Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

Data Handling Policy

1. Introduction and Regulatory Framework

anDREa B.V. (hereafter referred to as anDREa) is committed to protecting the data, confidentiality, and privacy of all stakeholders. To ensure a compliant cloud environment, anDREa maintains a comprehensive GDPR Compliance Assessment for the myDRE platform. This framework clearly outlines the technical evidence myDRE provides, alongside the corresponding obligations that institutional end-users must fulfill to remain fully GDPR-compliant.

1.1 Scope and Enforcement

This Data Handling Policy establishes the operational constraints and protective measures governing how information assets are managed. These rules apply universally to:

  • Full-time and part-time employees.
  • Temporary staff, interns, and external consultants.
  • Third-party contractors and service providers.

1.2 Policy Maintenance

This document is treated as a living control framework. It is formally reviewed, validated, and updated at least annually or immediately following significant architectural, legislative, or operational changes within anDREa's core environments.


2. Core Data Handling Directives

This policy covers all categories of data processed within anDREa’s infrastructure.

Foundational Privacy Status: anDREa operates strictly as a Data Processor (under GDPR definitions) and never as the Data Controller for information stored within collaborative environments.

To maintain strict tenant isolation and respect data sovereignty, anDREa enforces the following operational boundaries:

  • Strict Non-Intervention Baseline: Data stored within a myDRE Workspace—whether privacy-sensitive, intellectual property, or raw telemetry—must never be accessed, modified, or interacted with by anDREa personnel unless explicitly instructed by authorized customer roles.
  • Mandatory Ticket Tracking: Any authorized technical interaction, data recovery assistance, or structural manipulation performed by anDREa support staff must be documented within our central ticketing ecosystem.
  • Traceable Authorization Trail: Technical tasks may only begin after receiving explicit, written instructions via official email channels or authorized platform submission forms. These instructions must be fully traceable back to the verified identity of the requester.
  • Direct User Access Requests: myDRE platform end-users can request access to their personal data portfolios or account parameters by submitting a formal written request directly to the Director of anDREa.

3. Escalation Boundaries and Data Access Scopes

Unless explicitly approved in writing by the Director of anDREa, no user data may be accessed or shared outside the standard operating conditions. Access profiles are restricted to predefined scopes:


┌────────────────────────────────────────────────────────────────────────┐
│                        Data Access Limitations                         │
├───────────────────────────┬────────────────────────────────────────────┤
│ Tenant Mandated Person    │ Restricted exclusively to:                 │
│                           │ • Meta-data regarding their own employees  │
│                           │   (workspace history, access maps).        │
│                           │ • Content/Workspaces hosted strictly within│
│                           │   their specific Tenant Subscriptions.     │
├───────────────────────────┼────────────────────────────────────────────┤
│ Workspace Accountable /   │ Restricted exclusively to:                 │
│ Privileged Member         │ • Data, files, and logs belonging directly │
│                           │   to their assigned Workspace(s).          │
└───────────────────────────┴────────────────────────────────────────────┘

  • The Escalation Rule: If anDREa support engineers encounter any ambiguity, edge case, or conflicting access request, they must immediately pause the workflow and contact the Director of anDREa for formal verification and authorization.

4. Governance Registries and Audit Evidence

To demonstrate active compliance and data handling controls to external third-party auditors, the following validation logs are maintained:

  • The GDPR Compliance Assessment: The foundational accountability register mapping data responsibilities between anDREa and its clients is documented in GDPR Compliance Assessment.
  • Support Ticket Registers: Auditable technical communication records linking all workspace maintenance actions directly to verified customer approval forms (Authorized Support Personnel Only).
  • Director Approval Vault: Secure records documenting exceptional access permissions or structural overrides authorized by the Director.