Privacy Policy

Privacy Policy

Updated July 15, 2026

1. Introduction and Our Role

Valere Labs LLC (“Valere Labs,” “Company,” “we,” “us,” or “our”) develops and operates Dactic, an AI-powered platform that connects to an organization’s day-to-day tools, conducts structured interviews with personnel, and uses the resulting information to generate organizational knowledge (“Evidence,” “Org Lexicon,” “Playbooks”) and to configure, deploy, and operate AI agents on the organization’s behalf (collectively, the “Service”).

This Privacy Policy explains what personal data we collect, how we use and share it, how long we keep it, and the choices and rights available to you. It applies to the Dactic web application, APIs, and related services, and does not apply to third-party websites, tools, or services that Dactic may link to or connect with, which are governed by their own privacy policies.

Two roles, two responsibilities. Because Dactic is a business-to-business platform, personal data flows through it in two distinct ways, and our legal role differs for each:

  • Where we act as a data controller (or “business,” under U.S. state law): for account and administrative information you or your organization provide directly to us to create and manage a Dactic account (e.g., admin contact details, billing information, support communications), we determine the purposes and means of processing and are the controller of that data.
  • Where we act as a data processor (or “service provider”): for personal data contained in the systems your organization connects to Dactic (e.g., Gmail, Google Chat, Google Drive, Google Calendar, Monday.com, etc.) and for interview responses and derived Evidence generated from that data, your organization (“Customer”) is the data controller, and Valere Labs processes that data solely on Customer’s behalf and instructions, as described in this Policy and our customer agreement.

If you are an individual using Dactic through your employer or another organization, your organization — not Valere Labs — is primarily responsible for the lawfulness of collecting your personal data through the Service, including providing any notice or obtaining any consent required under workplace-monitoring, labor, or data protection law in your jurisdiction. Section 16 describes this allocation of responsibility in more detail.

2. Definitions

  • “Organization” or “Customer” — the company or entity that has contracted with Valere Labs to use Dactic and that administers accounts, resource connections, and agent deployments through Admin roles.
  • “Authorized User” — an individual (typically an employee of the Organization) who uses the Service under the Organization’s account, generally in the “Employee” role.
  • “Connected Source” — a third-party tool (Gmail, Google Chat, Google Drive, Google Calendar, Monday.com, and other integrations we may add) that an Authorized User links to Dactic.
  • “Evidence” — content collected from an approved Connected Source resource after it has passed through noise filtering and PII redaction, and been converted into a transformed, indexed representation for use by the platform.
  • “Org Lexicon” — the organization’s normalized vocabulary map (terms, canonical concepts, ownership, confidence, and status).
  • “Agent” — an AI-configured assistant, generated from admin-approved context, deployed into the Organization’s connected workspace (e.g., Monday.com) to perform a defined, permissioned task.
  • “Personal Data” has the meaning given under applicable data protection law (e.g., GDPR, CCPA/CPRA), generally referring to information relating to an identified or identifiable individual.

3. Information We Collect

3.1 Information You Provide Directly

  • Account information: name, email address, password (stored encrypted), job title, team, organization details, profile photo.
  • Billing information: processed by our payment processor (Stripe); we do not store full payment card numbers.
  • Support and communications: messages you send us, and records of your interactions with our support team.

3.2 Information from Connected Sources

When an Authorized User signs in via Google OAuth or connects Monday.com, and then explicitly approves specific resources (e.g., particular Gmail labels, Chat spaces, Drive folders, Calendars, or Monday boards), Dactic reads only the approved resources, using read-only, least-privilege scopes. Depending on what is approved, this may include:

  • Email metadata and content within approved Gmail labels
  • Messages within approved Google Chat spaces
  • File content and metadata within approved Google Drive folders
  • Calendar entries within approved calendars
  • Board, item, subitem, and comment content within approved Monday.com boards/workspaces

Nothing outside an explicitly approved resource is ever accessed. Authorized Users can review and revoke any connected source at any time from Account Settings, and revocation takes effect for all future syncs immediately.

3.3 Interview Data

Structured responses provided during Dactic’s guided interview, including role, team, reporting relationships, responsibilities, tools used, terminology, and named work artifacts, along with the transcript of that conversation.

