Legal
Privacy Policy
Effective October 7, 2026 · Controller: ISTRIADE GROUP LLC
This policy explains how DTP processes personal data. The current public surface does not activate customer accounts; authenticated processing remains separately gated.
Data we may process
- Account/authentication identifiers and session/security metadata.
- Workspace, role, membership, ownership-claim, and authorization records.
- Evidence and entity data submitted by users or obtained from lawful public sources.
- Public Trust-assessment records and methodology/evidence lineage.
- Technical, security, audit, incident, and support records.
Purposes and legal bases
- Accounts, workspaces, reports, and support: contract or requested pre-contract steps.
- Authentication, security, fraud prevention, and access control: contract, legitimate interests, and legal obligations where applicable.
- Evidence lineage, corrections, disputes, and public-source Trust intelligence: legitimate interests balanced against affected rights, and legal obligations where applicable.
- Marketing: consent where required or another lawful basis only where law permits.
- Legal claims: legitimate interests and/or legal obligation.
Sources and public profiles
Data may come from users, lawful public sources, infrastructure/security systems, and authorized integrations when separately enabled. Where public information identifies a natural person, DTP applies publication-safety controls. UNKNOWN data is not negative evidence. The public Trust surface does not make solely automated decisions producing legal or similarly significant effects on individuals.
Sharing
We may share data only as necessary with infrastructure, hosting, database, security, communications, professional-adviser, audit, or legal-service providers, or authorities where required. Current core infrastructure includes Cloudflare and Supabase when relevant features are enabled. We do not sell personal data.
International transfers
ISTRIADE is based in the United States. Where required, we use or rely on lawful transfer mechanisms under provider agreements, such as Standard Contractual Clauses, applicable UK mechanisms, adequacy decisions, or another lawful safeguard.
Retention and security
Data is retained only as long as necessary for purpose, security, auditability, disputes, legal obligations, and enforcement. See the Data Retention & Deletion Policy. DTP uses least-privilege access, tenant isolation, Row Level Security, secret separation, audit logging, fail-closed authorization, encrypted transport, controlled recovery, and publication-safety boundaries.
Your rights
Depending on jurisdiction and processing, you may have rights to information, access, correction, deletion, restriction, objection, portability, withdrawal of consent, complaint to a supervisory authority, and safeguards relating to qualifying automated decisions.
Contact admin@istriadegroup.com to exercise a privacy right. Identity verification may be required.
Colombia
Where Colombian law applies, data subjects may exercise applicable rights to know, update, rectify, and, where legally available, delete personal data or revoke authorization, subject to statutory exceptions.
EEA, UK, and Switzerland
Where applicable, DTP provides required lawful-basis, retention, recipient, transfer, and rights information. Mandatory local rights prevail over inconsistent provisions.
Children
DTP is not intended for children under 18 and does not knowingly create accounts for children.
Contact
ISTRIADE GROUP LLC · Wyoming, United States · admin@istriadegroup.com