Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

Privacy Policy

This Privacy Policy defines how anDREa B.V. (anDREa) collects, processes, and safeguards personal data across the myDRE platform (mydre.org) and the research support portal (support.mydre.org). Operating as a cloud-native Shared Tenant infrastructure, our data handling architecture is mapped against ISO 27001:2023 (A.05.34 - Privacy and Protection of PII) and NIS 2 governance frameworks.

This policy undergoes mandatory review and updating at least annually or immediately following significant operational changes.


Data Scope

This policy applies strictly to online data interactions, account telemetry, and visitor traffic across our public and authenticated web systems. It does not apply to offline collection channels or data processed within isolated research Workspaces.

Tenant-Driven Operations

anDREa acts strictly under the legal instruction of its institutional clients (Tenants).

  • Consent Enforced: A platform user account is generated only after an individual explicitly reviews and consents to these privacy terms.
  • Granular Transparency: The technical reasons for capturing data are detailed at the exact point of ingestion.

2. Information Ingestion Channels

  • Direct Inquiry Data: If you submit an inquiry or log an incident, anDREa receives your name, business email, telephone number, message contents, and any attachments you choose to upload.
  • Account Registration Tracking: Initial account enrollment captures your full name, direct contact information, telephone number (for verification routing), or a backup recovery email address.

Technical System Log Files

Like standard enterprise cloud hosting infrastructures, mydre.org and andrea-cloud.eu maintain automated system log files for security analysis and platform administration.

  • Telemetry Collected: Captures Internet Protocol (IP) addresses, browser metadata, Internet Service Provider (ISP) designations, date/time stamps, referring/exit pages, and basic click tracking.
  • Anonymization Boundary: This baseline analytics telemetry is structurally separated and is not linked to any personally identifiable information (PII).

3. How We Process and Use Information

anDREa leverages collected metadata to maintain platform availability, operational compliance, and security assurance:

  • Provisioning: Initializing, operating, and maintaining the myDRE ecosystem.
  • Optimization: Analyzing platform usage patterns to drive functional scaling and performance tuning.
  • Security & Verification: Executing behavioral auditing to detect, isolate, and prevent fraudulent activity or access exploits.
  • System Communications: Dispatching mandatory security updates, administrative alerts, and system-level notifications.

4. Comprehensive Data Inventory Matrix

Data TypeTechnical Details & Operational PurposeSecurity Classification
Personal IdentifiersFull name, business email address, and telephone number captured during enrollment. Essential to establish verifiable compliance baselines.High / Confidential (Personnel & corporate contract bounds)
Correspondence EmailLeverages the Azure Entra ID "Other Email" field. Used to route critical system mail and uniquely identify users across the tenant. Requires ongoing validation.Medium / Restricted
Account CredentialsUnique usernames (@mydre.org), hashed passwords, and Multi-Factor Authentication (MFA) metadata (including geo-location indicators, application context, and number matching parameters).High / Confidential (Critical access control asset)
Account Status / RoleVerifiable logging of a user's multi-tenant Workspace memberships paired with their explicit authorization roles (e.g., Accountable, Privileged Member).Medium / Restricted
Activity & Interaction LogsComprehensive audit trail: Entra ID sign-ins, PIM role activations, data ingress/egress requests, membership changes, resource provisioning events, and firewall ACL modifications. Forensic Retention: 2 years hot, minimum 7 years archived.High / Confidential (Forensic ledger integrity)
Support & Ticket DataOperational support data captured via Zoho Desk, including user names, emails, message text, and troubleshooting attachments.Medium / Restricted
Telemetry & CookiesAnalytical and functional cookies (e.g., ARRAffinity for load balancing; ai_session/ai_user for Application Insights tracking) mapping anonymous, unique session tokens to analyze volume.Low / Public (Anonymized usage analytics)

5. Regulatory Disclosures & Subject Rights

  • Data Monetization (CCPA): anDREa does not sell, lease, or commercially exploit any personal data, analytical metadata, or workspace telemetry.
  • Data Subject Rights (GDPR / AVG): Users retain comprehensive rights to access, rectify, restrict, or erase their platform account information. The legal processes and exceptions governing these parameters are defined inside the formal Data Processing Agreement (specimen).

Executive Inquiries & Support Portal Protocol

To submit a formal privacy request, log an access rights challenge, or contact our security team:

  1. Navigate to the secure myDRE Support Portal.
  2. Select Add ticket and choose the myDRE department routing template.
  3. Complete the structured privacy intake form and submit.