3.4 Derived Data (Evidence, Lexicon, and Playbooks)

Information generated by our platform from the sources above, including: filtered and PII-redacted Evidence items; candidate and confirmed terminology mappings (the Org Lexicon); role and reporting-relationship graph data; versioned team Playbooks and their citations; and the configuration bundles (instructions, skills, permissions) used to deploy Agents. Only these transformed, derived representations are retained — the original raw emails, chat messages, files, or logs from a Connected Source are not stored on an ongoing basis once they have been processed into Evidence.

3.5 Usage and Technical Information

Device and browser type, IP address, pages accessed and actions taken within the Service, and performance/error logs, collected automatically to operate, secure, and improve the Service.

3.6 Information We Do Not Collect

We do not perform biometric profiling, and we do not access any Connected Source resource that has not been explicitly approved by the Authorized User who owns that connection.

4. How We Use Information

We use the information described above to:

  • Provide, operate, secure, and improve the Service;
  • Run the Evidence pipeline: syncing approved resources, filtering low-signal noise, redacting personal data prior to any indexing, mining candidate terminology, and detecting contradictions for human review;
  • Conduct structured interviews and build role, team, and terminology profiles;
  • Generate, validate, and — upon Organization Admin approval — deploy AI Agents into the Organization’s connected workspace, and power “Ask AI” features grounded solely in that Organization’s own data;
  • Provide Organization administrators with aggregated, operational visibility (e.g., onboarding status, agent inventory, evidence-pipeline counts, audit logs) — never an individual’s raw messages or files (see Section 7.2);
  • Meter Agent and token usage for billing and account management;
  • Provide customer support, and communicate service, security, and account-related updates;
  • Detect, investigate, and prevent fraud, abuse, and security incidents, and maintain audit logs of privileged actions; and
  • Comply with applicable law and enforce our agreements.

We do not use your organization’s Interview Data, Connected Source content, or Evidence to train any public, shared, or externally released AI or foundation model.

5. Artificial Intelligence and Automated Processing

Because AI is central to how Dactic works, we want to be specific about it:

  • Redaction before indexing. Personal data is detected and redacted before any content is converted into vector embeddings or written to our graph data store. Raw personal data is never persisted in the Evidence index or knowledge graph; redaction is logged only as counts and categories of what was removed, not the underlying values.
  • Third-party model infrastructure. We use large-language-model infrastructure (including models made available through Amazon Bedrock, and lightweight models such as Claude Haiku) to filter noise, disambiguate terminology, and generate Agent instructions and conversational responses. These providers process data solely to generate output for your Organization, under contractual terms that prohibit using your data to train their own general-purpose models.
  • Human-in-the-loop before anything goes live. Every AI-suggested terminology mapping, role fact, and Playbook policy point is stored with a status of inferred or needs review and requires confirmation by an Organization Admin before it becomes authoritative. No unconfirmed, AI-generated content is ever used to ground a live, deployed Agent.
  • Bounded Agent permissions. Deployed Agents operate only within the read-only (or otherwise explicitly authorized) permission scope granted by the Organization and by the Authorized User who owns the underlying connection. Agents cannot delete data and cannot exceed their documented, audited permission set.
  • Periodic re-grounding. Because organizational context changes, Agents are automatically re-synced and re-grounded on a recurring cycle (by default, every 30 days). Newly observed terms re-enter human review before they can update a live Agent. Organizations and Authorized Users may request an earlier refresh.

6. Legal Bases for Processing (GDPR / UK GDPR)

Where the GDPR, UK GDPR, or similar law applies, we (or, where we act as a processor, your Organization as controller) rely on the following legal bases:

  • Performance of a contract — to provide the Service you or your Organization signed up for.
  • Legitimate interests — to secure the platform, prevent fraud and misuse, maintain and improve reliability, and generate organizational Evidence and Agents grounded in the Organization’s own data, in each case balanced against your interests and rights.
  • Consent — for optional features such as audio/video recording (where enabled), optional profile information, and the specific resources an Authorized User chooses to approve for a Connected Source. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Legal obligation — where processing is necessary to comply with applicable law.

Where Valere Labs acts as a processor, your Organization is responsible for establishing and, where required, documenting its own lawful basis (including any necessary workforce notice or consent) for permitting Connected Source content and interview data to be processed within Dactic.

