Privacy Policy
Effective Date: September 30, 2026 | Last Updated: September 30, 2026
This Privacy Policy explains how Daikon Corp. (“Daikon,” “we,” “us” or “our”) collects, uses, discloses and protects personal information in connection with our website at daikon.ai (the “Site”), our sales and marketing activities, and the Daikon software platform (the “Platform”).
Daikon provides enterprise quality management software to pharmaceutical and life sciences organizations. We do not sell products or services to consumers, and the Platform is not available for public sign-up.
1. Our Two Roles — Please Read This First.
This Policy covers two very different situations. Which one applies determines who you should contact about your information.
(a) When We Act as Controller. For personal information we collect through the Site, through our marketing and sales activities, from prospective customers, from candidates, and for the administration of Platform accounts, Daikon decides why and how that information is processed. We are the “controller” (GDPR) or “business” (CCPA/CPRA). Sections 2 through 11 of this Policy describe that processing.
(b) When We Act as Processor. Personal information contained in data that a customer organization submits to the Platform — including deviation records, investigation records and associated documents — is processed by us only on that organization’s documented instructions. That organization is the controller; we are the “processor” (GDPR) or “service provider” (CCPA/CPRA). Our handling of that data is governed by our master services agreement and data processing addendum with that organization, not by this Policy. See Section 12.
(c) If You Are a Platform User. If you access the Platform as an authorized user of a customer organization and have a question about the data in that organization’s environment — including records about you — please contact your own organization. We are not able to act on such requests directly and will refer them to the controlling organization.
2. Information We Collect.
(a) Information You Give Us. Contact and professional details you submit through the Site or to our team: name, business email address, telephone number, employer, job title, country, and the content of your message or request. If you register for a webinar, download material, subscribe to updates or contact us about our podcast, we collect the information you provide in that form.
(b) Account Administration Information. For authorized users of the Platform: name, business email address, employer, job title, role and permission assignments, authentication identifiers, and support correspondence. This information is provided to us by the customer organization or by the user.
(c) Information Collected Automatically. When you visit the Site we collect IP address, approximate location derived from it, browser and device type, operating system, referring page, pages viewed, links clicked, and dates and times of access, using cookies and similar technologies as described in Section 5. We also collect security and operational logs relating to Platform access, including authentication events and IP addresses.
(d) Information From Third Parties. We may receive business contact information from our customer relationship management and sales intelligence providers, from event organizers where you have consented, and from publicly available professional sources.
(e) What We Do Not Want. When acting as controller, we do not request or require special category or sensitive personal information — including health information, biometric data, government identifiers, or financial account numbers — through the Site or by email. Customer Platform data may contain such information where submitted by a customer, in which case we process it solely as a processor or service provider in accordance with Section 12.
3. How We Use Personal Information.
As controller, we use personal information to:
(a) operate, maintain, secure and improve the Site;
(b) respond to enquiries, provide information you request, and communicate about our products and services;
(c) provision, administer and support Platform accounts, and authenticate users;
(d) send marketing communications where permitted, from which you may opt out at any time;
(e) organize and follow up on events, webinars and demonstrations;
(f) detect, investigate and prevent fraud, abuse, security incidents and other unlawful activity;
(g) perform analytics on how the Site is used, in order to improve it;
(h) manage our contractual relationships, including billing and account management; and
(i) comply with legal obligations and establish, exercise or defend legal claims.
(j) No Automated Decision-Making. We do not use personal information collected as controller to make decisions that produce legal or similarly significant effects about you without human involvement.
(k) No Use of Customer Content for Marketing. We do not use personal information contained in customer Platform data for our own marketing, profiling or product promotion.
4. Legal Bases (EEA, UK and Switzerland).
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
(a) Legitimate Interests. To operate and secure the Site, administer accounts, carry out business-to-business marketing to professional contacts, understand how the Site is used, and protect our rights. We balance these interests against your rights and freedoms.
(b) Performance of a Contract. To administer Platform accounts and provide the services our customer has contracted for.
(c) Consent. For non-essential cookies, and for marketing communications where consent is required. You may withdraw consent at any time without affecting prior processing.
(d) Legal Obligation. To comply with applicable law, including tax, accounting and regulatory requirements.
5. Cookies and Similar Technologies.
(a) Essential Cookies. We use cookies and similar technologies that are strictly necessary for the Site and the Platform to function, including authentication, session management, load balancing and security. These do not require your consent.
(b) Analytics. On the Site, we also use analytics cookies and similar technologies to understand how visitors use it, such as which pages are viewed, referring pages and approximate location, so that we can improve the Site. Where the law requires it, we use these only with your consent.
(c) Advertising. We do not use advertising or remarketing cookies.
(d) Your Choices. You can manage your preferences through the cookie settings on the Site, where provided, and through your browser. You can configure your browser to refuse or delete cookies, but parts of the Site and the Platform will not function correctly without the essential ones.
6. How We Share Personal Information.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. For personal information we process as controller, we disclose information as follows:
(a) Service Providers. When we act as controller, to service providers that process personal information on our behalf under written contract and only on our instructions, including AWS, Anthropic, OpenAI, Microsoft, Auth0, and Okta. Separately, when we process Customer Platform Data as a processor, we engage subprocessors in accordance with our customer agreements. A current list of Platform subprocessors is available to customers on request.
(b) Within Our Group. To our affiliates, where applicable, for the purposes described in this Policy.
(c) Customer Organizations. For Platform account information, to the customer organization that authorized the account, including records of account activity.
