01Summary
We collect what we need to run the Service (account info, payment info, what you do in the app) and connect you to integrations you opt into (Google Search Console, etc.). We don't sell your data. We don't train third-party AI models on your content. We process data through trusted vendors listed below. You can export, correct, or delete your data anytime by emailing support@dorqa.io.
02Who we are
Dorqa is operated by BirdMatrix LLP, a Limited Liability Partnership registered in India under LLP ID AAY-2584, with its registered office in Gurugram, Haryana. For the purposes of GDPR, India's Digital Personal Data Protection Act, 2023 (DPDPA), and similar laws, BirdMatrix LLP is the data controller for personal data processed through the Service.
03What we collect
We collect the following categories of data when you use Dorqa:
04Why we collect it
We process personal data on the following legal bases:
- Contract — to create and maintain your Account, deliver the Service you subscribed to, process payments, and provide support
- Legitimate interest — to improve the Service, monitor for fraud and abuse, secure our infrastructure, and communicate product updates relevant to your use
- Consent — for marketing emails (which you can unsubscribe from anytime), optional analytics cookies, and integrations you choose to connect
- Legal obligation — to comply with tax, accounting, and regulatory requirements applicable to BirdMatrix LLP
05How we use it
We use your data to:
- Run your Account, projects, reports, and tracked queries
- Generate the SEO, AI Visibility, Local SEO, YouTube, Trend, and Audience Intelligence outputs you ask for
- Detect rising trends, citation gaps, and audience signals through our processing pipelines
- Charge you for paid Plans and issue invoices and receipts
- Respond to support requests and resolve issues
- Send Service announcements (always), product newsletters (only if you opt in)
- Detect and prevent abuse, fraud, scraping, and security threats
- Improve features and algorithms using aggregated, de-identified usage patterns
We do not sell your data to third parties. We do not use your project data, integrations, or content to train third-party AI models. We do not share your data with advertisers for behavioural targeting. We do not access your connected Google Search Console or YouTube data for any purpose other than generating your reports.
06Sub-processors
We use the following third-party processors to operate the Service. Each is bound by data-protection terms and processes data only on our instructions and for the purposes listed.
Infrastructure & hosting
Payment processors
Data & intelligence APIs
AI visibility tracking
Integrations you authorise
Dorqa's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request read-only access to Google Search Console and Google Analytics (GA4) data, use it solely to display search and analytics insights to you in the app, and never sell it, use it for advertising, or use it to train generalized AI/ML models. You can revoke access anytime by disconnecting your Google account.
Communication & operations
This list may evolve as the Service grows. We update this page when sub-processors change. For a current authoritative list at any time, email support@dorqa.io.
07Sharing & disclosure
We do not sell your personal data. We share data only:
- With sub-processors listed above, strictly to operate the Service
- With your authorisation when you connect an integration or share a report
- With professional advisors (lawyers, accountants, auditors) under confidentiality, where reasonably necessary
- For legal reasons when required by valid legal process — court order, subpoena, regulatory request — or to protect our rights, property, or safety, or those of our users or the public
- In a business transition such as a merger, acquisition, or sale of assets, in which case affected users will be notified and offered options consistent with this policy
08Cookies & tracking
We use a minimal set of cookies and similar storage technologies:
- Essential cookies — required for authentication, session management, and security. Cannot be disabled.
- Preference storage — local storage to remember theme (dark/light) and currency (INR/USD) preference.
- Analytics — privacy-respecting analytics for understanding aggregate usage patterns. No cross-site tracking, no advertising identifiers.
We do not use third-party advertising cookies, retargeting pixels, or behavioural tracking across other websites.
09Data retention
We retain your data for the following periods:
- Account data — for the lifetime of your Account, plus 30 days after closure to allow reactivation
- Project & report data — for the lifetime of your Account; historical depth depends on your Plan (12 months on Free, up to 24 months on paid Plans)
- Billing & tax records — for 7 years after the transaction, as required by Indian tax and accounting law
- Support communications — for 3 years after the last message
- Aggregated, de-identified data — may be retained indefinitely for product analytics and improvement
You can request earlier deletion at any time, subject to our legal obligations to retain certain records.
10Security
We protect your data with industry-standard measures:
- Encryption in transit (HTTPS/TLS 1.2+) and at rest (database-level encryption via Supabase)
- Hashed passwords (we never see or store passwords in plain text)
- Role-based access controls and audit logging on internal systems
- Regular dependency updates and infrastructure patching
- Limited employee access on a need-to-know basis
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the appropriate authorities in line with applicable law (GDPR Article 33/34, DPDPA Section 8(6)).
11International transfers
BirdMatrix LLP is based in India. Some of our sub-processors are based in the EU, UK, USA, Singapore, or other jurisdictions. When we transfer data internationally, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) where applicable and the data-protection commitments of our sub-processors.
12Your rights
Depending on your location, you have rights under GDPR (EEA/UK), DPDPA (India), CCPA (California), or similar laws, including the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your data, subject to our legal retention obligations
- Export your data in a portable, machine-readable format
- Restrict or object to certain processing
- Withdraw consent at any time for processing based on consent
- Lodge a complaint with your local data protection authority
To exercise any of these rights, email support@dorqa.io. We will respond within 30 days. We do not charge for reasonable requests and we do not retaliate against users who exercise their rights.
13Children
Dorqa is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact support@dorqa.io and we will delete it promptly.
14AI assistants
You can connect your Dorqa account to an AI assistant, such as ChatGPT or Claude, using Dorqa's connector at https://mcp.dorqa.io/mcp. See the AI assistants guide.
How the connection works. When you connect, the assistant sends you to a Dorqa sign-in and consent page. The assistant never sees your Dorqa password. After you click Allow, Dorqa issues the assistant an access token that lasts one hour and a refresh token that lasts 30 days. We store only a one-way hash of each token, never the token itself.
What the assistant can read. Only when you ask it something, and only through read-only tools:
- the projects (websites) in your Dorqa workspace, including your team's projects if you are part of a team, and whether Search Console and Analytics are connected;
- each project's Dorqa Brief: Search Console and Google Analytics figures, site audit results, domain overview, AI visibility results, internal link suggestions, questions people ask, audience research and watched trends, as already stored in Dorqa;
- Dorqa's shared question bank (public questions from search and communities, with search volume).
What the assistant cannot do. It cannot change anything in Dorqa or on your website, run paid lookups, spend your credits, or see your billing details, payment methods or password.
What Dorqa receives from the assistant. The tool request only: which tool, and inputs such as a project domain or a topic. Dorqa does not receive your conversation with the assistant. Your conversation is handled by the assistant's provider under their own privacy policy (for example OpenAI's or Anthropic's).
What Dorqa stores. The name the assistant registered with (for example "ChatGPT"), the address it returns you to, hashed tokens, when you connected and when the connection was last used. We keep these while the connection is active and delete them within 90 days of it ending.
Third parties. Dorqa does not sell or share data received through this connection. Data you choose to have an assistant read is sent to that assistant's provider at your request.
Disconnecting. In Dorqa, open your account menu, then AI assistants, then Disconnect. Access ends immediately. You can also remove Dorqa inside the assistant.
15Changes
We may update this Privacy Policy from time to time to reflect changes in the Service, our processors, or applicable law. Material changes will be communicated by email or in-app notification at least 30 days in advance. The "Last updated" date at the top reflects when this policy was most recently modified.
16Contact
For questions about this Privacy Policy or to exercise your rights, contact us: