Last modified on April 28, 2025
a. Personal Information
- Email address: Collected when you sign up for DFend.
- Phone number: Collected during sign-up or for verification purposes, managed through secure authentication mechanisms to ensure safe account access.
- Authentication info: Managed through secure authentication mechanisms, such as two-factor authentication (2FA), to ensure safe account login.
b. Automatically Collected Information
- App usage data: Information about how you interact with the app (e.g., screens visited, actions performed).
- Device information: Details such as device type, operating system, and device identifiers.
- Crash logs and diagnostics: Collected to improve app performance and reliability.
We use your information for the following purposes:
- To provide and maintain the DFend service.
- To secure user data in your encrypted vault and ensure safety.
- To personalize and enhance your experience.
- For analytics and performance monitoring (with user consent).
- To comply with regional legal requirements (e.g., GDPR, CCPA, LGPD).
We do not sell or rent your personal data. We share your data only in the following cases:
- Service Providers: We may share your data with trusted third-party service providers who assist us in delivering the Services.
- Legal authorities: If required by law, we may share data with legal authorities in accordance with applicable regulations.
Depending on your region and applicable laws, you may have the following rights regarding your data:
- Access: Request to access the personal information we hold about you.
- Update: Request to update your personal information.
- Deletion: Request to delete your personal information from our systems.
- Rectification: Request changes to your personal information.
- Export: Request to download your data in a machine-readable format.
- Opt-out: Opt-out of analytics and data collection processes.
You can manage your privacy preferences at any time within the app, including consent for tracking and personalization.
We use strong encryption methods and secure protocols to protect your personal information. However, no method of transmission over the internet can guarantee 100% security. You are responsible for keeping your password and account information confidential.
We retain your data as long as your account is active. If you wish to delete your account and associated data, you can do so at any time through the App. Data will be deleted in accordance with our retention policy and applicable laws.
DFend is not intended for children under 13 years old. We do not knowingly collect personal information from children under 13. During onboarding, you will be asked to confirm whether you are 13 or older. If you are under 13, account creation will be blocked, and the request will be logged for compliance.
In compliance with the relevant laws in your region, DFend implements the following:
- GDPR (EU): Explicit opt-in for tracking and processing, with the ability to access, delete, or rectify your data.
- CCPA/CPRA (California): Right to opt-out of the sale or sharing of personal data and access/delete rights.
- LGPD (Brazil): Opt-in required for sensitive data processing.
- COPPA (US): Age verification is required to prevent underage users from accessing the platform.
Region-specific data handling ensures we meet legal obligations across different jurisdictions (e.g., Europe, US, and other regions).
We collect consent for data usage in a region-specific manner:
- EU/EEA: Explicit opt-in for tracking (GDPR).
- California: Default opt-in with the right to opt-out ("Do Not Sell" – CCPA).
- Brazil (LGPD): Opt-in required for sensitive data.
- ROW: Default opt-in, with an optional opt-out.
Your consent preferences are stored securely and can be updated at any time in the app settings.
We use your information based on the following lawful bases:
- Consent: For tracking and personalization.
- Contractual necessity: To provide our services.
- Legal obligation: Compliance with data protection laws.
User profiles will include flags for region and consent preferences to determine the processing and regional behavior.
All actions, such as consent updates, data subject access requests (DSAR), and region assignments, are logged for transparency and legal compliance.
We respect your consent preferences and will not collect analytics data unless explicitly permitted. Analytics and other third-party services are only activated once consent is obtained.
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or service updates. The latest version will always be available in-app and on our website. We encourage you to review this policy periodically.
If you have any questions or concerns about this Privacy Policy, please contact us at: hello@dfend.app