Last updated: 16 September 2026
This Privacy Policy explains how Duda, Inc. and its relevant affiliates (collectively, “Duda,” “we,” “us,” or “our”) collect, use, disclose, and otherwise process personal information in connection with our websites, business relationships, and services. It also explains the choices and rights that may be available to you.
This Policy applies when you visit www.duda.co or another website operated by Duda, create or administer a Duda account, communicate with us, attend an event or webinar, use our platform or related services in an authorized business capacity, or otherwise interact directly with Duda. It does not replace the privacy notice of a Duda customer or site owner for information collected through a website, application, form, chatbot, campaign, or other digital property created, hosted, or enabled through Duda’s services.
This Policy does not apply to Duda personnel, who may be subject to a separate workforce privacy notice. Job applicants are covered by this Policy unless Duda provides a separate applicant privacy notice that applies to them.
Duda provides website building, hosting and management, ecommerce, forms and communications, marketing automation, AI-enabled tools, applications and integrations, support, and related services to businesses, agencies, software and SaaS providers, resellers, and other professional customers (the “Services”). Customers may provide access to the Services to their own clients or users, including through white-label environments.
The Duda entity responsible for personal information covered by this Policy is generally Duda, Inc., unless the applicable contract, collection notice, or local law identifies another Duda affiliate as responsible. Duda, Inc. is located at 577 College Avenue, Palo Alto, California 94306, United States.
Duda processes personal information in different roles depending on the context:
Duda may provide customers with tools or integrations that support privacy compliance, such as configurable notices, consent options, preference-management features, and deletion functionality. Customers are responsible for selecting, configuring, and maintaining these tools and for determining whether their use satisfies applicable legal requirements.
If you have a question or wish to exercise rights regarding information processed by Duda as a processor on behalf of its customers, such as collected through a customer website or customer-configured feature, please contact the relevant site owner or organization first.
The personal information Duda collects and processes depends on how you interact with us, the Services you use, and the features configured by you or by a Duda customer.
Unless otherwise indicated, you are not legally required to provide personal information to Duda. However, certain information may be necessary for us to enter into or perform a contract, provide or administer the Services, process a transaction, comply with applicable legal requirements, evaluate a job application, or respond to a request. If you do not provide information that is necessary for the relevant purpose, we may be unable to provide the applicable Service or feature, complete the transaction, progress your application, or otherwise fulfill your request. Where Duda processes personal information on behalf of a customer, the relevant customer determines whether providing that information is required and the consequences of not providing it.
We may collect the following categories of personal information:
When you create or administer an account, purchase or use the Services, or interact with Duda in a business capacity, we may collect information such as your name, business email address, telephone number, company, job title, account and user identifiers, login credentials, account permissions, subscription and billing information, transaction records, and information relating to our commercial relationship with you or your organization.
We may receive this information directly from you, from another administrator of your organization’s account, from a reseller or business partner, or from systems used to administer our relationship with you.
When you visit a Duda-operated website or use the Services, we may automatically collect information about your device and your interaction with our websites and Services. This may include your IP address, browser and device type, operating system, device identifiers, approximate location derived from your IP address, referring and exit pages, URLs, pages and features viewed or used, searches, clicks and other interactions, dates and times of access, session information, and similar usage information.
We may also collect diagnostic, performance, security and technical information, such as application and access logs, error reports, system events, fraud or abuse signals, and information used to troubleshoot, secure, maintain and improve our websites and Services.
Some of this information is collected through cookies, pixels, local storage and similar technologies. For more information, including how to manage your choices, see the section on Cookies and Similar Technologies below.
If you contact Duda, request support, participate in a survey or event, communicate with our sales or customer-success teams, or otherwise interact with us, we may process the information contained in those communications.
This may include emails, support tickets, chat messages, inquiries, survey responses, feedback, files, screenshots and other materials you provide, as well as call or meeting content or recordings where applicable and permitted by law.
Customers may use the Services to collect, host, store, transmit or otherwise process personal information relating to their own users, clients, website visitors and other individuals. In these circumstances, Duda generally processes the information on behalf of the relevant customer as a processor, service provider or subprocessor, as described in Section 2.
