Privacy

Swiss Federal Act on Data Protection and UK transparency standards · version 1.1 · 18 August 2026

Two separate modes: the free validator remains browser-only and transmits no selected file or result. A paid customer workspace stores agreement mappings, monthly workflow records and only those source and output files the subscriber intentionally uploads. Stripe separately hosts checkout. Do not send invoice files by email.

Controller

Dali AI GmbH, Wassergrabe 4, 6210 Sursee, Switzerland, UID/VAT number CHE-410.112.306. Privacy contact: [email protected].

What is processed

DataPurposeRecipientRetention
IP address, requested URL, device and security metadataDelivering and protecting the static websiteCloudflare, Inc.According to Cloudflare's service configuration and retention policy; Dali AI does not maintain a separate visitor log
Aggregated page-view counts: day, page path, linking site's domain, view and new-visit totalsMeasuring which public information pages are visitedDali AI and CloudflareDaily aggregate totals only; no IP address, cookie or visitor identifier is stored. Kept as an operational metric for as long as the page exists
Name, business contact details and message content sent by emailAnswering an enquiry and preparing a possible B2B relationshipDali AI and Hostpoint AG as email hostUntil the enquiry is resolved, or longer where required for an ensuing contract or legal record
Selected subscription, business name, billing address, tax ID, contact email, payment status and Stripe customer/subscription identifiersForming and administering the subscription, billing, fraud prevention and legal recordsDali AI, Stripe group entities, payment-method providers and their service providersFor the subscription and afterwards as required for accounting, tax, dispute and other legal records
Private-workspace identifier, agreement names and references, reusable field mappings, monthly run status, deadlines, validation counts and security eventsProviding and securing the paid production workflowDali AI and CloudflareFor the subscription and until workspace deletion, except minimal contract or security evidence retained where legally necessary. For a single return there is no subscription: workspace access ends 30 days after payment, the stored files expire on the same date rather than after 90 days, and the records are deleted with the workspace in the same way
Validation evidence metadata: coverage ID, template version, reporting month, output hash, row/error/warning counts, rule names and aggregate comparison figuresProviding a reproducible paid-workspace check record without storing invoice-line findings in D1Dali AI and CloudflareFor the subscription and until workspace deletion, subject to legal record duties
Paid-workspace source and generated output files, file names, sizes and SHA-256 integrity hashesSecure storage, review, download and deletion for the monthly production runDali AI as processor and Cloudflare as sub-processorFile values expire automatically 90 days after upload and may be deleted sooner; associated records are removed with workspace deletion or on a valid request, subject to legal duties
Private workspace bearer token on the subscriber's deviceKeeping the authorised browser signed in without a UK Filing passwordNo third-party recipient; the raw token is stored in that browser, while Dali AI stores only its one-way hashUntil the subscriber deletes browser storage or the workspace is deleted
Offer-dismissal preference stored on the visitor’s deviceNot repeating the post-check subscription message after it is dismissedNo recipient; it remains in the browser14 days

For UK visitors, the legal bases relied on are contract steps and performance for subscriptions, legal obligations for accounting and payment records, and legitimate interests for website security, fraud prevention and business enquiries. For customer-controlled personal data inside paid files and mappings, Dali AI acts on the subscribing business's instructions under the Data Processing Addendum. Published prices are calculated automatically only from the selected route and agreement quantity; no profiling or eligibility score changes them. Stripe may apply its own fraud and payment-risk processes.

Files checked in the browser

When a visitor chooses an MI file, the browser reads it into temporary working memory and applies the validation rules on the same device. The website sends no file content, file name, result, row count or framework selection back to Dali AI or an analytics service. Closing or refreshing the page removes the selected file and result from the page’s working memory.

For the RM6292 check, the browser downloads a compact reference containing the public GCA Service Table and customer URNs. That reference contains public authority identifiers; the visitor’s workbook is compared against it locally.

Files intentionally stored in the paid workspace

After Stripe confirms payment, UK Filing creates a private workspace and returns a bearer link. The workspace first reads a selected source file locally so the customer can set its mapping. When the customer creates the monthly run, the browser sends the source file and later the generated output to the authenticated same-origin storage endpoint. Dali AI records an integrity hash, file metadata and workflow status. The content is not used for advertising, analytics or AI training.

A subscriber may record a portal confirmation or submission reference and timestamp. UK Filing stores that customer-entered reference with the monthly run. The reference is not independently verified and does not prove operator receipt or acceptance.

The customer can download and delete individual files and can permanently delete the workspace. File values are also configured to expire automatically after 90 days. Deleting workspace data does not itself cancel Stripe billing; subscription cancellation is a separate authenticated action.

Service providers and locations

Cloudflare, Inc. delivers and protects the website, executes the workspace functions, stores workflow records in a D1 database whose primary region is configured as Eastern Europe, and stores paid-workspace files in encrypted Workers KV. KV and network delivery use Cloudflare's global infrastructure and may involve the United States and other countries used by its group and listed sub-processors. Dali AI relies on Cloudflare's Data Processing Addendum, including applicable transfer safeguards.

Stripe group entities provide the hosted checkout, recurring billing, payment processing, authentication and fraud prevention. Stripe receives the information entered on its checkout page and may share transaction data with banks, card networks, payment-method providers and service providers. Stripe acts as a processor for some payment activity and as a controller for purposes it determines itself. Stripe describes the relevant entities, international transfers and safeguards in its Privacy Center. Dali AI receives customer and transaction records from Stripe but not complete card numbers or security codes.

The subscription-management page links to a dedicated Stripe portal configuration. Stripe verifies access by sending a one-time passcode to the customer email used at checkout. The UK Filing website does not receive the entered email, passcode or portal activity.

Hostpoint AG hosts the dali-ai.ch email service in Switzerland. Email enquiries are not routed through the UK Filing website.

Cookies and analytics

Dali AI sets no analytics or advertising cookies, uses no tracking pixel and no third-party analytics service. On public information pages — never on the free validator or in the private workspace — the browser sends one same-origin request per page view: the page path, the referring page's address (if any) and a new-visit flag. Before anything is stored, the server reduces that address to the linking site's domain only and discards the rest. Dali AI stores these only as daily aggregate totals, without IP address, cookie or visitor identifier. The per-tab new-visit flag is kept in the browser's session storage and disappears when the tab closes. You can decline this count at any time by blocking scripts for this site in your browser; nothing else on the public pages depends on it. The browser stores a dismissed-offer expiry for 14 days and, after successful onboarding, the private workspace token until it is removed or invalidated. These local values are not advertising identifiers. Cloudflare may set strictly necessary security cookies. Stripe's separately hosted checkout may use cookies and similar technologies for payment security, authentication and fraud prevention.

Your rights

Subject to the applicable law, you may request access, correction, deletion, restriction, portability or objection by writing to the privacy contact above. Swiss data subjects may contact the Federal Data Protection and Information Commissioner. Where the UK GDPR applies, UK data subjects may complain to the Information Commissioner's Office.

Security and processor terms

Current technical measures, access-link limitations and incident contact are described on the Security page. Processor instructions, sub-processor authorisation, assistance, incident notice, audit and end-of-contract deletion are in the incorporated Data Processing Addendum.

The free validator sends no customer file. The paid workspace stores only intentional authenticated uploads and keeps submission to GCA or HTE outside UK Filing.