S I N C O

Privacy Policy

Last Updated: 23 Sep 2026

Introduction

This Privacy Policy describes how DIBIZ.Link (“We”, “Us”, “Our”, “DIBIZ”, “the Company”) collects, uses, stores and discloses information when You use the DIBIZ.Link application and related services (the “Service”).

DIBIZ.Link is built on a local-first architecture. The great majority of the business, contact, ledger, document and messaging data You create in the Service is generated and stored in an encrypted database on Your own device. Where You choose to enable Backup, an encrypted copy of that data is transferred directly from Your device to a personal cloud storage account that You control — such as Google Drive, Microsoft OneDrive, Apple iCloud, or another cloud storage provider You choose to connect. We do not hold a copy of, and cannot decrypt, the contents of Your Backup.

Some parts of the Service still depend on servers that DIBIZ operates or engages, for example to create and authenticate Your Account, to relay messages between Your devices in real time, to deliver push notifications, to process Electronic Signing requests and, for organizations on a paid/Full-Tier subscription plan, to store certain ledger and document metadata. This Policy explains, as precisely as possible, what stays on Your device or Your own cloud account, and what is processed on Our servers or those of Our service providers.

By using the Service, You acknowledge that Your personal data will be processed as described in this Privacy Policy and in accordance with the applicable legal bases described in “Legal Basis for Processing (EEA/UK Users)” below.

Beta Release

During the initial beta release period, DIBIZ.Link may be provided as a beta or early-access version. Certain features may be incomplete, experimental, subject to change, temporarily unavailable, or withdrawn as We test, improve, and validate the Service.

During the beta period, availability, performance, functionality, and user experience may differ from those of a generally available release. Users should maintain appropriate backups of important data and should not rely on beta functionality as the sole means of preserving or accessing important business information.

The beta status does not change the privacy, security, data-protection, or data-handling practices described in this Privacy Policy. When DIBIZ.Link transitions from beta to general availability, this Policy may be updated where necessary to reflect material changes in processing or the Service.

During the limited Beta Release period, certain Service features may change, be added, suspended, or removed as We test and improve the platform. Any such changes will not alter the data-processing practices described in this Privacy Policy without the updates and notices required by applicable law.

Interpretation and Definitions

Interpretation

The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

Collecting and Using Your Personal/Official Data

Account and Profile Data

While using Our Service, We may ask You to provide certain official/personally identifiable information needed to create and manage Your Account, including but not limited to:

This account/profile information is processed by Our authentication service in order to create and manage Your Account and Your sign-in sessions, and is stored on Our servers, located in India, for as long as Your Account remains active.

Where Your Local Storage and Backups Are Kept

Beyond the account information above, the substantive content You create and use in the Service — including Your organization’s contacts, partnerships, ledger entries and documents, messages, and email — is generated and stored in an encrypted local database on Your device (secured using SQLCipher/AES-based encryption), using encryption keys derived on Your device. By default, none of this content is transmitted to or stored on DIBIZ’s servers.

If You choose to enable Backup, an encrypted copy of this local database, and separately encrypted copies of Your file attachments, are uploaded directly from Your device to a personal cloud storage account that You control:

These uploads travel directly between Your device and the relevant cloud storage provider’s servers — they do not pass through, and are not stored on, any DIBIZ server. The database backup and Your file attachments are encrypted (using SQLCipher and AES-256-GCM respectively) with keys derived on Your device before they ever leave Your device, using different derived keys than those protecting Your live on-device data. DIBIZ does not hold a copy of, and cannot decrypt, the contents of Your Backup.

To let You recover Your Account and Backup on a new device, We store limited backup metadata on Our servers — specifically: Your account identifier; the authentication and key-derivation method and version You are using; a truncated cryptographic fingerprint of Your recovery Secret Key (never the key itself); whether You have set a recovery passphrase; timestamps for when Your Emergency Kit was issued and acknowledged; which cloud provider You have connected (stored only as a convenience hint); and basic records of the devices (type, platform, label) linked to Your account, up to a maximum number of devices. None of this metadata, alone or together, can be used to decrypt Your Local Storage or Backup.

