Legal
Privacy Policy
How New DAIS handles the information you give us and the information our site collects while you use it.
New DAIS, Inc. ("New DAIS," "we," "us," or "our") is a data and AI engineering firm that sells to businesses. This policy explains what personal information we collect through newdais.ai, why we collect it, who we give it to, and the choices and rights you have over it. It applies to this website and to the business development activity that runs through it.
Read section 6 if you want to turn off advertising and analytics tracking, and section 8 if you want to access, correct, or delete information we hold about you.
1. Who and what this policy covers
This policy covers information about visitors to newdais.ai and people who contact us through it, including business contacts acting on behalf of their employer. California and several other states treat business contact details as personal information, so the rights described below apply to you even when you reached out in a professional capacity.
This policy does not cover client data we process under a services agreement. When we build or operate data platforms for a client, that client decides what happens to the data in those systems and we act on their instructions under the contract and any data processing terms that go with it. If your information sits in a client's system, direct your request to that client. This policy also does not cover sites and services we do not run, including LinkedIn.
2. What information we collect
Information you give us
- Contact form. Your name, work email address, and whatever you write in the message field. We also record which page or button the form was opened from. We ask for a work address and reject common personal email domains.
- RFP submissions. Your contact email, the decision date you give us, and the documents you upload. Uploaded documents can contain anything you put in them, so please do not include sensitive personal information, personnel records, or regulated data in an RFP package.
- Self Assessment. Your work email address, the assessment area you picked, your answers to the assessment questions, the maturity scores and band calculated from those answers, and any sample use cases you flag as interesting.
- Direct correspondence. Anything you send us by email or say in a meeting we set up as a result.
Information collected automatically
- Server and request data. Your IP address, browser user agent, the pages you request, timestamps, and referring URLs. Our hosting and application logs record this as a normal part of serving the site.
- Anti-spam signals. When you submit a form, Google reCAPTCHA receives your IP address and interaction data so it can score whether the submission is automated.
- Advertising and analytics pixels. Subject to your choice in section 6, the Meta Pixel and the LinkedIn Insight Tag record your visit and the pages you view, and may read or set identifiers that let those platforms recognize you across other sites. See section 5.
- Local browser storage. We store your light or dark theme preference and your advertising opt-out choice in your browser's local storage. Neither leaves your device, and clearing site data removes both.
Information from third parties
When you submit one of our LinkedIn Lead Gen Forms, LinkedIn sends us the profile details you agreed to share, typically name, work email, employer, and job title. Our CRM may add publicly available business information to a contact record.
Sensitive information
We do not ask for or collect sensitive personal information as state privacy laws define it, and we do not use this site to infer characteristics about you.
3. How we use information
- Respond to your inquiry and route it to the right person on our team.
- Prepare and deliver proposals, scoping documents, and responses to RFPs.
- Calculate and return your Self Assessment results, and follow up on them.
- Manage our relationship with you and your organization in our CRM.
- Operate, secure, and debug the website, and detect fraudulent or automated submissions.
- Measure how our advertising performs, and show our ads to people likely to be interested in our services.
- Send business communications about our services where you asked for them or where the law otherwise allows.
- Meet legal, tax, audit, and contractual obligations, and defend legal claims.
We do not use what you send us through this site to train AI models.
4. Who we share information with
We disclose personal information to the categories of recipient below, each for the limited purpose listed. Apart from the advertising platforms, they process it on our behalf and are restricted to that purpose. The advertising platforms receive it as independent controllers and use it for their own purposes, which is why section 6 lets you switch them off.
| Category of recipient | Purpose |
|---|---|
| Customer relationship management platform | Stores contact records, message content, and assessment results, and tracks our follow-up. |
| Cloud infrastructure provider | Hosting, application logs, storage of RFP uploads, malware scanning of those uploads, and delivery of internal notification email. |
| Internal team messaging platform | Routes a new inquiry to the right person on our team. Includes your email address and a preview of your message. |
| Spam and abuse prevention (Google reCAPTCHA) | Scores form submissions to detect automated abuse. Receives your IP address and interaction data. |
| Content delivery networks | Serve stylesheet and font assets. Receive your IP address as a function of delivering the file. |
| Advertising platforms (Meta, LinkedIn) | Advertising measurement, audience building, and lead capture through the Meta Pixel, the LinkedIn Insight Tag, and Lead Gen Forms. Off when you opt out. |
To learn the specific provider behind any category, ask us at the address in section 15.
