← Donna OS

// legal

Privacy Policy

Last Updated: September 2026

This Privacy Policy explains how Donna OS collects, uses, stores, shares, and otherwise processes personal data when you visit our website, create or use a Donna OS account, communicate with us, or otherwise interact with our services.

Donna OS is operated by:

Uladzislau Veryn

Individual Entrepreneur registered in Georgia

Identification Number: 322783225

Registered Address: Giorgi Guramishvili 18, Tbilisi, Georgia

Email: info@donna-os.com

Website: https://donna-os.com

In this Privacy Policy, "Donna", "Donna OS", "we", "us", or "our" refers to the operator identified above.

1. Scope of this Privacy Policy

This Privacy Policy applies to personal data Donna processes for its own purposes, including when you:

Where a business Customer uses Donna OS to process personal data about its employees, customers, candidates, contractors, counterparties, or other individuals, that Customer generally determines the purposes of processing.

In those circumstances:

Customer generally acts as Controller, and Donna generally acts as Processor.

Such processing is additionally governed by the Donna OS Data Processing Agreement ("DPA").

2. Applicable Law

Donna processes personal data in accordance with applicable privacy and data-protection laws, including the Law of Georgia on Personal Data Protection.

Where another jurisdiction's mandatory privacy laws apply to particular processing, Donna will also comply with those requirements to the extent applicable.

3. Personal Data We Collect

The information we collect depends on how you interact with Donna OS.

3.1 Account Information

When you create or administer a Donna account, we may collect:

Passwords are handled through our authentication infrastructure and are not intended to be stored by Donna in readable plaintext form.

4. Company and Workspace Information

If you create or manage a Donna workspace, we may process:

5. Customer Content

Donna OS allows Customers and Authorized Users to enter, upload, create, and manage business information.

Depending on the modules used, this may include personal data relating to:

This information may include:

For this category of data, Donna generally processes the information on behalf of the Customer rather than determining why the information is processed.

6. Payment and Subscription Information

Donna uses Paddle to process subscriptions and payments.

When you purchase Donna OS, Paddle may collect information including:

Donna does not intend to directly collect or store complete payment-card numbers or card security codes when payment is handled through Paddle Checkout.

Paddle may act independently as a Merchant of Record and controller for certain payment-related processing.

Paddle's own privacy practices are governed by its Privacy Policy.

Donna may receive from Paddle information such as:

7. Communications and Email

Donna may collect and process information when we send transactional or service-related emails, including:

Donna currently uses Resend for transactional email delivery.

Resend states that email processing may include recipient metadata, email addresses and message content, and may include additional tracking information where such tracking features are enabled.

Donna does not intend to use unnecessary email tracking for authentication or security emails.

8. Technical and Usage Information

When you visit or use Donna OS, we or our service providers may automatically process technical information such as:

This data may be processed to:

9. Cookies and Local Storage

Donna OS may use cookies, browser storage, or similar technologies.

These may be used for:

Some cookies or storage technologies are necessary for the Service to function.

If Donna later introduces non-essential analytics, advertising, or similar technologies, consent will be obtained where required by applicable law.

Further information may be provided in our Cookie Policy.

10. Why We Process Personal Data

Donna may process personal data for the following purposes.

Providing Donna OS

Including:

Subscription Management

Including:

Security

Including:

Customer Support

Including:

Service Communications

Including:

Legal Compliance

Including compliance with:

Improving Donna OS

We may use aggregated, anonymized, or otherwise non-identifying information to understand how Donna OS is used and to improve our Service.

11. Legal Bases for Processing

Where applicable law requires a legal basis, Donna may process personal data based on one or more of the following:

Performance of a Contract

Where processing is necessary to:

Legal Obligation

Where processing is necessary to comply with applicable law.

Legitimate Interests

Where appropriate, Donna may process information for legitimate interests such as:

Such interests will be balanced against the rights and interests of Data Subjects as required by applicable law.

Consent

Where required, Donna may rely on consent.

Where processing is based on consent, you may withdraw that consent subject to applicable law.

12. Customer-Controlled Processing

When you use Donna OS through an employer or another organization, that organization may control the personal data stored in its Donna workspace.

For example, if your employer uses Donna HR to store your employment information:

your employer generally determines why that information is processed.

Donna processes it on the employer's behalf.

Requests concerning such Customer-controlled information should generally first be directed to the relevant Customer organization.

Donna may assist Customers in responding to such requests in accordance with our DPA.

13. Artificial Intelligence Features

Donna OS may provide artificial intelligence or automated functionality, including features that may:

Where AI functionality processes Customer Personal Data, such processing will be performed to provide the requested Donna functionality.

Relevant AI providers will be identified in Donna's Subprocessor List where they process Customer Personal Data on our behalf.

Unless otherwise expressly disclosed or agreed, Donna does not intend to use private Customer Personal Data to train general-purpose AI models for unrelated customers.

Users remain responsible for ensuring that the data they submit to AI functionality may lawfully be processed.

AI output may contain inaccuracies and should be reviewed before being relied upon for significant decisions.

14. Automated Decision-Making

Donna may provide automated analysis, indicators, alerts, rankings, forecasts, or recommendations.

Donna does not intend to make legally significant employment, financial, legal, disciplinary, credit, or similar decisions independently on behalf of Customers.

Customers remain responsible for decisions taken based on Donna OS.

Where applicable law requires human involvement, Customers are responsible for ensuring appropriate human review.

15. How We Share Personal Data

Donna does not sell Customer Personal Data.

We may share or disclose personal data in the following circumstances.