7. How We Share Information

We do not sell personal information, and we share it only as described below.

7.1 Sub-processors and Service Providers

We engage the following categories of service providers to operate the Service. Each is bound by a written agreement imposing confidentiality, security, and data-protection obligations consistent with this Policy, including, for cross-border transfers, Standard Contractual Clauses or an equivalent lawful transfer mechanism.

Sub-processor / CategoryPurposeData Involved
Amazon Web Services (hosting, graph database, secrets management, content delivery)Core infrastructure, storage, and encryption key/secret managementAll Service data, encrypted at rest and in transit
Amazon Bedrock / underlying model providers (e.g., Anthropic)AI inference for noise filtering, terminology disambiguation, and Agent/response generationEvidence, interview data, Lexicon data (post-redaction)
Google (OAuth / Workspace APIs)Identity sign-in and read-only access to Connected Source resources you approveContent of approved Gmail/Chat/Drive/Calendar resources
Monday.comDeployment target for Agents and boards/items your Organization connectsBoard/item/comment content within approved resources; deployed Agent configuration
StripePayment processing and billingBilling and payment information

7.2 Within Your Organization

Organization Administrators may access aggregated and operational information: onboarding status, KPI dashboards, agent inventory and status, evidence-pipeline stage counts, Org Lexicon entries, Playbooks, and audit logs.

Administrators do not have visibility into an Authorized User’s raw emails, chat messages, files, or logs. No admin-facing screen displays raw Connected Source content, and original messages/files are not retained on an ongoing basis once transformed into Evidence — this is a structural guarantee of the platform, not merely a permissions setting.

7.3 Legal and Safety

We may disclose information where we believe in good faith it is necessary to comply with applicable law, legal process, or governmental request; to enforce our agreements; or to protect the rights, property, or safety of Valere Labs, our customers, or the public.

7.4 Business Transfers

In connection with a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy (or a policy that provides materially equivalent protection) continuing to apply, or notice being provided to affected users.

7.5 Aggregated and De-identified Data

We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify an individual or an Organization (e.g., benchmarking statistics).

8. Data Security

We maintain a security program that includes:

  • Encryption at rest, including OAuth tokens (Fernet symmetric encryption) and stored organizational data (AES-256);
  • Encryption in transit via TLS across all endpoints;
  • Signed and verified webhooks (HMAC-SHA256) to prevent tampering;
  • Centralized secrets management, with no plaintext credentials in source code;
  • Server-side, least-privilege role and route enforcement for every request — access control is never enforced by the client alone;
  • Multi-tenant data isolation enforced at the query layer, across both our relational and graph data stores, so that one Organization’s data is never returned in another Organization’s queries;
  • Immutable audit logging of privileged actions (evidence reads, approvals, scope grants, refresh runs); and
  • Regular access reviews and internal security testing.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We continuously work to maintain safeguards appropriate to the sensitivity of the data we process. If you believe you have discovered a security vulnerability, please contact us at security@dactic.io.

9. Data Retention

  • Account and platform data is retained while your account or Organization remains active.
  • Interview transcripts, Evidence, Org Lexicon, and Playbook data are retained to support ongoing Agent grounding and the periodic refresh cycle described in Section 5. Raw Connected Source content is not retained beyond the filtering/redaction step — only the resulting transformed Evidence persists.
  • Upon deletion of your account or your Organization’s account, Customer content, transcripts, and recordings are permanently deleted within a reasonable period (not to exceed 90 days), except: (a) as required to comply with law, resolve disputes, or enforce our agreements, or (b) residual copies in encrypted backups, which are purged on our standard backup-rotation schedule.
  • Audit logs may be retained for a longer period where necessary for security, compliance, or legal purposes.

You may request earlier deletion using in-product controls (Connected Accounts, Governance → Revoke all access) or by contacting us at contact@dactic.io.

10. International Data Transfers

Our infrastructure providers may process or store data outside your country or region, including outside the European Economic Area, the United Kingdom, or Switzerland. Where this occurs, we use appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or other lawful transfer mechanisms recognized under applicable law.

