Legal
Privacy Policy
Effective date: January 4, 2026 · Last updated: May 18, 2026
1. Introduction & Scope
AgentCore LLC, a Delaware limited liability company doing business as "Dale" ("Company," "we," "our," or "us"), operates the Dale platform accessible at dale.legal and its associated subdomains (collectively, the "Platform"). This Privacy Policy ("Policy") describes how we collect, use, disclose, retain, and protect information when you access or use the Platform, whether as a registered account holder, an authorized user within an organization, or a visitor to our website.
This Policy applies to all personal information and confidential document data processed through the Platform. It does not apply to third-party websites or services that may be linked from the Platform, each of which is governed by its own privacy practices.
By creating an account, uploading documents, or otherwise using the Platform, you acknowledge that you have read and understood this Policy. If you are using the Platform on behalf of an organization, you represent that you are authorized to accept this Policy on behalf of that organization.
2. Definitions
For purposes of this Policy:
- "Personal Information" means information that identifies, relates to, describes, or is reasonably capable of being associated with a particular individual, including but not limited to name, email address, IP address, and professional title.
- "Document Data" means the content of Franchise Disclosure Documents ("FDDs") and other files uploaded to the Platform for analysis, together with the structured findings, compliance reports, and review outputs generated by the Platform in connection with such documents.
- "Usage Data" means information automatically collected about your interaction with the Platform, including access logs, feature usage, session duration, and navigation paths.
- "Sub-processor" means any third-party service provider that processes Personal Information or Document Data on our behalf in connection with the operation of the Platform.
3. Information We Collect
3.1 Information You Provide
Account & Profile Information. When you register for the Platform, we collect your first and last name, business email address, professional title or role, and organizational affiliation. If your account is provisioned through an organizational administrator, certain information may be provided by that administrator on your behalf.
Document Submissions. When you upload an FDD or related document for compliance review, we ingest and process the full content of that document, including all Items, exhibits, and schedules contained therein. This processing is performed solely to deliver the compliance analysis you have requested.
Communications. If you contact us for support, submit an inquiry, or provide feedback, we collect the content of those communications along with any associated metadata (e.g., timestamps, email headers).
3.2 Information Collected Automatically
Usage Data. We collect information about how you interact with the Platform, including pages and features accessed, review history, search queries, timestamps of activity, and the sequence and duration of actions taken within the Platform.
Device & Network Information. We automatically collect your IP address, browser type and version, operating system, device identifiers, screen resolution, referring URL, and general geographic location derived from your IP address.
Cookies & Local Storage. The Platform uses strictly necessary cookies and browser local storage to authenticate your session, persist your preferences (such as theme settings), and ensure the Platform functions correctly. We do not deploy third-party advertising cookies, tracking pixels, or behavioral analytics cookies. For additional detail, see Section 10 below.
4. Lawful Bases for Processing
We process Personal Information and Document Data on the following lawful bases, as applicable under the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and analogous frameworks:
- Performance of a Contract. Processing necessary to provide the Platform and fulfill our obligations under the Terms of Use, including document analysis, account management, and delivery of compliance reports.
- Legitimate Interests. Processing necessary for our legitimate business interests, including improving the Platform, ensuring security, preventing fraud, and conducting internal analytics, provided such interests are not overridden by your data protection rights.
- Compliance with Legal Obligations. Processing necessary to comply with applicable laws, regulations, court orders, or binding governmental requests.
- Consent. Where required by applicable law, we will obtain your explicit consent before processing. You may withdraw consent at any time by contacting us at privacy@dale.legal, without affecting the lawfulness of processing conducted prior to withdrawal.
5. How We Use Your Information
We use collected information for the following purposes:
- Service Delivery. To operate the Platform, process uploaded documents through our AI compliance analysis engine, generate structured findings and reports, and provide you with access to review results.
- Account Administration. To create and manage your account, authenticate your identity, manage organizational permissions, and process subscription-related activities.
