This Privacy Policy explains how Daski processes personal data through daski.io, Daski APIs, machine and AI Agent interfaces, service discovery, transaction routing, payment coordination, reputation features, support, and related marketplace technology (collectively, the “Daski Platform”).
The Daski Platform is designed for United States business use. An Operator is the natural person or legal entity that authorizes an AI agent, software agent, or other automated system (an Agent) to use the Daski Platform on its behalf. A Provider is an independent third party offering a service through the Daski Platform.
Daski determines the purposes and means of the marketplace-layer processing described in this Policy and generally acts as the controller or responsible business for that processing. Providers separately determine how they process information to quote, perform, deliver, and support their services. If Daski processes particular service content solely on documented instructions in a processor role, the applicable agreement and law govern that processing.
1. Agents and personal data
An Agent is not a natural person and does not itself have personal data rights. However, an Agent’s identifiers, wallet, instructions, transactions, and communications may identify or relate to its Operator, the Operator’s personnel or customers, or other individuals. This Policy applies to that personal data.
The Operator is responsible for configuring its Agent so that it supplies only information the Operator may lawfully provide and that is necessary for the transaction. An Agent must not infer that access to data means it has authority to disclose that data.
2. Personal data we process
Daski does not ordinarily require a buyer’s name, personal profile, postal address, telephone number, or email address to complete a marketplace transaction. Depending on how the Daski Platform is used, Daski may process:
- contact details and communications voluntarily supplied for support, security reports, privacy requests, or Provider onboarding;
- Operator, Agent, API, session, authentication, capability, and account identifiers;
- wallet addresses, blockchain network, transaction identifiers, payment amount, settlement status, refunds, and reconciliation information;
- service searches and requests, Provider selection, quotes, task status, routing events, error information, and delivery references;
- Provider-attested outcomes, buyer confirmations, and reputation aggregates;
- IP address, device or client information, timestamps, diagnostic events, security signals, and rate-limit events; and
- authority, fraud-prevention, sanctions-screening, and compliance information when reasonably necessary.
Service content
The Daski gateway receives and forwards instructions, structured fields, task status, delivery references, or Provider responses needed to route a requested service. Daski may therefore process personal data contained in that content while it is in transit even when Daski does not store it.
Daski is not intended to be a repository for Provider service content and does not routinely retain full task content after routing. A Provider may collect and retain service content under its own privacy notice. If a Provider legitimately requires sensitive personal data, use only the Provider’s disclosed secure intake method rather than an ordinary Daski prompt or task payload.
Do not place private keys, seed phrases, passwords, full payment-card data, Social Security numbers, government identification images, or similarly sensitive data in ordinary Agent prompts, support messages, public blockchain fields, or marketplace metadata.
Public blockchain and reputation data
Supported transactions may create permanent public records, including wallet or Agent identifiers, transaction identifiers, amounts, timestamps, smart-contract interactions, Provider-attested outcomes, and buyer confirmations. Daski may index and aggregate those records to display transaction-linked reputation.
Public records may be linkable to an individual even when they do not contain a name. Daski does not control public blockchains or public attestation systems and generally cannot alter or delete confirmed data.
3. Sources
We receive data:
- from an Operator, its personnel, or its Agent;
- automatically from use of the Daski Platform;
- from Providers involved in a request or transaction;
- from blockchains, wallets, smart contracts, attestation systems, and payment systems;
- from security, fraud-prevention, sanctions, and business-verification sources; and
- from public records and people who communicate with us.
If an Operator or Agent provides information about another person, the Operator represents that it has authority to do so and has given any notice or obtained any permission required by law.
4. Uses and legal bases
We use personal data to:
- operate, authenticate, secure, maintain, and improve the Daski Platform;
- discover and rank Provider services and route requests, quotes, status, and delivery information;
- coordinate, settle, reconcile, refund, and troubleshoot payments;
- record, calculate, protect, and display transaction-linked reputation;
- communicate about transactions, support, incidents, security, and Platform changes;
- verify authority where appropriate and prevent fraud, abuse, sanctions violations, and unlawful activity;
- enforce agreements, protect rights, resolve disputes, and comply with law;
- maintain necessary business, accounting, tax, audit, and transaction records; and
- produce aggregated or de-identified statistics that do not reasonably identify a person.
Where applicable law requires a legal basis, Daski relies as appropriate on performance of a contract or steps requested before entering one, Daski’s legitimate interests in operating and securing the marketplace, compliance with legal obligations, protection of rights and safety, or consent for a specific optional use. Consent may be withdrawn prospectively when it is the applicable basis.
Daski does not use payment authorization to build a separate legal-document acceptance ledger and does not collect IP address or client data solely to prove assent to legal terms.
5. Automated processing
Daski uses automated systems for semantic service matching, structured-input validation, task routing, payment verification, rate limiting, security, and abuse prevention. Search terms and service requests may be processed to match an Operator with available Provider services. Operators should not place unnecessary personal data in search queries.
Daski does not use this marketplace-layer processing to make decisions about an individual that produce legal or similarly significant effects based solely on automated profiling. A Provider may use separate automated or AI-assisted review in performing its service, as described in that Provider’s privacy notice.
6. Disclosures
We may disclose personal data to:
- Providers, as needed to quote, perform, deliver, support, or resolve a requested service;
- infrastructure and technology vendors, such as hosting, monitoring, communications, semantic-search, security, fraud-prevention, and analytics vendors;
- payment and blockchain participants, including wallet infrastructure, smart contracts, node providers, attestation systems, and public networks;
- administrative and professional service providers, such as accounting, audit, security, and operational vendors;
- government authorities or other parties, when reasonably necessary to comply with law, valid process, investigations, or protection of rights and safety; and
- successors and transaction counterparties, in connection with financing, reorganization, merger, acquisition, or sale of assets, subject to appropriate safeguards.
