PRIVACY
Your information should be handled with clarity.
Dryvn provides software for people operations, work, organizational change, and effectiveness. This notice explains how information is handled when you visit Dryvn, contact us, or use the Dryvn platform.
OVERVIEW
Privacy in plain language
Dryvn is operated by AAALABS TECHNOLOGIES LTD, company number 17270081, registered in England and Wales. This notice covers two related contexts: the public Dryvn website and the Dryvn SaaS platform used by customer organizations.
- Dryvn uses information to operate, secure, support, and improve the service and the business relationship around it.
- When an organization places workforce information in Dryvn, that organization determines its purpose and who is authorized to access it.
- Dryvn does not operate a business model based on selling personal information to advertisers or data brokers.
- Service providers may handle information where needed to deliver infrastructure, scheduling, communications, security, or professional support.
- Access to production services and customer information is restricted through technical and organizational controls.
- Questions about this notice or how information is handled can be sent through the Dryvn Contact page.
Collect what is needed to operate the relationship and service. Avoid collecting information simply because it can be collected.
Information Dryvn may collect
The information involved depends on whether you are browsing the website, requesting a conversation, creating or accessing an account, receiving support, or using Dryvn through a customer organization.
Information you provide directly
- Name, work email address, company, job title, and other business contact information
- Information submitted when requesting a demo, discussing a commercial relationship, or starting a trial
- Account and authentication information, including credentials and multi-factor authentication information where applicable
- Support requests, correspondence, and other information you choose to provide
- Information entered into Dryvn by an authorized user
Information generated when you use Dryvn
Dryvn may generate technical and operational records needed to run and protect the service.
- Authentication events and session activity
- Application and audit activity
- Browser, device, IP address, timestamp, and request information
- Security, diagnostic, error, and service-reliability information
Dryvn uses these categories to provide the service, protect accounts and infrastructure, troubleshoot problems, prevent abuse, and maintain operational evidence. It does not use them to create employee productivity profiles.
Information organizations place in Dryvn
Organizations may use Dryvn to manage information about employees, contractors, positions, organizational structures, time and work, change initiatives, and organizational-development activities.
When a company uses Dryvn to manage information about its workforce, that company determines why the information is used. Dryvn provides the platform and processes the information needed to deliver the service and support the customer relationship.
- Employee, contractor, contact, and employment records
- Jobs, grades, positions, managers, and reporting relationships
- Legal entities, organization units, locations, and related organizational context
- Schedules, attendance, time, assignments, work items, and reported work records
- Change-program, stakeholder, impact, readiness, intervention, and follow-up information
- Organizational-effectiveness signals, findings, actions, ownership, and follow-up
Dryvn provides the system. The customer controls the organizational purpose and authorized use of its workforce information.
How Dryvn uses information
Dryvn uses information for defined service, security, support, and business-relationship purposes rather than for unrelated advertising activity.
- Provide, operate, configure, and maintain the Dryvn service
- Authenticate users and maintain account, role, permission, and tenant context
- Respond to demo, commercial, service, and support requests
- Schedule meetings and provide relevant confirmations
- Administer subscriptions and customer relationships
- Protect accounts, systems, and infrastructure and detect abuse or security threats
- Maintain auditability, troubleshoot failures, and improve service reliability
- Send operational, security, account, or service communications
- Meet applicable contractual and legal obligations
Dryvn Copilot and AI processing
When an Authorized User starts a Copilot task, Dryvn processes the user's prompt, relevant selected conversation history, authorized tenant context, retrieved document excerpts, tool results, model output, credit and token usage, security and diagnostic metadata, and approval and audit metadata.
The customer determines the organizational purpose for workforce information; Dryvn processes that information to provide the contracted service. Authorized users choose the tasks they initiate, and the approved AI provider processes only the context submitted for inference.
Purpose
- Respond to the authorized user and analyse organizational context
- Draft requested material and select or propose approved Dryvn actions
- Maintain security, prevent abuse, and troubleshoot failures
- Meter Copilot Credits and preserve required approval and audit evidence
Context minimization
Pseudonymized information may remain personal information; pseudonymization is not the same as complete anonymization.
- Retrieve the minimum task-relevant authorized context
- Aggregate before individual detail where possible
- Redact identity fields or replace them with temporary pseudonymous references
- Exclude sensitive categories by default and rehydrate authorized display data locally
Managed-provider handling
Google Cloud is the managed AI service provider for standard Copilot processing and is listed in the Subprocessors directory. Provider request-response logging and persistent interaction storage are disabled. Limited provider security or abuse-monitoring processing may still apply under provider terms.