- Platform Improvement. To analyze usage patterns, diagnose technical issues, monitor system performance, and develop new features. When used for improvement purposes, Document Data is accessed only in aggregated or de-identified form and is never used to train third-party AI models.
- Security & Fraud Prevention. To detect, investigate, and prevent unauthorized access, abuse, or other security incidents affecting the Platform or its users.
- Communications. To send transactional and service-related messages, including account verification, security alerts, review completion notifications, and material changes to this Policy or our Terms of Use.
- Legal Compliance. To comply with applicable laws and regulations, respond to lawful requests from public authorities, and establish, exercise, or defend legal claims.
6. Document Handling, Confidentiality & Retention
6.1 Confidentiality of Document Data
We recognize that FDDs and related franchise documents contain confidential, proprietary, and commercially sensitive information. All Document Data is treated as confidential information and is subject to the following safeguards:
- Document Data is logically isolated on a per-organization basis. No user or organization can access another organization's documents or review outputs.
- Document Data is encrypted both in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
- Access to Document Data within our organization is restricted to personnel who require access for purposes of operating, maintaining, or improving the Platform, and all such personnel are bound by confidentiality obligations.
- We do not use your Document Data to train, fine-tune, or improve any third-party artificial intelligence or machine learning models. Document content is not shared with, or made accessible to, other customers of the Platform.
6.2 AI Processing Disclosure
The Platform uses artificial intelligence, including third-party large language model APIs, to analyze uploaded documents and generate compliance findings. When Document Data is transmitted to a third-party AI provider for processing, it is sent via encrypted channels and is subject to data processing agreements that prohibit the provider from retaining, using, or training on your data. We maintain a current list of AI Sub-processors, which is available upon request by contacting privacy@dale.legal.
6.3 Retention
We retain Personal Information for as long as your account remains active or as necessary to provide the Platform, comply with legal obligations, resolve disputes, and enforce our agreements. Upon account termination or deletion, we will delete or de-identify your Personal Information within ninety (90) days, except where retention is required by law.
Document Data and associated review outputs are retained in your account until you delete them or your account is terminated. You may delete individual reviews at any time through the Platform interface. Following account deletion, Document Data is purged from active systems within thirty (30) days and from backup systems within ninety (90) days.
7. Disclosure of Information
We do not sell, rent, or trade your Personal Information or Document Data. We may disclose information in the following limited circumstances:
- Sub-processors & Service Providers. We engage third-party vendors to assist in operating the Platform, including cloud infrastructure providers, AI model providers, email delivery services, and error monitoring tools. Each Sub-processor is bound by a data processing agreement that restricts its use of your information to the services performed on our behalf and imposes confidentiality and security obligations no less protective than those in this Policy. The current list of Sub-processors used in connection with organizational subscriptions is published in our Data Processing Agreement.
- Within Your Organization. If your account is part of a multi-user organizational subscription, your organization's administrator(s) may have access to account-level information and aggregated usage data associated with the organization's account.
- Legal Requirements. We may disclose information when we believe in good faith that disclosure is required by applicable law, regulation, legal process, or enforceable governmental request; to protect the rights, property, or safety of the Company, our users, or the public; or to detect, prevent, or address fraud, security, or technical issues.
- Business Transfers. In connection with a merger, acquisition, reorganization, asset sale, or similar transaction, your information may be transferred to the acquiring entity, provided that the successor entity assumes the obligations of this Policy with respect to the transferred information.
8. Data Security
We implement administrative, technical, and physical safeguards designed to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include, but are not limited to:
- Encryption of data in transit using TLS 1.2 or higher, and encryption of data at rest using AES-256 or equivalent algorithms
- Role-based access controls with the principle of least privilege
- Multi-factor authentication for administrative access to production systems
- Regular security assessments, penetration testing, and vulnerability scanning
- Logging and monitoring of access to systems containing Personal Information and Document Data
- Incident response procedures designed to promptly detect, contain, and remediate security incidents
Notwithstanding the foregoing, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a data breach affecting your Personal Information, we will notify you and any applicable regulatory authorities in accordance with applicable law.