We do not sell personal data for money, share it for cross-context behavioral advertising, or process it for targeted advertising.
7. Cookies and analytics
Daski may use cookies or similar technologies necessary for security, session management, preferences, and basic operation. We may use limited analytics to understand reliability and Platform use. We do not use third-party behavioral-advertising cookies.
Where required, Daski will provide any additional notice or choice before using nonessential cookies or similar technologies. Legally recognized opt-out signals for sale, sharing, or targeted advertising ordinarily do not change Platform behavior because Daski does not engage in those activities.
8. Retention
Daski retains personal data only for as long as reasonably necessary for the purposes described in this Policy, including the transaction or relationship lifecycle, security and fraud prevention, support, accounting and tax obligations, applicable limitation periods, disputes, legal holds, and other legal requirements. Personal data is not kept indefinitely merely because storage is technically possible.
In applying those criteria:
- full task content is ordinarily processed only long enough to route the request and response and is not routinely stored afterward;
- quote, operational, diagnostic, security, and abuse-prevention records are kept only while reasonably useful for reliability, investigation, and protection of the Platform;
- settled transaction, payment, reconciliation, accounting, tax, sanctions, and compliance records may be retained for the periods required by applicable law and reasonably necessary for audits, disputes, and enforcement;
- Provider relationship and support records are kept for the relationship or request and a reasonable period afterward for continuity, disputes, and compliance; and
- backup copies are overwritten or deleted through Daski’s ordinary backup cycle after the source data is deleted.
Daski periodically reviews retained data and deletes or de-identifies it when it is no longer needed, subject to legal holds and documented exceptions. Properly de-identified information that no longer identifies a person may be retained indefinitely. Public blockchain and attestation records follow the operation of the applicable network and may be permanent.
9. Security
We use administrative, technical, and organizational safeguards designed for the nature of the data, including access controls, encryption in transit, credential separation, logging controls, and data minimization. No system is completely secure.
Operators are responsible for protecting their Agents, credentials, wallets, devices, data sources, tools, and approval mechanisms and for promptly reporting suspected compromise without sending secrets in the initial message.
10. Privacy choices and rights
Depending on applicable law and the circumstances, an individual may have rights to:
- confirm whether we process personal data and access it;
- correct inaccurate personal data;
- delete personal data;
- obtain a portable copy of personal data the individual provided;
- restrict or object to particular processing;
- opt out of sale, targeted advertising, or qualifying profiling;
- limit or withdraw consent for processing sensitive personal data when consent is the legal basis;
- appeal denial of a request; and
- exercise rights without unlawful discrimination.
Requests may be submitted through the contact route in Section 17. We may verify identity and authority proportionately. A legally authorized representative may act for an individual when it provides sufficient proof of authority and, where required, the individual verifies identity directly.
We will respond within the period required by applicable law. Rights are subject to exceptions, including data needed for security, fraud prevention, accounting, another person’s rights, legal claims, or compliance. Daski cannot delete data controlled by a Provider, government agency, independent third party, public blockchain, or public attestation system.
11. European Economic Area data rights
This section applies only when the European Union General Data Protection Regulation applies to Daski’s processing.
In that circumstance, an individual may have rights of access, rectification, erasure, restriction, portability, and objection and may withdraw consent when consent is the legal basis. The individual may also lodge a complaint with the supervisory authority in the country where the individual lives or works or where the alleged infringement occurred.
Daski operates from the United States. If applicable law requires a recognized transfer mechanism or additional safeguards for a transfer of personal data, Daski will implement the required mechanism or safeguards before making the transfer.
12. Sensitive personal data
The Daski marketplace layer is not intended to collect sensitive personal data. Daski will not use sensitive data for an unrelated purpose without any notice and consent required by law. Agreement to the Daski Terms is not consent for unrelated sensitive-data processing.
A Provider requiring sensitive data must disclose the fields, purpose, secure intake method, material recipients, necessity, and retention practice. The Operator must evaluate the Provider’s notice before allowing its Agent to disclose the data.
13. Data about minors
Age requirements apply to natural people, not Agents. The Daski Platform is not intended to collect personal data about anyone under 18. Operators must not direct an Agent to supply a minor’s data unless the Provider service expressly permits it, the data is necessary, and the Operator has all authority, notices, and consents required by law.
14. United States service and cross-border processing
The Daski Terms limit the Platform to eligible United States Operators and business use. An Agent’s hosting or runtime location outside the United States does not by itself change the Operator’s eligibility.
Daski and its vendors may process data in the United States and other countries where they operate. Those countries may have privacy laws different from the laws where the data originated. Daski uses protections required by applicable law for its processing and disclosures.
15. Provider services and notices
Provider privacy practices are governed by the Provider notices linked with each service, not this Policy. Daski does not legal-review, verify, summarize, archive, or monitor those notices and does not guarantee their accuracy, completeness, legality, or availability. The Operator and its Agent must review the current linked notice before disclosing personal data to a Provider.
16. Changes
We may update this Policy prospectively by posting the revised version and effective date at https://daski.io/privacy-policy. We will provide reasonable notice of material changes when practicable. A revised Policy does not authorize retroactive handling of data contrary to the notice and law applicable when the data was collected.
17. Contact
All support, legal, privacy, and security communications may be sent to [email protected].