Privacy Policy
This page is a working draft published so the site's footer links resolve. It is not final and is not legal advice. Items in [BRACKETS] require input from DVARA and its counsel, and every factual statement (subprocessors, retention periods, transfer mechanisms) must be confirmed against current operations before this page is considered effective. Do not rely on it until the DRAFT banner is removed.
Effective date: [EFFECTIVE DATE]
Controller: DVARA Labs, Inc., a Delaware corporation, registered office c/o Resident Agents Inc., 8 The Green, Ste. R, Dover, DE 19901, United States ("DVARA," "we," "us"). Contact: privacy@dvarahq.com.
This Privacy Policy explains how we handle personal data when you visit our websites (dvarahq.com and its subdomains), use the assessment tools on them, or use the DVARA platform. It reflects the two distinct roles we play:
- DVARA as controller — for website visitors, people who request a trial or a demo, billing and administrative contacts, support, and marketing. This Policy governs that processing.
- DVARA as processor — for content our customers route through a deployment we operate on their behalf ("Managed Hosting") (prompts, completions, tool calls, and audit records derived from them — "Customer Content"). That processing is governed by our customers' instructions and our Data Processing Agreement ("DPA"), not by this Policy. If your data was submitted to DVARA by one of our customers, that customer is the controller — please direct privacy requests to them; we will assist them in responding.
- Self-hosted deployments — Customer Content in self-hosted installations never reaches DVARA. Telemetry from self-hosted software is opt-in and off by default.
1. Personal Data We Collect (as Controller)
| Category | Examples | Source |
|---|---|---|
| Contact and administrative data | Name, work email, company, role; credentials issued for a deployment's administrative console | You, when you request a trial, a demo, or a licence |
| Enquiry form submissions | First and last name, work email, company, team size, and anything you write in the message field, together with which form you used (trial, demo, or sales) | You, through the enquiry form available on every page |
| Assessment tool submissions | Your email address, plus the derived summary only: your coverage band, the number of gaps, and the count of gaps per category (Production-Readiness Scorecard) or which Article 50 paragraphs your facts triggered, your declared role, and whether you reported a system inventory (Article 50 Exposure Check). The answers themselves are never transmitted — scoring runs in your browser and the text of what you selected does not leave it. | You, only if you ask for the results by email |
| Billing data | Billing contact, billing address, purchase-order and invoice records | You, on an Order Form |
| Usage and telemetry (Managed Hosting) | Feature usage events, request counts and token volumes, consumption against agreed limits, dashboard activity, log and diagnostic data including IP address and user agent | Automatically |
| Website analytics | Pages viewed, referrer, approximate location (from IP), device/browser type | Automatically, via Google Analytics |
| Visitor identification | IP address, and the company it is associated with by our provider, together with the pages that visit covered | Automatically, via Leadfeeder |
| Support and communications | Emails to support/sales, scheduler bookings (via Zoho), call notes | You |
| Marketing | Newsletter subscription, content downloads | You |
We do not intentionally collect special-category/sensitive data about you as controller, and we ask that you not include it in support communications.
Operational note on the assessment tools. The Production-Readiness Scorecard and the Article 50 Exposure Check score entirely in your browser. Nothing is transmitted unless you enter an email address to receive a copy, and what is then sent is the derived summary described in the table above — never your individual answers, which the submission has nowhere to put. If you never enter an address, nothing about your use of either tool reaches us beyond the website analytics described below, which record that a sheet was started and finished and none of its content.
Operational note on Customer Content. A self-managed DVARA install runs entirely in the customer's own infrastructure, so the audit records of governed traffic stay there and never reach us. Where DVARA operates the platform on a customer's behalf under a managed-hosting agreement, audit records are retained for the period set in that agreement and may include redacted or tokenized content depending on the customer's configuration. That is processor-role data governed by the DPA, not by this Policy.
2. How We Use Personal Data
- Provide, operate, secure, and support the Services (contract performance).
- Invoice and administer subscriptions (contract performance / legal obligation).
- Monitor service health, prevent abuse and fraud, and enforce our Terms (legitimate interests).
- Improve the Services using telemetry and aggregated statistics (legitimate interests). We do not use Customer Content to train machine-learning models.
- Send service notices (contract performance) and, with your consent or as otherwise permitted, product news — every marketing email includes an unsubscribe link (consent / legitimate interests).
- Comply with law, respond to lawful requests, and protect rights (legal obligation / legitimate interests).
We do not sell personal data and do not share it for cross-context behavioral advertising.
3. How We Share Personal Data
We share personal data with service providers (subprocessors, for processor-role data) bound by contract to process only on our instructions:
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare | Website and documentation hosting, DNS and CDN; the lead-capture endpoint (Workers) and the database storing its submissions (D1) | United States |
| DigitalOcean | Cloud infrastructure and managed PostgreSQL for Managed Hosting deployments | United States |
| Formspree | Receives and forwards submissions from the enquiry form on this site | United States |
| Google Analytics | Website analytics | United States |
| Leadfeeder (Dealfront) | Identifies the company associated with a website visitor's IP address | [CONFIRM PROCESSING LOCATION AND TRANSFER MECHANISM] |
| Resend | Transactional email delivery | United States |
| Zoho | Demo and sales scheduling | United States |
Note on Cloudflare. Data submitted through the assessment tools on this site (for example the Production-Readiness Scorecard and the EU AI Act Article 50 Exposure Check) is stored in a Cloudflare D1 database whose primary region is North America. Separately, because Cloudflare operates a global edge network, the connection itself is terminated at the data centre nearest the visitor — so a visitor's IP address is processed at that location before the request reaches the United States. We do not currently offer a non-US storage region for these submissions.
