dualkind

Privacy policy

Effective 7 September 2026. Oxente Technologies, Unipessoal Lda, 13, Rua 1 Janeiro, 2530-316 Lourinha, Portugal (NIF 516438395), operates Dualkind. For privacy requests, contact support@dualkind.com.

Accounts and operation

We process your email address, login-provider identifiers, session credentials, project configurations, usage records, billing references and support correspondence to operate your account, fulfil our contract, prevent abuse and meet applicable obligations. Google sign-in shares your verified email and account identifier with us. Login-provider data is encrypted at rest; session credentials are stored as hashes. Stripe handles payment details; Dualkind keeps customer and subscription references rather than card numbers.

Product events

Customers choose which events, identifiers, context and outcome values to send from their sites, apps and games. This may include session activity, purchases, retention events and observed device information. Customers are responsible for their notices and legal basis. We process those records to provide their configured decision and measurement service. Do not include unnecessary personal or sensitive information. Contact the product operator first about events collected in a customer’s product; we can assist with requests relating to our processing.

Cookies and optional learning

Essential cookies support sign-in, security and your privacy choice. Optional first-party learning uses browser identifiers and interactions after permission. You can change that choice with the Privacy control. The browser SDK can respond to a supported consent-management platform; customers must configure their integration for the permissions and laws that apply to them. The public simulated learning lab uses temporary memory for simulation state.

Recipients and storage

Hosting infrastructure processes service data, our SMTP mail server sends account messages, Google participates when you choose Google login, and Stripe processes billing. We do not sell personal data. Necessary disclosures may also occur to meet legal obligations or protect the service. Payment and login providers describe their own processing in their privacy notices: Stripe and Google.

Account and project records are retained to provide the service and support delayed outcomes, corrections and security. There is currently no automatic age-based deletion of all project event records. You can download account and project records or delete your account in Account settings. Deletion removes your owned projects, their events and learning, connected login methods and browser/CLI sessions after billing cancellation is confirmed. If cancellation cannot be confirmed, deletion remains pending and you can retry or contact support. Contact support to arrange other deletion requests or an appropriate retention plan. Some transaction or legal records may need to remain after a deletion request; backups can retain copies until replaced. Hashed address suppression records remain to honour complaints and prevent unwanted email. Browser exports omit credentials and are paginated, so records may change during a download; large exports and records held in support mailboxes or by Stripe can be requested through support. We assess and explain retention limits when handling your request.

Your choices and rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability or object to processing. Where processing relies on consent, you can withdraw it without affecting prior lawful processing. We may verify your identity before acting. You may complain to your data-protection authority, including Portugal’s CNPD. Contact support about international processing safeguards or a data-processing agreement before sending data that requires additional contractual arrangements.