We also disclose information when we are legally required to, in response to lawful requests from public authorities, to protect our rights or the safety of others, and to professional advisers such as lawyers and accountants under a duty of confidence. If we are involved in a merger, acquisition, financing, or sale of assets, contact records may transfer as part of that transaction, and we will note the change here.
We do not sell your personal information for money. We do disclose identifiers and browsing activity to Meta and LinkedIn for cross-context behavioral advertising, which several state laws classify as a "sale" or as "sharing" or "targeted advertising" regardless of whether money changes hands. You can turn that off in section 6.
5. Cookies, pixels, and similar technology
The site uses two categories of technology:
- Strictly necessary. A session cookie for form security, reCAPTCHA's anti-abuse storage, and the local storage entries for your theme and privacy choices. These support how the site works and remember what you picked. None of them are used for advertising.
- Advertising and analytics. The Meta Pixel and the LinkedIn Insight Tag. These record which pages you view on this site and report back to Meta and LinkedIn, which use that data for conversion measurement, retargeting, and audience building against your profile on their platforms. Meta and LinkedIn act as independent controllers of the data they receive. Their handling of it is governed by their own policies, not this one.
Advertising pixels load only when you have not opted out. Blocking third-party cookies in your browser, or using a tracker-blocking extension, also stops most of this collection.
6. Your privacy choices
Use the control below to turn advertising and analytics pixels on or off for this browser. Your choice is stored on your device, so set it again on each browser and device you use, and re-apply it if you clear site data.
Advertising & analytics pixels
LoadingGlobal Privacy Control
We honor the Global Privacy Control signal. If your browser or extension sends GPC, we treat it as a valid request to opt out of targeted advertising and the sale or sharing of your personal information, and we apply it automatically without asking you to do anything else. You can read about GPC at globalprivacycontrol.org. We also treat a legacy Do Not Track header the same way.
Platform-level and email choices
- Ad preferences on the platforms themselves can be changed in your LinkedIn ad settings and your Meta ad preferences.
- Industry opt-out tools are available from the Digital Advertising Alliance and the Network Advertising Initiative.
- To stop marketing email from us, use the unsubscribe link in any message or write to us at the address in section 15. We will still send messages needed to answer an active request or administer a contract.
7. Your rights under state privacy laws
Depending on where you live, you may have some or all of the rights below. We extend them to every US resident who asks, rather than checking your state first.
- Know and access. Confirm whether we process personal information about you and get a copy of it, along with the categories we collect, the sources, our purposes, and the categories of third parties we disclose it to.
- Delete. Ask us to delete personal information we hold about you, subject to the exceptions the law allows.
- Correct. Ask us to fix inaccurate personal information.
- Portability. Receive a copy in a portable, readily usable format where technically feasible.
- Opt out of targeted advertising, sale, and sharing. Available immediately through section 6, or by written request.
- Opt out of profiling. Object to automated processing that produces legal or similarly significant effects about you. We do not do this. The Self Assessment scores your own answers and returns them to you; nothing about it decides anything on your behalf.
- Limit use of sensitive personal information. We do not collect or use sensitive personal information, so there is nothing to limit.
- Non-discrimination. We will not deny you service, charge a different price, or give you a lower quality of service because you exercised a privacy right. We run no financial incentive programs tied to personal information.
- Appeal. If we deny your request, you may appeal. See section 8.
8. How to make a privacy request
Email contact@newdais.ai with "Privacy Request" in the subject line. Tell us which right you want to exercise and which email address or addresses you used with us. That is the fastest route, and because we operate this business online it is the designated method for submitting requests.
Verification. Before we act on a request to access, delete, or correct information, we need reasonable confidence that you are the person the information is about. Usually that means confirming you control the email address on the record. We may ask for one additional matching detail if the request is broad or the information is unusually sensitive. We will not ask you for new categories of information solely to verify a request, and we use anything you send for verification only for that purpose.
Timing. We acknowledge requests within 10 business days and answer within 45 calendar days. If we need more time we will tell you why and take up to 45 additional days. Opt-out requests take effect as soon as we process them, and no later than 15 business days.
Authorized agents. An agent may submit a request for you with written, signed permission. We may contact you directly to confirm the authorization.
Appeals. If we refuse your request, reply to our decision with the word "Appeal" and your reason. We will review it and respond in writing within 45 days with our conclusion and the reasoning behind it. If we deny the appeal, you may complain to your state attorney general. California residents may also contact the California Privacy Protection Agency.
9. Notice for California residents
This section supplements the rest of the policy for residents of California, under the California Consumer Privacy Act as amended by the California Privacy Rights Act.
