Data protection COL-PRIV-001
Privacy policy
What data Colonela processes, why, for how long and how you can exercise your rights.
- Status
- Effective version
- Version
- v1.1
- Publication date
- 23. 8. 2026
- Document ID
- COL-PRIV-001
- Language
- EN — informative translation
- Operator
- DAOUBO DAO, LLC
This is the current public version. A material change creates a new version and is recorded in the change history.
Data controller
The controller of personal data is the operator of Colonela — DAOUBO DAO, LLC, a limited liability company formed under the laws of the State of Wyoming, USA (Wyoming DAO Supplement and Wyoming LLC Act), registered agent: 30 N Gould St Ste R, Sheridan, WY 82801, USA. The operator determines the purposes and means of processing and is responsible for GDPR compliance. Although the operator is registered in Wyoming, all personal data is processed and stored exclusively on servers in the European Union. For data-protection matters contact info@colonela.com; for general matters contact info@colonela.com.
What data we process
We process: (1) account data — email, optionally name and settings; (2) case content — documents, notes, timeline and statements you upload yourself; this content is encrypted in transit and at rest, and end-to-end encryption with client-held keys is not yet deployed; (3) technical and security logs — IP address, device type, sign-in time and event records needed for security and the audit trail; (4) payment data — paid subscriptions are not yet live; once they are, payment data will be handled solely by our payment processor and we will not store card numbers; (5) identity — in this version sign-in is handled by email; the full BlockID identity with user-held keys is in preparation. Sensitive data inside the case file is visible only to you and the people you grant access to.
Legal bases for processing
We process account data and case content to perform the service contract (Art. 6(1)(b) GDPR). We process security and technical logs based on our legitimate interest in securing the service and protecting your data (Art. 6(1)(f)). We keep some records to comply with legal obligations, such as accounting documents (Art. 6(1)(c)). Optional features not needed to run the service are enabled only with your consent (Art. 6(1)(a)), which you can withdraw at any time. Because this concerns data of people in criminal proceedings, we work with heightened care and data minimisation.
Encryption and content protection
Traffic between your device and the service is encrypted (HTTPS/TLS) and data is also encrypted at rest at the database provider. Access is limited by authentication and roles. Current state of the service: end-to-end encryption on the user's device (zero-knowledge) and 3-of-5 key recovery are in development and are NOT active in this version. Until they ship, the operator is technically able to access stored content. For now, please upload only content you are comfortable with on that basis. We will announce the rollout in advance and update this section.
Where data lives and transfers outside the EU
We store personal data in the European Union. The web application runs at Vercel in the Frankfurt region (Germany); the database and authentication run at Supabase in the Ireland region. Both providers are companies established in the USA; stored data remains in the EU. Exception — AI assistant: if you use the AI assistant, the content of your query is transferred to Anthropic (USA) for processing. This is a transfer to a third country under Chapter V of the GDPR. Using the AI assistant is optional; without it no such transfer takes place. If the set of providers changes, we will announce it in advance and ensure appropriate safeguards under Chapter V of the GDPR.
Processors and sub-processors
We use a limited set of processors, always under a data-processing agreement per Art. 28 GDPR: Vercel Inc. (web application hosting, Frankfurt region), Supabase Inc. (database and authentication, Ireland region) and Anthropic PBC (processing of AI assistant queries, only if you use it). These processors act on our instructions and only to the extent needed for the service. We will provide a current list on request at info@colonela.com. Paid subscriptions are not yet live; once they are, we will add the payment processor here.
Retention periods
We keep account data and case content for as long as your account exists. After you close your account we delete or anonymise the data, as a rule within 30 days, unless a legal obligation prevents it. We keep security logs only as long as necessary for security, usually no more than 12 months. Accounting and tax documents are kept for the statutory period. You can export your data at any time before deleting your account.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict processing of, and port your data, and to object to processing based on legitimate interest. You can withdraw any consent at any time. We handle requests as a rule within one month. If you believe we process data unlawfully, you have the right to lodge a complaint with the supervisory authority — in the Czech Republic the Office for Personal Data Protection (ÚOOÚ), Pplk. Sochora 27, Prague 7. We would appreciate it if you contacted us first at info@colonela.com — we resolve most matters quickly.
Automated decision-making and AI
We carry out no solely automated decision-making with legal effect within the meaning of Art. 22 GDPR. The AI agent in Colonela is assistive only: it drafts, organises, explains and supports, but it never decides for you or your attorney, and it always presents its output as a proposal to review. There is human oversight of the agent. We never use your case content to train AI models.
Technical and organisational measures
We protect your data with encryption in transit and at rest, access separation across roles, and an audit trail of every significant step. Only a necessary circle of people with individual authorisation can access systems. We handle security incidents under an internal procedure and will report any personal-data breach in line with the GDPR. End-to-end encryption of case content and multi-factor authentication are in preparation. Report suspected abuse or vulnerabilities to info@colonela.com.
Children
Colonela is not intended to be used independently by children. Accounts are created and managed by adults. The "Child" role within a family exists only under the supervision of a legal guardian, who is responsible for its use. If we learn that we obtained a child's data without a proper legal basis, we will delete that data.
Changes to this policy
We may update this policy, for example when the law or the scope of the service changes. We will inform you of material changes in advance, in the app or by email. The date of the last update is shown at the top of this document. By continuing to use the service after the changes take effect, you confirm that you have read the current version.
Data-protection contact
For any question or request about personal data, contact info@colonela.com. Direct security matters to info@colonela.com and general questions to info@colonela.com. We reply as a rule within 3 business days. Colonela is a technical tool, not a law firm — if you are dealing with a specific procedural step, we recommend discussing it with your attorney too.