Privacy Policy
1. Scope & Data Processing Roles
DragonVerse Media Inc. ("Evidlane", "we", or "us") is committed to protecting the privacy and security of corporate food manufacturer data, quality assurance records, and supplier documents processed on the Evidlane platform (getevidlane.com).
Under global data protection laws (including the EU/UK General Data Protection Regulation and California Consumer Privacy Act):
- Customer as Data Controller: When our customers upload vendor contact details, specifications, allergen records, and audit certificates, the customer is the Data Controller.
- Evidlane as Data Processor: Evidlane acts as the Data Processor, handling Customer Content solely pursuant to customer instructions, our Data Processing Addendum (DPA), and these terms.
2. Information We Collect & Ingest
We collect only the minimum information necessary to orchestrate supplier compliance and evidence collection:
3. Purpose & Legal Basis for Processing
We process data based on contractual necessity, legitimate business interests, and compliance with statutory recordkeeping requirements:
- To provide automated vendor evidence collection links with 7-day cryptographic single-use tokens.
- To send automated 30, 14, 7, and 0-day certificate expiration reminders via our transactional email engine.
- To execute background antivirus and payload validation scans (via ClamAV) before files are reviewed by QA teams.
- To compile one-click audit ZIP export packages for SQF, BRCGS, and FDA FSMA audits.
4. Authorized Infrastructure Subprocessors
Evidlane engages trusted infrastructure sub-processors subject to strict data processing agreements and enterprise security requirements:
| Subprocessor | Purpose | Data Location |
|---|---|---|
| Cloudflare R2 | Encrypted private object storage for vendor documents | United States / Global Edge |
| Neon Serverless Postgres | Tenant-isolated transactional database & audit ledger | United States (AWS us-east-1) |
| Brevo (Sendinblue) | Automated reminder & QA review transactional email dispatch | United States / EU |
| Stripe, Inc. | PCI-DSS Tier 1 subscription billing & invoices | United States |
| Vercel, Inc. | Application hosting, Edge compute, and DDoS mitigation | Global Edge Network |
5. Security Controls & Data Retention Schedule
Zero-Trust Architecture: Data is encrypted in transit using TLS 1.3 and at rest using AES-256. Files in Cloudflare R2 are accessible only via ephemeral presigned URLs with 300-second lifetimes.
Upload Token Expiry: Vendor upload links utilize 32-byte cryptographically random tokens stored strictly as SHA-256 hashes. Unused upload tokens automatically expire in 7 days.
Retention & Account Closure: Customer data is retained during the active lifecycle of your workspace. Upon workspace termination, data is permanently erased within 30 days following an export grace window.
6. Global Privacy Rights (GDPR & CCPA/CPRA)
Depending on your jurisdiction, you and your authorized data subjects have specific rights regarding your personal information:
- Right to Access & Portability: Request a complete copy of all data and audit trails stored in machine-readable JSON/ZIP formats.
- Right to Rectification: Update or correct inaccurate supplier contact details or organization metadata.
- Right to Erasure ("Right to be Forgotten"): Request the permanent deletion of user accounts and associated records.
- Right to Restrict or Object to Processing: Limit the processing of specific personal records.
7. Data Protection Officer & Privacy Inquiries
For privacy questions, data subject requests, or to execute a countersigned Data Processing Addendum, contact our security and privacy team:
Privacy & Compliance Office
DragonVerse Media Inc. · Attn: Data Privacy Officer
Email: privacy@getevidlane.com / defhnhqf@gmail.com
Address: DragonVerse Media Inc., Colorado, United States
Website: https://getevidlane.com