Privacy Policy

Last updated September 16, 2026

Karavela processes personal data about the people who sign in to the Karavela Dashboard. This policy describes that processing and the rights you have under the General Data Protection Regulation (GDPR).

Scope

This policy covers the dashboard and the systems it relies on, which are the identity provider that signs you in, the GraphQL API, the research database, and the logging pipeline. It applies to Karavela staff and to staff of investigation centers who hold a dashboard account, including operators, investigators, and physicians. Karavela employees are also covered by the employee privacy notice published in the internal wiki.

This policy does not cover research participants. The records shown in the dashboard are pseudonymized and contain no participant name, contact details, or date of birth. The key that links a study identifier to a person stays at the investigation center. The processing of participant data is governed by the applicable research protocol and by the informed consent form signed by the participant.

Data controller

Karavela, a simplified joint stock company registered with the Paris Trade and Companies Register under number 944 250 448, with registered offices at 198 avenue de France, 75013 Paris, France.

You can contact our Data Protection Officer at dpo@karavela.ai.

Processing activities

Account and access rights

Data
Username, display name, professional email address, the groups that carry your role and your center, the multi-factor authentication devices you enroll, and your authentication credentials.
Purpose
Creating and managing your account, signing you in, and determining which pages and which records you are allowed to see and to edit.
Legal basis
Performance of the contract under which you are given access, which is your employment contract or the agreement signed with your center (Article 6(1)(b) GDPR), and our legitimate interest in controlling access to a platform that holds research data (Article 6(1)(f) GDPR).
Retention
For as long as you need access. Your account is deactivated when your assignment ends and deleted afterwards.

Authentication events

Data
Date and time, username and account identifier, outcome of the attempt, application, authentication method, IP address, the approximate city, country, and network operator derived from that address, browser and operating system, and a request identifier.
Purpose
Securing accounts and the platform, detecting unauthorized sign-in attempts, and investigating security incidents.
Legal basis
Our legitimate interest in securing a platform that serves a research study (Article 6(1)(f) GDPR) and our obligation to secure processing (Article 32 GDPR).
Retention
One year in the identity provider. Sign-in, sign-out, and failed sign-in events are also copied to the audit trail of the research database and kept for the duration of the study.

Dashboard activity

Data
One record for each request, with date and time, username and account identifier, the role and center the request ran with, the operation and its parameters, IP address, request identifier, response size, and the outcome or the error returned. A record of an edit also holds the row before and after the change and the reason you enter in the change dialog.
Purpose
Tracing access to and changes in research data as required for the conduct, the monitoring, and the audit of the research study, and investigating security incidents.
Legal basis
Compliance with the traceability obligations that apply to the research study (Article 6(1)(c) GDPR) and our legitimate interest in the integrity of the research database (Article 6(1)(f) GDPR).
Retention
The duration of the study and of the archiving period set by the research protocol, which may run for several years. These records cannot be modified or deleted.

Technical logs and monitoring

Data
Server, container, and system logs of the services behind the dashboard, and host metrics. They contain timestamps, service names, error messages, request identifiers, and IP addresses. Study identifiers are removed before these logs leave the server.
Purpose
Keeping the platform available and diagnosing errors and incidents.
Legal basis
Our legitimate interest in operating and maintaining the platform (Article 6(1)(f) GDPR).
Retention
30 days in the log store, and no longer than one year where archives are moved to object storage. Encrypted infrastructure backups are kept for 14 days.

Cookies

Signing in sets an encrypted session cookie that holds your identity claims and the tokens issued by the identity provider. It keeps you signed in and is cleared when you sign out. The identity provider sets its own session cookie on its domain. One additional cookie remembers whether you collapsed the sidebar and expires after 30 days.

These cookies are strictly necessary to provide the service. The dashboard sets no analytics, advertising, or tracking cookie, embeds no third-party tag, and stores no record of your activity in your browser.

Recipients

Karavela operates the dashboard and every system behind it on its own infrastructure. No third party receives your data for its own purposes, and your data is not used for advertising, profiling, or automated decision-making.

Inside Karavela, access is limited to the administrators of the platform and of the identity provider, and to the holders of the monitor role, who can read and export the audit trail. The audit trail may also be disclosed to the monitors and auditors of the study sponsor and to the competent authorities during an inspection of the research study.

Scaleway hosts the servers and the object storage as our processor, under an agreement that contains the obligations required by Article 28 of the GDPR.

International transfers

All data described in this policy is stored in the European Union, on servers and object storage located in France. No data is transferred outside the European Union.

Security

The dashboard is served over HTTPS and requires single sign-on with multi-factor authentication. What you can see depends on your role, and staff of an investigation center can only read the records of their own center. The audit trail is written by a database account that can insert records but cannot modify or delete them. Backups are encrypted.

Your rights

Subject to the conditions set out in the GDPR, you have the following rights in respect of your personal data.

Access
Obtain confirmation that we process your data and a copy of it.
Rectification
Have inaccurate or incomplete data corrected.
Erasure
Have your data deleted where no legal obligation requires us to keep it.
Restriction
Obtain the restriction of processing in the cases provided for by law.
Objection
Object to processing based on our legitimate interest.
Portability
Receive the data you provided in a structured, commonly used, and machine-readable format.
Post-mortem instructions
Give instructions on the processing of your data after your death.

The audit trail is an exception. Its records cannot be corrected or erased, because the traceability required by the research study depends on them remaining unaltered, and they are kept for the period stated above. You can still submit a request, and we will tell you what we are able to do.

Exercising your rights

To exercise these rights, contact our Data Protection Officer at dpo@karavela.ai or write to Karavela, 198 avenue de France, 75013 Paris, France. We respond within one month. We may ask for proof of identity if we have reasonable doubt about who is making the request.

You can also lodge a complaint with the CNIL, the French data protection authority, at cnil.fr or by post to 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.

Changes to this policy

We may update this policy to reflect changes in the processing carried out through the dashboard. The date of the latest version is shown at the top of this page.