This Privacy Policy explains how Donna OS collects, uses, stores, shares, and otherwise processes personal data when you visit our website, create or use a Donna OS account, communicate with us, or otherwise interact with our services.
Donna OS is operated by:
Uladzislau Veryn
Individual Entrepreneur registered in Georgia
Identification Number: 322783225
Registered Address: Giorgi Guramishvili 18, Tbilisi, Georgia
Email: info@donna-os.com
Website: https://donna-os.com
In this Privacy Policy, "Donna", "Donna OS", "we", "us", or "our" refers to the operator identified above.
1. Scope of this Privacy Policy
This Privacy Policy applies to personal data Donna processes for its own purposes, including when you:
- visit donna-os.com;
- create a Donna OS account;
- administer a company account;
- communicate with Donna;
- receive service emails;
- purchase or manage a subscription;
- contact support;
- interact with our website or platform.
Where a business Customer uses Donna OS to process personal data about its employees, customers, candidates, contractors, counterparties, or other individuals, that Customer generally determines the purposes of processing.
In those circumstances:
Customer generally acts as Controller, and Donna generally acts as Processor.
Such processing is additionally governed by the Donna OS Data Processing Agreement ("DPA").
2. Applicable Law
Donna processes personal data in accordance with applicable privacy and data-protection laws, including the Law of Georgia on Personal Data Protection.
Where another jurisdiction's mandatory privacy laws apply to particular processing, Donna will also comply with those requirements to the extent applicable.
3. Personal Data We Collect
The information we collect depends on how you interact with Donna OS.
3.1 Account Information
When you create or administer a Donna account, we may collect:
- first and last name;
- email address;
- password-related authentication data;
- company name;
- organizational role;
- user identifier;
- account permissions;
- selected modules;
- account status;
- subscription status;
- language and locale preferences.
Passwords are handled through our authentication infrastructure and are not intended to be stored by Donna in readable plaintext form.
4. Company and Workspace Information
If you create or manage a Donna workspace, we may process:
- company name;
- business contact information;
- company identifiers;
- billing information;
- selected Donna modules;
- user roles;
- employee accounts;
- organizational structure;
- workspace configuration;
- subscription and plan information.
5. Customer Content
Donna OS allows Customers and Authorized Users to enter, upload, create, and manage business information.
Depending on the modules used, this may include personal data relating to:
- employees;
- candidates;
- contractors;
- customers;
- prospects;
- counterparties;
- suppliers;
- business contacts;
- managers;
- representatives.
This information may include:
- names;
- contact details;
- job information;
- salary information;
- employment records;
- attendance;
- leave requests;
- performance information;
- contracts;
- documents;
- client records;
- CRM activity;
- financial records;
- notes;
- correspondence;
- uploaded files;
- other information provided by the Customer.
For this category of data, Donna generally processes the information on behalf of the Customer rather than determining why the information is processed.
6. Payment and Subscription Information
Donna uses Paddle to process subscriptions and payments.
When you purchase Donna OS, Paddle may collect information including:
- name;
- email address;
- billing address;
- company information;
- tax or VAT information;
- payment method information;
- transaction details;
- subscription details;
- country or region;
- invoice information.
Donna does not intend to directly collect or store complete payment-card numbers or card security codes when payment is handled through Paddle Checkout.
Paddle may act independently as a Merchant of Record and controller for certain payment-related processing.
Paddle's own privacy practices are governed by its Privacy Policy.
Donna may receive from Paddle information such as:
- Paddle customer ID;
- subscription ID;
- transaction ID;
- subscription status;
- purchased products/modules;
- payment status;
- billing interval;
- transaction metadata.
7. Communications and Email
Donna may collect and process information when we send transactional or service-related emails, including:
- recipient email address;
- message content;
- delivery status;
- bounce status;
- security-related delivery information.
Donna currently uses Resend for transactional email delivery.
Resend states that email processing may include recipient metadata, email addresses and message content, and may include additional tracking information where such tracking features are enabled.
