Regulatory
GDPR & Compliance
Plain-English summary of the regulations DRIVUNO operates under, what we already do, and what we're working toward.
Status today
Your rights as a data subject
- Access — request a copy of your data via the GDPR export in your account settings.
- Rectification — update your profile and settings at any time.
- Erasure — request account deletion (30-day grace, then irreversible cryptographic erasure).
- Restriction — pause processing by deactivating sharing and disabling automation.
- Portability — the GDPR export delivers your data in a machine-readable format with a manifest.
- Objection — opt out of any non-essential processing.
- Withdraw consent — revoke optional channels (SMS, email recovery) without affecting your account.
Lawful bases we rely on
- Contract — to deliver the service you signed up for.
- Legal obligation — for billing records, tax, and disclosure requirements.
- Legitimate interest — for security event logging and abuse prevention.
- Consent — for optional channels (recovery email/SMS) and product communications.
International transfers
EU customer data is processed in the EU by default. Where a subprocessor operates outside the EU, transfers are governed by Standard Contractual Clauses with supplementary measures (encryption-at-rest, encryption-in-transit, and — critically — the client-side encryption that means no transferred bytes are readable plaintext).
API & webhook processing scope
For controllers integrating the DRIVUNO API or webhooks (including via Zapier/Make), the processing scope is limited to metadata and lifecycle events — file names, object IDs, timestamps, and event types. Decrypted file, message, or workspace content is never included in an API response or webhook payload, which simplifies your own data-processing assessment of the integration.
Assurance & continuous verification
Beyond policy commitments, we run automated technical checks on every change:
- An automated security test suite runs in CI on every change, covering access-control isolation between accounts.
- A fuzzing campaign continuously exercises database row-level security and remote procedure calls to probe for unintended data exposure.
- A dedicated CI gate blocks release of any change that would let sensitive data leave the device unencrypted, before it can reach production.
We do not currently hold SOC 2 or ISO 27001 certification; see the roadmap below for status.
Compliance roadmap
Due diligence pack
Everything a procurement or security team usually asks for, published and downloadable without a call or an NDA.
- Signable GDPR DPA (PDF) — art. 28 clauses, EU SCCs Module Two, UK IDTA, pre-filled with your entity and pre-signed by us.
- Sub-processor register — DPA Annex III, with a 30-day advance-notice commitment.
- Retention & deletion schedule — DPA Annex IV, legal basis and deletion mechanism per data category.
- Security architecture and threat model — the substance of DPA Annex II (technical and organisational measures).
- Vulnerability disclosure policy and security changelog.
Contact our Data Protection Officer: dpo@drivuno.com. See /privacy, /dpa, and /gdpr for the full policy text.