(d) Legal and Safety. Where required by law, regulation, subpoena, court order or governmental request; to enforce our agreements; or to protect the rights, property or safety of Daikon, our customers or others. Disclosures involving Customer Platform Data that we process on a customer’s behalf are governed by Section 12 and the applicable customer agreement.
(e) Corporate Transactions. In connection with a merger, acquisition, financing, reorganization or sale of assets, subject to the acquirer honoring this Policy or providing notice of any material change.
7. International Transfers.
We are based in the United States and our service providers may process personal information in the United States and other countries. Where we transfer personal information from the EEA, the United Kingdom or Switzerland to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary measures where appropriate. A copy of the relevant mechanism is available on request at security@daikon.ai. Platform hosting location is specified in each customer’s order form.
8. Retention.
For personal information we process as controller, we retain it only as long as necessary for the purposes described in this Policy, and then delete or de-identify it. In general: enquiry and marketing contact records are retained for 24 months after the last interaction; Platform account administration records for the duration of the customer relationship; security and access logs for the period required by compliance and legal considerations; and records required for tax, accounting or legal purposes for the period applicable law requires. Personal information within customer Platform data is retained according to the customer’s instructions and its master services agreement.
9. Security.
We maintain an information security program with administrative, physical and technical safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration and destruction, including encryption in transit and at rest, role-based access control, multi-factor authentication for administrative access, logging and monitoring, vulnerability management and independent testing. No system is completely secure, and we cannot guarantee absolute security. If you believe your interaction with us is no longer secure, contact us at security@daikon.ai.
10. Your Rights.
(a) EEA, UK and Switzerland. Subject to conditions and exceptions in applicable law, you have the right to access your personal information; to correct inaccurate information; to request erasure; to restrict or object to processing, including objecting to direct marketing at any time; to data portability; and to withdraw consent. You also have the right to lodge a complaint with your local supervisory authority.
(b) California. Subject to conditions and exceptions, California residents have the right to know the categories and specific pieces of personal information collected, the sources, the purposes and the categories of recipients; to delete personal information; to correct inaccurate personal information; and to be free from discrimination for exercising these rights. We do not sell personal information and do not share it for cross-context behavioral advertising, so no opt-out of sale or sharing is required. We do not use or disclose sensitive personal information for purposes requiring a right to limit.
(c) Other U.S. States. Residents of other states with comprehensive privacy laws may have similar rights of access, correction, deletion, portability and appeal. We honor these rights on the same basis.
(d) How to Exercise. Submit a request to security@daikon.ai. We will verify your identity using the information we already hold, and respond within the period required by applicable law. An authorized agent may submit a request on your behalf with proof of authority. If we decline a request, you may appeal by replying to our response; we will inform you of the outcome and of any further recourse available to you.
(e) Requests About Platform Data. If your request concerns personal information held in a customer organization’s Platform environment, we will refer you to that organization, which is the controller for that data.
11. Categories of Personal Information We Collect as Controller (U.S. Disclosure).
In the preceding twelve months, as controller, we have collected the following categories of personal information, as those categories are defined under California law:
Identifiers: Name, business email, telephone, IP address, account identifiers. Collected: Yes.
Customer records: Employer, job title, business contact details. Collected: Yes.
Commercial information: Records of enquiries, demonstrations, subscriptions and services discussed. Collected: Yes.
Internet or network activity: Pages viewed, links clicked, referring page, authentication and access logs. Collected: Yes.
Geolocation data: Approximate location derived from IP address. Collected: Yes.
Professional information: Role, seniority, function, industry. Collected: Yes.
Inferences: Product interest and account-fit indicators drawn from the above. Collected: Yes.
Sensitive personal information: Government identifiers, health data, financial account numbers, precise geolocation. Collected: No.
Biometric information: —. Collected: No.
Education information: —. Collected: No.
We collect these categories from the sources described in Section 2, use them for the purposes described in Section 3, and disclose them to the recipients described in Section 6. We have not sold personal information or shared it for cross-context behavioral advertising in the preceding twelve months.
12. Customer Platform Data.
Where a customer organization submits data to the Platform, that organization determines the purposes and means of processing and is the controller. We process such data only on its documented instructions, under our master services agreement and data processing addendum, which address security, subprocessing, international transfers, assistance with data subject requests, breach notification, and deletion or return on termination.
We do not use personal information contained in customer Platform data to train, fine-tune or improve any model made available to other customers, and our agreements with third-party model providers prohibit them from using customer data for training. Our data rights in de-identified and aggregated information derived from Platform use are set out in the applicable master services agreement.
Requests from individuals concerning data in a customer environment should be directed to that customer organization. We assist our customers in responding to such requests as their agreement requires.
13. Children.
The Site and the Platform are intended for business use by professionals. They are not directed to children and, in our capacity as controller, we do not knowingly collect personal information directly from anyone under 16. If you believe a child has provided us personal information directly, contact us at security@daikon.ai and we will delete it.
14. Changes to This Policy.
We may update this Policy from time to time. The current version is always posted at daikon.ai/privacy with the Last Updated date shown above. If we make a material change to how we handle personal information, we will provide prominent notice on the Site and, where required, obtain your consent. We encourage you to review this Policy periodically.
15. Contact Us.
For questions about this Policy or to exercise your rights:
Daikon Corp.
169 Madison Ave Ste 38534
New York, NY 10016, United States
Privacy: security@daikon.ai
Security: security@daikon.ai