DIBIZ does not hold, and has no technical ability to reset, recover, or bypass, a lost Secret Key, Emergency Kit, or recovery passphrase. If You lose access to all of Your devices and Your recovery credentials, Your Local Storage and Backup may become permanently and irrecoverably inaccessible — please see the Terms of Service for how liability for such loss is allocated.

DIBIZ may, in the future, offer an additional, optional server-side backup destination for Full-Tier Organizations. No such feature is currently available; if and when it is introduced, this Policy will be updated to describe it before it is offered.

Email Privacy

If You choose to connect Your own email account (for example, Gmail, Microsoft/Outlook, or another account accessible via IMAP/SMTP) so that Your email correspondence appears alongside chat within the Service, the content and metadata of that email are treated the same way as Your other User Data: they are stored in Your encrypted Local Storage on Your device, and, if You enable Backup, in Your encrypted Backup, using the same encryption described above. DIBIZ does not read, scan, or otherwise access the content of Your emails on Our servers as part of providing this feature, and Your email account credentials are used only to connect directly between Your device and Your email provider. Connecting an email account is entirely optional and remains under Your control; You may disconnect it at any time from within the Service, and You are responsible for reviewing Your email provider’s own privacy policy.

Usage Data

Usage Data is collected automatically when using the Service. Usage Data may include information such as Your device’s Internet Protocol (IP) address, device manufacturer, operating system and version, application version, the features of the Service that You use, the time and date of Your use, and other diagnostic data. We do not collect unnecessary personal or diagnostic data beyond what is needed to ensure platform compatibility, performance and security.

Tracking Technologies and Cookies

When You visit Our Website, We use Cookies and similar tracking technologies to keep You signed in and to remember Your preferences. You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent; however, if You do not accept Cookies, You may not be able to use some parts of Our Website.

We classify the Cookies used on Our Website as follows:

Where Our Website displays a cookie consent banner or preference tool, You can use it to accept or reject non-essential Cookie categories, and to change Your choice at any time. Where no such tool is displayed, You can manage or block Cookies using Your browser’s own settings.

Data We Process on Our Servers

Certain parts of the Service require server-side processing regardless of whether You use Backup:

Organizations on Our Free Tier do not have ledger records or Electronic Signing requests stored on Our servers.

Where Your Document Files Are Stored

Documents You upload are encrypted on Your device with AES-256-GCM before they leave it.

In neither case does the file itself pass through DIBIZ’s own servers.

Separately, if You place a document in a folder configured for AI-assisted parsing, an unencrypted copy of that document is staged with Our AI service provider and read to extract structured data, then deleted once parsing is complete. This is the only point at which an unencrypted document file is placed in cloud storage, and it happens only for documents You put in an AI-parsing folder. Our AI service provider is currently Google Cloud (using its Vertex AI service and Google Cloud Storage). We are not restricted to this provider and may engage a different AI service provider in the future; if We do, this Policy will be updated before the change takes effect, and equivalent protections (including the non-training commitment below) will continue to apply. Documents and data submitted for AI-assisted parsing are not used to train or improve any underlying machine-learning model, consistent with Our AI service provider’s standard enterprise terms. AI-assisted parsing is provided on a best-efforts basis and may produce inaccurate or incomplete results; You are responsible for reviewing extracted data before relying on it.

If We make a material change to the AI processing provider, processing purpose, or manner in which documents are processed, We will provide advance notice and, where required by applicable law, obtain any required consent or take any other legally required step before the changed processing begins.

Use of Your Official/Personal Data

The Company may use Your official and personal data for the following purposes:

Where an organization uses DIBIZ.Link to store or process personal data relating to its employees, customers, suppliers, counterparties, or other individuals, that organization remains responsible for determining the purposes and lawful basis for its processing and for providing any notices or obtaining any permissions required by applicable law. To the extent DIBIZ.Link processes such personal data on the organization's behalf, DIBIZ.Link will do so only as necessary to provide the Service and in accordance with the applicable Terms of Service and other lawful instructions.

