Skip to content
Last updated 22 July 2026

Privacy policy

How DustDHA collects, uses, shares, and protects assessment, provider, and RFQ information.

Assessment tools

Deadline and cost answers are used to calculate the result you request. A short-lived session snapshot may be retained for PDF delivery and RFQ prefill. Requesting a PDF sends one transactional report and does not subscribe you to marketing. The separate deadline-reminder checkbox is off by default; if you explicitly select it, DustDHA may send up to two relevant deadline reminders. Unsubscribing or replying revokes those reminders.

RFQ information

We collect the business contact and facility details needed to score and match a request. If the request qualifies, its contact details may be shared with up to 3 matched providers. You choose whether to engage any provider.

Provider information

Directory profiles summarize public business information. Provider-interest and profile-claim forms store the work email, company, consent record, and matching preferences needed to respond or verify the claim.

Analytics

We record a limited event trail such as page path, tool completion, and funnel stage. Raw form answers, names, phone numbers, and email addresses are not sent in browser analytics event properties. Optional GA4 and PostHog services are enabled only when production keys are configured; replay inputs are masked.

Payments

Provider checkout and payment details are processed by Dodo Payments as Merchant of Record. DustDHA stores provider, product, payment reference, subscription state, credit, refund, and ledger records, but does not store full card details.

Retention and security

Expired verification challenges and stale unqualified inquiries are removed on a scheduled retention cycle. Recipient fields in terminal lifecycle-dispatch records are anonymized after the applicable retention window; encrypted retry payloads are removed after a successful send. Commercial, delivery, dispute, and payment ledgers are retained where needed for contracts, accounting, fraud prevention, and legal obligations. Administrative access is restricted by a separate session, verified allowlisted account, network allowlist, and required multi-factor authentication.

Your choices

You can unsubscribe from non-transactional email using the link in the message or reply to stop the sequence. To request access, correction, or deletion where applicable, email [email protected]. We may retain records that must remain for accounting, dispute, security, or legal purposes.