Donna does not intend to use unnecessary email tracking for authentication or security emails.
8. Technical and Usage Information
When you visit or use Donna OS, we or our service providers may automatically process technical information such as:
- IP address;
- browser type;
- operating system;
- device type;
- requested URL;
- timestamps;
- session information;
- authentication events;
- security logs;
- error logs;
- basic usage information.
This data may be processed to:
- operate Donna OS;
- secure accounts;
- prevent abuse;
- diagnose errors;
- maintain service availability;
- improve performance.
9. Cookies and Local Storage
Donna OS may use cookies, browser storage, or similar technologies.
These may be used for:
- authentication;
- maintaining sessions;
- security;
- remembering language;
- remembering country or currency preferences;
- maintaining selected settings;
- preserving onboarding state.
Some cookies or storage technologies are necessary for the Service to function.
If Donna later introduces non-essential analytics, advertising, or similar technologies, consent will be obtained where required by applicable law.
Further information may be provided in our Cookie Policy.
10. Why We Process Personal Data
Donna may process personal data for the following purposes.
Providing Donna OS
Including:
- account creation;
- authentication;
- workspace creation;
- providing subscribed modules;
- maintaining Customer accounts;
- storing Customer information;
- providing requested functionality.
Subscription Management
Including:
- identifying subscribed modules;
- recording subscription status;
- processing renewals;
- enabling paid functionality;
- handling cancellation;
- responding to billing issues.
Security
Including:
- preventing unauthorized access;
- detecting suspicious activity;
- protecting accounts;
- investigating abuse;
- maintaining logs;
- securing infrastructure.
Customer Support
Including:
- responding to requests;
- investigating problems;
- providing technical assistance.
Service Communications
Including:
- account verification;
- password resets;
- invitations;
- security notifications;
- subscription information;
- important Service notices.
Legal Compliance
Including compliance with:
- applicable laws;
- court orders;
- tax and accounting obligations;
- regulatory requirements;
- lawful governmental requests.
Improving Donna OS
We may use aggregated, anonymized, or otherwise non-identifying information to understand how Donna OS is used and to improve our Service.
11. Legal Bases for Processing
Where applicable law requires a legal basis, Donna may process personal data based on one or more of the following:
Performance of a Contract
Where processing is necessary to:
- create and maintain your account;
- provide Donna OS;
- deliver subscribed functionality;
- manage your subscription;
- communicate regarding the Service.
Legal Obligation
Where processing is necessary to comply with applicable law.
Legitimate Interests
Where appropriate, Donna may process information for legitimate interests such as:
- securing the Service;
- preventing fraud;
- maintaining infrastructure;
- improving reliability;
- enforcing our Terms;
- protecting Donna and its Customers.
Such interests will be balanced against the rights and interests of Data Subjects as required by applicable law.
Consent
Where required, Donna may rely on consent.
Where processing is based on consent, you may withdraw that consent subject to applicable law.
12. Customer-Controlled Processing
When you use Donna OS through an employer or another organization, that organization may control the personal data stored in its Donna workspace.
For example, if your employer uses Donna HR to store your employment information:
your employer generally determines why that information is processed.
Donna processes it on the employer's behalf.
Requests concerning such Customer-controlled information should generally first be directed to the relevant Customer organization.
Donna may assist Customers in responding to such requests in accordance with our DPA.
13. Artificial Intelligence Features
Donna OS may provide artificial intelligence or automated functionality, including features that may:
- summarize information;
- generate drafts;
- analyze records;
- classify information;
- identify patterns;
- produce recommendations;
- generate forecasts;
- answer natural-language questions about Customer Data.
Where AI functionality processes Customer Personal Data, such processing will be performed to provide the requested Donna functionality.
Relevant AI providers will be identified in Donna's Subprocessor List where they process Customer Personal Data on our behalf.
