DrakaLabs Workspace

Privacy Policy

Last updated: 11 September 2026

This Privacy Policy explains how DrakaLabs ("we", "us", "our") collects, uses, discloses, and protects information when you use DrakaLabs Workspace (the "Service") — the messaging, files, directory, calendar, and administration platform provided to your organisation.

DrakaLabs Workspace is an organisational tool. Your organisation (for example, your university or employer) is the administrator and controller of your account and of much of the information processed through the Service. If you have questions about how your organisation uses your data, contact your organisation's administrator.

1. Who this applies to

  • Employees / staff: accounts created by an administrator, signing in with a staff ID and a PIN.
  • External / guest users: collaborators who sign in with a phone one-time code or an email magic link.

By using the Service you agree to this Policy. If you do not agree, do not use the Service.

2. Information we collect

a) Account and profile information

  • Name, staff ID, company email, and job title (set by your administrator).
  • Personal email and phone number (which you may add or edit).
  • Profile photo (avatar) that you upload.
  • Role (administrator or member) and account status.
  • User type (employee or external) and, for guests, access-expiry dates.

b) Authentication and device information

  • A stable device identifier generated once per browser/device.
  • Sign-in events, device-activation records, and active session information (platform, first-seen and last-seen times).
  • Access and refresh tokens used to keep you signed in. Refresh tokens are stored in a secure, HTTP-only cookie; short-lived access tokens are held in memory only.

c) Messages and content

  • The messages you send and receive, including text, quoted replies, and @mentions, together with a per-conversation sequence number and timestamps.
  • Files, images, videos, and other attachments you upload or download.
  • Reactions, pins, saved messages (bookmarks), and read/seen state.
  • Per-conversation settings such as mute and archive.

d) Calendar information

  • Events you are invited to or that are targeted to everyone, including titles, descriptions, times, locations, meeting links, and your RSVP.

e) Directory information

  • Information used to find and message colleagues (name, staff ID, email, job title, avatar), scoped by your organisation's rules.

f) Automated moderation signals

  • Messages are screened by an automated moderation service before delivery. This processing produces internal classification signals (for example an intent label and a confidence score) used to allow, hold, flag, or withhold a message. These signals are used for safety and policy enforcement.

g) Technical and log data

  • IP address, request metadata, and administrative audit records (see Section 6).

We do not ask you to enter, and the Service is not designed to collect, payment card numbers, government identification numbers, or financial-account credentials.

3. How we use information

  • To provide the Service: deliver messages in real time, sync history, store and serve files, run the calendar and directory, and keep you signed in.
  • To secure the Service: authenticate you, bind devices, detect and prevent abuse, and enforce account lock-outs after repeated failed sign-ins.
  • To enforce communication policy: automatically screen messages and, where a message is withheld, show the sender a brief notice.
  • To support administration: allow authorised administrators to manage users, groups, calendar events, and oversight functions on your organisation's behalf.
  • To send notifications: deliver in-app and, where enabled and configured, push notifications about relevant activity.
  • To comply with law and protect rights: respond to lawful requests and protect the safety of users and the organisation.

4. Automated message moderation

Every message is screened by an automated guard before it is delivered.

  • If a message is withheld, only the sender sees a short, neutral notice; the intended recipient never receives it. Withheld messages are not delivered and do not appear in conversation history for recipients.
  • The specific reason, category, or score behind a moderation decision is not shown to users.
  • Some messages may be held for administrative review; administrators may release or uphold them. Senders may appeal a withheld message; appeals are reviewed by administrators.

5. How information is shared

  • With other users: messages, reactions, mentions, calendar RSVPs, presence, and profile details are shared with the people and groups you interact with, according to conversation membership and directory scope.
  • With your organisation's administrators: administrators can manage accounts, create and manage groups and calendar events, review moderation queues and appeals, view audit logs, and — where authorised — browse conversations and read message transcripts (including direct messages). See Section 6.
  • With service providers: we use third-party infrastructure to operate the Service, which may include cloud hosting, media storage/delivery, email delivery, an automated moderation service, and (where configured) a push-notification provider. These providers process data on our behalf under appropriate obligations.
  • For legal reasons: where required by law, regulation, legal process, or to protect the rights, property, or safety of users or the public.

We do not sell your personal information.

6. Administrator oversight and transcripts

Because this is an organisational workspace, authorised administrators may have oversight capabilities, including the ability to browse conversations and read message transcripts (including private direct messages).

  • Every access to a raw conversation transcript is recorded in an audit log that identifies the administrator, the conversation, and the time of access.
  • Administrative actions (such as creating users, resetting PINs, releasing or upholding moderated messages, creating groups, and accessing transcripts) are recorded in the audit log.

You should have no expectation that messages, files, or other content in the Service are private from your organisation's authorised administrators.

7. Data retention

  • Messages, files, calendar events, and related records are retained for as long as your organisation maintains the workspace or as required to provide the Service, unless a shorter or longer period is set by your organisation or required by law.
  • Deactivating a user hides them from the directory and revokes their access, but message history and audit records are preserved.
  • Audit logs are retained to support accountability and security.

Specific retention periods are configured by your organisation. Contact your administrator for details.

8. Security

  • Traffic is encrypted in transit.
  • Refresh tokens are stored in secure, HTTP-only cookies and rotate on every use; reusing an old refresh token revokes the session.
  • Access tokens are short-lived (about 15 minutes) and held only in memory.
  • Devices must be activated, and accounts lock out after repeated failed sign-in attempts.
  • Attachments are served through access-controlled, time-limited links.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your choices and rights

  • Profile: you can add or update your personal email, phone number, and avatar. Certain fields (name, staff ID, job title, role, company email) are managed by administrators.
  • Devices: you can view your active sessions and remotely sign out a device.
  • Notifications: where push is available, you can enable or disable it.
  • Access, correction, and deletion: because your organisation controls your account, requests to access, correct, export, or delete your data should be directed to your organisation's administrator, who is responsible for responding consistent with applicable law. We will assist administrators as required.

10. Children

The Service is intended for use by members of an organisation and is not directed to children under the age required by your jurisdiction. Accounts are provisioned by administrators.

11. International transfers

Information may be processed and stored in countries other than your own, including where our service providers operate. Where required, appropriate safeguards are applied.

12. Changes to this policy

We may update this Policy from time to time. Material changes will be communicated through the Service or by your organisation. Continued use after an update constitutes acceptance of the revised Policy.

13. Contact

For questions about this Policy, contact your organisation's administrator or:

DrakaLabs
Email: privacy@drakalabs.com
Website: https://drakalabs.com

Note

This document is a template provided for convenience and does not constitute legal advice. Have it reviewed by qualified legal counsel and adapt it to the laws applicable to your organisation before publication.