Privacy Policy
Last updated: October 2026
Overview
Drel is an AI-native security assessment platform operated by Atela Capital S.L. (NIF B22564249), registered in Madrid, Spain ("Drel", "we", "us"). For data protection purposes, Atela Capital S.L. is the data controller.
We take privacy seriously — we collect only what we need to operate the service, we don't sell your data, and we give you control over what you share with us.
This policy explains what data we collect, why we collect it, how we use it, and your rights as a user. If you have questions, reach out at hello@drel.ai.
Data we collect
Account data. When you sign up, we collect your email address and, optionally, your name and company. This is used to authenticate you and communicate with you about your account.
Assessment inputs. When you generate an AI Security Review, we process the system description and questionnaire answers you provide. This content is used solely to generate your AI Security Review. It is never used to train a model (see AI training below).
Usage data. We collect standard analytics — pages visited, features used, session duration, and error logs. This helps us understand how the product is used and where to improve it. Usage data never includes the content of your assessments.
Payment data. Billing is handled by Stripe. We store only a reference to your Stripe customer ID — we never see or store your full card number.
Support communications. If you contact us by email, we retain those messages to resolve your issue and improve our support.
AI training & your content
We do not train any model on your data. Drel runs no model-training pipeline — your documents and assessment inputs are used only to generate your AI Security Review, and for nothing else.
AI analysis runs on Amazon Web Services infrastructure in the European Union. Our AI provider does not use your inputs or outputs to train its models and does not retain them after processing.
We do not share your assessment content with third parties, except the sub-processors that host and analyse it on our behalf, under contract and only on our instructions (see Data sharing below).
How we use your data
We use the data we collect to:
• Provide and operate the Drel service • Authenticate your account and protect against unauthorized access • Generate AI Security Reviews based on your inputs • Send transactional emails (account confirmation, billing receipts, password reset) • Send product updates and announcements (you can unsubscribe at any time) • Improve the product using usage analytics (pages visited, features used, errors) — never the content of your assessments • Respond to support requests • Comply with legal obligations
Legal bases (GDPR)
If you are in the EEA, UK, or Switzerland, we process your data under the following legal bases:
Contract performance (Art. 6(1)(b)). Creating your account, generating AI Security Reviews, processing payments, and providing customer support — these are necessary to deliver the service you signed up for.
Legitimate interest (Art. 6(1)(f)). Product analytics, security monitoring, and service improvement. We have assessed that these interests do not override your rights and freedoms.
Consent (Art. 6(1)(a)). Marketing communications and non-essential analytics cookies. You can withdraw consent at any time without affecting the lawfulness of prior processing.
Legal obligation (Art. 6(1)(c)). Retaining billing records for tax compliance and responding to lawful government requests.
Data sharing
We do not sell your personal data. We share data only with the following categories of service providers, under contracts that require them to protect it and to use it only to provide their service to us:
Where your data is processed.
• Assessment content — system descriptions, documents, questionnaire answers and the reviews Drel generates — is stored and analysed in the European Union (Germany and Ireland) on Amazon Web Services infrastructure. It is never used to train AI models. • Service operation. To run the service we use providers for application hosting, sign-in and identity, transactional email, payments, product analytics and service monitoring. Monitoring and analytics receive usage events, metrics, error diagnostics and redacted summaries rather than the content of your assessments. • Account and billing data — name, work email, organisation, sign-in and billing details — may be processed by some of these providers in the United States. Those transfers are governed by the EU Standard Contractual Clauses.
Payments. Stripe processes all billing. Their privacy policy applies to payment data.
Analytics cookies are set only as described in our Cookie Policy.
Sub-processor list. The current list of sub-processors, with the purpose, location and transfer safeguard of each, and a copy of the Standard Contractual Clauses, is available on request at hello@drel.ai. Business customers receive it with our Data Processing Agreement.
We may disclose data if required by law, court order, or to protect the rights and safety of Drel and its users.
Data retention
We retain your account data for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we are required to retain it for legal or financial compliance purposes (typically up to 7 years for billing records).
Your assessments and evidence packs are retained while your account is open — including, read-only, after a paid subscription ends — until you delete them or close your account. You can export or delete your assessments at any time from the dashboard.
Your rights
If you are in the EEA, UK, or Switzerland, you have the following rights under GDPR:
• Access (Art. 15). Request a copy of the personal data we hold about you. • Rectification (Art. 16). Ask us to correct inaccurate or incomplete data. • Erasure (Art. 17). Request deletion of your personal data ("right to be forgotten"). • Portability (Art. 20). Receive your data in a structured, machine-readable format. • Objection (Art. 21). Object to processing based on legitimate interests. • Restriction (Art. 18). Ask us to restrict processing in certain circumstances. • Withdraw consent (Art. 7(3)). Where processing is based on consent, withdraw it at any time.
To exercise any of these rights, email hello@drel.ai with subject line "Privacy Request". We will respond within 30 days as required by law. We may ask you to verify your identity before processing the request.
Supervisory authority. You have the right to lodge a complaint with your local data protection authority. In Spain, this is the Agencia Espanola de Proteccion de Datos (AEPD) at https://www.aepd.es.
Security
We apply industry-standard security practices to protect your data:
• All data in transit is encrypted with TLS 1.2+ • Data at rest is encrypted using AES-256 • Access to production systems is restricted to authorized personnel with MFA • We conduct regular security assessments of our own infrastructure (we use Drel for this) • Vulnerability disclosures can be sent to security@drel.ai
No system is perfectly secure. If you believe you have found a security issue, please report it responsibly before public disclosure.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will notify you by email and update the "Last updated" date at the top of this page. Continued use of the service after changes take effect constitutes acceptance of the updated policy.
Questions about this policy?
Reach out to our privacy team and we'll respond within 2 business days.
hello@drel.ai →