Legal

Privacy Policy

Dr. Nolyn Johnson LLC  ·  Effective Date: July 5, 2026  ·  Last Updated: August 24, 2026

Plain-language summary: Diliventa collects only what it needs to operate your account and provide the service. We do not sell your data. We do not use your vendor assessment data to train AI models. Your organization's data is isolated from all other tenants by row-level security.

1. Who We Are

Diliventa™ is a vendor security assurance and GRC (Governance, Risk, and Compliance) SaaS platform operated by Dr. Nolyn Johnson LLC ("Company," "we," "us," or "our"), a limited liability company. Our platform is accessible at diliventa.io and app.diliventa.io.

For privacy inquiries, contact us at privacy@diliventa.io.

2. Information We Collect

2.1 Account & Identity Information

When you sign in via WorkOS AuthKit (our authentication provider), we receive:

We do not store passwords. Authentication is handled entirely by WorkOS.

2.2 Platform Content You Create

To provide the service, we store data you enter into the platform:

2.3 Usage & Technical Data

2.4 Billing Information

Payment processing is handled entirely by Stripe. We do not store credit card numbers or bank account details. We receive subscription status, plan type, and Stripe customer identifiers from Stripe's servers.

3. How We Use Your Information

We do not use your vendor assessment data for marketing, benchmarking, or any purpose beyond operating your account.

4. Tenant Isolation & Data Security

Every table in our database is protected by PostgreSQL Row-Level Security (RLS). A transaction-local configuration variable (GUC) set by our API ensures that every query is scoped to your organization's identifier. Your data is never accessible to another tenant, even within a shared database connection pool.

Evidence files and board report snapshots are stored in Cloudflare R2 with object keys prefixed by your tenant ID. Files are accessible only through our API, which enforces the same session-based tenant check.

Additional safeguards:

In the event of a security incident that compromises the confidentiality, integrity, or availability of your personal data, we will notify affected customers without undue delay and, where legally required, within 72 hours of becoming aware of the incident, consistent with GDPR Article 33.

5. Data Sharing & Third-Party Processors

We do not sell your data. We share data only with the following sub-processors required to operate the platform:

We may disclose information when required by law, subpoena, or regulatory order, or to protect the rights, property, or safety of Dr. Nolyn Johnson LLC, our users, or the public.

6. Data Retention

You may request deletion of your account and associated data at any time by contacting privacy@diliventa.io.

7. Your Rights

Depending on your jurisdiction, you may have the following rights:

To exercise any of these rights, contact privacy@diliventa.io. We will respond within 30 days.

8. GDPR (EU/UK Users)

If you are located in the European Union or United Kingdom, we process your personal data under the following legal bases:

You have the right to lodge a complaint with your local data protection authority (e.g., the ICO in the UK or your national DPA in the EU).

International transfers. Our infrastructure providers (Cloudflare, Neon, WorkOS, Anthropic, Stripe) process data in the United States and other countries. Where we transfer personal data out of the EU/UK, we rely on the European Commission's Standard Contractual Clauses (SCCs) or an equivalent lawful transfer mechanism with each processor. A Data Processing Agreement (DPA) is available on request for Enterprise customers — contact privacy@diliventa.io.

9. CCPA (California Users)

California residents have the right to know what personal information we collect, to delete personal information, and to opt out of its sale. We do not sell personal information. To submit a request, contact privacy@diliventa.io.

10. Cookies

We use the following cookies:

We do not use advertising cookies, tracking pixels, or third-party analytics cookies. No consent banner is required because we use only strictly necessary cookies.

11. Children's Privacy

Diliventa is a professional B2B platform intended for use by adults in organizational settings. We do not knowingly collect personal information from anyone under 18 years of age.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and notify active subscribers via email at least 14 days before the change takes effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

13. Contact Us

For questions, requests, or concerns about this Privacy Policy: