Who we are
We are Daniwoo SAS, doing business as Daniwoo, a company registered in France at 60 rue François 1er, 75008 Paris. Our VAT number is FR12893712604. We build a learning platform that runs natively inside Salesforce.
This policy explains what happens to personal data when you visit daniwoo.io, ask for a demo, download a document, subscribe to our newsletter or start a chat with us. It is written to be read, not to be survived: if anything below is unclear, write to legal@daniwoo.io and we will explain it in plain words.
1What this policy covers
This policy covers our website and our commercial relationship with you: the forms you fill in, the documents you download, the emails you ask to receive, and the technical data your browser sends while you read our pages.
It does not cover the learner data processed inside the Daniwoo LMS when your organization is a customer of ours. That is a different relationship, described in section 4.
2Information we collect
We do not buy contact lists, and we do not ask for more than we need. Everything we hold about you comes from one of the following.
Demo requests
When you submit the form on our contact page, we collect your first name, last name, work email, company, and the answers you choose: who you plan to train, how many learners, whether you already use Salesforce, and anything you write in the free-text field. This is sent directly into our own Salesforce org, where it becomes a lead record.
Gated documents
To download the LMS RFP kit we ask for your email, your company and your evaluation stage. To download the KPMG case study we ask for your email. In both cases the address is recorded in our Salesforce org together with the document requested, so that we know what to send you and what to follow up on.
Newsletter
When you subscribe, we record your email address, the page you subscribed from, your IP address, the date and time, and the exact wording displayed next to the field at that moment. We keep that wording because it is the evidence of what you agreed to. Your subscription itself is managed by WordPress.com, which sends the emails and handles unsubscribing; a copy of the sign-up is also recorded in our Salesforce org.
Live chat
Our website embeds a chat widget provided by Tidio. If you open it and write to us, Tidio processes the content of your messages along with technical data about your session, so that we can answer you.
Technical and audience data
Like any website, ours records technical data: IP address, browser and device type, pages viewed, and the page that referred you. This comes from our host's server logs, from our security tooling, and from the audience-measurement tools described in section 8.
Anti-spam
Form submissions are screened by Akismet, an anti-spam service operated by Automattic. To decide whether a submission is spam, Akismet processes the content of the form, your IP address and your browser's user agent.
3Why we use it, and on what legal basis
Under the GDPR we must tell you not only what we do, but why we are allowed to do it.
| What we do | Why | Legal basis |
|---|---|---|
| Answer a demo request | To reply, prepare the demo and discuss your project | Steps taken at your request before entering a contract |
| Send a requested document | To deliver the RFP kit or case study you asked for | Steps taken at your request; our legitimate interest in following up with professionals who showed interest |
| Send the newsletter | To send new articles and occasional updates | Your consent, which you can withdraw at any time |
| Answer you in chat | To respond to questions asked through the widget | Our legitimate interest in answering visitors |
| Measure our audience | To understand which pages are useful | Your consent for non-essential cookies and trackers |
| Keep the site safe | To block spam, abuse and attacks, and to keep logs | Our legitimate interest in securing our own site |
| Meet our obligations | Accounting, tax and responding to legal requests | Compliance with a legal obligation |
Where we rely on legitimate interest, we have weighed it against your rights. We only contact professionals, about a professional subject, and every email we send carries a way to stop receiving them.
4Learner data inside the Daniwoo LMS
The Daniwoo LMS is installed as a managed package inside our customer's own Salesforce org. Course records, enrolments, completions and quiz results stay in that org, under that organization's own security model.
For this data, the customer is the controller and Daniwoo acts as a processor, only on the customer's documented instructions, under the agreement and data-processing terms signed with them. If you are a learner and want to exercise your rights over your training records, contact the organization that enrolled you — they decide what happens to that data, and we will support them in answering you.
5Who we share information with
We do not sell personal data, and we do not share it for anyone else's advertising. We do rely on a small number of service providers, each acting for a defined purpose.
| Provider | What it does for us |
|---|---|
| Salesforce | Our CRM: leads, demo requests, document downloads and newsletter sign-ups are recorded there |
| Automattic / WordPress.com | Hosting of this website, image delivery, audience statistics, newsletter delivery and Akismet anti-spam |
| Web fonts served on our pages | |
| Tidio | The live chat widget |
| AddToAny | The social sharing buttons on our articles |
| Sucuri | Security monitoring of the website |
| Amazon Web Services | Storage and delivery of training media for the product |
We may also share data with our professional advisers, or with public authorities where the law requires it.
6International transfers
Several of the providers above are established in the United States or process data there. When personal data leaves the European Economic Area, that transfer is covered by the safeguards the GDPR allows — in practice the European Commission's standard contractual clauses, and, where the provider is certified, the EU-US Data Privacy Framework.
You can ask us for details of the safeguards applying to a specific provider by writing to legal@daniwoo.io.
7How long we keep it
- Prospects and demo requests — up to three years from our last contact with you, which is the retention period the French data protection authority recommends for business prospection.
- Newsletter subscribers — until you unsubscribe, plus a short period to honour your withdrawal.
- Customers — for the duration of the contract, then for as long as accounting and tax rules require.
- Chat conversations — for as long as needed to handle your question and for a reasonable period afterwards for support history.
- Technical logs and security data — a limited period, typically no more than twelve months.
8Cookies and similar technologies
Some cookies are strictly necessary: they keep the site working, remember your cookie choices and protect our forms. Those are set without asking, because the site cannot function without them.
Everything else — audience measurement, the chat widget, sharing buttons — is non-essential, and we ask for your consent through the banner shown on your first visit. You can change your mind at any time using the Cookie settings link in the banner, or by clearing the cookies stored by your browser.
Our audience measurement uses a single tool: WordPress.com statistics, which counts page views for the site. We do not run Google Analytics, and we do not use advertising or profiling trackers. Our pages do load Google Fonts directly from Google's servers, which means your IP address is transmitted to Google when a page is displayed.
9Your rights
If you are in the European Economic Area, you have the right to access your data, to have it corrected or erased, to restrict or object to its use, to receive it in a portable format, and to withdraw your consent at any time where we relied on it. You can also give us instructions about what happens to your data after your death.
To exercise any of these, write to legal@daniwoo.io. We answer within one month. We may ask you to confirm your identity if the request is not obviously coming from you.
To stop receiving our newsletter, use the unsubscribe link at the bottom of any issue — it works immediately and you do not need to ask us.
If you believe we have not handled your data properly, you can lodge a complaint with the French data protection authority, the CNIL (3 place de Fontenoy, 75007 Paris, cnil.fr), or with the supervisory authority of the country where you live.
10Security
Access to our CRM is restricted and authenticated. The website is served over HTTPS, kept up to date, and monitored for intrusion. Our product-side infrastructure is described in our security documentation, which we share with customers and prospects on request.
No system is perfect. If you find a vulnerability on our site, please tell us at legal@daniwoo.io before disclosing it publicly, and we will work with you.
11Children
This website is aimed at professionals. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, write to us and we will delete it.
12Changes to this policy
When we change how we handle personal data, we update this page and change the date shown at the top. If the change is significant and affects you directly, we will tell you — by email if you are a subscriber or a customer.
13Contact us
For any question about this policy, or to exercise your rights:



