Legal

Privacy Policy

How DataNivra collects, uses, shares and retains personal data about website visitors, prospects, customer account users and billing contacts — and what we never receive.

Version: 2026-10-01 · Effective date: October 1, 2026

1. Who we are

In plain English: this policy explains what personal data DataNivra handles as a business, why, and your rights.

1.1 DataNivra is a business-to-business Test Data Management platform provided by ForgeZen Labs LLC, a North Carolina limited liability company, NC Secretary of State filing number 3344952, organized July 29, 2026, 4030 Wake Forest Rd Ste 349, Raleigh, North Carolina 27609 (DataNivra, we, us). For the personal data described in section 3, DataNivra is the controller.

1.2 Contact. Privacy questions and requests: privacy@datanivra.com. No Data Protection Officer or EU/UK representative has been appointed as of the effective date of this policy.

1.3 Related documents. The short privacy notice for website enquiries summarises the part of this policy that applies to our contact and demo forms. Customers' use of the service is governed by the Terms of Service, and the processing we perform on customers' behalf is governed by the Data Processing Addendum. Defined terms such as Control-Plane Metadata and Customer Source Data have the meanings given in the Terms of Service.

2. Scope

In plain English: this policy covers our website, our enquiry forms and the accounts of people who use DataNivra. It does not cover the data our customers process with DataNivra in their own environments — we do not receive that data.

2.1 In scope. This policy covers personal data about:

  1. website visitors of our public website;
  2. prospects who contact us or request a demo through our website forms;
  3. customer account users — people whom a customer authorises to use the DataNivra console, API or CLI;
  4. billing and contract contacts at our customers; and
  5. people who correspond with us, for example about support or security reports.

2.2 Out of scope — Customer Source Data. Our customers use DataNivra software that they install in their own environments (the Customer-Resident Components) to discover, mask, subset and generate test data. The data processed there — including production records about our customers' own customers, patients or employees — stays in the customer's environment. The DataNivra software is designed so that such raw production rows are not transmitted to, or stored by, DataNivra's hosted service. Our customers decide how that data is processed; if you have a question about it, please contact the relevant organisation.

2.3 Processing on behalf of customers. Where Control-Plane Metadata that DataNivra's hosted service stores for a customer contains personal data (for example the names and email addresses of that customer's users in audit events), DataNivra processes it as the customer's processor under the Data Processing Addendum, and the customer's privacy notice applies to it. This policy describes that processing for transparency.

3. Personal data we collect

In plain English: we collect what you type into our forms, what we need to run your account, and limited technical data for security. We do not use analytics or advertising cookies.

3.1 Website enquiries (contact and demo forms).

  1. What you enter: name, work email address, company, optional job title, the topic of your enquiry, an optional preferred demo date and an optional message.
  2. Your consent to be contacted and the version of the privacy notice you agreed to.
  3. A pseudonymous client key: a keyed hash (HMAC-SHA-256) of your network (IP) address computed with a secret key. We use it to limit repeated submissions and detect abuse. We do not store your IP address with your enquiry.
  4. A tamper-evident event log for each enquiry (for example submitted, notification sent, deleted) containing event types, reason codes, identifiers and the pseudonymous client key, but no name, email, company or message.

Submissions that are refused (for example as spam or because consent was not given) are not stored; only a log entry with a reason code is kept.

3.2 Customer account users.

  1. Profile: work email address, display name, the roles assigned by the customer, account status, the customer organisation (tenant) you belong to, and timestamps.
  2. Sign-in: the type of identity provider used (single sign-on through the customer's OpenID Connect (OIDC) identity provider) and the subject identifier the identity provider issues for you. We do not receive or store your identity-provider password.
  3. Sessions: short-lived access tokens (by default valid for 15 minutes) and, when you sign out, a revocation record (token identifier, user and tenant identifiers and expiry) that is kept until the token would have expired.
  4. Audit events: records of actions taken in the service (for example who approved a policy or requested a dataset), containing your user identifier, the action, its target, its outcome, reason codes and timestamps. Audit events do not contain IP addresses or data values.
  5. Activity metadata: the Control-Plane Metadata you create while using the service (for example job requests and policy versions) is linked to your user identifier.