Service Providers

We use third-party infrastructure and service providers to operate Donna OS.

Current providers may include:

Supabase

Database, authentication, backend infrastructure and storage.

Vercel

Application hosting and deployment.

Resend

Transactional email delivery.

Paddle

Payments, subscriptions, tax handling, invoices and transaction services.

These providers receive only information necessary for their relevant functions.

Vercel publishes both a Privacy Notice and Data Processing Addendum governing its processing activities.

Resend similarly publishes a Privacy Policy, DPA and Subprocessor framework.

16. Subprocessors

Where Donna acts as Processor for Customer Personal Data, Donna may use subprocessors to provide the Service.

Our current Subprocessors are described in the Donna OS DPA and may also be maintained in a separate Subprocessor List.

Donna may update this list as the Service evolves.

Where required, Customers will be given appropriate information regarding material new subprocessors.

17. International Data Transfers

Donna uses cloud infrastructure and service providers that may process data outside Georgia.

This may include jurisdictions in which our infrastructure providers, subprocessors, or their affiliates operate.

Donna will take appropriate steps to ensure that international transfers comply with applicable data-protection law.

Depending on the transfer, safeguards may include:

The Georgian Personal Data Protection Law regulates international transfers of personal data and requires an appropriate legal basis or safeguards where applicable.

18. Data Security

Donna implements reasonable technical and organizational measures designed to protect personal data.

Depending on the relevant system, these measures may include:

No online system can be guaranteed to be completely secure.

Users are responsible for protecting their passwords, devices and credentials.

19. Data Retention

Donna retains personal data only for as long as reasonably necessary for the purposes for which it is processed or where retention is required by law.

Retention periods depend on the category of data.

Account Data

Generally retained while your Donna account remains active and for a reasonable period after account closure where necessary for:

Customer Data

Customer Data is generally retained for the duration of the Customer relationship.

Following termination, Donna may provide a period for Customer Data retrieval or export.

After applicable retention periods, Customer Data may be deleted or anonymized.

Backups

Deleted information may remain temporarily in secure backup systems until the relevant backup cycle expires.

Billing Data

Certain transaction or subscription data may need to be retained for legally required accounting, taxation, compliance or dispute-resolution periods.

Paddle may separately retain payment-related information according to its own legal obligations.

20. Data Subject Rights

Depending on the applicable law and circumstances, individuals may have rights concerning their personal data.

These may include rights to:

The current Georgian Personal Data Protection Law establishes rights and obligations concerning the processing of personal data and applies to automated processing in Georgia.

21. Exercising Your Rights

To make a privacy request concerning data controlled by Donna, contact:

info@donna-os.com

We may need to verify your identity before processing a request.

Where the relevant Personal Data is controlled by a Donna Customer, we may direct your request to that Customer or process the request in accordance with that Customer's instructions.

We will respond within the period required by applicable law.

22. Complaints

If you believe that your personal data has been processed unlawfully, you may contact Donna using the details below.

You may also have the right to lodge a complaint with the competent data-protection supervisory authority in Georgia.

Nothing in this Privacy Policy restricts rights available under mandatory law.

23. Security Incidents

If Donna becomes aware of a personal-data breach, we will investigate the incident and take appropriate action.

Where required by applicable law, Donna will notify:

as applicable.

Where Donna acts solely as Processor, Donna will notify the relevant Controller in accordance with the DPA.

24. Children

Donna OS is a business software platform and is not intended for use by children.

Donna does not knowingly offer accounts directly to children for personal use.

If Customer processes information concerning minors through Donna OS, Customer is responsible for ensuring that such processing is lawful and appropriate.

25. Marketing Communications

Donna may send marketing communications where permitted by applicable law.

Marketing communications are separate from essential service communications such as:

Where required, marketing communications will include an appropriate unsubscribe method.

Unsubscribing from marketing does not prevent essential Service communications.

26. Service Emails

Donna may send emails necessary to operate your account, including:

These communications are generally necessary for providing the Service and cannot always be opted out of while maintaining an active account.

27. Links to Third-Party Services

Donna OS may contain links to third-party websites or services.

Donna does not control the independent privacy practices of such third parties.

You should review their privacy notices separately.

28. Business Transfers

If Donna or the Donna OS business is involved in:

personal data may be transferred as part of the relevant transaction, subject to applicable privacy obligations.

29. Legal Disclosures

Donna may disclose personal data where reasonably necessary to:

Where legally permitted, Donna will seek to limit disclosure to information reasonably necessary for the relevant purpose.

30. Data Accuracy

Users and Customers are responsible for ensuring that information they enter into Donna OS is accurate and appropriately maintained.

Donna may provide tools allowing account information to be updated directly within the Service.

31. Changes to this Privacy Policy

Donna may update this Privacy Policy from time to time due to changes in:

The current version will be published on donna-os.com and will include an updated "Last Updated" date.

Where required by law, we will provide additional notice of material changes.

32. Relationship with the DPA

This Privacy Policy primarily describes Donna's own privacy practices.

Where Donna processes Customer Personal Data as a Processor, the Donna OS Data Processing Agreement applies in addition to this Policy.

If this Privacy Policy conflicts with the DPA regarding Donna's processing on behalf of Customer, the DPA controls for that processing.

33. Contact

For privacy questions, requests, or complaints:

Donna OS

Operator: Uladzislau Veryn

Status: Individual Entrepreneur registered in Georgia

Identification Number: 322783225

Registered Address: Giorgi Guramishvili 18, Tbilisi, Georgia

Privacy Email: info@donna-os.com

Website: https://donna-os.com