Privacy

Privacy Policy

How Dralvia processes platform, website, support, and security-related data.

Last updated: 2026-07-06

Quick links

Public legal route map

These pages are intentionally crawlable and static so buyers, counsel, and operators can reach them without platform login or hash-route context.

Contact

For platform help, onboarding, or support requests, contact [email protected].

For policy, privacy, or contracting questions, contact [email protected].

For security disclosure, contact [email protected].

Controller and contacts

  • Quantabridge Innovations SRL, operating as Dralvia.
  • Registered office: Drumul Gura Calitei 4-32, Bl. 6, Sc. A, Et. 9, Ap. 134, Sector 3, Bucharest, Romania
  • Romanian Trade Register number: J40/13876/2023
  • Fiscal code / CUI: 48546300
  • Privacy and legal inquiries: [email protected]
  • No public DPO contact is currently published. Dralvia will publish one if and when a formal DPO appointment becomes required.

What Dralvia processes

  • Account and workspace metadata such as workspace identifiers, plan information, and administrative contacts.
  • Detection telemetry such as submitted URLs, domain signals, contract metadata, EvidencePack metadata, and support context.
  • Usage and quota metrics used for licensing, billing, platform security, and capacity planning.
  • Support, bug-report, and feedback communications.

Why Dralvia processes data

  • To deliver the security platform and supporting product workflows.
  • To investigate suspicious activity and generate explainable detection output.
  • To maintain billing, quota enforcement, platform integrity, and customer support.
  • To generate aggregated product analytics where consent or another valid legal basis exists.

Legal bases, recipients, transfers, and retention

Dralvia relies on contractual necessity, legitimate interests, consent where required for optional telemetry, and legal obligation where applicable.

Core recipients and subprocessors currently include Contabo GmbH for hosted infrastructure, Cloudflare, Inc. for DNS/edge security/CDN functions, and Google LLC for consent-gated docs analytics and Google-hosted assets where those services are requested. Customer-configured downstream systems operate under customer instructions and are not enabled globally by default.

Where data leaves the EEA or UK, Dralvia relies on provider contractual commitments, including SCC-based transfer terms where required, and reviews transfer posture as part of legal/vendor review. The public subprocessor page summarizes the current list.

EvidencePacks and transparency entries are retained for 24 months by default unless a contract or workspace configuration sets another period. Usage records are retained for 18 months, and support records for 24 months after closure, unless law or contract requires otherwise.

Rights and complaints

Data subjects may request access, correction, deletion, restriction, objection, or export where applicable. Requests should be sent to [email protected].

Data subjects may also complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania, www.dataprotection.ro, or to another competent supervisory authority where applicable.

Public-site position

The marketing site exists to explain the platform and direct visitors into the live product. Public legal pages live here so they are crawlable, linkable, and accessible without entering the platform console.

Platform legal center

The product platform also maintains legal-center routes for authenticated and guest users. Use the public pages here for external sharing and the live platform for operational/legal workflow context.