Privacy & Cookie Policy
Last updated: 8 July 2026
Privacy & Cookie Policy
We may update these terms; check back for changes.
1. Who we are
Demographix Lab ("Demographix", "we", "us", "our") operates the Demographix Lab data portal, including the DxDatabase, DxChat, and QBuilder products (collectively, the "Service"). For the purposes of the EU/UK General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act), Demographix is the data controller / data fiduciary for personal data processed through the Service.
Contact: privacy@demographix.ai
2. Scope
This Policy explains what personal data we collect, why we process it, the lawful bases we rely on, how long we keep it, who we share it with, and the rights available to you. It applies to all users of the Service worldwide.
3. Personal data we collect
a. Account & profile data (provided by you)
- Name
- Email address
- Country
- Organisation / institution (optional, self-reported)
- Designation / role (optional, self-reported)
- Authentication identifiers (managed via our identity provider)
b. Usage & content data (generated as you use the Service)
- Search queries and DxChat prompts, and their interpreted meaning
- Datasets viewed, opened, downloaded, exported, or saved to lists
- Session and interaction metadata (timestamps, feature usage, channel)
- Derived signals about how the Service performed for you (for example, whether a query was confidently answered or represents unmet demand)
c. Technical data
- IP address, device/browser information, and cookies strictly necessary for authentication, security, and core functionality.
We do not intentionally collect special-category / sensitive personal data. Please do not enter sensitive personal information into free-text query fields.
4. How and why we use your data (purposes)
- To provide the Service — authenticate you, run searches, generate answers, deliver and export datasets, and enforce plan quotas and billing.
- To secure the Service — detect abuse, fraud, and security incidents, and maintain audit trails.
-
To improve the Service (product analytics) — understand aggregate demand, identify gaps in our data catalogue, measure answer quality, and prioritise what to build next. This includes:
- Audience segmentation — grouping accounts into segments defined by identity attributes (such as email domain or organisation) and/or by server-computed behavioural tiers, so that demand can be analysed by audience.
- Behavioural analytics — computing internal indicators of engagement and of how well the catalogue currently serves an account.
- To communicate with you — service, security, and (where permitted) product updates.
5. Lawful bases for processing
Depending on your jurisdiction and the activity, we rely on:
- Performance of a contract — to provide the Service you have requested.
- Consent — for the "Content & usage review to improve the product" setting (Section 6), and where otherwise required by law.
- Legitimate interests — for security, and for internal, aggregate product analytics and segmentation, balanced against your rights and freedoms. Where the DPDP Act applies, we rely on your consent and applicable "legitimate uses" as permitted by that Act.
You may withdraw consent at any time (Section 6); this does not affect the lawfulness of processing before withdrawal.
6. Consent, content & usage review, and aggregate-only analytics
Your account settings include a "Allow content & usage review to improve the product" control. When enabled, you consent to our reviewing your search and chat content and analysing your usage patterns and profile details (such as name, email domain, and organisation) for the product-improvement purposes in Section 4, including audience segmentation and behavioural analytics.
We commit to the following safeguards for these analytics:
- Aggregate-only outputs. Analytics that use content, profile, or behaviour are published to our internal teams only in aggregate form.
- Minimum group size (small-cell suppression). Segmented or grouped results are not displayed unless they meet a minimum group-size threshold, to prevent singling out an individual.
- No automated decisions about you. These analytics inform our product and catalogue roadmap. They are not used to make automated decisions that produce legal or similarly significant effects concerning you (for example, pricing, access, or eligibility).
- Access control & auditing. Access to identifiable data for the purpose of defining segments is restricted to authorised administrators and is logged.
- Curation vs. analysis separation. Where administrators curate audience segments, membership is managed by identity attributes; individual behavioural metrics are computed by our systems and surfaced only within aggregate views.
If you turn this setting off, your content, profile, and usage will be excluded from these product-analytics views. Turning it off never affects security, quota, or billing records.
7. Cookies
We use cookies and similar technologies that are strictly necessary for authentication, session management, and security. Where required by law, we will seek consent for any non-essential cookies before they are set.
8. Sharing and sub-processors
We do not sell your personal data. We share personal data only with:
- Infrastructure and AI sub-processors that host or process data on our behalf under contract (for example, cloud hosting and model-inference providers), bound by confidentiality and data-protection obligations.
- Authorities, where required by law or to protect our legal rights.
9. International transfers
The Service and its sub-processors may process data in jurisdictions other than your own. Where we transfer personal data internationally, we use appropriate safeguards (such as Standard Contractual Clauses or an equivalent mechanism recognised under applicable law).
10. Data retention
We retain personal data only as long as necessary for the purposes described, or as required by law. Aggregated and de-identified analytics that can no longer be linked to you may be retained for longer. Upon account deletion (Section 11), associated personal data — including audience-segment membership — is deleted or irreversibly de-identified, subject to legal retention obligations for billing and security records.
11. Your rights
Subject to your jurisdiction, you may have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten"), including via the in-product Delete Account flow;
- Withdraw consent (including the content & usage review setting) at any time;
- Restrict or object to processing based on legitimate interests;
- Data portability;
- Lodge a complaint with your supervisory authority (for EU/UK users) or the Data Protection Board of India (for DPDP Act users).
To exercise these rights, use your account settings or contact privacy@demographix.ai. We will respond within the timeframe required by applicable law.
12. Children
The Service is not directed to children below the age of consent in their jurisdiction. Where the DPDP Act applies, we will obtain verifiable parental consent before processing a child's personal data where required.
13. Security
We implement technical and organisational measures appropriate to the risk, including access controls, auditing, encryption in transit, and least-privilege administration. No system is perfectly secure; we continuously improve our controls.
14. Changes to this Policy
We may update this Policy from time to time. Material changes — including any change that broadens how we use your content, profile, or behaviour for analytics — will be notified to you, and where required we will seek renewed consent before the new processing begins.
15. Contact & grievance
- Privacy / Data Protection: privacy@demographix.ai
- Grievance Officer (DPDP Act): grievance@demographix.ai
Governing law and jurisdiction are set out in the Terms of Service.