Legal Basis for Processing (EEA/UK Users)

If You are located in the European Economic Area or the United Kingdom, the General Data Protection Regulation (GDPR) and the UK GDPR require Us to identify the legal basis under Article 6 on which We process Your personal data. The table below maps Our main processing activities to their legal basis:

Where We rely on Your consent, You may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal, as described in “Your Data Protection Rights” below.

Retention of Your Data

The limited post-closure retention period may include the minimum information reasonably necessary to prevent fraud or abuse, resolve disputes, enforce contractual rights, maintain required business records, or comply with legal obligations. Such retained information is not used for unrelated purposes.

All data retention practices are reviewed periodically to ensure data is not held longer than necessary and that user privacy is respected at every stage.

Transfer of Your Data

Account/authentication data, message relay data, and Full-Tier ledger metadata are processed on servers located in India as described in this Policy and in accordance with the applicable legal basis identified above.

Your Backup is transferred directly to — and is governed by the privacy practices and data-hosting locations of — Google, Microsoft, Apple, or whichever other cloud storage provider You choose to connect, depending on the provider You choose to use for Backup. We encourage You to review the relevant provider’s own privacy policy. Where optional AI-assisted parsing is used, the temporary document copy is processed using Our AI service provider's infrastructure (currently Google Cloud), which may be located outside India.

This treatment of Your Backup is distinct from third-party providers engaged by DIBIZ.Link to operate features of the Service. For DIBIZ-selected providers, DIBIZ.Link remains responsible for applying the contractual and data-protection safeguards required under applicable law.

No data transfer will occur unless adequate safeguards are in place to protect the confidentiality, integrity, and lawful processing of Your information. Where We transfer personal data out of the European Economic Area, the United Kingdom, or another jurisdiction that restricts such transfers, We rely on recognized transfer mechanisms, such as the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or an equivalent mechanism recognized under applicable law, to protect that data to a standard consistent with this Policy.

Business Continuity

The Company has established Business Continuity plans to ensure the timely recovery of Our server-side services (such as authentication, message relay, and server-side ledger/Electronic Signing features) in the event of a disaster or significant disruption. Because Your Local Storage resides on Your own device and Your Backup resides in Your own cloud account, Your core data remains available to You independently of DIBIZ’s own service availability.

Security of Your Data

The security of Your data is important to Us. While no method of transmission over the Internet or electronic storage is completely secure, We implement commercially reasonable and industry-standard measures to protect Your data, including:

To further strengthen Our security posture, DIBIZ Global employs Zero Trust Network (ZTN) tools and principles. This means:

All authorized DIBIZ.Link personnel are bound by confidentiality obligations and are prohibited from processing client data for any purpose other than as instructed by the client or as required by law.

Deletion and Return of Content

Hosting and Processing Locations

Data Hosting Location:

Data Processing Location:

Disclosure of Personal/Official Information

The Company will disclose or share Your personal information, without prior notice, only when required to do so by law or under the following circumstances:

We may also disclose Your account/authentication and Full-Tier server-side data to third parties in the following situations:

Where legally permissible, DIBIZ will notify You prior to such disclosures, unless prohibited by law or regulatory obligations. Note that Your Local Storage and Backup are encrypted end-to-end and are not accessible to DIBIZ, and therefore cannot be disclosed by Us in a readable form under any of the above circumstances.

Access to, Updating, and Non-Use of Your Personal/Official Information

Because Your Local Storage resides on Your own device, You have direct and immediate access to view, update, or delete that content at any time from within the Service.

For account/authentication and server-side Full-Tier data, You have the right to request access to the information We hold about You. If You would like a copy of Your data, please contact Us at [email protected].

If an organization provides Your personal data to DIBIZ.Link through its use of the Service, You may need to contact that organization to access, correct, or delete that data.

We are committed to ensuring that Your information is accurate and up to date. If any of Your details change — such as Your name, email address, or contact number — please notify Us by emailing [email protected]. You may also request corrections or deletions of any inaccurate or outdated information.

You have the right to object to or restrict the collection, use, processing, or disclosure of Your information as described in this Privacy Policy. You may withdraw Your consent at any time by contacting Us at the email address above.

Your Data Protection Rights

Depending on Your jurisdiction (including under the GDPR/UK GDPR, Singapore’s Personal Data Protection Act (PDPA), India’s Digital Personal Data Protection Act (DPDP Act), and other applicable data protection laws), You may have some or all of the following rights in relation to Your personal data:

To exercise any of these rights, contact Us at [email protected] or Our Data Protection Officer at [email protected]. We will respond within the timeframe required by applicable law. We may need to verify Your identity before acting on a request, and some rights may be subject to exceptions or limitations under applicable law.

California and Other U.S. State Privacy Rights

If You are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives You additional rights over Your personal information, including the right to know what personal information We collect, use, and disclose; the right to delete Your personal information; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of Your personal information; the right to limit the use of sensitive personal information; and the right not to be discriminated against for exercising these rights.

Do Not Sell or Share My Personal Information: DIBIZ does not sell Your personal information, and does not share it for cross-context behavioral advertising, in either case as those terms are defined under the CCPA/CPRA. If this changes in the future, We will update this Policy and provide the required opt-out mechanism before doing so.

Residents of other U.S. states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, and Utah) may have similar rights to know, access, correct, delete, and opt out of certain processing of their personal data; You can exercise these rights using the contact details above.

Links to Other Websites and Third-Party Services

Our Service integrates with, or contains links to, third-party websites and services that are not operated or controlled by DIBIZ. We strongly encourage You to review the privacy policy of each service listed below, particularly for those You choose to use (such as Backup providers).

DIBIZ.Link is not responsible for the content, privacy practices, or policies of any third-party websites or services.

DIBIZ.Link Electronic Signing and Verification

This section describes the Electronic Signing feature and the independent verification record generated for completed electronic signatures. Electronic Signing is provided directly by DIBIZ.Link.

1. Electronic Signing by DIBIZ.Link

2. Verification Record and Document Storage

Legal enforceability of Electronic Signatures: DIBIZ.Link's Electronic Signing feature is currently provided as a technical signing and verification workflow only. DIBIZ.Link does not currently represent or warrant that electronic signatures created through the Service are legally enforceable or equivalent to a qualified, certified, or otherwise legally recognized electronic signature under any particular jurisdiction. Work to assess and support applicable legal enforceability requirements is ongoing. Users are responsible for determining whether the Electronic Signing feature is suitable for their particular transaction and applicable legal requirements.

The Hedera verification record is intended to contain only technical verification information (such as a cryptographic reference and timestamp) and not the contents of the signed document. DIBIZ.Link does not intentionally place the signed document itself or its substantive personal information on the public ledger.

3. Data Security

4. User Consent

Children’s Privacy

The Service is not intended for use by individuals under the age of 13 (or the minimum age required in Your jurisdiction). By using the Service, You affirm that You meet the applicable age requirement.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in Our practices, legal requirements, or service offerings. When We make material changes, We will notify You by:

We encourage You to review this Privacy Policy periodically to stay informed about how We protect Your data. Changes become effective once posted on this page unless otherwise specified.

Data Protection Officer

DIBIZ has designated a Data Protection Officer (DPO) as Our privacy representative to oversee Our data protection practices and to serve as a point of contact for privacy-related matters, in accordance with applicable data protection laws. You can contact Our DPO directly at [email protected] with any question about this Privacy Policy, Our data protection practices, or to exercise any of the rights described in “Your Data Protection Rights” above.

Contact Us

If You have any questions about this Privacy Policy, You can contact Us:

By visiting this page on Our website: www.dibizlink.com, by emailing Us at [email protected], or by contacting Our Data Protection Officer at [email protected].

DIBIZ.Link

Privacy Policy  ·  Terms of Service

INDIBIZ Technologies Pvt Ltd, India  |  DIBIZ Pte Ltd, Singapore

© 2026 DIBIZ.Link  ·  All Rights Reserved.