Privacy Policy
This Privacy Policy defines how anDREa B.V. (anDREa) collects, processes, and safeguards personal data across the myDRE platform (mydre.org) and the research support portal (support.mydre.org). Operating as a cloud-native Shared Tenant infrastructure, our data handling architecture is mapped against ISO 27001:2023 (A.05.34 - Privacy and Protection of PII) and NIS 2 governance frameworks.
This policy undergoes mandatory review and updating at least annually or immediately following significant operational changes.
1. Compliance Framework & Consent
Data Scope
This policy applies strictly to online data interactions, account telemetry, and visitor traffic across our public and authenticated web systems. It does not apply to offline collection channels or data processed within isolated research Workspaces.
Tenant-Driven Operations
anDREa acts strictly under the legal instruction of its institutional clients (Tenants).
- Consent Enforced: A platform user account is generated only after an individual explicitly reviews and consents to these privacy terms.
- Granular Transparency: The technical reasons for capturing data are detailed at the exact point of ingestion.
2. Information Ingestion Channels
- Direct Inquiry Data: If you submit an inquiry or log an incident, anDREa receives your name, business email, telephone number, message contents, and any attachments you choose to upload.
- Account Registration Tracking: Initial account enrollment captures your full name, direct contact information, telephone number (for verification routing), or a backup recovery email address.
Technical System Log Files
Like standard enterprise cloud hosting infrastructures, mydre.org and andrea-cloud.eu maintain automated system log files for security analysis and platform administration.
- Telemetry Collected: Captures Internet Protocol (IP) addresses, browser metadata, Internet Service Provider (ISP) designations, date/time stamps, referring/exit pages, and basic click tracking.
- Anonymization Boundary: This baseline analytics telemetry is structurally separated and is not linked to any personally identifiable information (PII).
3. How We Process and Use Information
anDREa leverages collected metadata to maintain platform availability, operational compliance, and security assurance:
- Provisioning: Initializing, operating, and maintaining the myDRE ecosystem.
- Optimization: Analyzing platform usage patterns to drive functional scaling and performance tuning.
- Security & Verification: Executing behavioral auditing to detect, isolate, and prevent fraudulent activity or access exploits.
- System Communications: Dispatching mandatory security updates, administrative alerts, and system-level notifications.
4. Comprehensive Data Inventory Matrix
| Data Type | Technical Details & Operational Purpose | Security Classification |
|---|---|---|
| Personal Identifiers | Full name, business email address, and telephone number captured during enrollment. Essential to establish verifiable compliance baselines. | High / Confidential (Personnel & corporate contract bounds) |
| Correspondence Email | Leverages the Azure Entra ID "Other Email" field. Used to route critical system mail and uniquely identify users across the tenant. Requires ongoing validation. | Medium / Restricted |
| Account Credentials | Unique usernames (@mydre.org), hashed passwords, and Multi-Factor Authentication (MFA) metadata (including geo-location indicators, application context, and number matching parameters). | High / Confidential (Critical access control asset) |
| Account Status / Role | Verifiable logging of a user's multi-tenant Workspace memberships paired with their explicit authorization roles (e.g., Accountable, Privileged Member). | Medium / Restricted |
| Activity & Interaction Logs | Comprehensive audit trail: Entra ID sign-ins, PIM role activations, data ingress/egress requests, membership changes, resource provisioning events, and firewall ACL modifications. Forensic Retention: 2 years hot, minimum 7 years archived. | High / Confidential (Forensic ledger integrity) |
| Support & Ticket Data | Operational support data captured via Zoho Desk, including user names, emails, message text, and troubleshooting attachments. | Medium / Restricted |
| Telemetry & Cookies | Analytical and functional cookies (e.g., ARRAffinity for load balancing; ai_session/ai_user for Application Insights tracking) mapping anonymous, unique session tokens to analyze volume. | Low / Public (Anonymized usage analytics) |
5. Regulatory Disclosures & Subject Rights
- Data Monetization (CCPA): anDREa does not sell, lease, or commercially exploit any personal data, analytical metadata, or workspace telemetry.
- Data Subject Rights (GDPR / AVG): Users retain comprehensive rights to access, rectify, restrict, or erase their platform account information. The legal processes and exceptions governing these parameters are defined inside the formal Data Processing Agreement (specimen).
Executive Inquiries & Support Portal Protocol
To submit a formal privacy request, log an access rights challenge, or contact our security team:
- Navigate to the secure myDRE Support Portal.
- Select Add ticket and choose the myDRE department routing template.
- Complete the structured privacy intake form and submit.