terms of Service for how liability for such loss is allocated.
DIBIZ may, in the future, offer an additional, optional server-side backup destination for Full-Tier Organizations. No such feature is currently available; if and when it is introduced, this Policy will be updated to describe it before it is offered.
Email Privacy
If You choose to connect Your own email account (for example, Gmail, Microsoft/Outlook, or another account accessible via IMAP/SMTP) so that Your email correspondence appears alongside chat within the Service, the content and metadata of that email are treated the same way as Your other User Data: they are stored in Your encrypted Local Storage on Your device, and, if You enable Backup, in Your encrypted Backup, using the same encryption described above. DIBIZ does not read, scan, or otherwise access the content of Your emails on Our servers as part of providing this feature, and Your email account credentials are used only to connect directly between Your device and Your email provider. Connecting an email account is entirely optional and remains under Your control; You may disconnect it at any time from within the Service, and You are responsible for reviewing Your email provider’s own privacy policy.
Usage Data
Usage Data is collected automatically when using the Service. Usage Data may include information such as Your device’s Internet Protocol (IP) address, device manufacturer, operating system and version, application version, the features of the Service that You use, the time and date of Your use, and other diagnostic data. We do not collect unnecessary personal or diagnostic data beyond what is needed to ensure platform compatibility, performance and security.
Tracking Technologies and Cookies
When You visit Our Website, We use Cookies and similar tracking technologies to keep You signed in and to remember Your preferences. You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent; however, if You do not accept Cookies, You may not be able to use some parts of Our Website.
We classify the Cookies used on Our Website as follows:
- Essential/Strictly Necessary Cookies — required for the Website to function, such as maintaining Your sign-in session and enabling core navigation. These cannot be switched off and do not require consent.
- Functionality Cookies — remember Your choices and preferences (such as display settings) to give You a more personalized experience.
- Analytics Cookies — help Us understand how visitors use Our Website (such as pages visited and time spent) so We can improve it. These are only set with Your consent, where required by applicable law.
- Marketing Cookies — used to measure the effectiveness of Our marketing communications. We do not currently set marketing Cookies on Our Website; if this changes, this Policy will be updated and, where required by applicable law, We will request Your consent beforehand.
Where Our Website displays a cookie consent banner or preference tool, You can use it to accept or reject non-essential Cookie categories, and to change Your choice at any time. Where no such tool is displayed, You can manage or block Cookies using Your browser’s own settings.
Data We Process on Our Servers
Certain parts of the Service require server-side processing regardless of whether You use Backup:
- Account & Authentication: creating Your Account, signing You in (via email/password, magic link, or Google/Microsoft/Apple single sign-on), and managing Your active sessions across devices.
- Message Delivery: when You send a message to another user or organization, it is briefly queued on Our messaging servers to ensure delivery to devices that are offline. Delivered messages are automatically purged from Our servers, typically within 24 hours and in any case no later than 7 days.
- Push Notifications: We use Firebase Cloud Messaging, a Google service, to deliver push notifications to Your device. This requires sharing a device push token with Firebase.
- Electronic Signing and Verification: when You use the Electronic Signing feature, the document to be signed is processed by DIBIZ.Link as necessary to provide the signing functionality and, once signing is complete, an independent verification record referencing a Hedera public-ledger consensus timestamp is generated. See “DIBIZ.Link Electronic Signing and Verification” below.
- Ledger and Document Metadata (Full-Tier Organizations only): for organizations on a paid/Full-Tier subscription plan, certain ledger/document metadata (such as file names, document types, amounts, and counterparty names) is stored on Our servers, in addition to being stored locally, to support cross-organization document workflows. See “Where Your Document Files Are Stored” below for how the underlying document files themselves are handled.
Organizations on Our Free Tier do not have ledger records or Electronic Signing requests stored on Our servers.
Where Your Document Files Are Stored
Documents You upload are encrypted on Your device with AES-256-GCM before they leave it.
- Free-Tier Organizations: the encrypted file is uploaded directly to Cloudflare R2 edge storage and is automatically deleted after 7 days — it is a transfer buffer, not a system of record, so the authoritative copy remains on Your device and in Your own Backup.
- Full-Tier Organizations: the encrypted file is uploaded directly to Microsoft Azure Blob Storage and retained for the duration of Your subscription, together with the document metadata held on Our servers described above.
In neither case does the file itself pass through DIBIZ’s own servers.