[ATTORNEY: confirm whether a payment processor is used for invoicing and, if so, add it to the table above. DVARA takes no card payments through the website, so no card data is collected here — the previous draft listed Stripe on the assumption of a self-serve checkout that does not exist.]
The authoritative, current subprocessor list is maintained by DVARA and available on request; DPA customers receive advance notice of additions.
We may also disclose personal data: to comply with law or valid legal process; to protect the rights, safety, or property of DVARA, our customers, or others; and in connection with a merger, financing, or sale of assets, with notice of any resulting change in this Policy.
4. International Transfers
We are based in the United States, and Managed Hosting deployments are operated in the United States unless the Order Form says otherwise. Where personal data of EEA, UK, or Swiss individuals is transferred internationally, we rely on the Standard Contractual Clauses and implement supplementary safeguards as appropriate. [ATTORNEY: confirm transfer mechanism — SCCs vs EU–US Data Privacy Framework certification.] We will not represent residency options that are not actually available; the regions available for a Managed Hosting deployment are those stated in the Order Form.
5. Retention
- Contact, administrative and billing data: for the life of the customer relationship and 7 years thereafter, as required for tax and accounting.
- Telemetry and logs: 12 months.
- Website analytics: up to 14 months, per the Google Analytics configuration.
- Support communications: 24 months.
- Assessment tool submissions (Production-Readiness Scorecard, EU AI Act Article 50 Exposure Check): retained until you ask us to delete them. We do not apply an automatic deletion window to these submissions, and we would rather tell you that than publish a period we do not enforce. We store the email address you give us, a summary of your result, and basic request metadata (IP address and browser user-agent); we never receive or store your individual answers. To have a submission removed, email
privacy@dvarahq.com— see Section 6. - Enquiry form submissions: retained until you ask us to delete them, on the same basis as assessment tool submissions above — no automatic deletion window applies. A copy also sits in the mailbox the form notifies and with the form provider, and a deletion request under Section 6 covers all of them.
- Customer Content audit records (processor role): only where DVARA operates the platform on a customer's behalf under a managed-hosting agreement — retained for the period set in that agreement, and in any event deleted within 30 days of termination. Self-managed deployments keep their audit records in the customer's own infrastructure and we hold no copy.
- Trial licences: a trial unlocks the self-hosted software for 30 days. The software runs in your infrastructure and the traffic it governs never reaches us; what we hold is the contact record from your request, kept with the sales and support communications above.
Scope of an assessment-tool deletion. Removing the stored submission does not by itself reach two other copies that exist by design: the internal notification email sent to our team when you submit, which sits in a mailbox with its own retention, and the delivery logs kept by our email provider. A deletion request under Section 6 covers all three.
6. Your Rights
Depending on your location, you may have rights to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time (without affecting prior processing).
- EEA / UK: rights under the GDPR / UK GDPR, including the right to complain to your supervisory authority. Our legal bases are noted in Section 2. [ATTORNEY: confirm whether an EU/UK representative under Art. 27 is required.]
- California: rights under the CCPA/CPRA to know, delete, correct, and opt out of sale/sharing (we do not sell or share as defined), and to non-discrimination.
- Other jurisdictions (for example, other US state privacy laws, Canada PIPEDA): equivalent rights as applicable.
Exercise rights by emailing privacy@dvarahq.com. We will verify your identity and respond within the legally required period. If we hold your data as a processor for one of our customers, we will refer your request to that customer.
7. Cookies and Similar Technologies
We use strictly necessary cookies for authentication and session management, and analytics cookies set by Google Analytics to understand website usage. Where required (for example, for EEA/UK visitors), we present a cookie-consent mechanism before setting non-essential cookies. [ATTORNEY: confirm cookie-consent banner scope for the final analytics configuration.] You can also control cookies through your browser settings.
8. Security
We apply administrative, technical, and physical safeguards appropriate to the data we process, including encryption in transit (TLS) and at rest, access controls, and audit logging. No system is perfectly secure; we will notify affected customers and authorities of personal-data breaches as required by law.
9. Children
The Services are not directed to children under 18, and we do not knowingly collect their data. If you believe a child has provided personal data, contact us and we will delete it.
10. Changes to This Policy
We will post updates here and revise the effective date; material changes will be notified by email or in-product notice at least 14 days in advance. The current version always governs.
11. Contact
DVARA Labs, Inc.
Registered office: c/o Resident Agents Inc., 8 The Green, Ste. R, Dover, DE 19901, United States
privacy@dvarahq.com
See also the Terms of Service.