DLH Logo

Privacy Policy

Last updated: July 13, 2026

DLH.io ("dlh.io," "we," "us," or "our") is an enterprise data integration platform provided by AICG, Inc. This Privacy Policy explains how we collect, use, share, and protect personal data on the DLH.io marketing website and through related sales, marketing, and support activities. It also describes the rights and choices available to you.

If you have questions about this Privacy Policy or our privacy practices, please contact us at privacy@dlh.io or at the address listed in the "Contacting Us" section below.

Table of contents

1. Processing activities covered

This Privacy Policy applies to the following processing activities:

  • Visiting the DLH.io website and related pages that link to this Privacy Policy;
  • Submitting forms, requesting information, downloading content, or contacting us;
  • Registering for and attending DLH.io webinars, events, or demonstrations;
  • Receiving marketing, sales, or support communications from us;
  • Applying for or participating in partner or career opportunities, where applicable.

This Privacy Policy does not apply to information that DLH.io processes on behalf of a customer through the DLH.io platform or services. That processing is governed by the customer agreement and the Data Processing Addendum (DPA). See the "Your rights relating to Customer Data" section for more information.

Our website may contain links to third-party websites or services. The privacy practices of those third parties are governed by their own privacy policies, and we encourage you to review them.

2. Responsible DLH.io entity

DLH.io is provided by AICG, Inc., a Delaware corporation with its principal place of business at 2764 Pleasant Rd. #11437, Fort Mill, SC 29708, United States. For the purposes of the GDPR and UK GDPR, AICG, Inc. is the controller of personal data collected through the DLH.io marketing website, except where we process customer data as a processor or service provider under a customer contract and the DPA.

Our platform and related cloud products and services are offered under the Software as a Service Agreement and the DPA. Through those services, our customers may create their own applications, send communications, and collect or analyze personal data from their own end users. This Privacy Policy does not apply to that processing.

3. What personal data we collect

3.1 Personal data we collect directly from you

We may collect the following categories of personal data directly from you:

  • Contact and professional details - name, job title, company name, business email address, phone number, mailing address, and any information you provide in a "Contact Us" form, support request, demo request, or event registration.
  • Account and event registration information - username, password, and event preferences when you create an account or register for a webinar, demonstration, or event.
  • Communications - the content of emails, messages, and other correspondence you send us.
  • Financial and billing information - billing name and address and payment details, if you make a purchase through our website or enter into a paid agreement with us.

3.2 Personal data we collect from other sources

We may collect business contact information and intent data from third-party providers to support our marketing and sales activities. This may include name, job title, company name, business email address, business phone number, mailing address, IP address, social media handles, LinkedIn URL, and inferred interests or intent signals. We combine this information with data you provide directly to keep our records accurate, identify potential customers, and deliver more relevant marketing content and advertising.

3.3 Personal data we collect automatically

When you visit our website or interact with our emails, we automatically collect certain device and usage data through cookies, web beacons, log files, and similar technologies. This may include your IP address, browser type and version, device identifiers, operating system, referring and exit pages, pages viewed, search terms, links clicked, date and time stamps, and interaction events. See the "What device and usage data we process" section for more information.

We do not intentionally collect special categories of personal data (such as health, biometric, racial or ethnic origin, religious or philosophical beliefs, trade union membership, or government identification numbers) through our marketing website. Please do not submit such information through our forms or other communications.

4. What device and usage data we process

4.1 Log files

Like most websites, we collect log file information automatically. This may include your IP address (or proxy server), device and application identifiers, browser type, internet service provider or mobile carrier, pages and files viewed, searches performed, operating system and system configuration, and date and time stamps associated with your use. We use this information to analyze trends, administer and improve our website, help diagnose technical issues, and maintain security.

4.2 Cookies and similar technologies

We use cookies and similar technologies, including web beacons, tags, and scripts, to operate our website, remember your preferences, measure traffic and engagement, and support marketing and advertising. For a full description of the cookies we use, including provider, purpose, duration, and category, see our Cookie Policy.

