Legal
Privacy Policy
Dr. Nolyn Johnson LLC · Effective Date: July 5, 2026 · Last Updated: August 24, 2026
Plain-language summary: Diliventa collects only what it needs to operate your account and provide the service. We do not sell your data. We do not use your vendor assessment data to train AI models. Your organization's data is isolated from all other tenants by row-level security.
1. Who We Are
Diliventa™ is a vendor security assurance and GRC (Governance, Risk, and Compliance) SaaS platform operated by Dr. Nolyn Johnson LLC ("Company," "we," "us," or "our"), a limited liability company. Our platform is accessible at diliventa.io and app.diliventa.io.
For privacy inquiries, contact us at privacy@diliventa.io.
2. Information We Collect
2.1 Account & Identity Information
When you sign in via WorkOS AuthKit (our authentication provider), we receive:
- Name and email address from your identity provider (e.g., Google, Microsoft, or SAML/SSO)
- Organization name and a unique organization identifier
- Your assigned role within the organization
We do not store passwords. Authentication is handled entirely by WorkOS.
2.2 Platform Content You Create
To provide the service, we store data you enter into the platform:
- Vendor assessment data (vendor names, scoring inputs, control answers, deny trigger flags, determinations)
- Evidence documents you upload for AI analysis (SOC 2 reports, ISO certificates, penetration test reports, privacy policies, etc.)
- GRC records: controls, risks, findings, and audits
- Human-in-the-Loop decisions, reviewer names, and justifications
- Board reports generated from your assessments
2.3 Usage & Technical Data
- IP address, browser type, and operating system
- Pages visited, features used, and session duration
- Error events and performance telemetry (via Sentry)
- Audit log entries (actions performed, timestamps, actor identifiers)
2.4 Billing Information
Payment processing is handled entirely by Stripe. We do not store credit card numbers or bank account details. We receive subscription status, plan type, and Stripe customer identifiers from Stripe's servers.
3. How We Use Your Information
- Provide and operate the platform — processing vendor assessments, running AI analysis, generating reports, enforcing tenant isolation
- AI analysis — documents you upload to the AI Analysis tab are sent to Anthropic's API for processing. Anthropic does not use your data to train models under our enterprise agreement. Documents are processed in-memory and are not retained by Anthropic.
- Security and fraud prevention — malware scanning of uploaded evidence documents via Cloudmersive, monitoring for anomalous authentication patterns
- Error tracking and reliability — error events are reported to Sentry so we can identify and fix platform bugs
- Billing and subscription management — communicating plan status, processing payments, handling upgrades and cancellations via Stripe
- Legal compliance — maintaining immutable audit logs, responding to lawful requests
We do not use your vendor assessment data for marketing, benchmarking, or any purpose beyond operating your account.
4. Tenant Isolation & Data Security
Every table in our database is protected by PostgreSQL Row-Level Security (RLS). A transaction-local configuration variable (GUC) set by our API ensures that every query is scoped to your organization's identifier. Your data is never accessible to another tenant, even within a shared database connection pool.
Evidence files and board report snapshots are stored in Cloudflare R2 with object keys prefixed by your tenant ID. Files are accessible only through our API, which enforces the same session-based tenant check.
Additional safeguards:
- All data in transit is encrypted via TLS 1.3
- Secrets (API keys, session signing keys) are stored in Cloudflare Worker Secrets — never in code or configuration files
- Sessions use sealed, tamper-evident cookies with HttpOnly and Secure flags, and expire after 2 hours of inactivity (a sliding window — refreshed automatically while you remain active)
- CSRF protection via double-submit token pattern on all state-changing requests
- Optional two-factor authentication (TOTP) available on every account
In the event of a security incident that compromises the confidentiality, integrity, or availability of your personal data, we will notify affected customers without undue delay and, where legally required, within 72 hours of becoming aware of the incident, consistent with GDPR Article 33.
5. Data Sharing & Third-Party Processors
We do not sell your data. We share data only with the following sub-processors required to operate the platform:
- Cloudflare — edge network, Workers runtime, R2 object storage, DDoS protection (SOC 2 Type II, PCI DSS L1, GDPR DPA)
- Neon — managed PostgreSQL database (SOC 2 Type II, GDPR DPA, AES-256 at rest)
- WorkOS — authentication and SSO (SOC 2 Type II, GDPR DPA)
- Anthropic — AI analysis of uploaded documents (SOC 2 Type II; no training on customer data)
- Stripe — subscription billing and payment processing (SOC 2 Type II, PCI DSS L1, GDPR DPA)
- Sentry — error monitoring and performance telemetry (SOC 2 Type II)
- Cloudmersive — malware/virus scanning and OCR of uploaded evidence documents (certifications not independently verified — we recommend against relying on this row for your own compliance representations)
- Resend — transactional email delivery (notifications, team invitations, password reset)
We may disclose information when required by law, subpoena, or regulatory order, or to protect the rights, property, or safety of Dr. Nolyn Johnson LLC, our users, or the public.
6. Data Retention
- Account data — retained for the life of your subscription plus 30 days after cancellation, then deleted
- Assessment and GRC data — retained for the life of your subscription plus 30 days
- Evidence files and board reports in R2 — retained per your subscription; deleted with account data upon termination
- Audit logs — retained for 12 months from the date of each event
- Billing records — retained as required by Stripe and applicable tax law (typically 7 years)
You may request deletion of your account and associated data at any time by contacting privacy@diliventa.io.
7. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access — request a copy of personal data we hold about you
- Correction — request correction of inaccurate data
- Deletion — request deletion of your account and personal data
- Portability — receive your assessment data in a machine-readable format (JSON export is available within the platform)
- Restriction — request that we limit processing of your data in certain circumstances
- Objection — object to processing based on legitimate interests
To exercise any of these rights, contact privacy@diliventa.io. We will respond within 30 days.
8. GDPR (EU/UK Users)
If you are located in the European Union or United Kingdom, we process your personal data under the following legal bases:
- Contract performance — processing necessary to deliver the platform services you subscribed to
- Legitimate interests — security monitoring, fraud prevention, error tracking
- Legal obligation — compliance with applicable law and regulatory requirements
You have the right to lodge a complaint with your local data protection authority (e.g., the ICO in the UK or your national DPA in the EU).
International transfers. Our infrastructure providers (Cloudflare, Neon, WorkOS, Anthropic, Stripe) process data in the United States and other countries. Where we transfer personal data out of the EU/UK, we rely on the European Commission's Standard Contractual Clauses (SCCs) or an equivalent lawful transfer mechanism with each processor. A Data Processing Agreement (DPA) is available on request for Enterprise customers — contact privacy@diliventa.io.
9. CCPA (California Users)
California residents have the right to know what personal information we collect, to delete personal information, and to opt out of its sale. We do not sell personal information. To submit a request, contact privacy@diliventa.io.
10. Cookies
We use the following cookies:
- Session cookie — a sealed, HttpOnly session token required for authentication. Expires when your browser session ends or after 2 hours of inactivity.
- CSRF cookie — a short-lived token used to prevent cross-site request forgery. Session-scoped.
We do not use advertising cookies, tracking pixels, or third-party analytics cookies. No consent banner is required because we use only strictly necessary cookies.
11. Children's Privacy
Diliventa is a professional B2B platform intended for use by adults in organizational settings. We do not knowingly collect personal information from anyone under 18 years of age.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and notify active subscribers via email at least 14 days before the change takes effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
13. Contact Us
For questions, requests, or concerns about this Privacy Policy: