Privacy Policy
We take the protection of your personal data seriously. This Privacy Policy explains what personal data we process when you visit our website, create an account, and use driply (the "Service"), on what legal basis, with whom we share it, and what rights you have. It is provided in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR / DSGVO), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).
1. Controller
The controller responsible for the data processing described here is:
Björn Schwenzer, sole proprietor, trading as nightworks
Wengenrothstr. 19, 61250 Usingen, Germany
Phone: +49 6081 9498900 · Email: hello@driply.app
For all data protection matters you can reach us at: hello@driply.app.
2. Data protection officer
We are not legally required to appoint a data protection officer (§ 38 BDSG) and have not appointed one. You can address any questions about this Privacy Policy or your rights to the contact above.
3. Two roles: when we are "controller" and when we are "processor"
driply is a business-to-business tool. It is important to distinguish two situations:
- We act as the controller for: visitors to our website, the data of the person who registers and administers a customer account, billing data, and our own communications with you. This Privacy Policy governs that processing.
- We act as a processor (Auftragsverarbeiter, Art. 28 GDPR) for the personal data that a business customer enters into or imports into its own workspace ("tenant") within driply — for example, the names, email addresses, access grants and audit records of that customer's employees and team members. For that data, our customer is the controller, and our processing is governed by the Data Processing Agreement (AVV) concluded with that customer, not by this Privacy Policy. If you are an employee or team member of a driply customer and have questions about how your data is used in driply, please contact your employer (the controller).
4. Hosting and infrastructure
The Service and its production database are hosted on the infrastructure of Supabase in a data centre in the European Union (Frankfurt, Germany — region eu-central-1). The application front end and edge/serverless functions are operated via Vercel. Server log data necessarily processed by this infrastructure (see § 5.1) is processed on the basis of our legitimate interest in providing a stable, secure Service (Art. 6 (1) (f) GDPR).
5. Processing activities (as controller)
5.1 Provision of the website and server log files
When you access our website, the infrastructure automatically collects technical data that your browser transmits, in particular: IP address, date and time of the request, the page requested, the referrer URL, browser type and version, and operating system. This data is necessary to deliver the website and to ensure its stability and security.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a secure, functioning service).
Retention: server/security logs are retained only as long as necessary for these purposes and then deleted or anonymised.
5.2 Account registration and use of the Service
To use driply, an authorised representative of a business customer creates an account. We process: name, business email address, password (stored only as a salted hash; we never see your password in plain text), organisation/tenant name, role and admin status, account status, and authentication/session data.
Purpose: to set up and operate the account and provide the contractually agreed Service.
Legal basis: Art. 6 (1) (b) GDPR (performance of the contract / pre-contractual steps).
5.3 Transactional emails
We send transactional emails (e.g. sign-in/magic links, invitations, password resets, notifications, digest emails) via our email provider Resend. To do so we process the recipient's email address and the content of the message.
Legal basis: Art. 6 (1) (b) GDPR (contract performance) and Art. 6 (1) (f) GDPR (legitimate interest in operating the Service).
5.4 Billing and payment (paid plans)
Paid subscriptions (monthly and yearly plans) are sold and billed through our payment provider Polar (Polar Software, Inc.), which acts as the Merchant of Record. This means that, for the payment transaction, Polar is the seller of record and an independent controller: Polar operates the checkout, processes payment-method data, issues the invoice and handles applicable VAT/sales tax (including EU B2B reverse charge). We do not receive or store your full payment-card details.
We receive from Polar only the billing metadata we need to manage your subscription (e.g. customer/company name, billing email, country, VAT ID where applicable, plan, subscription and payment status). We process this to manage your plan and to comply with our own commercial and tax record-keeping duties.
Legal basis: Art. 6 (1) (b) GDPR (contract) and Art. 6 (1) (c) GDPR (compliance with statutory retention obligations under German commercial and tax law).