Depending on the Services selected and how they are configured, this information may include:
Customers determine what information they collect through their websites and customer-configured functionality and the purposes for which it is used. Where Duda processes this information on their behalf, the customer’s privacy notice and Duda’s agreement with that customer, including any applicable data processing agreement, govern that processing.
When AI-enabled features are used, the information processed may include prompts and instructions, uploaded files or images, website and business content, relevant website context, site configuration and analytics, usage information, and generated code, content, images, recommendations, responses or other outputs.
The particular information processed depends on the AI feature and how it is configured. Where an AI feature is used by a Duda customer to process information on its behalf, Duda generally acts as a processor or subprocessor. Where Duda uses AI in connection with its own websites or business activities, Duda may act as a controller. More information about these uses is provided in the Artificial Intelligence section below.
We may receive personal information from other sources, including:
We may combine information received from these sources with other information we hold where permitted by applicable law.
If you apply for a position with Duda or otherwise participate in our recruitment process, we may collect information such as your name and contact details, resume or CV, employment and education history, professional qualifications, references, interview notes, application status, information you provide during the recruitment process, and other information relevant to evaluating your candidacy.
We may receive this information directly from you, from recruitment agencies or platforms, from references, or from publicly available professional sources. We use it to manage recruitment, assess candidates, communicate with applicants, maintain recruitment records, and comply with legal obligations.
Duda does not generally require you to provide sensitive personal information in order to use its websites or Services. Please do not provide sensitive information, such as government identification numbers, health information, full payment-card information, passwords or authentication secrets, or other highly sensitive information unless a particular feature expressly requires and is designed to process that information.
Where customers use the Services to process personal information on their own behalf, they are responsible for determining whether their use involves sensitive or special-category information and for ensuring that appropriate legal bases, notices, safeguards and configurations are in place.
For payment transactions, full payment-card information is generally handled by the applicable payment provider rather than stored by Duda, except to the extent expressly supported by a particular Service.
We use personal information for the following purposes, as applicable:
Where Duda processes personal information solely on behalf of a customer, the customer determines the relevant purposes of processing and Duda processes the information in accordance with the customer’s instructions and the applicable agreement.
Where the EU GDPR, UK GDPR, or Swiss data protection law applies, we rely on one or more of the following legal bases:
Where Duda processes personal information as a processor or service provider on behalf of a customer, Duda does not determine the customer’s legal basis for that processing. The relevant customer is responsible for identifying and documenting the appropriate legal basis for its processing.
Duda offers or may offer AI-enabled features in different contexts:
Duda does not use personal information submitted to or generated through AI features to train general-purpose or cross-customer AI models and requires relevant model providers acting on Duda’s behalf not to do so, unless the customer expressly authorizes such use. Duda may process relevant information for inference, retrieval, generation, security, abuse prevention, troubleshooting, analytics, and customer-specific configuration or improvement.
Where you connect an external AI service or enable an MCP or similar connector, information may be exchanged with that provider at your direction. The provider’s own terms and privacy practices apply to its independent processing.
Please avoid including personal information in AI prompts or chatbot conversations where it is not necessary for your request.
We may send you service-related communications, such as security, account, billing, support, and legal or service update notices. These communications are part of administering the Services and may not include an unsubscribe option.
Subject to applicable law, we may also send promotional communications about Duda products, services, events, and content. You can unsubscribe from promotional emails using the link in the message or by contacting us. We may retain limited suppression information to honor your preferences.
We may also use cookies and similar technologies for analytics, campaign measurement, and advertising, subject to applicable law and your choices. For more information and to manage your preferences, see Section 8.
Duda does not use personal information that it processes on behalf of customers through customer marketing automation campaigns for Duda’s own marketing, cross-customer profiling, or targeted advertising.
Duda and third parties acting on our behalf use cookies, pixels, local storage, software development kits, and similar technologies on Duda-operated websites and Services. These technologies may be used to:
For current information about the specific cookies and similar technologies we use, including their providers, purposes, categories, and retention periods, please see our Cookie Settings / Your Privacy Choices tool or click “Customize” on the cookie banner.
Some technologies are strictly necessary for the operation, security, or functionality of our websites and Services and may be used without consent where permitted by law. Depending on your jurisdiction, other technologies, such as analytics, advertising, or similar non-essential technologies, may be used only with your consent or may be subject to an opt-out right.
