Privacy Policy
Last updated: September 8, 2026
This document is a professional drafting base prepared for Dolirah. It describes the processing actually carried out by the platform as of today. It has not yet been reviewed by legal counsel and constitutes neither legal advice nor a compliance attestation. Dolirah claims no certification or formal compliance at this stage (in particular Quebec Law 25, GDPR, SOC 2 or ISO 27001): an independent assessment would be required before making any such claim.
This policy explains what data Dolirah processes, why, with which providers, and what choices are available.
Dolirah acts in two distinct capacities. For the data of its own business customers (the subscribing businesses), Dolirah acts as controller. For the data those businesses enter about their own clients, Dolirah acts as a provider acting on behalf of the subscribing business, which remains responsible for it.
1. Account and business data
When an account is created and used, the platform processes the data needed to identify the customer and manage the contractual relationship.
- Professional identity and contact details: name, email address, phone number.
- Authentication data: password stored as a cryptographic hash, never in clear text; account verification status.
- Business data: legal name, locations, addresses, opening hours, language and currency.
- Roles and permissions assigned to the business's users.
2. Data about the subscribing business's own clients
The subscribing business enters data about its own clients into the platform. Dolirah hosts and processes it on that business's behalf.
- Client records: name, email address, phone, preferences, notes and allergies where the business chooses to record them.
- Appointment history: date, service, duration, amount, status, location, assigned staff member.
- Commercial history: orders, line items, amounts, payments, invoices.
- Communication preferences, including marketing consent and unsubscribes.
3. Technical data and logs
The platform keeps operational and security logs necessary for it to work correctly.
- Audit logs of sensitive actions: denied access, support mode activation, governance changes.
- Authentication logs, including failed attempts, for the purpose of limiting brute-force attacks.
- Technical request data necessary for security and diagnostics.
- Cookies strictly necessary for the authenticated session and for protection against cross-site request forgery (CSRF).
4. Data processed by artificial intelligence features
When you use an artificial-intelligence-assisted feature, the content needed for the request is transmitted to a third-party model provider in order to produce a response.
Depending on the feature, this may include the conversation text, a description of the business, the list of its services and products, and the generated website content. Passwords are never transmitted.
The model providers are established outside Canada: the data concerned is therefore transferred outside the country.
5. Categories of third-party providers actually used
The categories below correspond to the integrations actually present in the platform. A named, up-to-date list of subprocessors must be maintained and made available on request.
- Payment processing: Stripe, Inc., for subscriptions and for routing payments to the subscribing business's own account (Stripe Connect).
- Transactional and marketing email delivery: Resend, or an SMTP server configured by the operator.
- Artificial intelligence models: Alibaba Cloud (DashScope service, Qwen models) and, depending on configuration, Anthropic.
- WhatsApp messaging: only if a third-party service is explicitly configured by the operator; no provider is integrated by default.
- Hosting and infrastructure: the hosting provider selected for the deployment, to be specified in the final version of this document.
6. Purposes and legal bases
- Performance of the contract: providing the service, managing the account, billing and support.
- Legitimate interest: platform security, prevention of fraud and abuse, service improvement.
- Consent: marketing communications, withdrawable at any time.
- Legal obligation: accounting and tax retention, responding to requests from competent authorities.
7. No sale of data
Dolirah does not sell personal data and does not make it available to third parties for advertising purposes. Data is shared only with the providers necessary to deliver the service, or where required by law.
8. Isolation between subscribing businesses
The platform is multi-business. Each subscribing business has an isolated space: one business's data is not accessible to another.
Support access by Dolirah staff is technically possible for diagnostic purposes; such access is logged.
9. Data retention and deletion
Data is retained for the duration of the subscription, then for as long as necessary to meet legal, accounting and evidentiary obligations.
A formal, documented deletion and export procedure for the end of the contract must be finalised and published. In the meantime, requests are handled case by case through the Contact page.
10. Security
Technical measures are in place: encryption in transit, hashed passwords, role-based access control, login attempt throttling, audit logging and isolation of customer spaces.
No measure can guarantee absolute security. No independent certification is claimed at this time.
11. Your rights
Subject to applicable law, you may request access to your data, its correction, its deletion, and the withdrawal of your consent to marketing communications.
If you are a client of a business that uses Dolirah, please send your request directly to that business, which is responsible for your data. Dolirah will assist it in handling the request.
12. Contact
Any question or request about this policy can be sent through the Contact page on the Dolirah website.
Appointing a privacy officer and publishing their contact details are among the items to be finalised with legal counsel.
