Skip to content
DandeLiion
Simulate Documentation Sign in Create account

Version 2026-07

Privacy Notice

1. Who we are

DandeLiion Technologies Limited ("DandeLiion", "we", "us" or "our") operates the DandeLiion token portal and simulation API.

DandeLiion Technologies Limited is the controller of the personal data described in this Privacy Notice. We are registered in England and Wales under company number 17169962, with our registered office at 19 Water Lilies, Bristol, United Kingdom, BS11 0GJ.

2. Scope of this Privacy Notice

This Privacy Notice applies to personal data processed in connection with:

  • the DandeLiion token portal at portal.dandeliion.com;
  • account registration, authentication and administration;
  • the creation, management and validation of API tokens;
  • service tiers, allowances and quotas;
  • access to the DandeLiion simulation API;
  • security, monitoring and support activities; and
  • communications between you and DandeLiion relating to these services.

Our Terms of Service govern your use of the portal and simulation API. This Privacy Notice explains how we collect and use personal data and is separate from the Terms of Service.

3. Personal data we collect

Depending on how you use the Service, we may collect and process the following categories of personal data.

Account information

  • your email address;
  • your name, where supplied;
  • password information stored in securely hashed form;
  • email-verification records;
  • account status, service tier and registration date; and
  • account-deletion request information.

Terms and Privacy Notice records

  • the versions of the Terms of Service and Privacy Notice presented to you;
  • the date and time of acceptance or acknowledgement; and
  • the source IP address associated with the acceptance or acknowledgement.

API-token information

  • a short visible token prefix;
  • a keyed cryptographic digest used to validate the token;
  • any label assigned to the token;
  • creation, expiry, revocation and last-use dates;
  • token status; and
  • successful-use counts.

Quota and service-tier information

  • your service tier and applicable allowance;
  • quota period and renewal information;
  • usage and remaining allowance;
  • manual quota adjustments or resets; and
  • the reasons for and administrators associated with those adjustments.

Validation and simulation-service information

  • token-validation outcomes and timestamps;
  • the relevant account and token, where known;
  • the account balance following a validation request;
  • sanitised request identifiers;
  • simulation job identifiers and status information;
  • submission, cancellation and result-access events; and
  • technical information needed to operate and support the simulation service.

The simulation API may also process parameters, configuration information, input files, simulation requests and generated results submitted or requested by users. The extent to which these contain personal data depends on what users choose to submit.

Security and technical information

  • IP addresses;
  • authentication and password-reset events;
  • rate-limit information;
  • server, application and security logs;
  • browser, device and network information; and
  • information relating to suspected misuse, unauthorised access or security incidents.

Communications

We may process information that you provide when contacting us for technical support, reporting a security issue, exercising your data-protection rights or otherwise communicating with us.

4. API-token security

A full API token is displayed only once when it is created. It is also processed transiently when submitted for validation.

We do not store full API tokens in plaintext and do not intentionally include them in application logs, monitoring data, error reports or analytics systems.

We retain only a short visible prefix and a keyed cryptographic digest used to validate the token. We cannot recover or display the full token after it has been created.

When you use the portal's simulation form, the portal creates a short-lived ordinary API token. Its secret is placed only in an encrypted, necessary, HTTP-only browser cookie for up to 24 hours and is decrypted in memory when the portal makes an authorised request on your behalf. The secret is not placed in your Django session, browser-visible page content, JavaScript, URL, database fields, cache or logs.

5. How we obtain personal data

We obtain personal data:

  • directly from you when you register, manage your account, create or revoke tokens, submit simulations, contact us or exercise your rights;
  • automatically when your browser, application or the DandeLiion API communicates with our systems; and
  • from an administrator authorised to manage your account, service tier or quota, where applicable.

6. Why we use personal data

Purpose Lawful basis
Creating, verifying and administering your account Performance of our contract with you, or steps taken at your request before entering into a contract
Creating, managing and validating API tokens Performance of our contract with you
Providing access to the simulation API and making simulation results available Performance of our contract with you
Administering service tiers, allowances, quotas and usage limits Performance of our contract with you and our legitimate interests in administering the Service
Sending email-verification, password-reset, security and service-related communications Performance of our contract and our legitimate interests in operating and securing the Service
Preventing misuse, detecting security incidents, applying rate limits and protecting users and systems Our legitimate interests in providing a secure and reliable Service
Diagnosing errors, monitoring performance and improving reliability Our legitimate interests in maintaining and improving the Service
Maintaining token, quota, acceptance and administrative audit records Our legitimate interests in maintaining accountable business and security records
Establishing, exercising or defending legal claims Our legitimate interests in protecting our legal rights
Complying with legal, regulatory or law-enforcement requirements Compliance with a legal obligation

We do not use portal or API-token data for advertising or behavioural marketing.

7. Terms acceptance and Privacy Notice acknowledgement

When you create an account, you must agree to the current Terms of Service and acknowledge that you have read the current version of this Privacy Notice.

We record the relevant document versions, date and time, account identifier and source IP address.

Your acknowledgement of this Privacy Notice does not mean that you consent to every use of your personal data. We rely on the lawful bases described above, including performance of a contract, legitimate interests and compliance with legal obligations.

If the Terms of Service or Privacy Notice are materially updated, you may be required to accept or acknowledge the new version before you can create or manage API tokens.

8. Information you must provide

You must provide a valid email address, authentication information and the required legal acceptances or acknowledgements to create and use an account. If you do not provide this information, we cannot register your account or provide token-management and API-access functionality.

Technical, validation and security information is generated automatically when the Service is used. This information is necessary for authentication, quota enforcement, token validation and protection of the Service.

9. Automated token validation

The portal uses automated rules to evaluate:

  • whether a submitted token is recognised;
  • whether the token has expired or been revoked;
  • whether the associated account is active; and
  • whether sufficient shared quota remains.

These checks determine whether a new API submission may proceed and whether a use is deducted from the account's allowance.

This processing is necessary to provide and secure the Service and to administer our contract with you. We do not use token-validation information for advertising or behavioural profiling.

We do not consider these checks to constitute solely automated decision-making producing legal or similarly significant effects under UK data-protection law.

10. Who we share personal data with

We may disclose personal data to:

  • cloud-hosting, database, networking, backup, monitoring and email-delivery providers acting on our instructions;
  • professional advisers, insurers, accountants, auditors and legal advisers where reasonably necessary;
  • law-enforcement bodies, courts, regulators or public authorities where disclosure is required by law or reasonably necessary to protect legal rights or security; and
  • a purchaser, investor or successor organisation in connection with a proposed or completed merger, financing, restructuring or transfer of all or part of our business, subject to appropriate confidentiality protections.

Our service providers include Amazon Web Services for infrastructure and transactional-email services. We do not sell personal data.

11. International transfers

Our primary production systems are intended to be hosted in the United Kingdom. However, some service providers or their subprocessors may process or access personal data from other countries.

Where personal data is transferred outside the United Kingdom, we use a transfer mechanism recognised under UK data-protection law where required. This may include transfer to a country covered by UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or another lawful transfer mechanism.

You may contact us for further information about the safeguards applying to an international transfer.

12. How long we keep personal data

We retain personal data only for as long as it is reasonably required for the purposes described in this Privacy Notice.

Information Retention period
Active account information For the life of the account
Direct account identifiers following confirmed deletion Removed or anonymised immediately, except where continued retention is legally required
Simulation parameters, runtime logs, results and selected-stream temporary remnants 14 days, after which they are deleted under the simulation API's artifact-retention process
Minimal simulation run and event metadata 365 days, after which it is deleted
Token metadata, validation events, Terms and Privacy Notice records, and quota-adjustment audit records For as long as reasonably needed for contractual, security, audit or legal purposes; direct identifiers are removed or anonymised when an account is deleted
Routine authentication, rate-limit and security logs For as long as reasonably needed to operate and secure the Service, or longer where required to investigate an incident or misuse
Support and data-rights correspondence For as long as reasonably needed to resolve the matter, meet legal obligations or establish, exercise or defend legal claims
Backup copies Until overwritten through the normal backup cycle

We may retain particular records for longer where necessary to investigate a security incident, comply with law, resolve a dispute or establish, exercise or defend a legal claim.

13. Account deletion

You may request account deletion through the token dashboard.

Confirmed account deletion:

  • disables login to the portal;
  • permanently revokes API tokens associated with the account;
  • removes or anonymises your email address and name;
  • clears source IP addresses held in legal-acceptance records; and
  • records the date on which deletion was requested.

Certain token, quota, validation, security and legal-acceptance records may be retained in anonymised, pseudonymised or access-restricted form for the applicable retention period where necessary for security, audit, legal compliance or legal claims.

Deleting your portal account may not immediately delete simulation requests, results or operational records stored separately by the simulation API. That information is handled under the 14-day artifact and 365-day minimal metadata periods above.

Account deletion does not require the immediate removal of information from encrypted backups. Backup copies are removed when the applicable backup is overwritten through the normal backup cycle.

14. Your data-protection rights

Depending on the circumstances and the lawful basis being used, you may have the right to:

  • request access to the personal data we hold about you;
  • ask us to correct inaccurate or incomplete personal data;
  • ask us to erase your personal data;
  • ask us to restrict how we use your personal data;
  • receive certain personal data in a structured, commonly used and machine-readable format;
  • object to processing based on our legitimate interests; and
  • complain about how we have handled your personal data.

These rights are not absolute and may not apply in every circumstance.

Your right to object: You may object to processing based on our legitimate interests. We will stop the relevant processing unless we have compelling legitimate grounds to continue or the processing is required for the establishment, exercise or defence of legal claims.

You may download a copy of your portal data through the token dashboard.

We may need to ask for information to verify your identity before responding to a request.

15. Cookies

The portal uses only cookies that are necessary for authentication, account security and protection against forged requests. We do not currently use advertising, behavioural-tracking or analytics cookies.

Cookie Purpose Duration
sessionid Maintains your authenticated session Up to 2 weeks, or until you sign out
csrftoken Protects forms and account actions against cross-site request forgery Up to 1 year
dandeliion_simulator Holds encrypted, short-lived simulator access for the signed-in user and browser Up to 24 hours, or until you sign out

These cookies are necessary to provide and secure the Service and therefore cannot normally be disabled through the portal. You may configure your browser to block them, but doing so may prevent registration, login, token management or browser-based simulation access from functioning correctly. Clearing the simulator cookie, signing out or changing browsers makes affected runs inaccessible through the portal.

16. Security

We use appropriate technical and organisational measures designed to protect personal data. These include encrypted network connections, secure password hashing, cryptographic token validation, restricted administrative access, multi-factor protection for administrative accounts, security logging and rate limiting, database and infrastructure access controls, and procedures intended to prevent API-token secrets from being stored or logged.

No internet-based service can guarantee absolute security.

17. Children

The Service is intended for users aged 18 or over. We do not knowingly permit children to create portal accounts.

18. Complaints

You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection:

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk

19. Changes to this Privacy Notice

We may update this Privacy Notice to reflect changes to the Service, our processing activities, service providers or applicable law.

The current version will be published on this page. Where a change materially affects how we use personal data, we will take reasonable steps to bring it to the attention of registered users.

You may be required to acknowledge an updated Privacy Notice before you can create or manage API tokens.

20. Contact details

DandeLiion Technologies Limited
Company number: 17169962
Registered office: 19 Water Lilies, Bristol, United Kingdom, BS11 0GJ
© 2026 DandeLiion Technologies LtdTerms · Privacy · Documentation