Unless otherwise expressly disclosed or agreed, Donna does not intend to use private Customer Personal Data to train general-purpose AI models for unrelated customers.
Users remain responsible for ensuring that the data they submit to AI functionality may lawfully be processed.
AI output may contain inaccuracies and should be reviewed before being relied upon for significant decisions.
14. Automated Decision-Making
Donna may provide automated analysis, indicators, alerts, rankings, forecasts, or recommendations.
Donna does not intend to make legally significant employment, financial, legal, disciplinary, credit, or similar decisions independently on behalf of Customers.
Customers remain responsible for decisions taken based on Donna OS.
Where applicable law requires human involvement, Customers are responsible for ensuring appropriate human review.
15. How We Share Personal Data
Donna does not sell Customer Personal Data.
We may share or disclose personal data in the following circumstances.
Service Providers
We use third-party infrastructure and service providers to operate Donna OS.
Current providers may include:
Supabase
Database, authentication, backend infrastructure and storage.
Vercel
Application hosting and deployment.
Resend
Transactional email delivery.
Paddle
Payments, subscriptions, tax handling, invoices and transaction services.
These providers receive only information necessary for their relevant functions.
Vercel publishes both a Privacy Notice and Data Processing Addendum governing its processing activities.
Resend similarly publishes a Privacy Policy, DPA and Subprocessor framework.
16. Subprocessors
Where Donna acts as Processor for Customer Personal Data, Donna may use subprocessors to provide the Service.
Our current Subprocessors are described in the Donna OS DPA and may also be maintained in a separate Subprocessor List.
Donna may update this list as the Service evolves.
Where required, Customers will be given appropriate information regarding material new subprocessors.
17. International Data Transfers
Donna uses cloud infrastructure and service providers that may process data outside Georgia.
This may include jurisdictions in which our infrastructure providers, subprocessors, or their affiliates operate.
Donna will take appropriate steps to ensure that international transfers comply with applicable data-protection law.
Depending on the transfer, safeguards may include:
- recognized adequate jurisdictions;
- contractual protections;
- standard contractual mechanisms;
- vendor data-protection agreements;
- other lawful transfer mechanisms.
The Georgian Personal Data Protection Law regulates international transfers of personal data and requires an appropriate legal basis or safeguards where applicable.
18. Data Security
Donna implements reasonable technical and organizational measures designed to protect personal data.
Depending on the relevant system, these measures may include:
- HTTPS/TLS encryption;
- managed authentication;
- restricted database access;
- role-based permissions;
- tenant separation;
- secret management;
- infrastructure access controls;
- security logging;
- backups;
- monitoring;
- software updates;
- incident response procedures.
No online system can be guaranteed to be completely secure.
Users are responsible for protecting their passwords, devices and credentials.
19. Data Retention
Donna retains personal data only for as long as reasonably necessary for the purposes for which it is processed or where retention is required by law.
Retention periods depend on the category of data.
Account Data
Generally retained while your Donna account remains active and for a reasonable period after account closure where necessary for:
- security;
- legal compliance;
- dispute resolution;
- fraud prevention.
Customer Data
Customer Data is generally retained for the duration of the Customer relationship.
Following termination, Donna may provide a period for Customer Data retrieval or export.
After applicable retention periods, Customer Data may be deleted or anonymized.
Backups
Deleted information may remain temporarily in secure backup systems until the relevant backup cycle expires.
Billing Data
Certain transaction or subscription data may need to be retained for legally required accounting, taxation, compliance or dispute-resolution periods.
Paddle may separately retain payment-related information according to its own legal obligations.
20. Data Subject Rights
Depending on the applicable law and circumstances, individuals may have rights concerning their personal data.
These may include rights to:
- obtain information about processing;
- access personal data;
- correct inaccurate or incomplete information;
- request updating of information;
- request deletion where legally applicable;
- request restriction of processing;
- object to certain processing;
- withdraw consent where consent is the legal basis;
- obtain information concerning recipients;
- exercise rights concerning automated processing where applicable;
- lodge a complaint with the competent supervisory authority.