Categories collected in the last 12 months
| Statutory category | Examples we collect | Sold or shared? |
|---|---|---|
| Identifiers | Name, work email address, IP address, cookie and pixel identifiers | Shared for cross-context behavioral advertising |
| Commercial information | Services you expressed interest in, prior quotes you told us about, RFP contents | No |
| Internet or network activity | Pages viewed, referring URL, timestamps, interaction with our forms | Shared for cross-context behavioral advertising |
| Professional or employment information | Employer, job title, and role context, whether you gave it to us or it came from a LinkedIn form | No |
| Inferences | Self Assessment maturity band and dimension scores derived from your own answers | No |
| Sensitive personal information | None collected | No |
Sources, purposes, and recipients for each category are described in sections 2 through 4. We have not sold personal information for monetary consideration in the last 12 months. We have disclosed identifiers and internet activity to Meta and LinkedIn for advertising, which counts as sharing.
Do Not Sell or Share My Personal Information
The control in section 6 is our "Do Not Sell or Share My Personal Information" mechanism, and the "Your Privacy Choices" link in the site footer points to it from every page. A Global Privacy Control signal from your browser has the same effect without any action from you.
Shine the Light
California Civil Code section 1798.83 lets California residents ask once a year about personal information we shared with third parties for their own direct marketing. We do not share personal information for that purpose. Requests for confirmation go to the address in section 15.
Retention
We do not keep personal information longer than reasonably necessary for the purpose it was collected for. See section 11 for the periods we work to.
10. Notices for other states
Residents of Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia have rights under their own state privacy laws. The rights in section 7 and the request process in section 8 cover them. A few state-specific points:
- Colorado, Connecticut, Minnesota, Montana, New Jersey, Oregon, and Texas require us to recognize a universal opt-out signal. We honor Global Privacy Control, as described in section 6.
- Maryland limits collection to what is reasonably necessary for the requested product or service and prohibits the sale of sensitive personal information. We collect only what the relevant form needs, and we do not collect sensitive personal information at all.
- Oregon residents may request a list of the specific third parties to which we disclosed personal information, not only the categories. Ask and we will provide it.
- Minnesota residents may ask us to review and explain a profiling decision. We do not profile in the sense the statute addresses.
- Nevada residents may direct us not to sell covered information under NRS 603A. We do not sell it.
- Washington and Nevada consumer health laws apply to consumer health data. We do not collect, use, or share consumer health data through this site.
- Texas residents: we disclose personal data to third parties for targeted advertising, and you may opt out through section 6.
11. How long we keep information
- CRM contact records, including message content and assessment results: for the life of the business relationship, and for up to three years after our last substantive contact with you, unless you ask us to delete them sooner.
- RFP documents: for the duration of the pursuit and up to two years after it closes, so we can support any resulting engagement. Download links we generate for internal review expire within 24 hours.
- Internal notification email and team chat messages: under the retention settings of those tools, and no longer than needed for triage.
- Server and application logs: short-term, generally 90 days or less, for security and debugging.
- Records we must keep for tax, audit, or legal defense reasons: for as long as the relevant law requires.
12. Security
The site is served over HTTPS. Uploaded files are stored in access controlled cloud storage and scanned for malware on arrival, and the internal links we generate to them are time limited. Access to our CRM and internal tools is limited to staff who need it for their work.
No method of transmission or storage is perfectly secure, and we cannot promise absolute security. Please do not send regulated data, credentials, or sensitive personal information through the forms on this site.
13. Children and minors
This site sells professional services to businesses. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. We do not knowingly sell or share the personal information of consumers under 16. If we learn that we have collected information from a minor, we delete it. If you believe a minor has given us information, write to us at the address in section 15.
14. Other terms
Links to other sites
Our pages link to third-party sites, including LinkedIn and vendor documentation. We do not control those sites and are not responsible for their privacy practices. Read their policies before giving them information.
Where information is processed
We are based in the United States and process information here. If you visit from outside the US, understand that US law may give personal information less protection than your home jurisdiction does. By using the site you accept that your information is handled in the US.
Changes to this policy
We may update this policy. When we do, we will change the effective date at the top of the page. If a change materially affects how we handle information we already hold about you, we will give notice through the site or by email before it takes effect. Continued use of the site after the effective date means you accept the updated policy.
15. Contact us
Questions about this policy, or requests under section 8, go to:
New DAIS, Inc.
Attn: Privacy
contact@newdais.ai
Offices in Atlanta | Charlottesville | Charleston
We answer privacy correspondence within 10 business days.