Scope and controller
This policy applies to dodvir.com, the customer cabinet, and DODVIR-hosted licensing and support services. The contracting DODVIR operator identified in your order form or access letter is the data controller. Privacy requests may be sent to m.golov@dodvir.com.
Data we process
- Account data: email, display name, authentication provider identifiers, session and access records.
- Licensing data: customer and project identifiers, edition, activation identifiers, machine-binding hashes, IP address, lifecycle and denial events.
- Waitlist and support data: contact details, company, role, submitted request, consent record, correspondence, and attachments you choose to provide.
- Security and operations data: timestamps, IP address, user agent, request identifiers, audit records, service errors, and incident evidence.
Purposes and legal bases
- Provide accounts, licensed releases, updates, support, and contracted services: performance of a contract or steps requested before a contract.
- Protect services, investigate abuse, maintain auditability, and meet reliability obligations: legitimate interests and legal obligations.
- Send requested waitlist or product communications: consent, which may be withdrawn at any time.
Retention
- Authentication sessions: no longer than the configured session lifetime; expired server-side sessions are deleted or rendered unusable.
- Waitlist records: 12 months after the last interaction unless you ask for earlier deletion or a contract requires migration to a customer record.
- Support records: 24 months after closure; security incident and access audit records: 12 months, unless a longer period is necessary for an active investigation or legal obligation.
- License and contract records: for the contract term plus the legally required limitation and accounting period stated in the applicable order.
Sharing, transfers, and security
We share data only with infrastructure, authentication, communications, and support processors needed to operate the service, under contractual confidentiality and data-protection terms. The current processor list and transfer mechanism are provided with the order or DPA. DODVIR uses access controls, encryption in transit, protected credentials, audit logs, backups, and incident procedures; no system can guarantee absolute security.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may complain to your supervisory authority. Send a request from the account email to m.golov@dodvir.com. We verify identity before disclosure and normally respond within 30 days unless local law requires another period.