The current Georgian Personal Data Protection Law establishes rights and obligations concerning the processing of personal data and applies to automated processing in Georgia.
21. Exercising Your Rights
To make a privacy request concerning data controlled by Donna, contact:
info@donna-os.com
We may need to verify your identity before processing a request.
Where the relevant Personal Data is controlled by a Donna Customer, we may direct your request to that Customer or process the request in accordance with that Customer's instructions.
We will respond within the period required by applicable law.
22. Complaints
If you believe that your personal data has been processed unlawfully, you may contact Donna using the details below.
You may also have the right to lodge a complaint with the competent data-protection supervisory authority in Georgia.
Nothing in this Privacy Policy restricts rights available under mandatory law.
23. Security Incidents
If Donna becomes aware of a personal-data breach, we will investigate the incident and take appropriate action.
Where required by applicable law, Donna will notify:
- affected Customers;
- relevant authorities;
- Data Subjects,
as applicable.
Where Donna acts solely as Processor, Donna will notify the relevant Controller in accordance with the DPA.
24. Children
Donna OS is a business software platform and is not intended for use by children.
Donna does not knowingly offer accounts directly to children for personal use.
If Customer processes information concerning minors through Donna OS, Customer is responsible for ensuring that such processing is lawful and appropriate.
25. Marketing Communications
Donna may send marketing communications where permitted by applicable law.
Marketing communications are separate from essential service communications such as:
- email confirmation;
- security alerts;
- password resets;
- billing notices;
- subscription notices.
Where required, marketing communications will include an appropriate unsubscribe method.
Unsubscribing from marketing does not prevent essential Service communications.
26. Service Emails
Donna may send emails necessary to operate your account, including:
- confirmation emails;
- password reset emails;
- security notifications;
- account invitations;
- subscription notifications;
- service notices.
These communications are generally necessary for providing the Service and cannot always be opted out of while maintaining an active account.
27. Links to Third-Party Services
Donna OS may contain links to third-party websites or services.
Donna does not control the independent privacy practices of such third parties.
You should review their privacy notices separately.
28. Business Transfers
If Donna or the Donna OS business is involved in:
- a merger;
- acquisition;
- corporate restructuring;
- investment;
- sale of assets;
- transfer of business,
personal data may be transferred as part of the relevant transaction, subject to applicable privacy obligations.
29. Legal Disclosures
Donna may disclose personal data where reasonably necessary to:
- comply with applicable law;
- respond to a valid legal process;
- enforce agreements;
- protect the security of Donna OS;
- investigate fraud or abuse;
- protect rights, property, or safety.
Where legally permitted, Donna will seek to limit disclosure to information reasonably necessary for the relevant purpose.
30. Data Accuracy
Users and Customers are responsible for ensuring that information they enter into Donna OS is accurate and appropriately maintained.
Donna may provide tools allowing account information to be updated directly within the Service.
31. Changes to this Privacy Policy
Donna may update this Privacy Policy from time to time due to changes in:
- law;
- Donna OS functionality;
- infrastructure;
- subprocessors;
- privacy practices.
The current version will be published on donna-os.com and will include an updated "Last Updated" date.
Where required by law, we will provide additional notice of material changes.
32. Relationship with the DPA
This Privacy Policy primarily describes Donna's own privacy practices.
Where Donna processes Customer Personal Data as a Processor, the Donna OS Data Processing Agreement applies in addition to this Policy.
If this Privacy Policy conflicts with the DPA regarding Donna's processing on behalf of Customer, the DPA controls for that processing.
33. Contact
For privacy questions, requests, or complaints:
Donna OS
Operator: Uladzislau Veryn
Status: Individual Entrepreneur registered in Georgia
Identification Number: 322783225
Registered Address: Giorgi Guramishvili 18, Tbilisi, Georgia
Privacy Email: info@donna-os.com
Website: https://donna-os.com