3.3 Billing and contract contacts. Names, business contact details and contract information. Where online payment is enabled, payments are handled by our payment processor; we store a customer reference issued by the processor and the status of subscriptions and invoices. We do not store full payment card numbers.

3.4 Security and technical data.

  1. IP addresses are used in memory to rate-limit sign-in and anonymous requests; the service's own application logs do not record IP addresses, request bodies, headers or tokens.
  2. Edge and infrastructure logs: our cloud hosting provider's edge network, web application firewall and managed services generate access and security logs that include client IP addresses and request metadata. We use them to operate and secure the service and keep them for a limited period (section 7).
  3. Our frontend hosting provider processes technical request data (such as IP addresses) to deliver the website and console.

3.5 Browser storage and cookies. Neither the website nor the console sets cookies, and neither uses analytics, advertising or third-party tracking scripts. They use your browser's storage only for these purposes:

WhereKey (prefix)PurposeLifetime
Website — local storagedatanivra.web.themeYour colour-theme choiceUntil you clear it
Website — local storagedatanivra.web.walkthrough-prefsNarration speed, mute and caption settingsUntil you clear it
Console — session storagedatanivra.sessionYour access token while signed inUntil the browser tab is closed
Console — session storagedatanivra.oidc.attemptA single sign-in attempt in progressUntil sign-in completes or the tab closes
Console — local storagedatanivra.oidc.tenantThe organisation you last signed in toUntil you clear it
Console — local storagedatanivra.onboarding.*Onboarding progress (for example the chosen agent install target)Until you clear it

These items stay on your device and are strictly necessary for the features you use. The website's narrated walkthroughs can use your browser's built-in speech synthesis; depending on your browser, the browser vendor may process the narration text (which is website content, not your personal data) under its own terms.

3.6 Correspondence. If you email us, contact support or report a vulnerability, we keep the correspondence and your contact details.

4. What we do not collect

4.1 We do not receive customers' raw production rows, source-data samples, credentials or secret values; the software is designed to keep them in the customer's environment. Please do not put customer, patient, financial or production data in our forms, support requests or free-text fields.

4.2 We do not knowingly collect special categories of personal data about you, and we do not sell personal data or share it for cross-context behavioural advertising.

In plain English: we use personal data to answer you, provide the service, bill for it, keep it secure and meet our legal obligations.
PurposeDataLegal basis (EU/UK GDPR-style)
Answer your enquiry and arrange a demoEnquiry data (3.1)Your consent; our legitimate interest in responding to business enquiries
Protect forms and the service from abusePseudonymous client key, IP addresses in memory, security logsLegitimate interests (security and fraud prevention)
Provide the service and your account, including sign-in and access controlAccount data, sessions, audit eventsPerformance of our contract with the customer; legitimate interests in operating the service for the customer's authorised users
Keep a tamper-evident audit trail for the customerAudit eventsPerformance of contract; legitimate interests (security and accountability)
Meter usage and bill the customerUsage meters (no personal data), billing contactsPerformance of contract; legal obligations (tax and accounting)
Support and service communicationsAccount and correspondence dataPerformance of contract; legitimate interests
Comply with law and defend legal claimsRelevant recordsLegal obligation; legitimate interests

Where we rely on consent, you can withdraw it at any time; this does not affect processing before withdrawal. Where we rely on legitimate interests, you can object (section 9). We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.

6. Sharing and sub-processors

In plain English: we share personal data only with the service providers that help us run DataNivra, and with others only when the law requires it.

