The short version
Where your data lives
Everything Dory keeps for you is stored on servers in Frankfurt. Where those servers are is a fixed part of how Dory is set up, not something picked request by request. Traffic to and from Dory runs over TLS.
What the model providers see
When you send a message, your request and the content needed to answer it go to the model you picked. You pick that model per message, and you can see which one you are on before you send.
Your stored data does not move for this. What travels is the request and the context for that one answer. Storing and processing are two different things, and we keep them apart: what Dory stores for you is in Frankfurt, while a request goes to whoever serves the model you picked.
How integrations connect
Most integrations connect through OAuth. You authorise Dory in the tool itself, the way you would authorise any app, and you can withdraw that authorisation there at any time. Which integrations are available at all is your admins' decision.
Not every tool offers OAuth. For those, an API key or a service account is entered once and we store it encrypted. For the integrations in our catalogue that is an admin's decision, not something Dory asks a team member for.
You stay in control
Before Dory writes to one of your tools, sends something out or deletes something, it shows you what will happen and waits. This is a mechanism in the product, not a promise in a document. Reading does not ask, apart from the first time Dory uses an integration you have just connected.
You decide how long a yes lasts: for this chat, for a set time, or for a month. You can take any of them back. Deleting a Document, a contact or an appointment is the exception: it asks every time and cannot be granted in advance.
The same openness applies to what Dory remembers. Memory is visible in the app, deletable entry by entry or all at once, and you can switch it off. Switching it off stops new entries, deleting removes the old ones, and the two are separate on purpose.
The paperwork
Your company stays the controller of its content. We process it on your instruction only, under Art. 28 GDPR. Every subprocessor we use is named in the data processing agreement (AVV), which is an annex inside the terms rather than a form you have to request. Where a subprocessor is outside the EU, transfers run under EU standard contractual clauses (Art. 46 GDPR).
What we do not claim yet
Three things a security review will ask about are on our roadmap and not in the product. We would rather tell you here than have you find out.
Still have a question? Ask the people who built it.
No trust portal, no questionnaire form. Write to support@dory-ai.com and a person who works on the system answers. Your data protection officer is welcome to write directly.