Data Protection Policy
This document defines anDREa B.V.’s (anDREa) framework for safeguarding data privacy and maintaining compliance with the General Data Protection Regulation (GDPR). It supports our governance requirements under A.05.34 - Privacy and protection of personal identifiable information (PII) and NIS 2.
This policy should be read in conjunction with the Data Handling Policy and undergoes mandatory review at least annually or upon significant infrastructure updates.
1. Governance & Data Responsibility Matrix
An independent GDPR Compliance Assessment has been conducted to delineate the technical boundaries of the myDRE platform. Responsibility for personal data depends on its classification:
| Data Type | anDREa Role | Tenant / Accountable Party Role |
|---|---|---|
| User Account Data (Identity data, profiles, and configuration settings) | Processor Acts strictly on the instructions of the Tenant. | Controller Retains legal ownership and accountability. |
| User Activity Logs (Audit trail records and platform actions) | Processor Collected to provide demonstrable compliance evidence. | Controller Retains legal ownership and accountability. |
| Data in Workspaces (Research assets, datasets, files) | Passive Processor Provides the secure infrastructure; cannot access or manipulate contents. | Controller Fully responsible for data governance and compliance. |
2. Core Data Protection Principles
In alignment with GDPR Article 5, all data operations within myDRE are systematically designed around six fundamental pillars:
- Lawfulness, Fairness, & Transparency: Data is processed legally and transparently, with explicit technical baselines provided to users.
- Purpose Limitation: Telemetry and user data are collected only for specified, legitimate operational purposes and never repurposed.
- Data Minimization: Processing is strictly limited to the minimum data necessary to run, secure, and verify the platform.
- Accuracy: Built-in validation pipelines ensure platform-managed identity and config data remain accurate and up-to-date.
- Storage Limitation: Identity information is kept only as long as necessary for the operational lifecycle, subject to specific regulatory archiving and audit logging baselines.
- Integrity & Confidentiality: State-of-the-art technical and organizational measures (TOMs) protect all information from unauthorized access, accidental loss, or tampering.
3. Data Subject Rights
Under the GDPR, platform users retain specific rights regarding their User Account Data.
These rights apply exclusively to platform-level user information managed by anDREa. They do not apply to data stored inside a research Workspace, which remains under the exclusive control of the respective Tenant. Exercise of rights may also be limited by anDREa's statutory duty to maintain unalterable forensic audit logs.
- Right to be Informed & Access: Users may request a transparent summary and copy of their stored personal data.
- Right to Rectification: Users can demand the correction of inaccurate data or the completion of incomplete profiles.
- Right to Erasure ("Forgotten"): Under specific conditions, users can request data deletion.
- Right to Restrict or Object: Users may challenge or object to certain processing workflows.
- Right to Data Portability: Users have the right to request a secure transfer of their profile data to another platform or organization.
- Automated Decision-Making Safeguards: Users have the right to challenge any algorithmic profiling or automated decisions if they suspect processing non-compliance.
4. Privacy Requests & Contact Protocol
To exercise any data subject rights or submit formal privacy inquiries, requests must be submitted through our secure support ecosystem:
- Navigate to the myDRE Support Portal.
- Click Add ticket.
- Select the anDREa Organization department.
- Provide the exact details of the request and submit.
Workspace Data Inquiries: If an inquiry concerns data residing inside a specific research Workspace, anDREa cannot modify or access it. However, you can contact us via the ticket protocol above, and we will route your request directly to the designated Data Controller for that Workspace.