Where consent is required, you can provide, refuse, or withdraw your consent at any time through our cookie management tool. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
You can manage cookies and similar technologies on Duda-operated websites through the cookie banner or preference center made available on the relevant site. Where applicable, you may also use the “Your Privacy Choices” or “Do Not Sell or Share My Personal Information” link to opt out of sale, sharing, or targeted advertising.
Duda may work with advertising and analytics partners to help promote Duda and measure the effectiveness of our campaigns, including by displaying advertising on third-party websites or services. Depending on applicable law, these activities may involve the use of cookies or similar technologies and may constitute targeted advertising or the “sale” or “sharing” of personal information.
Browser and device settings may provide additional controls over cookies and similar technologies. Disabling certain technologies may affect the availability or functionality of parts of our websites or Services.
Where required by applicable U.S. law, Duda processes qualifying opt-out preference signals, including Global Privacy Control, as a request to opt out of sale or sharing for the browser or device through which the signal is received, to the extent technically applicable.
Because there is no uniform industry standard for Do Not Track signals, we do not generally respond to DNT signals.
Duda can control cookies and similar technologies on Duda-operated websites, but not those placed on customer websites by customers or customer-selected third parties. Duda’s cookie preferences do not apply to customer websites, and the relevant site owner’s privacy and cookie notices govern those technologies.
We may disclose personal information to the following categories of recipients:
If you choose to make information publicly available through a website, profile, comment, community, or other public-facing feature, that information may be accessible to anyone who can view the relevant content.
We may disclose aggregated or irreversibly anonymized information that does not identify individuals.
The Services may allow customers or users to install, connect, or use third-party applications, widgets, scripts, marketplaces, integrations, or external AI tools. When you choose a third-party service, information may be disclosed directly to that third party or collected by it. The third party’s own terms and privacy policy apply, and Duda is not responsible for the third party’s independent processing. Review the relevant terms and settings before enabling a third-party service.
Custom widgets, code, scripts, and integrations created or deployed by customers may collect information from site visitors or transmit information to third parties selected by the customer. Duda does not determine the purposes of that customer-controlled processing. The customer or site owner is responsible for reviewing generated or custom code, identifying relevant recipients, providing required notices and choices, and ensuring that the functionality complies with applicable law.
Duda operates internationally, and personal information may be processed in the United States, Israel, the European Economic Area, the United Kingdom, Canada, and other countries where Duda, its affiliates, or service providers operate. These countries may have data protection laws that differ from those in your jurisdiction.
Where required, we use recognized safeguards for international transfers, such as adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, contractual and technical supplementary measures, or the Data Privacy Framework described in Section 17. Distributed cloud, content-delivery, edge, support, and communications infrastructure may route or cache data globally according to user location and technical requirements.
We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining the business relationship, complying with legal obligations, resolving disputes, enforcing agreements, and protecting security and legal rights.
Retention periods depend on the type of information, the relevant purpose, account status, legal and contractual requirements, technical constraints, and applicable limitation periods. Examples include:
When information is no longer required, we delete it, render it inaccessible, or irreversibly anonymize it in accordance with our procedures and applicable law.
We use administrative, technical, and organizational safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures may include access controls, encryption, network and cloud security, monitoring, vulnerability management, personnel confidentiality, incident response, vendor management, and business continuity measures.
No method of transmission or storage is completely secure. You are responsible for protecting your credentials, using available security settings, and promptly notifying us of suspected unauthorized account access.
Depending on where you live and subject to applicable law, you may have rights in relation to your personal information, including the rights to:
If you are in the EEA, UK or Switzerland, you may also lodge a complaint with the data protection authority in your country or region. We encourage you to contact us first so that we can try to address your concern.
To submit a request concerning information for which Duda is controller, contact privacy@duda.co. Please describe your request and the context in which you interacted with Duda. We may need to verify your identity and authority before acting. Authorized agents may submit requests where permitted by law, subject to verification requirements.
If your request concerns information processed through a customer website or customer-configured feature, contact the relevant site owner or organization. We may redirect the request to the appropriate customer.