11. Your Privacy Rights and Choices

Depending on your location, you may have the right to:

  • Access the personal data we hold about you;
  • Correct or update inaccurate information;
  • Delete your personal data;
  • Restrict or object to certain processing;
  • Port your data in a structured, commonly used format;
  • Withdraw consent where processing is based on consent, without affecting prior lawful processing; and
  • Non-discrimination for exercising any of these rights.

Self-Service Controls

Many of these rights can be exercised directly in the product: revoke a Connected Source in Account Settings → Connected Accounts; an Organization Admin may revoke all access via Governance; and export tools are available in Governance and Billing.

Requests to Us

To exercise a right not available through self-service tools, contact us at contact@dactic.io. We may need to verify your identity (and, where relevant, confirm your Organization’s authorization) before fulfilling a request.

European Economic Area / UK

If you are located in the EEA or UK, you also have the right to lodge a complaint with your local data protection supervisory authority.

California (CCPA/CPRA)

California residents have the right to know the categories and specific pieces of personal information we collect, to delete, to correct, and to opt out of the “sale” or “sharing” of personal information (as those terms are defined by California law) and the use of sensitive personal information for purposes beyond what is necessary to provide the Service.

We do not sell or share personal information, and have not done so in the preceding 12 months. You may designate an authorized agent to submit a request on your behalf, subject to identity verification.

Other U.S. States

Residents of states with comprehensive privacy laws (e.g., Virginia, Colorado, Connecticut, Utah, and others as they take effect) have similar rights to access, correct, delete, and port personal data, and to opt out of targeted advertising, sale, or certain profiling — none of which we currently engage in with respect to Service data. You may exercise these rights using the contact information in Section 18.

Other Jurisdictions

Where applicable law provides equivalent rights (e.g., Brazil’s LGPD, Canada’s PIPEDA), we honor requests consistent with this Section.

12. Cookies and Similar Technologies

We use cookies and similar technologies to keep you signed in, remember preferences, and understand how the Service is used. You can control cookies through your browser settings; disabling certain cookies may affect Service functionality.

13. Children’s Privacy

Dactic is a business tool not directed to, and not intended for use by, individuals under 16 years of age (or the applicable age of consent in your jurisdiction), and we do not knowingly collect personal data from children. If we learn that we have inadvertently collected such data, we will delete it. If you believe a child has provided us personal data, contact us at legal@dactic.io.

14. No Warranty on AI-Generated Content

Agents, Playbooks, and Lexicon mappings are generated using automated and AI-assisted processes and are subject to human review and approval gates as described in Section 5, but they may nonetheless contain errors or inaccuracies. The Service, and any AI-generated output, is provided on an “as available” basis, and Valere Labs makes no warranty as to the accuracy or completeness of AI-generated content; use of such output for consequential business decisions remains the responsibility of the Organization and its personnel.

15. Data Breach Notification

If we become aware of a security incident involving unauthorized access to personal data that we control, we will notify affected individuals and/or applicable regulators as and to the extent required by applicable law. Where we act as a processor on behalf of an Organization, we will notify the Organization without undue delay so that it may satisfy its own notification obligations.

16. Your Organization’s Role and Responsibilities

If you access Dactic through an employer or other Organization, your Organization administers your account and, through its Admins, may access certain aggregated and administrative information about your use of the Service as described in Section 7.2.

Your Organization — not Valere Labs — is responsible for:

  • Ensuring it has a lawful basis, and where required by applicable law, providing notice to or obtaining consent from its personnel before connecting Gmail, Chat, Drive, Calendar, Monday.com, or other sources that contain personal data about those personnel;
  • Determining which resources to approve for collection, and ensuring that determination is appropriate given its own legal and workplace obligations;
  • Promptly notifying Valere Labs of any need to restrict, correct, export, or delete personal data; and
  • Its own compliance with labor, works-council, or employee-monitoring notification laws applicable to its use of the Service.

Valere Labs’ role with respect to such data is limited to processing it on the Organization’s behalf and instructions, as described in this Policy and our customer agreement.

17. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date above. If changes are material, we will provide additional notice through the Service or by other reasonable means.

18. Contact Us

Valere Labs LLC
399 Boylston St. Suite 650 Boston, MA, 02116.
General privacy inquiries and rights requests: legal@dactic.io
Security disclosures: security@dactic.io