Polar's own processing of your data as Merchant of Record is governed by Polar's privacy policy.
5.5 Integrations you choose to connect (Slack, Google Workspace)
A customer's administrator may connect third-party services to a tenant:
- Google Workspace (read-only directory sync) to discover and reconcile team members;
- Slack (request/approve workflow and member discovery).
These connections are initiated by the customer via OAuth and are part of the tenant data we process as a processor on the customer's behalf (see § 3 and the AVV). Access tokens are encrypted at rest and are never exposed to other tenants or to clients. Data exchanged with Google and Slack is processed in accordance with those providers' own terms and privacy policies.
5.5.1 Google user data (Google API Services)
This section specifically discloses how driply accesses, uses, stores, shares and retains data obtained through Google APIs / Google Workspace, in accordance with the Google API Services User Data Policy and the Google APIs Terms of Service. driply interacts with Google in two separate, optional flows: (A) an administrator connecting their Google Workspace for read-only directory sync, and (B) an end user choosing "Sign in with Google". If neither is used, driply accesses no Google user data.
Data we access.
- (A) Google Workspace directory sync. When a Workspace administrator connects Google, driply requests one restricted scope —
https://www.googleapis.com/auth/admin.directory.user.readonly— plus the non-sensitive sign-in scopesopenidandemail. Using the Google Admin SDK Directory API (scoped to the connecting admin's own organisation,customer=my_customer), we read, for each member of that Workspace: the immutable Google user ID, the primary email address, the given/family/full name, the account status (whether the account is suspended or archived), and any email aliases. To identify the connecting administrator we additionally read, via OpenID Connect, that admin's Google account ID, email address, hosted (Workspace) domain and name. We request no write, provisioning, Gmail, Calendar, Drive or other data scopes, and we do not use domain-wide delegation. - (B) Sign in with Google. When a user signs in with Google, we use OpenID Connect with the scopes
openid,emailandprofile. We receive the user's Google account ID, email address, email-verified status, name and basic profile information.
How we use it.
- (A) Directory data is used only to provide the governance features the customer connected the integration for: to populate and reconcile the customer's Roster (proposing directory members as candidates), to match a person's identity across Google Workspace, Slack and driply using email and aliases, and to surface suspended/archived Google accounts as access-review prompts.
- (B) Sign-in data is used only to authenticate the user and bind them to their existing driply person record.
- Google user data is never used for advertising, and is never used to develop, improve or train any generalised or standalone artificial-intelligence or machine-learning model. driply's AI-assisted features (§ 5.9) are grounded strictly in the relevant tenant's own governance data and never transmit Google user data to a model provider for training. Our aggregated catalogue/benchmarking pipeline (§ 5.8) does not ingest Google user data — it uses only non-personal information about third-party tools.
How we share it. We do not sell Google user data and do not share it with third parties for their own independent purposes, for advertising, or with data brokers. Google user data is disclosed only to the infrastructure sub-processors that operate the Service on the customer's behalf, and only to provide user-facing features of the Service: Supabase (EU-hosted database, authentication and storage of the data), Vercel (application hosting / serverless functions that process the data in transit), and — where a Service email is sent to a person — Resend (transactional email delivery of the recipient's email address). These providers act as our processors under Art. 28 GDPR (see § 7) and may not use the data for any other purpose. We do not otherwise transfer Google user data to any third party except where required by law.
How we store and protect it. Google OAuth refresh and access tokens are encrypted at rest, are never exposed to other tenants or to browser clients, and are never written to logs. Google user data is stored in our production database hosted in the European Union (Frankfurt, region eu-central-1) and is isolated per tenant by Postgres Row-Level Security, so one customer's data can never be read by another. All data is transmitted over encrypted connections (TLS). We follow the principle of least privilege (a single read-only restricted scope; no write access), and we maintain the technical and organisational security measures described in § 5.5, § 7 and our security documentation.
