Privacy Policy

Current Version: 1.0 Effective: 31/08/2025
Privacy Policy
Effective Date: 31/08/2025
Last Updated: 31/08/2025

1. Introduction

Welcome to The Dotty Initiative ("we," "our," or "us"). This Privacy Policy explains how we collect, use, and protect your personal information when you use our website and AI-powered services.

Our Commitment: We are committed to protecting your privacy and being transparent about our data practices. We only collect information that is necessary for providing our services.

2. GDPR Data Controller and Roles

Data Controller: The Dotty Initiative
Contact: Click to show email
Location: United Kingdom

Data Protection Responsibilities:

Data Controller (The Dotty Initiative): Determines how and why personal data is processed
Data Processor: We act as our own data processor for all services
Data Protection Officer: For privacy inquiries, contact Click to show email

3. Information We Collect and Legal Basis

3.1 Account Information

What we collect:

Name
Email address
Password (encrypted and securely stored)
Legal Basis: Contract Performance - This information is necessary to provide you with an account and deliver our services.

3.2 System-Generated Information

What we generate:

User role information (for access control and feature permissions)
Account creation timestamps
Chat tier assignments
Legal Basis: Legitimate Interest - We need this information to manage system access and provide appropriate service levels while protecting your interests.

3.3 Service Usage Data

What we collect:

AI Chat Messages: Your conversations with our AI chat system (securely encrypted - only you can access these)
Story Generation Requests: Prompts and generated stories
Usage Statistics: Basic usage counts for chat messages and sessions (for system management)
Legal Basis: Contract Performance - This data is necessary to provide the AI services you've requested and maintain system functionality.

3.4 Automatically Collected Information

What we collect:

Session cookies (essential for login functionality)
CSRF tokens (for security)
Instance preferences (for AI system administration)
Usage timestamps (for basic system management)
Legal Basis: Legitimate Interest - These are essential for website security, preventing fraud, and basic system operation.

4. How We Use Your Information

We use your information solely to:

Provide Services: Enable AI chat and story generation features
Maintain Security: Protect against unauthorized access and maintain system security
Improve Functionality: Monitor system performance and optimize AI responses
Account Management: Manage user accounts and access permissions
PDF Document Access: Provide secure viewing of admin-uploaded documents (no usage tracking)

We do NOT:

Sell your personal information to third parties
Use your data for advertising or marketing
Share your AI conversations or generated content with others
Track your browsing behaviour or website usage patterns
Track you across other websites

5. Data Sharing and Third-Party Disclosure

5.1 No Data Sales or Marketing Sharing

We do not sell, rent, or trade your personal information to any third parties for any reason.

5.2 Limited Sharing Circumstances

We only share personal data in these specific situations:

Legal Compliance: When required by law, court order, or regulatory authority
Security Protection: To protect our rights, property, or safety, or that of our users

5.3 AI Processing Disclosure

Local Processing Only: All AI conversations are processed using local AI models (Ollama) on our own servers
No External AI Providers: We do not send your data to OpenAI, Google, Anthropic, or any external AI companies
Complete Data Control: All AI processing occurs entirely within our controlled infrastructure

5.4 Hosting and Infrastructure
Self-Hosted Infrastructure: Our website and AI systems are hosted on privately owned, rack-mounted servers that we directly control. This means:

No third-party hosting providers have access to your data
Complete physical and digital control over all data storage
No external cloud services involved in data processing
All AI processing occurs on our own dedicated hardware using local Ollama systems

5.5 Our Privacy Commitment and Data Harvesting Stance

Complete Rejection of Data Harvesting: The Dotty Initiative maintains a strict policy of never working with data harvesting companies or services. This includes:

No Google Services: We completely refuse to integrate Google Analytics, Google Ads, Google Fonts (we use Bunny Fonts), or any other Google tracking services
No Social Media Tracking: We do not use Facebook Pixel, Twitter tracking, or similar social media analytics
No Advertising Networks: We will never integrate advertising platforms that collect user data
No Third-Party Analytics: We refuse all external analytics services that track user behaviour

Future Commitment: We pledge to maintain this stance permanently. We will never introduce data harvesting technologies, regardless of potential revenue or analytical benefits.

Why We Do This: We believe in your fundamental right to browse the internet without being tracked, profiled, or having your data sold to advertisers.