- Customer data is not used to train or fine-tune shared provider models without explicit permission
- Dryvn does not train shared Dryvn models on customer prompts, context, or outputs without explicit written opt-in
- Standard inference uses the configured regional or jurisdictional endpoint
Retention and human decisions
Conversation and approved-output retention is controlled in Dryvn. Full prompt content is not placed in general application logs by default; usage, security, billing, and audit metadata may follow separate retention periods.
- Copilot does not independently make hiring, termination, promotion, discipline, compensation, medical, or other significant employment decisions
- Customers remain responsible for evidence, human review, lawful use, and final decisions
Minimum context. Named access. Human-controlled action.
Payment and subscription processing
When a customer initiates a payment or billing flow and Stripe is configured, Stripe handles card and payment details needed for payment authentication, fraud prevention, billing, and transaction processing. Dryvn receives billing identifiers, transaction and subscription state, and information needed to administer the account.
- Stripe technology loads only in payment or billing contexts
- Workforce information is not sent to Stripe for payment processing
- Necessary payment technology remains separate from optional marketing analytics
Google Calendar appointment scheduling
Dryvn uses Google Calendar Appointment Scheduling for demo bookings. When the embedded scheduler loads, the booking experience is served directly by Google. Information entered into the scheduler is handled through Google's booking service and becomes available to the meeting organizer as needed to arrange and confirm the appointment.
The scheduler loads directly on the Dryvn Contact page. Booking details may be included in Google Calendar and confirmation messages, and a Google Meet link may be generated for the appointment.
- Google owns the booking transaction and availability interface
- Dryvn does not intercept or duplicate scheduler form fields through its website merely to perform the booking
- Dryvn does not add scheduler-specific analytics around the embedded booking component
- An external Google booking link remains available if the embedded calendar cannot be used
The meeting organizer will receive the booking information needed to arrange the conversation. The scheduler is not anonymous.
How Dryvn protects information
Dryvn uses technical and organizational controls intended to protect information against unauthorized access, loss, alteration, or disclosure. No security architecture can guarantee that risk is eliminated.
- Encrypted transport and private application and database infrastructure
- Tenant-aware authentication, authorization, and role-based access
- Restricted database roles and PostgreSQL Row-Level Security as an additional tenant boundary
- Least-privilege cloud identities and managed secrets
- Controlled software delivery, security scanning, logging, monitoring, and alerting
- Backups, recovery procedures, and governance around privileged access
Privacy governs why information is used. Security helps protect it while it is being handled.
Where information may be processed
Dryvn and the service providers used to operate the platform may process information in locations appropriate to the delivery, support, security, and administration of the service.
This notice does not promise that every category of information remains in one country. Standard Copilot requests use a configured Google Cloud regional or jurisdictional endpoint. Organizations with additional infrastructure, AI, isolation, or data-residency requirements can contact Dryvn to discuss available regional, customer-managed, or dedicated deployment options.
How long information is kept
Dryvn retains information for as long as reasonably necessary to provide the service, maintain security and audit records, meet contractual requirements, resolve disputes, and satisfy applicable legal obligations. Exact periods can vary by the information and context.
Customer data
Customer workforce and organizational data is retained according to the service relationship and applicable account, export, closure, and deletion processes. Backup and audit records may follow separate operational or legal lifecycles.
Business contacts and inquiries
Demo, support, and other business-contact records may be retained while the inquiry or relationship remains relevant and for reasonable follow-up, security, record-keeping, or legal needs.
Dryvn does not publish a universal retention period because the appropriate period depends on the record, customer relationship, security need, and applicable requirement.
Your choices and rights
Depending on where you are located and the context in which your information is processed, you may have rights relating to access, correction, deletion, restriction, objection, portability, or withdrawal of consent. These rights do not apply identically in every location or circumstance.
Where Dryvn processes workforce information on behalf of an employer or customer organization, requests concerning that information may need to be directed to that organization. Dryvn can support customers in responding according to the applicable service relationship.
Account closure, export, or deletion
Customers can contact Dryvn regarding account closure, export, or deletion requirements. A request may remain subject to contractual, security, backup, dispute, or legal retention needs.
Children's privacy
Dryvn is a business software platform and is not intended for use by children as a consumer service. Customer organizations are responsible for determining what information is appropriate to place in Dryvn for their authorized business purposes.
Changes to this Privacy Notice
We may update this notice as Dryvn, its services, or applicable requirements change. The latest version will be published on this page with an updated revision date.
Contact us about privacy
Dryvn is operated by AAALABS TECHNOLOGIES LTD. If you have questions about this notice or how information is handled, contact Dryvn through the public Contact page.
Company number: 17270081. Registered in England and Wales.
Registered office: 20 Wenlock Road, London, England, N1 7GU, United Kingdom.