Privacy Policy
Last updated September 16, 2026
Karavela processes personal data about the people who sign in to the Karavela Dashboard. This policy describes that processing and the rights you have under the General Data Protection Regulation (GDPR).
Scope
This policy covers the dashboard and the systems it relies on, which are the identity provider that signs you in, the GraphQL API, the research database, and the logging pipeline. It applies to Karavela staff and to staff of investigation centers who hold a dashboard account, including operators, investigators, and physicians. Karavela employees are also covered by the employee privacy notice published in the internal wiki.
This policy does not cover research participants. The records shown in the dashboard are pseudonymized and contain no participant name, contact details, or date of birth. The key that links a study identifier to a person stays at the investigation center. The processing of participant data is governed by the applicable research protocol and by the informed consent form signed by the participant.
Data controller
Karavela, a simplified joint stock company registered with the Paris Trade and Companies Register under number 944 250 448, with registered offices at 198 avenue de France, 75013 Paris, France.
You can contact our Data Protection Officer at dpo@karavela.ai.
Processing activities
Account and access rights
- Data
- Username, display name, professional email address, the groups that carry your role and your center, the multi-factor authentication devices you enroll, and your authentication credentials.
- Purpose
- Creating and managing your account, signing you in, and determining which pages and which records you are allowed to see and to edit.
- Legal basis
- Performance of the contract under which you are given access, which is your employment contract or the agreement signed with your center (Article 6(1)(b) GDPR), and our legitimate interest in controlling access to a platform that holds research data (Article 6(1)(f) GDPR).
- Retention
- For as long as you need access. Your account is deactivated when your assignment ends and deleted afterwards.
Authentication events
- Data
- Date and time, username and account identifier, outcome of the attempt, application, authentication method, IP address, the approximate city, country, and network operator derived from that address, browser and operating system, and a request identifier.
- Purpose
- Securing accounts and the platform, detecting unauthorized sign-in attempts, and investigating security incidents.
- Legal basis
- Our legitimate interest in securing a platform that serves a research study (Article 6(1)(f) GDPR) and our obligation to secure processing (Article 32 GDPR).
- Retention
- One year in the identity provider. Sign-in, sign-out, and failed sign-in events are also copied to the audit trail of the research database and kept for the duration of the study.
Dashboard activity
- Data
- One record for each request, with date and time, username and account identifier, the role and center the request ran with, the operation and its parameters, IP address, request identifier, response size, and the outcome or the error returned. A record of an edit also holds the row before and after the change and the reason you enter in the change dialog.
- Purpose
- Tracing access to and changes in research data as required for the conduct, the monitoring, and the audit of the research study, and investigating security incidents.
- Legal basis
- Compliance with the traceability obligations that apply to the research study (Article 6(1)(c) GDPR) and our legitimate interest in the integrity of the research database (Article 6(1)(f) GDPR).
- Retention
- The duration of the study and of the archiving period set by the research protocol, which may run for several years. These records cannot be modified or deleted.
Technical logs and monitoring
- Data
- Server, container, and system logs of the services behind the dashboard, and host metrics. They contain timestamps, service names, error messages, request identifiers, and IP addresses. Study identifiers are removed before these logs leave the server.
- Purpose
- Keeping the platform available and diagnosing errors and incidents.
- Legal basis
- Our legitimate interest in operating and maintaining the platform (Article 6(1)(f) GDPR).
- Retention
- 30 days in the log store, and no longer than one year where archives are moved to object storage. Encrypted infrastructure backups are kept for 14 days.
Cookies
Signing in sets an encrypted session cookie that holds your identity claims and the tokens issued by the identity provider. It keeps you signed in and is cleared when you sign out. The identity provider sets its own session cookie on its domain. One additional cookie remembers whether you collapsed the sidebar and expires after 30 days.
These cookies are strictly necessary to provide the service. The dashboard sets no analytics, advertising, or tracking cookie, embeds no third-party tag, and stores no record of your activity in your browser.
Recipients
Karavela operates the dashboard and every system behind it on its own infrastructure. No third party receives your data for its own purposes, and your data is not used for advertising, profiling, or automated decision-making.
Inside Karavela, access is limited to the administrators of the platform and of the identity provider, and to the holders of the monitor role, who can read and export the audit trail. The audit trail may also be disclosed to the monitors and auditors of the study sponsor and to the competent authorities during an inspection of the research study.
Scaleway hosts the servers and the object storage as our processor, under an agreement that contains the obligations required by Article 28 of the GDPR.
International transfers
All data described in this policy is stored in the European Union, on servers and object storage located in France. No data is transferred outside the European Union.
Security
The dashboard is served over HTTPS and requires single sign-on with multi-factor authentication. What you can see depends on your role, and staff of an investigation center can only read the records of their own center. The audit trail is written by a database account that can insert records but cannot modify or delete them. Backups are encrypted.
Your rights
Subject to the conditions set out in the GDPR, you have the following rights in respect of your personal data.
- Access
- Obtain confirmation that we process your data and a copy of it.
- Rectification
- Have inaccurate or incomplete data corrected.
- Erasure
- Have your data deleted where no legal obligation requires us to keep it.
- Restriction
- Obtain the restriction of processing in the cases provided for by law.
- Objection
- Object to processing based on our legitimate interest.
- Portability
- Receive the data you provided in a structured, commonly used, and machine-readable format.
- Post-mortem instructions
- Give instructions on the processing of your data after your death.
The audit trail is an exception. Its records cannot be corrected or erased, because the traceability required by the research study depends on them remaining unaltered, and they are kept for the period stated above. You can still submit a request, and we will tell you what we are able to do.
Exercising your rights
To exercise these rights, contact our Data Protection Officer at dpo@karavela.ai or write to Karavela, 198 avenue de France, 75013 Paris, France. We respond within one month. We may ask for proof of identity if we have reasonable doubt about who is making the request.
You can also lodge a complaint with the CNIL, the French data protection authority, at cnil.fr or by post to 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.
Changes to this policy
We may update this policy to reflect changes in the processing carried out through the dashboard. The date of the latest version is shown at the top of this page.