5.6 No Social Media Integration

Complete Social Media Absence: The Dotty Initiative maintains no presence on any social media platforms including Facebook, Twitter/X, Instagram, Snapchat, TikTok, LinkedIn, or any other social networks.

What This Means for Your Privacy:

No social media tracking pixels or widgets on our website
No data sharing with social media companies
No social login options that could leak your information
No cross-platform data correlation or profiling
Complete elimination of social media-related privacy risks
Our Position: We believe social media platforms fundamentally compromise user privacy through extensive data collection and behavioural tracking. By maintaining no social media presence, we eliminate these privacy risks entirely.

5.7 No Analytics or Tracking Services

As reinforced above, we explicitly do not use any external analytics or tracking services.

6. Data Storage and Security

6.1 Security Measures

All passwords are encrypted using industry-standard methods
AI conversations and generated content are encrypted in our database
Access to personal data is restricted to essential system functions only
Regular security updates and monitoring

6.2 Data Encryption and Protection

Automatic Encryption: All personal data you enter into our dashboard features is automatically encrypted using AES-256-CBC encryption before being stored in our database. This includes:

Scratch Pad Content: Your personal notes and ideas are encrypted at rest
Todo Items: Task titles and descriptions are encrypted for privacy
Saved Links: Link titles, URLs, and descriptions are encrypted before storage
Personal Dashboard Data: All user-generated content in dashboard features is protected

Encryption Technical Details:

Encryption Method: AES-256-CBC with HMAC-SHA256 authentication
Key Management: Encryption keys are stored separately from encrypted data using Laravel's secure key management
Data Protection: Even if someone gained unauthorized database access, your personal information would be unreadable without encryption keys
Transparent Operation: Encryption and decryption happen automatically - you don't need to do anything special

Your Responsibility for Sensitive Data: While we encrypt your data for protection, we strongly recommend you do not enter the following types of sensitive information anywhere on our platform:

Financial Information: Credit card numbers, bank account numbers, routing numbers
Government IDs: Social Security Numbers, passport numbers, driver's license numbers
Security Credentials: Passwords, PINs, security questions/answers, API keys
Medical Information: Health records, medical IDs, protected health information
Other Confidential Data: Any information that could be used for identity theft or unauthorized access

Automated Protection: Our system includes validation to detect and prevent entry of potentially sensitive information patterns (such as credit card numbers or Social Security Numbers). You will receive warnings if our system detects such patterns.

6.3 Data Retention

Account Data: Retained while your account is active
AI Conversations: Stored encrypted for service functionality (you can delete chat sessions)
Generated Stories: Stored temporarily unless saved by you
Logs: Technical logs retained for up to 90 days for security and performance monitoring

7. Your Rights Under UK GDPR

As a UK resident, you have the right to:

Access: Request a copy of your personal data
Rectification: Correct inaccurate personal data
Erasure: Request deletion of your personal data
Portability: Receive your data in a portable format
Restriction: Limit how we process your data
Object: Object to processing based on legitimate interests
Withdraw Consent: Where processing is based on consent
How to Exercise Your Rights:

Use the automated tools in your dashboard for data export/deletion
Contact our dedicated privacy inbox: privacy@dotty-initative.co.uk
Response Time: We respond to all privacy requests within 30 days

8. Lawful Basis for Processing

We process your personal data based on:

Contract Performance: To provide the services you've signed up for
Legitimate Interests: To maintain security and improve our services (where this doesn't override your rights)
Consent: Where explicitly given for optional features
Legal Obligation: To comply with legal requirements (e.g., data retention for security)

9. International Data Transfers

Self-Hosted UK Infrastructure: Your data is processed and stored on our privately owned servers located within the UK. We do not transfer personal data outside the UK/EU.

No Third-Party Hosting: Since we self-host our infrastructure, there are no external hosting providers involved in your data processing.

10. Automated Decision Making and Profiling

No Automated Decisions: We do not use automated decision-making or profiling that would significantly affect you.

AI Interactions: While our AI systems generate responses, these do not constitute automated decision-making under GDPR as they are interactive tools rather than systems that make decisions about you.

11. Cookies and Tracking

11.1 Essential Cookies Only

We only use cookies that are strictly necessary for our website to function:

Session Cookies: Keep you logged in
Security Cookies: Protect against cross-site request forgery
Preference Cookies: Remember your AI instance settings (admin users only)

11.2 No Third-Party Tracking

We do not use:

Google Analytics or similar tracking tools
Social media tracking pixels
Advertising cookies
Third-party analytics services

12. Data Sharing and Third-Party Disclosure

12.1 No Data Sales or Marketing Sharing

We do not sell, rent, or trade your personal information to any third parties for any reason.

12.2 Limited Sharing Circumstances

We only share personal data in these specific situations:

Legal Compliance: When required by law, court order, or regulatory authority
Security Protection: To protect our rights, property, or safety, or that of our users

12.3 AI Processing Disclosure

Local Processing Only: All AI conversations are processed using local AI models (Ollama) on our own servers
No External AI Providers: We do not send your data to OpenAI, Google, Anthropic, or any external AI companies
Complete Data Control: All AI processing occurs entirely within our controlled infrastructure

12.4 Hosting and Infrastructure

Self-Hosted Infrastructure: Our website and AI systems are hosted on privately owned, rack-mounted servers that we directly control. This means:

No third-party hosting providers have access to your data
Complete physical and digital control over all data storage
No external cloud services involved in data processing
All AI processing occurs on our own dedicated hardware using local Ollama systems

12.5 Our Privacy Commitment and Data Harvesting Stance

Complete Rejection of Data Harvesting: The Dotty Initiative maintains a strict policy of never working with data harvesting companies or services. This includes:

No Google Services: We completely refuse to integrate Google Analytics, Google Ads, Google Fonts (we use Bunny Fonts), or any other Google tracking services
No Social Media Tracking: We do not use Facebook Pixel, Twitter tracking, or similar social media analytics
No Advertising Networks: We will never integrate advertising platforms that collect user data
No Third-Party Analytics: We refuse all external analytics services that track user behaviour

Future Commitment: We pledge to maintain this stance permanently. We will never introduce data harvesting technologies, regardless of potential revenue or analytical benefits.

Why We Do This: We believe in your fundamental right to browse the internet without being tracked, profiled, or having your data sold to advertisers.

12.6 No Social Media Integration

Complete Social Media Absence: The Dotty Initiative maintains no presence on any social media platforms including Facebook, Twitter/X, Instagram, Snapchat, TikTok, LinkedIn, or any other social networks.

What This Means for Your Privacy:

No social media tracking pixels or widgets on our website
No data sharing with social media companies
No social login options that could leak your information
No cross-platform data correlation or profiling
Complete elimination of social media-related privacy risks
Our Position: We believe social media platforms fundamentally compromise user privacy through extensive data collection and behavioural tracking. By maintaining no social media presence, we eliminate these privacy risks entirely.

12.7 No Analytics or Tracking Services

As reinforced above, we explicitly do not use any external analytics or tracking services.

13. Children's Privacy

Age Restriction: Our services are not intended for children under 13. We do not knowingly collect personal information from children under 13.

Account Termination: Any accounts found to be used or created by any person or persons under the age of 13 will be immediately terminated and deleted without possibility of recovery.

14. Data Breach Procedures

In the event of a data breach:

We will notify the ICO within 72 hours if required by law
Affected users will be notified within 72 hours if the breach poses a high risk
We maintain incident response procedures to minimize impact

15. Contact Information and Privacy Inquiries

Primary Privacy Contact: Click to show email

General Support: Click to show email

Website: www.dotty-initiative.co.uk

Dedicated Privacy Mailbox: For GDPR compliance verification - privacy (at) dotty-initiative (dot) co (dot) uk

Response Times:

Privacy requests: Within 30 days
General inquiries: Within 5 business days

16. Complaints and Regulatory Authority

If you believe we have not handled your personal data in accordance with this policy, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

ICO Contact:

Website: ico.org.uk
Phone: 0303 123 1113
Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

17. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify users of significant changes by:

Posting the updated policy on our website
Updating the "Last Updated" date
For material changes, providing direct notice to registered users

18. Acknowledgment and Consent

By using The Dotty Initiative Website and Services, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your personal information as described in this Privacy Policy.

About The Dotty Initiative: The Dotty Initiative is the online presence for Void Smasher's creations, including game modifications and AI-powered tools. We strive to provide useful and engaging digital experiences while maintaining user privacy and security.

Last Updated: 31/08/2025