Regulatory

GDPR & Compliance

Plain-English summary of the regulations DRIVUNO operates under, what we already do, and what we're working toward.

Status today

GDPR (EU 2016/679)
DRIVUNO is built as a data processor in GDPR terms. The architecture makes data minimization the default. Data Processing Agreement available at /dpa.
Swiss FADP
Coverage equivalent to GDPR for Swiss data subjects.
UK GDPR + DPA 2018
Same processing standards applied to UK data subjects.
ePrivacy
We use no advertising cookies. Analytics are cookieless and privacy-preserving.

Your rights as a data subject

  • Access — request a copy of your data via the GDPR export in your account settings.
  • Rectification — update your profile and settings at any time.
  • Erasure — request account deletion (30-day grace, then irreversible cryptographic erasure).
  • Restriction — pause processing by deactivating sharing and disabling automation.
  • Portability — the GDPR export delivers your data in a machine-readable format with a manifest.
  • Objection — opt out of any non-essential processing.
  • Withdraw consent — revoke optional channels (SMS, email recovery) without affecting your account.

Lawful bases we rely on

  • Contract — to deliver the service you signed up for.
  • Legal obligation — for billing records, tax, and disclosure requirements.
  • Legitimate interest — for security event logging and abuse prevention.
  • Consent — for optional channels (recovery email/SMS) and product communications.

International transfers

EU customer data is processed in the EU by default. Where a subprocessor operates outside the EU, transfers are governed by Standard Contractual Clauses with supplementary measures (encryption-at-rest, encryption-in-transit, and — critically — the client-side encryption that means no transferred bytes are readable plaintext).

API & webhook processing scope

For controllers integrating the DRIVUNO API or webhooks (including via Zapier/Make), the processing scope is limited to metadata and lifecycle events — file names, object IDs, timestamps, and event types. Decrypted file, message, or workspace content is never included in an API response or webhook payload, which simplifies your own data-processing assessment of the integration.

Assurance & continuous verification

Beyond policy commitments, we run automated technical checks on every change:

  • An automated security test suite runs in CI on every change, covering access-control isolation between accounts.
  • A fuzzing campaign continuously exercises database row-level security and remote procedure calls to probe for unintended data exposure.
  • A dedicated CI gate blocks release of any change that would let sensitive data leave the device unencrypted, before it can reach production.

We do not currently hold SOC 2 or ISO 27001 certification; see the roadmap below for status.

Compliance roadmap

In progress
SOC 2 Type I readiness assessment · ISO 27001 gap analysis · external cryptography review.
Planned
SOC 2 Type II · ISO 27001 certification · regional data-residency commitments (Japan, APAC) · HIPAA BAA for Business plans on request.

Due diligence pack

Everything a procurement or security team usually asks for, published and downloadable without a call or an NDA.

Contact our Data Protection Officer: dpo@drivuno.com. See /privacy, /dpa, and /gdpr for the full policy text.

Encrypted on your device · upload in 1 click
Upload