01Who is responsible
DAISI is the learning platform of Digital Bricks. Most people use it because their employer has arranged access for them.
For your training records — the courses assigned to you, your progress, quiz results and certificates — your employer decides why and how they are used. Under the GDPR your employer is the controller and Digital Bricks is its processor, bound by a data processing agreement (Art. 28 GDPR).
For running the platform itself — keeping accounts secure, remembering preferences and the optional choices you make — Digital Bricks is the controller.
Questions about any of this go to privacy@digitalbricks.ai. We answer within one month, usually much sooner.
02What we collect
We collect only what DAISI needs to run your learning. We do not buy data about you, and we do not combine it with data from other sources.
Account & profile
Who you are on DAISI.
- Name
- Work email address
- Job title
- Company and role
- Password (as a one-way hash)
- Language preference
Learning progress
What you learn and how you do.
- Assigned courses
- Lectures completed and video position
- Quiz answers and scores
- Certificates earned
Security records
How your account is kept safe.
- Sign-in date and time
- Successful and failed attempts
- IP address
- Browser and device type
Preferences & choices
How you like DAISI to behave.
- Interface language
- Light or dark theme (kept in your browser only)
- Your privacy choices and when you made them
03What we never collect
Some things we never collect, however useful they might look.
- Your precise location
- Health, religion, politics or any other special-category data
- Your contacts, camera or microphone
- What you do on other websites
- Advertising or marketing profiles
04Why we use it, and on what legal basis
Every use of your data rests on a legal basis in Article 6 of the GDPR. None of the essential processing depends on your consent — which is why the only things you can switch off are genuinely optional.
| Data | Why | Legal basis |
|---|---|---|
| Account & profile | To create your account, sign you in and put your name on your certificates. | Performance of a contract and your employer's legitimate interest in training its people — Art. 6(1)(b) and (f) GDPR. |
| Learning progress | To track your progress, pick up where you stopped, grade quizzes and issue certificates your employer can verify. | Performance of a contract and your employer's legitimate interest — Art. 6(1)(b) and (f) GDPR. |
| Security records | To protect your account, detect misuse and show your company administrator when people last signed in. | Legitimate interest in keeping the platform secure — Art. 6(1)(f) GDPR. |
| Preferences & choices | To remember your settings and to be able to show what you agreed to. | Performance of a contract, and our legal duty to demonstrate consent — Art. 6(1)(b) and (c), Art. 7(1) GDPR. |
Optional usage statistics and product emails are only ever used with your consent — Art. 6(1)(a) GDPR — which you can withdraw at any time in Settings.
06Where your data is stored
Your data is stored and processed in Microsoft Azure's West Europe region, in the Netherlands. Backups stay in the same region.
We do not transfer your data outside the European Economic Area. Should Microsoft ever need to access it from outside the EEA — for example to resolve a support incident — that is covered by the EU Standard Contractual Clauses and the EU–US Data Privacy Framework.
07How we protect it
All traffic is encrypted with TLS. The database and file storage are encrypted at rest with AES-256.
Passwords are stored as salted bcrypt hashes. Invite and reset links are single-use, expire, and are only ever stored as hashes.
Access is limited by role and checked on the server for every request. Each company only ever sees its own people.
Every sign-in attempt is logged so unusual activity stands out. If a breach ever put your rights at risk, we would inform your organisation and the supervisory authority within 72 hours, and you directly where required.
08How long we keep it
We keep data only for as long as it serves the purpose it was collected for. The periods per category are listed in the table above.
Backups roll off automatically within 35 days, so erased data disappears from them too. Records of your privacy choices are kept for as long as your account exists, as proof of what you agreed to.
| Data | Kept for |
|---|---|
| Account & profile | As long as your account exists. Erased within 30 days after it is removed. |
| Learning progress | As long as your account exists. Erased within 30 days after it is removed. |
| Security records | 12 months, then deleted automatically. |
| Preferences & choices | As long as your account exists. |
09Cookies and browser storage
DAISI uses no advertising or analytics cookies and no third-party trackers — which is why there is no cookie banner to click through. The only browser storage is what the platform needs to work. Under the Dutch Telecommunications Act, strictly necessary storage like this does not require consent.
| Name | Purpose | Duration |
|---|---|---|
authjs.session-token | Keeps you signed in. Encrypted, signed and unreadable to scripts on the page. | 7 days |
authjs.csrf-token | Protects the sign-in form against cross-site request forgery. | Browser session |
authjs.callback-url | Sends you back to the page you asked for after you sign in. | Browser session |
daisi-locale | Remembers your interface language. | 12 months |
daisi.theme | Remembers light or dark mode. Kept in your browser's local storage and never sent to us. | Until you clear it |
10Your rights
To use any of these rights, email privacy@digitalbricks.ai from the address you sign in with. It is free, and we respond within one month.
Several are self-service: correct your name in Settings, download all your data as a file, and change your optional choices at any time.
If you think we have handled your data wrongly, please tell us first so we can put it right. You also have the right to lodge a complaint with a supervisory authority — in the Netherlands the Autoriteit Persoonsgegevens — or with the authority in the EU country where you live or work.
- Art. 15See your dataAsk what we hold about you, why, and who has seen it.
- Art. 16Correct itFix anything inaccurate. Your name and job title you can edit yourself.
- Art. 17Erase itHave your account and everything linked to it deleted.
- Art. 18Pause itAsk us to stop using your data while a question about it is being resolved.
- Art. 20Take it with youDownload your data as a machine-readable file, straight from Settings.
- Art. 21ObjectObject to processing based on legitimate interest, and we stop unless there are compelling grounds.
- Art. 7(3)Change your mindWithdraw an optional consent at any time. It is exactly as easy as giving it.
- Art. 22A human decidesNo decision with legal or similarly significant effect is made about you by automated means alone.
11Changes to this notice
When this notice changes in a way that matters, we raise the version number and ask you to read and accept it again the next time you use DAISI. Earlier versions are available on request.
12Contact
Digital Bricks · privacy@digitalbricks.ai
If your question is about how your employer uses your training records, you can also contact your company administrator or your employer's data protection officer.