Privacy
This notice covers the public site at drellon.com and the invite-only application behind it. It is written to be read, not to be survived; if something here is unclear, ask us at privacy@drellon.com.
What the access form collects
The form at /request-access collects exactly what you type into it:
- your work email address
- your company
- your role
- optionally, a short description of the decision you are working on
Submitting the form requires you to agree to this notice, and the request itself is the record of that agreement.
Two things happen that are not fields on the form. We keep a one-way hash of the network address the submission came from, so the form's rate limits can be enforced without keeping a list of addresses that asked for access. And the form carries one hidden field that a person never sees; if it arrives filled in, the submission is treated as automated and nothing is stored.
We use what you send to reply to you and to decide whether to invite you. We do not sell it, and we do not use it to build a marketing list.
Drellon is invite-only
A request is not an account. Submitting the form never creates one, and there is no sign-up. Access begins when a person at Drellon sends you an invitation, and the invitation link is the only thing that creates an account.
Demonstration content is synthetic
A workspace is either a demonstration workspace or a live one, and the difference is enforced by the system rather than by a label. Demonstration workspaces hold synthetic content: invented companies, invented documents and invented authority. It exists to show how the product works and it is not advice, not a position on anyone's facts, and never usable in a live workspace.
Drellon is decision-support technology. Jurisdiction-specific positions are reviewed by qualified professionals, and nothing the product produces is a substitute for that review.
How your data is handled
- Tenant isolation. Every record that belongs to a workspace carries that workspace's identity and is read under a database policy scoped to it. One customer's evidence, facts, authority, rules, decisions and packs are not visible to another, and no ordinary request is served without that scope in place.
- No cross-customer training. Your content is never used to train or tune a model, for us or for anyone else. Models are used to extract, retrieve and draft inside one workspace, always labelled as such, and never to verify a fact, approve a rule or approve a decision — those are human acts, recorded as human acts.
- Retention on request. Tell us what you want removed and we will remove it. A deleted workspace is exported to an encrypted archive that only we can open, kept for a short operator undo window, and then destroyed. An access request you would rather we did not keep is deleted on request in the same way.
- Sharing is deliberate and revocable. A decision pack reaches an external recipient only through a share grant a person in your workspace created for a named recipient, and that grant can be revoked.
- We log identifiers, not content. Operational logs carry request, workspace and user identifiers, a route and a status. They do not carry document text, prompts, tokens or share codes.
Contact
Write to privacy@drellon.com for anything in this notice: a copy of what we hold, a correction, a deletion, or a question about how something works.