9. Your Rights & Choices
9.1 General Rights
Depending on your jurisdiction, you may have the following rights with respect to your Personal Information:
- Access. The right to request confirmation of whether we process your Personal Information and to obtain a copy of such information.
- Rectification. The right to request correction of inaccurate or incomplete Personal Information.
- Erasure. The right to request deletion of your Personal Information, subject to certain exceptions (e.g., where retention is required by law or necessary for the performance of a contract).
- Restriction of Processing. The right to request that we restrict the processing of your Personal Information under certain circumstances.
- Data Portability. The right to receive your Personal Information in a structured, commonly used, and machine-readable format, and to transmit that information to another controller.
- Objection. The right to object to the processing of your Personal Information on grounds relating to your particular situation, where processing is based on legitimate interests.
To exercise any of these rights, please contact us at privacy@dale.legal. We will not discriminate against you for exercising your rights. Specific procedures for deletion and other rights requests are set out in Section 9.2 below.
9.2 Data Deletion & Rights-Request Procedure
This section describes how to submit a request to delete your Personal Information (or to exercise any other right described in Section 9.1), how we verify your identity, the timeframes within which we will respond, and how we will confirm completion.
How to submit a request. Send your request to privacy@dale.legal with the subject line "Data Subject Request" or "Deletion Request." Please include:
- Your full name and the email address associated with your Dale account (or the email address through which you interacted with the Platform or our marketing site, if you do not have an account);
- The specific right you wish to exercise (e.g., deletion / erasure, access, correction, portability, restriction, objection); and
- If you are submitting the request through an authorized agent, written authorization signed by you, together with the agent's contact information. We may separately contact you to confirm that you have authorized the agent to act on your behalf.
Identity verification. Before acting on a request, we will take reasonable steps to verify that the request comes from you (or your authorized agent). The level of verification will be proportionate to the sensitivity of the Personal Information and the risk of harm from unauthorized disclosure or deletion, and may include:
- Confirming control of the email address associated with your account by sending a verification message to that address;
- Matching identifying details you provide against information already in our records (e.g., name, organizational affiliation, account email, recent activity); and
- For requests involving sensitive Personal Information or a complete account deletion, requesting one or more additional pieces of information that only you would reasonably know, or a signed declaration under penalty of perjury that you are the data subject (or, for authorized-agent requests, government-issued identification of the data subject and a written, signed authorization).
If we cannot reasonably verify your identity, we will notify you and, where permitted, treat the request as a request to opt out of any applicable processing rather than as a deletion or access request. We will not use Personal Information collected for verification purposes for any other purpose.
Response timeframes. We will acknowledge receipt of a verifiable request promptly, and in any event within ten (10) business days. We will substantively respond to and, where applicable, complete the request within the timeframes required by applicable law, including:
- GDPR / UK GDPR / FADP. Within thirty (30) days of receipt of a verifiable request. This period may be extended by up to a further sixty (60) days where necessary, taking into account the complexity and number of the requests, in which case we will notify you of the extension and the reasons for it within the initial thirty-day period.
- CCPA / CPRA and other U.S. State Privacy Laws. Within forty-five (45) days of receipt of a verifiable request. We may extend this period by an additional forty-five (45) days where reasonably necessary, in which case we will notify you of the extension and the reasons for it before the end of the initial forty-five-day period.
- Other jurisdictions. Within the timeframe required by applicable law, or, if no specific timeframe is prescribed, within forty-five (45) days.
Scope of deletion. Upon a verified deletion request, we will delete or de-identify your Personal Information from our active production systems and instruct our Sub-processors to do the same with respect to Personal Information held on our behalf. Document Data and other Personal Information held in encrypted backup systems will be purged in accordance with the retention timelines described in Section 6.3 (within ninety (90) days for backups). We may retain a limited subset of Personal Information where retention is permitted or required by law, including to (a) comply with legal obligations or governmental requests; (b) detect, prevent, or investigate security incidents or fraud; (c) establish, exercise, or defend legal claims; or (d) honor opt-out or do-not-contact preferences. Any retained information will continue to be protected in accordance with this Policy.