Separately, if You place a document in a folder configured for AI-assisted parsing, an unencrypted copy of that document is staged with Our AI service provider and read to extract structured data, then deleted once parsing is complete. This is the only point at which an unencrypted document file is placed in cloud storage, and it happens only for documents You put in an AI-parsing folder. Our AI service provider is currently Google Cloud (using its Vertex AI service and Google Cloud Storage). We are not restricted to this provider and may engage a different AI service provider in the future; if We do, this Policy will be updated before the change takes effect, and equivalent protections (including the non-training commitment below) will continue to apply. Documents and data submitted for AI-assisted parsing are not used to train or improve any underlying machine-learning model, consistent with Our AI service provider’s standard enterprise terms. AI-assisted parsing is provided on a best-efforts basis and may produce inaccurate or incomplete results; You are responsible for reviewing extracted data before relying on it.
If We make a material change to the AI processing provider, processing purpose, or manner in which documents are processed, We will provide advance notice and, where required by applicable law, obtain any required consent or take any other legally required step before the changed processing begins.
Use of Your Official/Personal Data
The Company may use Your official and personal data for the following purposes:
Where an organization uses DIBIZ.Link to store or process personal data relating to its employees, customers, suppliers, counterparties, or other individuals, that organization remains responsible for determining the purposes and lawful basis for its processing and for providing any notices or obtaining any permissions required by applicable law. To the extent DIBIZ.Link processes such personal data on the organization's behalf, DIBIZ.Link will do so only as necessary to provide the Service and in accordance with the applicable Terms of Service and other lawful instructions.
- To provide and maintain the Service, including Local Storage, encryption and Backup features, and monitoring the server-side systems (authentication, message relay, push notifications, Electronic Signing) for performance and reliability.
- To create and manage Your Account, including authenticating You across devices and managing active sessions.
- To enable Backup and Restore of Your Local Storage to a cloud storage account You control.
- To deliver messages between Your devices and other users or organizations in real time.
- To send You push notifications and service communications, regarding account activity or service updates.
- To provide Electronic Signing and independent verification services .
- To provide technical support, including issue tracking, resolution and customer service interactions.
- To fulfil contractual obligations, such as processing subscription payments for Your Subscription Plan.
- To comply with legal obligations or respond to lawful requests.
- To inform You about updates or features that may be of interest, unless You have opted out of such communications.
Legal Basis for Processing (EEA/UK Users)
If You are located in the European Economic Area or the United Kingdom, the General Data Protection Regulation (GDPR) and the UK GDPR require Us to identify the legal basis under Article 6 on which We process Your personal data. The table below maps Our main processing activities to their legal basis:
- Creating and administering Your Account, and providing the core Service: Performance of a contract with You (Article 6(1)(b)).
- Enabling and operating optional features You choose, such as Backup, Electronic Signing, or AI-assisted parsing: Your consent (Article 6(1)(a)), which You may withdraw at any time by disabling the relevant feature.
- Message delivery, push notifications, security monitoring, and fraud/abuse prevention: Our legitimate interests in operating and securing the Service (Article 6(1)(f)), balanced against Your rights.
- Full-Tier ledger/document metadata processing, where used by Your organization: Performance of a contract with You and/or Your organization (Article 6(1)(b)).
- Complying with legal obligations, responding to lawful requests, and retaining records as required by law: Legal obligation (Article 6(1)(c)).
Where We rely on Your consent, You may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal, as described in “Your Data Protection Rights” below.
Retention of Your Data
- Local Storage: retained on Your device until You delete it (for example, by uninstalling the Service or clearing app data). DIBIZ has no ability to remotely access or delete Your Local Storage.
- Backup: retained in Your own Google Drive, OneDrive, iCloud, or other connected cloud storage account until You delete it using that provider’s own tools, or until unreferenced backup data is automatically pruned by the Service.
- Account and Authentication Data: retained on Our servers for as long as Your Account is active, and for a limited period afterward to comply with legal obligations, resolve disputes, and enforce Our agreements.
The limited post-closure retention period may include the minimum information reasonably necessary to prevent fraud or abuse, resolve disputes, enforce contractual rights, maintain required business records, or comply with legal obligations. Such retained information is not used for unrelated purposes.
- Message Relay Data: retained only transiently (typically no more than 7 days) for delivery purposes, then purged.
- Full-Tier Ledger Metadata and related server-side records (including any signed documents stored as part of the Full-Tier ledger record): retained during Your organization’s subscription and, where applicable, made available for up to thirty (30) days after termination to allow the organization to access or retrieve its server-side records. After that period, such data may be deleted, subject to applicable legal, regulatory and contractual retention requirements.
- Document Files (Free-Tier): encrypted copies held in Cloudflare R2 edge storage are automatically deleted after 7 days.
- Document Files (Full-Tier): encrypted copies held in Microsoft Azure Blob Storage are retained for the duration of Your organization’s subscription.
- AI-Parsing Staging Copies: unencrypted copies staged in Google Cloud Storage for Vertex AI parsing are deleted immediately once parsing of the document is complete.
All data retention practices are reviewed periodically to ensure data is not held longer than necessary and that user privacy is respected at every stage.
Transfer of Your Data
Account/authentication data, message relay data, and Full-Tier ledger metadata are processed on servers located in India as described in this Policy and in accordance with the applicable legal basis identified above.
Your Backup is transferred directly to — and is governed by the privacy practices and data-hosting locations of — Google, Microsoft, Apple, or whichever other cloud storage provider You choose to connect, depending on the provider You choose to use for Backup. We encourage You to review the relevant provider’s own privacy policy. Where optional AI-assisted parsing is used, the temporary document copy is processed using Our AI service provider's infrastructure (currently Google Cloud), which may be located outside India.
This treatment of Your Backup is distinct from third-party providers engaged by DIBIZ.Link to operate features of the Service. For DIBIZ-selected providers, DIBIZ.Link remains responsible for applying the contractual and data-protection safeguards required under applicable law.
No data transfer will occur unless adequate safeguards are in place to protect the confidentiality, integrity, and lawful processing of Your information. Where We transfer personal data out of the European Economic Area, the United Kingdom, or another jurisdiction that restricts such transfers, We rely on recognized transfer mechanisms, such as the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or an equivalent mechanism recognized under applicable law, to protect that data to a standard consistent with this Policy.
Business Continuity
The Company has established Business Continuity plans to ensure the timely recovery of Our server-side services (such as authentication, message relay, and server-side ledger/Electronic Signing features) in the event of a disaster or significant disruption. Because Your Local Storage resides on Your own device and Your Backup resides in Your own cloud account, Your core data remains available to You independently of DIBIZ’s own service availability.
Security of Your Data
The security of Your data is important to Us. While no method of transmission over the Internet or electronic storage is completely secure, We implement commercially reasonable and industry-standard measures to protect Your data, including:
- On-device database encryption using SQLCipher, with encryption keys derived on Your device and never transmitted to Us.
- Client-side AES-256-GCM encryption of file attachments and backup archives before they are uploaded to Your chosen cloud provider.
- Secure, app-only or hidden storage locations at Google Drive, Microsoft OneDrive, Apple iCloud, or any other cloud storage provider You connect, sandboxed from Your regular files where that provider supports it.
- Industry-standard OAuth 2.0 authentication flows for connecting Your cloud storage account, using dedicated application credentials separate from Your sign-in credentials.
- Encryption in transit for all data exchanged with Our servers and with Our service providers.
To further strengthen Our security posture, DIBIZ Global employs Zero Trust Network (ZTN) tools and principles. This means:
- Every access request is continuously authenticated and authorized, regardless of the user’s location or network.
- Access is granted based on least privilege, ensuring users and devices only access what is necessary.
- Anomalous behaviour is actively monitored and addressed to prevent lateral movement and privilege escalation.
All authorized DIBIZ.Link personnel are bound by confidentiality obligations and are prohibited from processing client data for any purpose other than as instructed by the client or as required by law.
Deletion and Return of Content
- In-App Account Deletion: You may request deletion of Your Account at any time from within the Service, via Settings > Delete Account. After You confirm this action, Your Account is scheduled for deletion on Our servers and You are immediately signed out. A limited reactivation window applies, during which You may sign back in and choose to reactivate Your Account to cancel the deletion. This action does not, by itself, erase Your Local Storage on this device — to remove Local Storage as well, uninstall the Service or use the in-app data-clearing option described below. See Section 8.2 of the Terms of Service for how using this option affects Your Subscription Plan, Your notice obligations, and any fees already due.
- Local Storage: uninstall the Service from Your device, or use any in-app data-clearing option where available, to delete Your Local Storage.
- Backup: use Google Drive, OneDrive, iCloud, or Your other connected cloud storage provider’s own account tools to remove the DIBIZ.Link application data folder, or contact Us for assistance.
- Server-Side Data: in addition to the in-app Account deletion option above, You may request a copy or deletion of Your Account data and any related data held on Our servers (including Full-Tier ledger metadata) by contacting Us at [email protected] or [email protected]. We will take reasonable steps to provide or delete such data within a reasonable timeframe, unless retention is required by law or for legitimate business purposes.
