Privacy Policy
This policy explains what personal data Drogo collects, why we collect it, and the choices and rights you have. We've tried to write it in plain English.
Last updated: 8 August 2026
1. Who we are
Drogo ("Drogo", "we", "us", or "our") is operated by Hera Global Holdings Ltd, a company registered in England and Wales.
Hera Global Holdings Ltd
Company number: 15792143
Registered office: 24-26 Arcadia Avenue, Fin009, London, England, N3 2JU
For the purposes of UK GDPR and EU GDPR, Hera Global Holdings Ltd is the data controller for the personal data described in this policy, unless stated otherwise.
2. Scope of this policy
This policy applies to personal data we process through drogo.ai, our applications, and related services (together, the "Service"), including our website, workspace product, and any mobile or desktop clients. It applies to visitors, prospective customers, registered users, and members of a Drogo workspace. It does not apply to third-party websites or services we link to, which have their own privacy practices.
3. Data we collect
We collect the following categories of data:
Account and identity data
Name, work email address, password (hashed), job title, profile photo, and workspace/company details you provide when you sign up or are invited to a workspace.
Workspace content
The content you and your team create or upload while using Drogo — goals, tasks, taskboards, chat messages, documents, spreadsheets, notes, files, CRM records, and Composer app data. This is content your organisation controls; see "Controller and processor roles" below.
Billing data
Billing name, address, and transaction history. Card and payment details are collected and processed directly by our payment processor, Stripe — we do not store full card numbers on our own systems.
Usage and device data
Log data such as IP address, browser type, device identifiers, pages viewed, features used, timestamps, and referring URLs, collected automatically when you use the Service.
Communications
Records of correspondence when you contact us for support, sales, or other enquiries.
Integration data
If you or your workspace admin connect a third-party tool (e.g. email, calendar, storage, or communication providers) to Drogo, we process the data needed to power that integration, as authorised by you.
4. How we collect data
- Directly from you — when you create an account, fill in a form, upload content, or contact us.
- Automatically — through cookies and similar technologies as you use the Service (see "Cookies").
- From your workspace — when a workspace admin invites you or enters data about you (e.g. HR records).
- From third parties — such as our payment processor confirming a successful payment, or a service you choose to connect via integrations.
5. Our legal basis for processing
Under UK GDPR and, where applicable, EU GDPR, we rely on the following legal bases:
- Performance of a contract — to create your account, provide the Service, and deliver features you request.
- Legitimate interests — to secure and improve the Service, prevent fraud and abuse, and communicate about product updates, provided this does not override your interests or fundamental rights.
- Consent — where you have opted in, for example to receive marketing emails or for non-essential cookies. You can withdraw consent at any time.
- Legal obligation — to comply with applicable law, such as tax and accounting requirements.
6. How we use your data
- Provide, operate, and maintain the Service, including Goals, Taskboards, Workroom, Composer, Docs, Sheets, and Drive.
- Authenticate you and keep your account and workspace secure.
- Process payments and manage subscriptions and billing.
- Provide customer support and respond to your requests.
- Power AI features such as Maya and Greg (see below).
- Send service communications, including security and billing notices.
- Send product updates or marketing where you have consented, or opted in; you can unsubscribe at any time.
- Monitor, analyse, and improve the performance, reliability, and usability of the Service.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with legal obligations and enforce our terms.
7. AI features (Maya & Greg)
Maya (your workspace copilot) and Greg (our sales assistant) use large language model providers, including OpenAI and Anthropic, to generate briefings, summaries, answers, and suggestions grounded in your workspace data.
- Relevant workspace content (for example, the goals, tasks, or messages needed to answer your question) is sent to these providers strictly to generate a response — it is not used by us to build a profile of you outside the Service.
- We use these providers under API terms that exclude your prompts and data from being used to train their general-purpose models.
- AI outputs may occasionally be inaccurate. Use judgment when relying on AI-generated content for decisions.
- Workspace admins can contact us at privacy@drogo.ai for more detail on how AI features process a specific workspace's data.
10. International transfers
Some of our service providers process data outside the UK and European Economic Area (EEA), including in the United States. Where we transfer personal data internationally, we put appropriate safeguards in place, such as the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, and we only work with providers who commit to protecting your data to a standard consistent with UK and EU GDPR.
11. Data retention
We retain personal data for as long as needed to provide the Service and for legitimate business purposes, including:
- Account and workspace data, for as long as your account or workspace is active, and for a reasonable period afterward in case you wish to reactivate it.
- Billing records, for as long as required by UK tax and accounting law (typically six years).
- Support communications, for as long as needed to resolve your query and for a reasonable period afterward.
When a workspace is deleted, we remove or anonymise the associated personal data within a reasonable period, except where we are required to retain it by law or for the establishment, exercise, or defence of legal claims.
12. Keeping your data secure
We use technical and organisational measures designed to protect your data, including encryption of data in transit, access controls limiting who within our team can access personal data, and regular review of our security practices. No method of transmission or storage is 100% secure, but we work to protect your data and to respond promptly if an incident occurs, including notifying affected individuals and regulators where required by law.
13. Your rights
Under UK GDPR and EU GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data, in certain circumstances.
- Restrict or object to certain processing, including direct marketing.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at privacy@drogo.ai. If your data is held within a workspace managed by your employer or organisation, we may direct you to your workspace admin, who controls that data.
You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, or, if you are in the EU, with your local data protection authority.
14. Controller and processor roles
Drogo is a workspace tool used by organisations and their teams. Depending on the data in question, we act in different roles:
- We are the controller of account data (such as your login and billing details) and website visitor data.
- We are typically a processor acting on behalf of the workspace (the controller) for workspace content — such as HR records, CRM data, or documents your organisation creates and manages within Drogo. Your organisation's own privacy notice governs how it collects and uses that data, and its instructions govern how we process it.
A data processing agreement (DPA) is available on request for organisations that need one — contact privacy@drogo.ai.
15. Children's privacy
Drogo is a business tool intended for use by organisations and their employees. It is not directed at, and we do not knowingly collect personal data from, children under the age of 16. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.
16. Third-party links and integrations
The Service may contain links to third-party websites, or allow you to connect third-party integrations. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before sharing data with them.
17. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. If we make material changes, we will notify you by email or through the Service before the changes take effect. The "Last updated" date at the top of this page shows when this policy was last revised.
18. Contact us
If you have questions about this policy or how we handle your data, contact us:
privacy@drogo.ai
We aim to respond within 30 days.
Hera Global Holdings Ltd
24-26 Arcadia Avenue, Fin009, London, England, N3 2JU