You can manage cookie preferences through your browser settings or the Your Privacy Choices page. For more information about the cookies we use, including duration and category, see our Cookie Policy.

4.3 Third-party analytics and advertising

We use analytics and advertising services to understand how visitors use our website and to deliver relevant marketing. For example, we use Google Analytics to measure website traffic and engagement. We may also use advertising platforms such as LinkedIn to measure and deliver marketing campaigns.

You can learn more about how Google uses data from sites that use its services at https://policies.google.com/technologies/partner-sites and opt out of Google Analytics by installing the Google Analytics opt-out browser add-on at https://tools.google.com/dlpage/gaoptout.

5. Purposes and legal bases for processing

We process personal data for the following purposes and on the following legal bases:

  • Providing our website and services - to perform our contract with you or to take steps at your request before entering into a contract.
  • Communicating with you - to respond to inquiries, provide support, and send transactional messages.
  • Marketing and sales - to send newsletters, product updates, event invitations, and other communications that may interest you, based on your consent or our legitimate interests, where permitted by law.
  • Advertising and personalization - to deliver targeted advertising and content based on your interests and activity, based on your consent or our legitimate interests, where permitted by law.
  • Security and fraud prevention - to verify accounts, monitor for suspicious activity, investigate misuse, and protect our rights and the rights of others, based on our legitimate interests or legal obligation.
  • Analytics and improvement - to analyze trends, track usage of our website and emails, and improve our content and user experience, based on our legitimate interests or your consent, where required.
  • Legal compliance - to comply with applicable law, respond to lawful requests, and enforce our terms and policies, based on legal obligation or legitimate interests.

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing based on consent before its withdrawal.

6. Who we share personal data with

We may share personal data with the following categories of recipients:

  • Service providers and subprocessors - companies that provide services such as hosting, infrastructure, content management, customer relationship management, email delivery, analytics, advertising, payment processing, and customer support. A current list of subprocessors used for the DLH.io platform is available in our Authorized Subcontractors list.
  • Professional advisers - lawyers, auditors, insurers, accountants, and other professional advisers who provide services to us under confidentiality obligations.
  • Advertising and analytics partners - third-party platforms that measure advertising performance or help us deliver marketing, such as Google Analytics and LinkedIn, subject to your choices and applicable law.
  • Business transferees - in connection with a merger, acquisition, financing, or sale of assets, we may transfer personal data to the relevant third party, subject to applicable law.
  • Government authorities and others - when required by law or to protect our rights, property, or safety, or the rights, property, or safety of others.

We do not sell personal information for money. Certain advertising and analytics activities, including the use of cookies for cross-context behavioral advertising, may be considered a "sale" or "sharing" of personal information under the CCPA/CPRA and similar state laws. You can opt out through the Your Privacy Choices page.

Any personal data you choose to submit in public forums or community areas on our website may be read, collected, or used by others. Please consider this before posting.

7. International transfer of information collected

We are based in the United States, and personal data we collect may be transferred to, stored in, or processed from the United States and other countries where our service providers or affiliates operate. These countries may not provide the same level of data protection as your home country.

When we transfer personal data outside the European Economic Area, the United Kingdom, or Switzerland, we use appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, or another lawful transfer mechanism. You may contact us for more information about the safeguards we use.

8. Children

Our website is not directed to children under 16, and we do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us and we will take steps to delete such data from our systems.

9. How long do we keep your personal data

We keep personal data for as long as necessary to fulfill the purposes for which it was collected, including to provide our services, maintain our relationship with you, meet legal and regulatory obligations, resolve disputes, and enforce our agreements. When personal data is no longer needed for these purposes, we delete or anonymize it in accordance with our retention schedule.