Hosting and Processing Locations
Data Hosting Location:
- India — account/authentication data, message relay, and Full-Tier ledger metadata
- Your own Google Drive, Microsoft OneDrive, Apple iCloud, or other connected cloud storage provider — for Your Backup, hosted per that provider’s own infrastructure
- Cloudflare R2 (global edge network) — for Your encrypted document file, Free-Tier Organizations only, as a temporary transfer buffer
- Microsoft Azure Blob Storage — for Your encrypted document file, Full-Tier Organizations only, for the duration of Your subscription
- Our AI service provider (currently Google Cloud) — for optional AI-assisted document parsing
Data Processing Location:
- India, and the respective infrastructure of Google, Microsoft, Apple, DIBIZ.Link, Hedera and Cloudflare, as applicable to the features You use.
Disclosure of Personal/Official Information
The Company will disclose or share Your personal information, without prior notice, only when required to do so by law or under the following circumstances:
- To comply with legal obligations or respond to lawful requests, such as subpoenas or court orders.
- To protect and defend the rights, property, or safety of the Company.
- To act in urgent circumstances to protect the personal safety of users of Our Service or the general public.
We may also disclose Your account/authentication and Full-Tier server-side data to third parties in the following situations:
- In connection with a merger, acquisition, or sale of all or a portion of Our business or assets, in which case Your data may be shared with the prospective buyer or seller.
- If DIBIZ or substantially all of its assets are acquired by a third party, personal data held by Us may be transferred as part of that transaction.
Where legally permissible, DIBIZ will notify You prior to such disclosures, unless prohibited by law or regulatory obligations. Note that Your Local Storage and Backup are encrypted end-to-end and are not accessible to DIBIZ, and therefore cannot be disclosed by Us in a readable form under any of the above circumstances.
Access to, Updating, and Non-Use of Your Personal/Official Information
Because Your Local Storage resides on Your own device, You have direct and immediate access to view, update, or delete that content at any time from within the Service.
For account/authentication and server-side Full-Tier data, You have the right to request access to the information We hold about You. If You would like a copy of Your data, please contact Us at [email protected].
If an organization provides Your personal data to DIBIZ.Link through its use of the Service, You may need to contact that organization to access, correct, or delete that data.
We are committed to ensuring that Your information is accurate and up to date. If any of Your details change — such as Your name, email address, or contact number — please notify Us by emailing [email protected]. You may also request corrections or deletions of any inaccurate or outdated information.
You have the right to object to or restrict the collection, use, processing, or disclosure of Your information as described in this Privacy Policy. You may withdraw Your consent at any time by contacting Us at the email address above.
Your Data Protection Rights
Depending on Your jurisdiction (including under the GDPR/UK GDPR, Singapore’s Personal Data Protection Act (PDPA), India’s Digital Personal Data Protection Act (DPDP Act), and other applicable data protection laws), You may have some or all of the following rights in relation to Your personal data:
- Right of Access — to request confirmation of whether We process Your personal data, and a copy of it.
- Right to Rectification — to request correction of inaccurate or incomplete personal data.
- Right to Erasure (“Right to be Forgotten”) — to request deletion of Your personal data, subject to any legal or contractual retention requirements described in “Retention of Your Data” above.
- Right to Restrict Processing — to request that We limit how We use Your personal data in certain circumstances.
- Right to Data Portability — to request a copy of the personal data You have provided to Us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Right to Object — to object to Our processing of Your personal data based on legitimate interests, including for direct marketing.
- Right to Withdraw Consent — where processing is based on Your consent, to withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
- Right to Lodge a Complaint — to lodge a complaint with a data protection authority, such as Singapore’s Personal Data Protection Commission (PDPC), India’s Data Protection Board, Your local EEA/UK supervisory authority, or the equivalent authority in Your jurisdiction.
To exercise any of these rights, contact Us at [email protected] or Our Data Protection Officer at [email protected]. We will respond within the timeframe required by applicable law. We may need to verify Your identity before acting on a request, and some rights may be subject to exceptions or limitations under applicable law.
California and Other U.S. State Privacy Rights
If You are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives You additional rights over Your personal information, including the right to know what personal information We collect, use, and disclose; the right to delete Your personal information; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of Your personal information; the right to limit the use of sensitive personal information; and the right not to be discriminated against for exercising these rights.
Do Not Sell or Share My Personal Information: DIBIZ does not sell Your personal information, and does not share it for cross-context behavioral advertising, in either case as those terms are defined under the CCPA/CPRA. If this changes in the future, We will update this Policy and provide the required opt-out mechanism before doing so.
Residents of other U.S. states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, and Utah) may have similar rights to know, access, correct, delete, and opt out of certain processing of their personal data; You can exercise these rights using the contact details above.
Links to Other Websites and Third-Party Services
Our Service integrates with, or contains links to, third-party websites and services that are not operated or controlled by DIBIZ. We strongly encourage You to review the privacy policy of each service listed below, particularly for those You choose to use (such as Backup providers).
- Google Drive / Google Account (used only if You enable Backup via Google) — https://policies.google.com/privacy
- Microsoft OneDrive / Microsoft Account (used only if You enable Backup via Microsoft) — https://privacy.microsoft.com/privacystatement
- Apple iCloud (used only if You enable Backup via Apple) — https://www.apple.com/legal/privacy/
- Any other cloud storage provider You choose to connect for Backup — governed by that provider’s own privacy policy, which We encourage You to review before connecting it
- Firebase Cloud Messaging (Google) (used for push notifications) — https://policies.google.com/privacy
- Hedera (used for independent verification recording of completed electronic signings) — https://hedera.com/privacy
- Cloudflare (used to hold Your encrypted document file as a temporary transfer buffer, Free-Tier Organizations only) — https://www.cloudflare.com/privacypolicy/
- Microsoft Azure (used to store Your encrypted document file for the duration of Your subscription, Full-Tier Organizations only) — https://privacy.microsoft.com/privacystatement
- Google Cloud / Vertex AI (Our current AI service provider, used only if You enable optional AI-assisted document parsing) — https://cloud.google.com/terms/cloud-privacy-notice — if We change AI service providers in the future, this Policy will be updated to name the new provider before the change takes effect
DIBIZ.Link is not responsible for the content, privacy practices, or policies of any third-party websites or services.
DIBIZ.Link Electronic Signing and Verification
This section describes the Electronic Signing feature and the independent verification record generated for completed electronic signatures. Electronic Signing is provided directly by DIBIZ.Link.
1. Electronic Signing by DIBIZ.Link
- DIBIZ.Link processes Your document and related signer information as necessary to provide the Electronic Signing service. This may include Your name, email address, and other required information.
- DIBIZ.Link’s Electronic Signing functionality is provided directly by DIBIZ.Link and does not currently rely on a third-party electronic-signing provider.
2. Verification Record and Document Storage
- Once the signing process is complete, an independent verification record referencing a Hedera public-ledger consensus timestamp is generated to verify that the signing occurred at that time. This record is a technical timestamp proof, not a notarial or legal certification act.
Legal enforceability of Electronic Signatures: DIBIZ.Link's Electronic Signing feature is currently provided as a technical signing and verification workflow only. DIBIZ.Link does not currently represent or warrant that electronic signatures created through the Service are legally enforceable or equivalent to a qualified, certified, or otherwise legally recognized electronic signature under any particular jurisdiction. Work to assess and support applicable legal enforceability requirements is ongoing. Users are responsible for determining whether the Electronic Signing feature is suitable for their particular transaction and applicable legal requirements.
The Hedera verification record is intended to contain only technical verification information (such as a cryptographic reference and timestamp) and not the contents of the signed document. DIBIZ.Link does not intentionally place the signed document itself or its substantive personal information on the public ledger.
- A copy of the signed document is securely stored on DIBIZ servers, as part of the Full-Tier ledger record, for compliance and record-keeping purposes.
3. Data Security
- Data processed by DIBIZ.Link for Electronic Signing is handled using the security measures described in this Policy and the Terms of Service.
4. User Consent
- By using Our Service and opting to sign documents through the Electronic Signing feature, You consent to the transfer and processing of Your data by DIBIZ.Link, and to the recording of a verification record on the Hedera public ledger, as described above.
Children’s Privacy
The Service is not intended for use by individuals under the age of 13 (or the minimum age required in Your jurisdiction). By using the Service, You affirm that You meet the applicable age requirement.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in Our practices, legal requirements, or service offerings. When We make material changes, We will notify You by:
- Posting the updated Privacy Policy on this page,
- Updating the “Last Updated” date at the top of the policy, and
- Providing notice via email and/or a prominent message within Our Services, where appropriate.
We encourage You to review this Privacy Policy periodically to stay informed about how We protect Your data. Changes become effective once posted on this page unless otherwise specified.
Data Protection Officer
DIBIZ has designated a Data Protection Officer (DPO) as Our privacy representative to oversee Our data protection practices and to serve as a point of contact for privacy-related matters, in accordance with applicable data protection laws. You can contact Our DPO directly at [email protected] with any question about this Privacy Policy, Our data protection practices, or to exercise any of the rights described in “Your Data Protection Rights” above.
Contact Us
If You have any questions about this Privacy Policy, You can contact Us:
By visiting this page on Our website: www.dibizlink.com, by emailing Us at [email protected], or by contacting Our Data Protection Officer at [email protected].