Confirmation of completion. Once your request has been processed, we will send a written confirmation to the email address used for verification, stating (a) the action taken (e.g., deletion completed, request denied in whole or in part), (b) the categories of Personal Information affected, (c) any information lawfully retained and the basis for retention, and (d) where applicable, that we have instructed our Sub-processors to delete the relevant Personal Information held on our behalf. If we deny a request in whole or in part, we will explain the reasons and inform you of your right to appeal (where available) and, for residents of the EEA, the United Kingdom, or Switzerland, of your right to lodge a complaint with your local supervisory authority.
No fee. We do not charge a fee for responding to verifiable rights requests. We may charge a reasonable fee, or refuse to act, only where a request is manifestly unfounded or excessive (in particular because of its repetitive character), and only to the extent permitted by applicable law.
9.3 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"). In the preceding twelve (12) months, we have collected the categories of Personal Information described in Section 3 above. We do not "sell" or "share" (as those terms are defined under the CCPA) your Personal Information, and we have not done so in the preceding twelve (12) months. You have the right to request access to, deletion of, and correction of your Personal Information, to opt out of any future "sale" or "sharing," and to designate an authorized agent to submit requests on your behalf. To submit a request, follow the procedure described in Section 9.2.
9.4 EEA, UK & Swiss Residents
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the rights described in Section 9.1 above, exercisable through the procedure in Section 9.2, and you may also lodge a complaint with your local supervisory authority. Our lawful bases for processing are described in Section 4 above.
10. Cookies & Tracking Technologies
10.1 The Platform
The Platform uses only strictly necessary cookies and browser local storage mechanisms required for authentication, session management, and user preference persistence. We do not employ third-party advertising cookies, cross-site tracking pixels, or behavioral analytics tools on the Platform. Because these cookies are essential to the operation of the Platform, they cannot be disabled without impairing core functionality.
10.2 Public marketing website (dale.legal)
When you browse our public marketing website, we use strictly necessary mechanisms so the site can function. We also use analytics (Google Analytics 4 and Vercel Web Analytics) to understand how the site is used. For visitors in the European Union and United Kingdom, analytics is off by default until you opt in via the privacy choices banner or footer control. Elsewhere, analytics runs on a default-on basis; you may opt out at any time using Your Privacy Choices in the site footer, which opens our preferences panel. Your choice is stored in the browser (local storage). We do not use third-party advertising or behavioral ad cookies on the marketing site.
11. International Data Transfers
The Platform is operated from the United States. If you access the Platform from outside the United States, your information may be transferred to, stored, and processed in the United States or other jurisdictions where our Sub-processors maintain facilities. Where such transfers occur, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission or other transfer mechanisms recognized under applicable law. For organizational customers, the specific cross-border transfer mechanisms applicable to processing on Customer's behalf are set out in our Data Processing Agreement.
12. Children's Privacy
The Platform is not directed to individuals under the age of eighteen (18), and we do not knowingly collect Personal Information from children. If we become aware that we have collected Personal Information from a child, we will take steps to delete such information promptly.
13. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will (a) update the "Last updated" and, if applicable, "Effective date" at the top of this page, and (b) provide notice through the Platform or via email to the address associated with your account. Your continued use of the Platform following the effective date of a revised Policy constitutes your acceptance of the changes. We encourage you to review this Policy periodically.
14. Contact Information
If you have questions, concerns, or requests regarding this Policy or our data practices, please contact us:
AgentCore LLC
Attn: Privacy
Email: privacy@dale.legal
For data subject rights requests, please use privacy@dale.legal and include sufficient information for us to verify your identity and process your request.