Skip to content

We hold as little personal data as we need to run the service, and we tell you exactly what we hold, why we hold it, and how to get rid of it. This page is the canonical version. The plain-language summary above each section is for reading; the body is what counts.

01

Who we are

DMCE.ai is operated by [Legal entity name TBC], a company registered in [Country TBC] at [Registered address TBC].

For any privacy question, write to max@dmce.ai. Our Data Protection Officer reads this inbox directly.

02

What we collect

We collect four categories of data, and only what we need to operate the service.

  • Form data. Name, work email, company name, role, country, current quoting tool, and monthly quote volume - submitted when you book a demo or contact us.
  • Account data. User profile, authentication credentials, and team membership information when you become a customer.
  • Usage data. Aggregate, pseudonymized product usage that helps us improve the service. We do not sell or disclose this data.
  • Customer data. Supplier records, itineraries, pricing rules, and customer-uploaded content. This belongs to you. We process it on your behalf, under contract.

03

Why we collect it

  • To operate, secure, and improve the DMCE.ai service.
  • To provide customer support and onboarding.
  • To bill you and meet our accounting and tax obligations.
  • To comply with legal and regulatory requirements.

05

Who we share data with

We use a small list of subprocessors. Each is bound by a Data Processing Agreement.

  • Hosting: [Provider TBC] - EU region.
  • Email & transactional messaging: [Provider TBC] - EU region where available.
  • Analytics: [Provider TBC] - privacy-preserving (no cross-site tracking).
  • Payments & invoicing: [Provider TBC].
  • Customer support tooling: [Provider TBC].
  • CRM: Pipedrive - used internally to manage prospect and customer relationships.

We update this list when subprocessors change. Customers under contract are notified directly. For the current list, email max@dmce.ai.

06

International transfers

We host customer data in the European Union. Where data must move outside the EU (e.g. for a subprocessor with global operations), we rely on the European Commission's Standard Contractual Clauses or equivalent transfer mechanisms.

If we cannot meet your data-residency requirement, we will tell you before you sign.

07

How long we keep data

  • Form submissions from prospects: 24 months from last contact, then deleted.
  • Customer data: for the duration of the contract plus 90 days, after which it is exported and deleted on request.
  • Billing and accounting records: retained for the period required by applicable law (typically 5-10 years).
  • Backups: rotated on a 30-day cycle.

08

Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate personal data.
  • Have your personal data deleted.
  • Restrict processing or object to it.
  • Receive your data in a portable format.
  • Lodge a complaint with your supervisory authority.

To exercise any of these rights, email max@dmce.ai. We respond within 30 days.

09

Cookies

We use a small number of strictly necessary cookies and a privacy-preserving analytics cookie. We do not use third-party advertising cookies. Full details and opt-out controls are at our cookies notice.

10

Children

DMCE.ai is a B2B product. We do not knowingly collect personal data from anyone under 16. If you believe a minor has shared personal data with us, contact max@dmce.ai and we will delete it.

11

Changes to this policy

We may update this policy as the product, our subprocessors, or regulation changes. Material changes are emailed to active customers at least 30 days before they take effect. The current version is always at /privacy.

12

Contact

Email: max@dmce.ai

Postal address: [TBC]

Data Protection Officer: [Name TBC] · [max@dmce.ai]