NEWFSMA 204 & SQF Edition 9 Evidence Templates are now live.Run free spreadsheet audit →
Home/Legal/Privacy Policy
DATA PROTECTION & PRIVACY

Privacy Policy

Effective Date: September 5, 2026 Entity: DragonVerse Media Inc. (Colorado, USA) Compliance: GDPR, CCPA/CPRA, SOC 2 Ready
Table of Contents

1. Scope & Data Processing Roles

DragonVerse Media Inc. ("Evidlane", "we", or "us") is committed to protecting the privacy and security of corporate food manufacturer data, quality assurance records, and supplier documents processed on the Evidlane platform (getevidlane.com).

Under global data protection laws (including the EU/UK General Data Protection Regulation and California Consumer Privacy Act):

  • Customer as Data Controller: When our customers upload vendor contact details, specifications, allergen records, and audit certificates, the customer is the Data Controller.
  • Evidlane as Data Processor: Evidlane acts as the Data Processor, handling Customer Content solely pursuant to customer instructions, our Data Processing Addendum (DPA), and these terms.

2. Information We Collect & Ingest

We collect only the minimum information necessary to orchestrate supplier compliance and evidence collection:

Workspace Account Data
Account work email, cryptographically hashed passwords, workspace role (Owner, Admin, QA Reviewer), organization profile.
Supplier Records & Files
Vendor company name, site location, contact email, GFSI certificates, raw material specs, COAs, allergen disclosures, and expiration dates.
Immutable Audit Logs
Timestamps, reviewer user IDs, approval decisions, rejection rationale, token generation events, and ZIP export history.
Billing & Transaction Data
Stripe Customer IDs, subscription plan tiers, invoice history. We never receive or store raw credit card numbers.

3. Purpose & Legal Basis for Processing

We process data based on contractual necessity, legitimate business interests, and compliance with statutory recordkeeping requirements:

  • To provide automated vendor evidence collection links with 7-day cryptographic single-use tokens.
  • To send automated 30, 14, 7, and 0-day certificate expiration reminders via our transactional email engine.
  • To execute background antivirus and payload validation scans (via ClamAV) before files are reviewed by QA teams.
  • To compile one-click audit ZIP export packages for SQF, BRCGS, and FDA FSMA audits.
✓ Strict Anti-Monetization Commitment: We NEVER sell, rent, monetize, or share your proprietary supplier records or audit data with advertisers, third-party brokers, or AI model trainers.

4. Authorized Infrastructure Subprocessors

Evidlane engages trusted infrastructure sub-processors subject to strict data processing agreements and enterprise security requirements:

SubprocessorPurposeData Location
Cloudflare R2Encrypted private object storage for vendor documentsUnited States / Global Edge
Neon Serverless PostgresTenant-isolated transactional database & audit ledgerUnited States (AWS us-east-1)
Brevo (Sendinblue)Automated reminder & QA review transactional email dispatchUnited States / EU
Stripe, Inc.PCI-DSS Tier 1 subscription billing & invoicesUnited States
Vercel, Inc.Application hosting, Edge compute, and DDoS mitigationGlobal Edge Network

5. Security Controls & Data Retention Schedule

Zero-Trust Architecture: Data is encrypted in transit using TLS 1.3 and at rest using AES-256. Files in Cloudflare R2 are accessible only via ephemeral presigned URLs with 300-second lifetimes.

Upload Token Expiry: Vendor upload links utilize 32-byte cryptographically random tokens stored strictly as SHA-256 hashes. Unused upload tokens automatically expire in 7 days.

Retention & Account Closure: Customer data is retained during the active lifecycle of your workspace. Upon workspace termination, data is permanently erased within 30 days following an export grace window.

6. Global Privacy Rights (GDPR & CCPA/CPRA)

Depending on your jurisdiction, you and your authorized data subjects have specific rights regarding your personal information:

  • Right to Access & Portability: Request a complete copy of all data and audit trails stored in machine-readable JSON/ZIP formats.
  • Right to Rectification: Update or correct inaccurate supplier contact details or organization metadata.
  • Right to Erasure ("Right to be Forgotten"): Request the permanent deletion of user accounts and associated records.
  • Right to Restrict or Object to Processing: Limit the processing of specific personal records.

7. Data Protection Officer & Privacy Inquiries

For privacy questions, data subject requests, or to execute a countersigned Data Processing Addendum, contact our security and privacy team:

Privacy & Compliance Office

DragonVerse Media Inc. · Attn: Data Privacy Officer
Email: privacy@getevidlane.com / defhnhqf@gmail.com
Address: DragonVerse Media Inc., Colorado, United States
Website: https://getevidlane.com