Privacy policy
Dayfile privacy policy.
Last updated: 16 September 2026
1) Who we are
Dayfile (“we”, “us”) is provided by Dayfile Ltd, a company registered in England and Wales under company number 17122272, of The Old Coach House Mynydd Ednyfed, Caernarfon Road, Criccieth, Gwynedd, Wales, LL52 0PH. VAT registration number 517005231.
Contact: privacy@getdayfile.com
2) What this policy covers
This policy explains how we collect and use personal data when you:
- visit our website;
- use the Dayfile platform; and/or
- contact us, request a trial or book a demo.
3) The data we collect
We may collect and process:
- Account data: name, work email, role, company, authentication details.
- Usage data: log data, IP address, device and browser information, feature usage.
- Customer content: emails and attachments, Microsoft Teams messages and the transcripts of recorded meetings, and messages, photos and videos from the WhatsApp groups you choose to connect, together with related metadata (for example sender, recipients, subject, timestamps), plus any notes or corrections added by users. Personal, HR and non-project correspondence is identified and left out of your Dayfile.
- Communications: messages you send us, support tickets and meeting notes.
- Cookies and analytics data: where enabled (see Cookies).
4) How we use your data
We use personal data to:
- provide, operate and improve Dayfile;
- organise customer content by project, company and topic, and produce the summaries, answers, reports and exports requested by users;
- authenticate users and administer accounts;
- secure the service and prevent misuse;
- provide support and service communications;
- carry out permitted B2B marketing;
- comply with legal obligations.
Customer content is never used to train artificial-intelligence models.
5) Lawful bases
Under UK GDPR, we rely on one or more of:
- Contract — to deliver the service you use;
- Legitimate interests — service improvement, security and B2B communications;
- Consent — where required (for example non-essential cookies);
- Legal obligation — where applicable.
6) Customer content and data roles
For customer content, your organisation is the Data Controller and Dayfile acts as a Data Processor, processing content only on your documented instructions via the platform. Dayfile’s connection to Microsoft 365 is read-only: it cannot send, edit or delete anything, and you can revoke it at any time from your Microsoft 365 admin centre.
7) Sharing and sub-processors
We may share data with trusted service providers (for example hosting, infrastructure, security and AI model providers) acting as sub-processors under written terms. A current sub-processor list is available on request.
8) Hosting and international transfers
Customer content is hosted in the United Kingdom by default. If your business is in the USA, Australia or Canada, we can host your Dayfile in that country so your data stays where you are. Where any data is transferred outside the UK, we use appropriate safeguards such as the UK International Data Transfer Agreement (IDTA) or approved contractual addenda.
9) Security
We apply technical and organisational measures appropriate to the risk, including access controls, encryption in transit and at rest, logical isolation of each customer’s data, logging and least-privilege access. Dayfile is Cyber Essentials certified.
10) Retention
- Account and usage data is retained for as long as an account is active and as required for security and compliance.
- Customer content is retained for the duration of your subscription, according to your organisation’s configuration, or until deletion or export is requested, subject to legal requirements.
- On cancellation, you may export customer content for 30 days, after which it is deleted.
11) Your rights
Individuals may have rights to access, rectify, erase, restrict, object to and request portability of their data. Where Dayfile acts as a processor, we assist the controller with these requests.
12) Cookies
Our website uses necessary cookies. If analytics or marketing cookies are introduced, consent will be requested where required by law.
13) Marketing
We may send B2B marketing communications where permitted. You can opt out at any time.
14) Contact and complaints
Contact us at privacy@getdayfile.com. You may also complain to the UK Information Commissioner’s Office (ICO).