You will not be discriminated against for exercising applicable privacy rights. Where an appeal right applies, you may appeal by replying to our decision or contacting privacy@duda.co and stating that you wish to appeal.
Duda’s websites and direct business Services are not directed to children, and Duda does not knowingly collect personal information directly from children in circumstances where parental consent is required. Customers may create websites or services intended for children, in which case the customer or site owner is responsible for applicable notices, consents, age-assurance measures, and other legal requirements. If you believe a child has provided personal information directly to Duda inappropriately, contact privacy@duda.co.
This section provides additional information for residents of U.S. states with comprehensive privacy laws, including California. The disclosures below describe Duda’s practices during the preceding 12 months. Terms such as “sell,” “share,” “targeted advertising,” and “sensitive personal information” have the meanings given to them under applicable law.
For the categories of personal information described below, Duda collects information from the sources described in Section 3 and uses it for the business and commercial purposes described in Section 4. We may disclose these categories to the recipients described in Section 9 for business purposes, including service delivery, security, analytics, customer support, payment processing, communications, legal compliance, and business operations.
| Category | Examples | Sources | Purposes | Categories disclosed to | Sold/shared? |
|---|---|---|---|---|---|
| Identifiers and customer records | Name, business email, phone number, postal or billing address, account identifiers, IP address and device identifiers | You; your organization/account administrator; customers, resellers and partners; automatically from devices and services | Account administration; service delivery; authentication; support; security; marketing; legal and business operations | Affiliates; cloud, security, support, CRM, communications and marketing providers; customers/account administrators where relevant | May be shared where advertising or analytics technologies constitute “sharing” or “sale” under applicable law |
| Commercial information | Subscriptions, products or features purchased, transaction and billing information, invoices and payment status | You; your organization; payment and commerce providers | Provide Services; billing; accounting; customer relationship management; analytics; legal compliance | Payment providers; finance/accounting providers; affiliates; customer-management providers | No, except where linked identifiers or activity are disclosed in a manner that constitutes sale/sharing |
| Internet or network activity | Browsing activity, pages viewed, clicks, feature usage, interactions, logs, referring URLs and cookie or similar-technology data | Automatically from websites, devices, applications and Services; analytics and advertising partners | Operate and secure Services; analytics; improve user experience; measure campaigns; advertising where permitted | Cloud, analytics, security, marketing and advertising providers | May be shared for cross-context behavioral advertising or similar activities, where applicable |
| Geolocation information | Approximate location derived from IP address | Automatically from device/network information | Security; localization; analytics; service operation; marketing where permitted | Cloud, security, analytics and marketing providers | May be shared where associated with advertising or analytics technologies, where applicable |
| Audio, electronic, visual and communications information | Support calls or meetings, chatbot conversations, emails, messages, screenshots, files and feedback | You; Duda communications and support systems | Support; quality; sales routing; personnel training; security; legal and business operations | Communications, support, CRM, AI/model and professional-service providers | Generally no, except where related identifiers/activity are disclosed in a manner that constitutes sale/sharing |
| Professional or employment-related information | Company, role, job title, business contact details and professional interests | You; your organization; public sources; business partners and professional networks | Sales; account management; events; business-to-business marketing; relationship management; recruitment | CRM, marketing, events and business service providers; affiliates | May be shared where used with advertising or analytics technologies, where applicable |
| Inferences | Likely business interests, product interests, account-risk or usage trends derived from other information | Derived from information described above | Personalization; sales and marketing; analytics; security; product improvement | CRM, analytics, marketing, security and business service providers | May be shared for advertising or marketing measurement, where applicable |
| Sensitive personal information | Account credentials and other information treated as sensitive under applicable law, to the extent collected | You; your organization; automatically through account/security systems | Authentication; security; fraud prevention; service delivery; legal compliance | Cloud, identity, security and service providers | Duda does not use or disclose sensitive personal information for purposes that require a right to limit under California law, except as permitted by law |
Duda does not sell personal information for money. Certain disclosures through advertising, analytics, cookies, pixels, or similar technologies may be considered a “sale,” “sharing,” or targeted advertising under applicable U.S. state privacy laws. Where applicable, you may opt out by using the “Your Privacy Choices” or “Do Not Sell or Share My Personal Information” link on Duda-operated websites. We also process qualifying opt-out preference signals, including Global Privacy Control, where required by applicable law.