How long we retain it, and how to delete it. Directory-derived data is held as the customer's tenant data for the duration of the customer's contract. It is deleted when: (i) the administrator disconnects the Google integration — the stored Google OAuth tokens are revoked and deleted and no further Google data is read; (ii) the organisation is deleted — an administrator can delete the whole organisation from Settings at any time, after which all data, including directory-derived data, is permanently erased following a 10-day grace period (see § 9); or (iii) the contract ends (§ 9). If you are a member of a customer's Workspace, you may request access to or deletion of your data by contacting that customer (the controller) or by emailing us at hello@driply.app, and we will act on it as their processor. Administrators and account holders can exercise the deletion routes above directly.
Limited Use. driply's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5.6 Support and communication
If you contact us (e.g. by email), we process the data contained in your message to handle your request.
Legal basis: Art. 6 (1) (b) GDPR (where related to a contract) or Art. 6 (1) (f) GDPR (legitimate interest in responding to enquiries).
5.7 Audit log
The Service keeps an audit log of governance-relevant actions (e.g. requests, approvals, grants, admissions, offboarding) as a core product feature. Within a tenant this is part of the customer's controller-side data (processor role). For our own account-administration actions, the legal basis is Art. 6 (1) (f) GDPR (legitimate interest in accountability and security).
5.8 Aggregated analysis and improvement of our shared catalogue
(a) Anonymised statistics and benchmarks. We create aggregated and anonymised statistics across customer workspaces (for example, anonymised benchmarks and product-improvement metrics). This is done through a pipeline designed so that the output contains no personal data and cannot be attributed to any individual, customer or tenant (including exclusion of values that could be unique to a single tenant). Once data is anonymised, it no longer constitutes personal data and falls outside the scope of the GDPR.
(b) Generic catalogue of tools and templates. driply maintains a generic, built-in catalogue of common third-party tools and applications (and related templates) that we make available to all customers to make set-up easier. To keep this catalogue current and useful, we analyse which third-party tools and applications are used across workspaces and use that insight to decide which entries to add to, or improve in, the catalogue. For this purpose we use only non-personal information about the tool or application itself — such as its name, vendor, website/domain, logo and category — and never the people, access grants, requests, approvals, notes or any other tenant content associated with it. We exclude entries that appear to be custom, internal or otherwise capable of identifying a particular customer (for example, a tenant's bespoke internal application). The names of commercially available software products are not personal data.
Legal basis (for both (a) and (b)): our legitimate interest in operating, securing and improving the Service and its shared catalogue (Art. 6 (1) (f) GDPR) and, where we act as processor, the authorisation set out in the AVV.
5.9 AI-assisted features
Where the Service offers AI-assisted features (e.g. natural-language queries over a tenant's own governance data, or decision-support for approvers), these features are strictly grounded in the relevant tenant's own data, subject to per-user authorisation, and are assistive only. The AI never grants, revokes or approves access autonomously. No automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR takes place.
6. Cookies and similar technologies
driply uses only strictly necessary cookies. We do not use analytics, advertising, profiling or tracking cookies, and we therefore do not display a cookie consent banner, because the cookies we set are technically required to provide the Service that you have expressly requested.
| Cookie | Purpose | Type / provider | Storage period |
|---|---|---|---|
sb-<project-ref>-auth-token (may be split into …-auth-token.0, .1) | Stores your authenticated session (login) so you stay signed in across requests. HTTP-only, secure. | Strictly necessary / Supabase | Duration of the session / until token expiry or sign-out |
| PKCE / code-verifier cookie (transient) | Secures the sign-in (OAuth/PKCE) exchange. | Strictly necessary / Supabase | Deleted immediately after sign-in completes |
These cookies are exempt from the consent requirement under § 25 (2) TDDDG (storage strictly necessary to provide a telemedia service expressly requested by the user). Their use is based on Art. 6 (1) (b) and (f) GDPR. Our hosting infrastructure (Vercel) may additionally set transient, technically required cookies for security and load balancing; we do not use them for tracking. You can delete or block cookies in your browser settings, but the Service will not function without the session cookie.