Specific retention periods or criteria depend on the type of data and the purpose of processing. For example, marketing contact data is retained for the duration of our relationship and any applicable legal limitation period; log files and analytics data are retained for a shorter period needed for security, troubleshooting, and analysis; and financial and billing records are retained for as long as required by tax, accounting, and legal obligations.

10. Your rights and choices

10.1 GDPR and UK GDPR rights

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you may have the following rights regarding your personal data, subject to applicable law:

  • Right to access the personal data we hold about you;
  • Right to rectify inaccurate or incomplete personal data;
  • Right to erasure (right to be forgotten) of your personal data;
  • Right to restrict processing of your personal data;
  • Right to data portability;
  • Right to object to processing based on our legitimate interests, including direct marketing;
  • Right to withdraw consent at any time, where processing is based on consent;
  • Right to lodge a complaint with a supervisory authority.

To exercise any of these rights, contact us at privacy@dlh.io. We will respond within one month of receiving your request, and may extend that period by an additional month for complex or numerous requests. We may need to verify your identity before fulfilling your request.

10.2 Your US state privacy rights

If you are a resident of California, you have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA). Residents of other states, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Rhode Island, Indiana, Kentucky, and other states with comprehensive privacy laws, may have similar rights depending on your state of residence.

These rights may include the right to:

  • Know what personal data we collect, use, disclose, and share;
  • Request deletion of your personal data;
  • Request correction of inaccurate personal data;
  • Opt out of the sale or sharing of personal information for cross-context behavioral advertising;
  • Limit the use or disclosure of sensitive personal information, where applicable;
  • Not be discriminated against for exercising your privacy rights;
  • Use an authorized agent to submit requests on your behalf.

To exercise these rights, visit the Your Privacy Choices page or email us at privacy@dlh.io. We will verify your identity before responding. We generally respond within 45 days of receiving a verifiable request and may extend that period by an additional 45 days when reasonably necessary.

Appeals

If we decline to take action on your request, you have the right to appeal our decision. Submit your appeal by emailing privacy@dlh.io with "Privacy Request Appeal" in the subject line. We will respond to your appeal within the timeframe required by applicable law, generally 45 days, with a maximum extension of 45 days where permitted. If your appeal is denied, you may contact your state Attorney General or the relevant state privacy regulator.

Sensitive personal information

We do not intentionally collect sensitive personal information as a controller through our marketing website. If you are a DLH.io customer and use our platform to process payroll, human resources, or other operational data that may contain sensitive personal information, we process that data as a processor or service provider on your behalf under the customer agreement and the DPA, not as a business under the CCPA/CPRA. You can limit the use of any sensitive personal information we process as a controller through the Your Privacy Choices page or by emailing privacy@dlh.io.

CCPA/CPRA disclosure of personal information collected

The table below describes the categories of personal information we may collect through our website and business operations, the sources of that information, the purposes for which it is used, the categories of third parties to whom it may be disclosed, and the criteria used to determine retention. This table covers personal data DLH.io processes as a controller. It does not cover customer data processed on a customer's behalf through the DLH.io platform, which is governed by the customer agreement and the DPA.

Category of personal informationSourcesBusiness or commercial purposesCategories of third partiesRetention criteria
Identifiers (name, job title, company, address, phone, email, username, IP address)You, third-party data providers, automatic collectionProvide services, communicate, market, sell, support, security, analyticsService providers, analytics, advertising, professional advisers, business transfereesDuration of relationship and applicable legal limitation or record-keeping period
Financial information (billing name and address, payment card or bank account information)YouProcess payments, fulfill contracts, billing, tax, accountingPayment processors, accounting providers, professional advisersDuration of contract plus period required by tax, accounting, and legal obligations
Commercial information (purchases, content downloaded, services inquired about)You, analytics and tracking technologiesProvide services, measure interest, improve content, personalize marketingAnalytics, advertising, CRM providers, business transfereesDuration of relationship and marketing campaign period
Internet or network activity (log files, browsing, searches, email interaction)Automatic collectionSecurity, analytics, improve website, marketing, personalizationAnalytics, advertising, security providersShort-term security and analytics retention period, then deleted or aggregated
Geolocation data (approximate location derived from IP address)Automatic collectionSecurity, analytics, localized contentAnalytics, security providersRetained with associated log data and then deleted or aggregated
Professional or employment information (job title, department, company, industry)You, third-party data providersMarketing, sales, account management, product developmentCRM, analytics, advertising, event partnersDuration of relationship and marketing campaign period
Inferences and intent data (interests, product fit, engagement signals)Analytics, third-party data providersMarketing, sales, personalization, advertisingAnalytics, advertising, CRM providersDuration of marketing campaign or until you opt out

10.3 Your rights relating to Customer Data

As described above, DLH.io may process personal data as a processor or service provider on behalf of our customers through the DLH.io platform. If your personal data has been submitted to us by a DLH.io customer and you wish to exercise any rights under applicable data protection laws, please contact that customer directly.

Because we can only access customer data upon instruction from the respective customer, if you contact us directly, please provide the name of the DLH.io customer that submitted your data. We will refer your request to that customer and support them as needed in responding to your request within a reasonable timeframe. Processing of customer data is governed by the customer agreement and the DPA.

10.4 Your preferences for marketing communications

If you receive marketing communications from us, you can opt out at any time by clicking the "unsubscribe" link at the bottom of our emails, replying with "STOP" if we send SMS messages, or by emailing privacy@dlh.io. Even if you opt out of marketing, we may still send you transactional or service-related communications.

11. Security and data breach notification

We use reasonable administrative, technical, and organizational measures designed to protect personal data against unauthorized access, loss, misuse, or alteration. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.

DLH.io maintains an incident response process and will notify affected individuals and applicable regulators as required by law. This includes notifying the relevant supervisory authority within 72 hours under GDPR Article 33 and complying with applicable US state breach notification statutes. Breach notification obligations relating to customer data are governed by the customer agreement and the DPA.

12. Automated decision-making and AI

Our marketing website does not use automated decision-making that produces legal effects or similarly significant effects on individuals.

The DLH.io platform includes AI summarization features that operate on customer data under customer instruction and contract. Your raw data is not used to train or fine-tune any AI or machine learning model. Model calls are made through enterprise LLM endpoints that process data only to provide the service and do not retain or use it for model training.

Any third-party AI providers used by the platform are engaged as subprocessors under the DPA and are listed or governed by the Authorized Subcontractors list.

13. Do Not Track and Global Privacy Control

Some browsers offer a "Do Not Track" signal. Because there is no common industry standard for interpreting these signals, our website does not rely on DNT alone.

We do detect and honor the Global Privacy Control (GPC) opt-out preference signal. When your browser sends a GPC signal, we disable non-essential analytics and advertising cookies and limit the sale or sharing of your personal information for that browser. You can also manage your choices at any time through the Your Privacy Choices page.

14. Changes and version history

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, provide additional notice. Your continued use of the site after an update means you accept the revised policy.

  • July 13, 2026 - Restructured the privacy notice to add US state privacy rights, CCPA/CPRA disclosure tables, Global Privacy Control and Your Privacy Choices controls, an AI and automated decision-making statement, a data breach notification statement, related document links, and clearer controller and service-provider distinctions.
  • October 2025 - Prior version of the DLH.io Privacy Policy.

15. Contacting us

If you have questions about this Privacy Policy, wish to exercise your rights, or want to lodge a complaint, please contact us:

Email: privacy@dlh.io
Postal address:
AICG, Inc.
2764 Pleasant Rd. #11437
Fort Mill, SC 29708
United States

If you are located in the EEA or the UK, you also have the right to lodge a complaint with your local data protection supervisory authority, such as the Information Commissioner's Office in the United Kingdom.