Duda does not knowingly sell or share the personal information of individuals under 16. Duda does not use or disclose sensitive personal information for purposes other than those permitted without a right to limit under the CCPA.
Subject to applicable exceptions, residents of certain U.S. states may have the right to request access to or confirmation of personal information, correction, deletion, portability, and information about the categories of personal information collected, the sources from which it was collected, Duda’s business or commercial purposes, the categories of third parties to whom it was disclosed, the categories sold or shared, and the specific pieces of personal information Duda maintains about them. You may also have rights to opt out of sale, sharing, targeted advertising, or certain profiling; limit certain uses of sensitive personal information; and appeal a decision concerning a privacy request.
To exercise applicable rights, contact privacy@duda.co or use any privacy request form or other request method identified on Duda’s website. We may verify a request by matching information you provide against our records and may request additional information where reasonably necessary. You are not required to create an account solely to submit a privacy request. Authorized agents may submit requests where permitted by law; we may request proof of authorization and, where permitted, separately verify the consumer’s identity.
You will not receive discriminatory treatment for exercising applicable privacy rights. Where an appeal right applies, you may appeal by replying to our decision or contacting privacy@duda.co and stating that you wish to appeal.
Duda does not currently offer financial incentives or price or service differences in exchange for the collection, sale, sharing, or retention of personal information.
Duda does not currently use automated decisionmaking technology in its controller-side activities to make decisions about individuals that produce legal or similarly significant effects.
Duda does not disclose personal information to third parties for their own direct marketing purposes as contemplated by California’s “Shine the Light” law.
Duda complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF), as set forth by the U.S. Department of Commerce. This section applies to personal data received by Duda in the United States in reliance on the applicable Data Privacy Framework and within the scope of Duda’s certification.
Duda has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Duda has also certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF.
If there is any conflict between the terms of this Privacy Policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the applicable Principles will govern. To learn more about the Data Privacy Framework program and to view Duda’s certification, please visit https://www.dataprivacyframework.gov/.
With respect to personal data received or transferred pursuant to the Data Privacy Frameworks, Duda is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission.
Pursuant to the Data Privacy Frameworks, EU, UK, and Swiss individuals have the right to obtain confirmation of whether Duda maintains personal data relating to them in the United States. Upon request, Duda will provide access to personal data that it holds about you. You may also request correction, amendment, or deletion of personal data that Duda holds about you.
If you seek access to, or correction, amendment, or deletion of, personal data transferred to the United States under the Data Privacy Frameworks, please contact privacy@duda.co. If you request deletion of data, Duda will respond within a reasonable timeframe.
Duda will provide individuals with an opportunity to opt out, or to opt in where required for sensitive data, before Duda discloses personal data to third parties other than its agents or uses it for a purpose materially different from the purpose for which it was originally collected or subsequently authorized. To request to limit the use or disclosure of your personal data in these circumstances, please contact privacy@duda.co.
Duda remains liable under the DPF Principles for onward transfers to third parties acting as agents where such third parties process personal data in a manner inconsistent with the DPF Principles, unless Duda can demonstrate that it is not responsible for the event giving rise to the damage.
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Duda commits to refer unresolved complaints concerning its handling of personal data received in reliance on the applicable Data Privacy Framework to BBB National Programs, an alternative dispute resolution provider based in the United States.
If you do not receive timely acknowledgment of your DPF Principles-related complaint from Duda, or if Duda has not addressed your complaint to your satisfaction, please visit https://bbbprograms.org/programs/all-programs/dpf-consumers for more information or to file a complaint. The services of BBB National Programs are provided at no cost to you.
If your DPF complaint cannot be resolved through the channels described above, under certain conditions you may invoke binding arbitration for certain residual claims not resolved by other redress mechanisms. For more information, see https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction.
We may update this Policy from time to time to reflect changes in law, technology, our Services, or our practices. We will post the updated Policy with a revised “Last updated” date and provide additional notice where required by law. Material changes will apply prospectively unless otherwise permitted or required.
Questions, concerns, and privacy requests may be submitted to: