Privacy Policy

Last updated: March 28, 2026

1. Data Controller

KozaWings Inc., located at 1-7-8 Chuo, Okinawa City, Okinawa, Japan, is the data controller responsible for your personal data. Contact: dunn@getdunnai.com

2. What Data We Collect

a) Data you provide directly:

  • Your email address (for account access and service notifications)
  • Business name and sender preferences

b) Data from your connected Stripe account (restricted access):

  • Failed payment events and decline codes
  • Subscription status and amounts
  • Your customers' email addresses (for recovery emails only)

c) Data we never access:

  • Full card numbers or bank account details
  • The ability to move, transfer, or initiate charges
  • Any Stripe data beyond what is required for payment recovery

3. Legal Basis for Processing (GDPR)

We process your data on the following legal bases:

  • Contract performance: to deliver the Service you have signed up for
  • Legitimate interests: to improve the Service and prevent fraud
  • Legal obligation: to comply with applicable laws

4. How We Use Your Data

  • To detect failed payments and schedule smart retries
  • To send recovery emails to your customers on your behalf
  • To display analytics and recovery history in your dashboard
  • To operate our billing system via Stripe

5. Data Storage and Security

  • All data is stored in Supabase (hosted on AWS, US region)
  • Your Stripe API key is encrypted with AES-256 at rest and never logged in plain text
  • Data is encrypted in transit via TLS
  • We do not sell or share your data with third parties for marketing purposes

6. Sub-processors

We use the following third-party services to operate DunnAI:

ServicePurposeLocation
SupabaseDatabase and authenticationUS (AWS)
StripeBilling and payment processingUS
ResendTransactional email deliveryUS
VercelHosting and infrastructureUS

Each sub-processor is bound by data processing agreements consistent with GDPR requirements.

7. Data Retention

  • Active accounts: data retained for the duration of your subscription
  • Cancelled accounts: data deleted within 30 days of cancellation
  • Upon request: all data deleted within 48 hours

8. Your Rights (GDPR and applicable law)

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing
  • Request a portable copy of your data

To exercise any of these rights, contact dunn@getdunnai.com. We will respond within 30 days.

9. Cookies

DunnAI uses only essential cookies required for authentication and session management. We also use Google Analytics to understand how users interact with the Service. Google Analytics collects usage data such as pages visited and session duration. You may opt out by installing the Google Analytics Opt-out Browser Add-on.

10. International Data Transfers

Your data may be processed in the United States by our sub-processors. These transfers are subject to appropriate safeguards including Standard Contractual Clauses where required.

11. Children's Privacy

DunnAI is intended for use by businesses and is not directed at individuals under the age of 18.

12. Changes to This Policy

We will notify you of material changes via email before they take effect. The “Last updated” date at the top of this page reflects the most recent revision.

13. Contact and Complaints

For privacy-related inquiries: dunn@getdunnai.com

If you are located in the EU/EEA and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection authority.

KozaWings Inc.
1-7-8 Chuo, Okinawa City, Okinawa, Japan