6.1 Service providers. We use the following categories of providers, which process personal data on our instructions:

ProviderServicePersonal data involved
Microsoft AzureHosting of the control plane, database, key management, edge network and firewall, logging and monitoring (region: United States — specific Microsoft Azure production region to be confirmed before execution)All data described in section 3 that reaches the hosted service
VercelHosting and delivery of the public website and the console web applicationTechnical request data
Stripe (or another payment provider we configure) — only when online payment is enabledPayment processing and subscription billingBilling contact and payment data
Email delivery provider (SMTP) — when configuredDelivery of internal enquiry notifications and service emailsEnquiry and contact data
The customer's chosen identity providerSingle sign-on (OIDC) — selected and contracted by the customer, not by DataNivraSign-in data, under the customer's own arrangements

The current list of sub-processors, with their locations, is maintained at https://www.datanivra.com/legal/subprocessors (last updated September 29, 2026).

6.2 Other disclosures. We may disclose personal data to professional advisers under confidentiality; to a successor in a merger, acquisition or sale of assets, subject to this policy; and to authorities where required by law or to protect rights, safety and security.

6.3 No sale. We do not sell personal data and do not share it for targeted advertising.

7. Retention

In plain English: we keep personal data only as long as needed. Enquiries are deleted automatically after one year.
DataRetention
Website enquiriesDeleted automatically 365 days after submission (our current configured period), or sooner on a valid deletion request. The enquiry event log (no name, email, company or message) is kept to evidence handling and deletion; it is deleted automatically 365 days after the event (our current configured period)
Account profilesFor the life of the customer account, then deleted as described in the Terms of Service (section 16)
Session revocation recordsUntil the revoked token would have expired
Audit eventsFor the audit retention period configured for the customer's account (365 days by default, and as set in the customer's Plan or Order Form), then purged automatically
Job, policy and other Control-Plane MetadataFor the life of the customer account, then deleted as described in the Terms of Service
Edge, firewall and infrastructure logsUp to 90 days
Database backupsUp to 35 days
Billing and contract recordsAs required by tax and accounting law (7 years after the applicable transaction or longer if required by law)
Correspondence and support records3 years after the matter is closed, unless a longer period is required for legal claims, security, or compliance

8. Security

8.1 We protect personal data with technical and organisational measures, including tenant isolation enforced in the database, encryption in transit, role-based access control with separation of duties, secrets held in a key vault and referenced rather than copied, a tamper-evident hash-chained audit trail, and logging policies that exclude data values, tokens and request bodies. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Annex 2 of the Data Processing Addendum summarises these measures.

9. Your rights

In plain English: depending on where you live, you can ask to access, correct, delete or move your data, and to object to or restrict its use. Contact us and we will respond within the time the law requires.

9.1 Rights. Subject to applicable law, you may have the right to: access your personal data; correct it; delete it; restrict or object to its processing; receive it in a portable format; withdraw consent; and lodge a complaint with a data-protection supervisory authority.

9.2 US state privacy rights. If you are a resident of a US state with a consumer privacy law, you may have rights to know, access, correct and delete personal information, and to opt out of its sale or sharing for targeted advertising. We do not sell or share personal information for targeted advertising. We will not discriminate against you for exercising your rights. You may use an authorised agent where the law allows.

9.3 How to exercise them. Contact privacy@datanivra.com or use the contact form. We may need to verify your identity. If you are a customer account user, or your data is in a customer's Control-Plane Metadata, we will refer your request to the customer (our controller for that data) and assist it as required by the Data Processing Addendum. Enquiry records can be deleted on request, which removes the record and any pending notification.

10. International transfers

10.1 We and our service providers may process personal data in countries other than yours, including United States — specific Microsoft Azure production region to be confirmed before execution and the United States. Where the law requires it, we protect such transfers with the European Commission Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), using the applicable module, together with the UK International Data Transfer Addendum or other legally valid transfer mechanism where required (for example the European Commission's Standard Contractual Clauses and the UK addendum).

11. Children

11.1 DataNivra is a business service and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided personal data to us, contact us and we will delete it.

12. Changes to this policy

12.1 We will update this policy when our practices change. We will post the new version with its effective date and, for material changes, notify customer administrators by email or in the console before the change takes effect.

13. Contact

13.1 ForgeZen Labs LLC, 4030 Wake Forest Rd Ste 349, Raleigh, North Carolina 27609. Email: privacy@datanivra.com.

← All legal documents