7. Recipients and processors
We use carefully selected service providers who process personal data on our behalf or, where indicated, as independent controllers. The main recipients are:
| Recipient | Function | Location of processing | Role |
|---|---|---|---|
| Supabase (Supabase, Inc.) | Database, authentication, hosting of production data | EU (Frankfurt, Germany) | Processor |
| Vercel (Vercel Inc.) | Application hosting / edge functions | EU/US (global edge network) | Processor |
| Resend (Resend, Inc.) | Transactional email delivery | US | Processor |
| Polar (Polar Software, Inc.) | Payment / Merchant of Record (paid plans) | US | Independent controller for the payment transaction |
| Google (Google Ireland Ltd. / Google LLC) | Workspace directory sync — only if the customer connects it | EU/US | Processed on the customer's behalf (processor role) |
| Slack (Slack Technologies / Salesforce) | Request/approval and member discovery — only if the customer connects it | EU/US | Processed on the customer's behalf (processor role) |
We conclude the data processing agreements required under Art. 28 GDPR with our processors.
8. Transfers to third countries
Some recipients (e.g. Vercel, Resend, Polar; and Google/Slack depending on configuration) may process data in or with access from the United States or other countries outside the EU/EEA. Where this happens, the transfer is safeguarded by the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and, where applicable, the recipient's certification under the EU–US Data Privacy Framework, together with supplementary measures as required. You can request a copy of the relevant safeguards from us using the contact details in § 1.
9. Storage and erasure
We retain personal data only as long as necessary for the purposes described above or as required by statutory retention obligations:
- Account data is deleted promptly after the contract ends. A self-service export (including the audit trail) is available at any time during the term, and you are responsible for exporting before the contract ends; deletion is subject to backup expiry and to the statutory retention of billing records (see our Terms).
- Self-service organization deletion. An administrator can delete the entire organization from Settings at any time. Deletion is not immediate: the organization is locked and its integration connections are revoked straight away, then all of its data — people, tools, grants, requests and the audit log, together with every member's sign-in login — is permanently erased after a 10-day grace period. During that window an administrator can restore the organization; once the window lapses, erasure is irreversible (subject only to backup expiry and the statutory retention of billing records).
- Billing/accounting records are retained for the statutory periods under German commercial and tax law (generally 6–10 years; see § 257 HGB, § 147 AO).
- Tenant data (processor role) is returned or deleted at the end of the contract in accordance with the AVV.
10. Your rights
Under the GDPR you have the right to:
- access your personal data (Art. 15);
- rectification of inaccurate data (Art. 16);
- erasure ("right to be forgotten", Art. 17);
- restriction of processing (Art. 18);
- data portability (Art. 20);
- object to processing based on Art. 6 (1) (f), on grounds relating to your particular situation (Art. 21); and
- withdraw consent at any time, where processing is based on consent, with effect for the future.
To exercise any of these rights, contact us at hello@driply.app. If you are a member of a customer's workspace, please direct requests about your tenant data to that customer (the controller); we will support them as their processor.
Right to object (Art. 21 GDPR): You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data based on Art. 6 (1) (f) GDPR.
11. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority. The authority competent for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI)
Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany
Postfach 3163, 65021 Wiesbaden
Phone: +49 611 1408-0 · Email: poststelle@datenschutz.hessen.de
You may also contact the supervisory authority of your habitual residence or place of work.
12. Is provision of data mandatory?
Providing the account and contract data described in § 5.2–5.4 is necessary to enter into and perform the contract. Without it, we cannot provide the Service. There is no statutory obligation to provide the data, but we cannot conclude or perform the contract without it.
13. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to the Service or the legal situation. The current version is always available on our website. The date below indicates the latest revision.
Last updated: 1 July 2026.