DDScore.ai
For Investors For Evaluators For Founders Example Report Pricing News About
Sign In
For Investors For Evaluators For Founders Example Report Pricing News About Sign In

DDScore.ai — Privacy Policy

Effective date: 13 August 2026

2026.08.13 22:00

This Privacy Policy explains how Playful Pixels Oy ("we," "us," "our"; Finnish Business ID 2410516-5) collects, uses, discloses and safeguards your personal data when you use DDScore.ai (the "Service"). It complies with the EU General Data Protection Regulation (GDPR) and applicable Finnish data-protection laws.

1. Data Controller

Playful Pixels Oy | Business ID 2410516-5 | Espoo, Finland | [email protected]

Two roles. When you submit material for analysis, or enable a check of an individual's professional background against public sources, you act as controller and we act as processor under our Data Processing Addendum. In everything else — your account, payments, support requests, campaign participation and marketing choices — we are the controller and you are a data subject. Rows marked (we act as processor) in the table below fall into the first category; all others fall into the second.

2. Personal Data We Collect

CategoryExamplesLegal basis (GDPR Art. 6)
Account dataE-mail address, phone number, hashed password or single-sign-on identifier.Contract (§1 b)
Subscription metaStripe customer ID, subscription ID, transaction tokens. We never store card numbers or other payment-instrument details.Contract; Legal obligation (§1 c)
Technical logsIP address, browser type, OS, device identifiers, timestamps.Legitimate interest (§1 f) — security & fraud prevention
Device hashA one-way hash that lets us recognise the same device across sessions. We use it only to detect and prevent fraudulent or abusive use of the Service. It does not contain, and cannot be used to derive, any information about your device, its configuration or its contents.Legitimate interest (§1 f) — security and abuse prevention
Support dataMessages and attachments you send to our help desk, including the report (automatically attached) and any source materials voluntarily attached to support requests.Legitimate interest (§1 f) — Attachments retained 14 days from submission, extendable by mutual agreement of both parties; ticket text retained 24 months
Processing data (we act as processor)Uploaded business documents and generated analysis reports.You are the controller for third-party personal data contained in the documents and determine the legal basis; we process it on your instructions under the DPA — source files deleted immediately upon report completion; reports deleted <24h after generation, or, where you activate a share link, retained while the link is active and deleted within 24 hours of its deletion
Public Data (we act as processor)Professional background, education, and public profiles of an individual named in materials you submit, checked against public sources only where you switch that check on for that specific individual.You decide whether this check is carried out and about whom; you are the controller for this data and determine the legal basis; we carry it out on your instruction under the DPA — deleted with the related report
Published share contentReports or main images you choose to publish via the in-service share link function.Contract (§1 b) and your consent — Retained while the share link is active
Campaign survey dataAudience and role, survey answers, campaign source, timestamps, connected account reference and e-mail, the result of the automated eligibility check, entitlement records, report-use trigger, campaign-message status, and the accepted Campaign Terms version.Contract (§1 b) — performance of the campaign you asked to join, covering the survey answers, entitlement administration and campaign messages; Legitimate interest (§1 f) for duplicate and abuse prevention and for evaluating and improving the Service
Marketing consent recordWhether you have given or withdrawn consent to electronic marketing, the exact wording and version of the consent shown to you, where and when it was given, and any withdrawal or suppression record.Consent (§1 a); Legal obligation (§1 c) — to demonstrate and honour your choice
Anonymous statistical dataThe 12 section scores, GICS-based industry classification, country/region, and timestamp. No link to user identity or submitted material.Not personal data (GDPR Recital 26)

Payment details: All card and bank information is collected and processed directly by Stripe Payments Europe Ltd ("Stripe"). Playful Pixels Oy does not receive or store your full payment-instrument data.

3. How We Use Your Data

  • To provide, maintain and authenticate access to the Service.
  • To manage subscriptions and process recurring payments via Stripe.
  • To send essential service communications (e.g. security alerts, policy updates).
  • To monitor performance, ensure security and prevent abuse.
  • To perform analysis of business documents and professional backgrounds using AI-powered analysis combined with mathematical methods, including proprietary Advanced Probabilistic Analysis. We do this as processor, on your instruction; you are the controller for the personal data involved.
  • To handle support requests and feedback you submit through the Service.
  • To enable the optional in-service share link function when you choose to use it.
  • With your separate consent, to send you electronic marketing about DDScore. Consent is optional, is asked separately from account creation and from any campaign, and may be withdrawn at any time; every marketing message contains an easy way to unsubscribe.
  • To administer campaign participation you requested, including analysing survey answers, delivering the promotional entitlement, preventing duplicate or abusive claims, and sending the campaign messages described in the Campaign Terms.

We also collect anonymous, aggregated statistical data — consisting of the 12 section scores, GICS-based industry classification, country/region, and timestamp — to develop and improve the Service. This data is statistical and contains no link to your identity or to the submitted material.

No Training: We do not use your personal data, uploaded documents, or generated reports to train or fine-tune machine learning models. The anonymous statistical data described above is also not used to train AI models and is not transferred to third parties.

Campaign participation

Participation in a DDScore survey campaign is optional and separate from ordinary paid use of the Service. We are the controller for campaign answers and campaign records. Acceptance of the Campaign Terms is not consent to marketing or to non-essential tracking.

4. Data Sharing

We do not sell or rent your personal data. We share it only with trusted service providers (Stripe for payments, third-party AI model services, and an email delivery provider for service, campaign and marketing messages) under contracts that require confidentiality and GDPR-compliant safeguards. Our own servers are located in a machine room we operate ourselves in Finland; no external party administers them or has access to them. Your Stripe customer ID is linked to your account for billing purposes, but no payment-instrument data is copied into our systems. We share data when legally required to comply with applicable law or valid governmental requests.

If you choose to use the in-service share link function (Terms of Service, Section 7), the report or main image you publish is made accessible via a public link on the open Internet. This is your voluntary choice on a per-report basis. The published version is produced by a rule-based anonymization designed to remove all personal data; the company name and the general analytical content of the report remain visible. No automated system is infallible, and the publishing user remains responsible for verifying the published content before activating the share link, as required by Section 7.4 of the Terms of Service. We apply industry best-practice measures designed to reduce the likelihood of share links being indexed by search engines or stored in web archives, but because the published content is hosted on the public Internet, we cannot guarantee that it will not be indexed, archived, or cached by parties outside our control. The likelihood increases substantially if you distribute the link via third-party platforms (e.g., social media, online forums). Source materials are not part of the share function and are deleted immediately upon report completion regardless of any sharing choice. Upon deletion of the share link or closure of your account, the published content is removed from our servers immediately.

5. Data Retention (Zero Trace Policy)

Data typeRetention period
Uploaded source filesAutomatically and permanently deleted immediately upon completion of report generation
Generated analysis reportsAutomatically and permanently deleted within 24 hours of generation, regardless of whether they have been accessed. Where you activate a share link, the report is retained for as long as the share link is active and is deleted within 24 hours of the link being deleted (Terms of Service §7.6, §7.8).
Public-source background data (we act as processor)Deleted with the related report, and therefore subject to the same retention period as the report
Published share content (when share link function is used)Retained while the share link is active. Removed from our servers immediately upon deletion of the share link or closure of the account.
Support ticket attachments (report and any voluntarily attached source materials)14 days from submission. Either party may request an extension subject to mutual agreement.
Anonymous statistical dataRetained indefinitely for product development. Not personal data.
Account & Subscription recordsDuration of customer relationship + 10 years (Finnish Accounting Act)
Technical logs24 months
Device hash10 years
Support tickets (text content)24 months after last correspondence
Incomplete or unconnected campaign submissions30 days
Identifiable campaign survey answersDeleted or effectively anonymised 12 months after campaign closure
Marketing consent recordWhile your consent remains active; after withdrawal, only the record needed to honour the withdrawal and to demonstrate compliance is kept
Campaign terms acceptance, eligibility and entitlement evidenceCampaign duration plus the period needed to resolve any related claim, after which the data is deleted or minimised

6. Your Rights

You have the right to: access, correct or delete your personal data; restrict or object to processing; receive your data in a portable format; and withdraw consent at any time (where processing is based on consent). To exercise these rights, contact [email protected]. We may need to verify your identity. We reply within one (1) month, extendable by two (2) months for complex requests. You may lodge a complaint with the Finnish Data Protection Ombudsman.

For personal data in the rows marked (we act as processor), we act on the instructions of the user who submitted the material. If you are an individual named in material submitted by one of our users, that user is the controller and is the correct addressee for your request; we will assist them as required under the DPA. If you do not know who submitted the material, you may contact us at the address above and we will forward your request to the controller where we are able to identify them. Because of the deletion periods set out in Section 5, this is often no longer possible.

7. Data Security

Encryption: TLS 1.3 encryption in transit and AES-256 encryption at rest. Access Control: Role-based access controls and multi-factor authentication for staff. In the context of support-request handling, access to submitted materials is restricted to the support team and the development team. Automatic Purge: Hard-coded automatic purge of uploaded source files immediately upon report completion, and of generated reports within 24 hours of generation, unless a share link is active — see the retention table in Section 5. Testing: Regular vulnerability scanning and third-party penetration testing. Continuity: Back-up, business-continuity and disaster-recovery plans for system infrastructure and metadata (excluding processed documents).

8. International Transfers

Your data is primarily stored and processed within the EU/EEA. If processing occurs outside the EEA, we rely on EU adequacy decisions or Standard Contractual Clauses plus any additional safeguards required by GDPR.

9. Business Use (B2B)

The Service is intended for professional use by users aged 18 and older. We do not knowingly collect personal data from children; if we become aware of such data, we will delete it promptly.

10. Cookies

We use essential cookies for authentication and security. We may use anonymized analytics to improve user experience. You can manage cookies via your browser settings.

11. Changes to This Policy

We may update this Policy to reflect operational or legal changes. For material changes we will notify you (e-mail or in-app) at least 14 days before the new version takes effect.

Contact

Playful Pixels Oy Business ID 2410516-5 Espoo, Finland [email protected]

© 2026 Playful Pixels Oy — All rights reserved.

DDScore.ai - Make Better Decisions

Company

Login For Investors For Evaluators For Founders Pricing News About

Legal

Terms of Service Data Processing Addendum Privacy Policy Register Description

© 2026 DDScore.ai — A Playful Pixels Product