This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Evaident Ltd (“Processor”, “Evaident”) and the Customer (“Controller”). It applies where we process personal data on the Controller’s behalf and reflects Article 28 of the UK GDPR and EU GDPR. If you require a counter-signed copy for your records, contact dpo@evaident.com.
1. Roles and scope
The Controller determines the purposes and means of processing the personal data it submits to the service. The Processor processes that data only to provide and support the service. This DPA prevails over any conflicting term in the Terms in respect of data protection.
2. Subject-matter, duration, nature and purpose
- Subject-matter: provision of the Evaident AI accountability platform.
- Duration: for the term of the subscription and until deletion of Customer Data as set out below.
- Nature and purpose: hosting, recording, governing and reporting on the Controller's use of AI, including usage metadata, optional content and cost attribution.
- Types of data: identifiers and usage metadata of the Controller's staff; and, where the Controller enables content capture, the contents of prompts and responses (with optional PII redaction), which may contain further personal data.
- Categories of data subject: the Controller's personnel and, where relevant, individuals referenced in captured content.
3. Processor obligations
- Process personal data only on the Controller's documented instructions, including the configuration choices made in the platform, unless required by law (in which case we will inform the Controller where lawful).
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (see Annex below).
- Not engage another subprocessor without general written authorisation and notice as set out below.
- Assist the Controller, taking into account the nature of processing, with data-subject requests and with security, breach-notification and data-protection-impact obligations.
- On termination, delete or return Customer Data at the Controller's choice, subject to legal-hold settings and routine backup cycles, and delete existing copies unless storage is required by law.
- Make available information necessary to demonstrate compliance and allow for and contribute to audits, subject to reasonable confidentiality and security safeguards.
4. Retention, return and erasure of Customer Personal Data
4.1 Customer instructions. The Processor processes Customer Personal Data only on the documented instructions of the Controller, including instructions given through the service settings. Those instructions include the Controller’s configuration of retention periods, content-capture settings, redaction settings, access roles, exports, deletion requests and legal holds.
4.2 Audit-record retention. The Controller is responsible for determining the lawful basis and retention period for Customer Personal Data within the audit record. The service is designed with a minimum audit-record retention period of six months and plan-specific maximum retention periods. The six-month minimum is intended to support customers with AI-governance, audit and record-keeping requirements, including customers subject to EU AI Act log-retention obligations where those obligations apply. The Controller must not configure or use the service in a way that is inconsistent with any legal, regulatory, employment, professional or contractual obligation that applies to the Controller.
4.3 Content retention. Prompt and response content is captured only where enabled by the Controller for the relevant source or route. Captured content may be subject to a separate and shorter retention period than audit metadata. Where captured content is purged, the Processor may retain hashes, digests, references, timestamps, event metadata and other integrity evidence required to maintain the verifiability of the tamper-evident audit chain.
4.4 Data-subject requests. Taking into account the nature of the processing, the Processor will assist the Controller by appropriate technical and organisational measures, insofar as possible, to fulfil the Controller’s obligations to respond to data-subject requests. The service enables the Controller to revoke a user’s access and delete or deactivate that user’s account profile. The Controller acknowledges that deletion of a live account profile does not necessarily delete historical audit records already attributed to that user. The Controller instructs the Processor to retain such historical audit records for the configured retention period where the Controller determines that retention is necessary for compliance with a legal or regulatory obligation, for governance, security or misuse investigation, for an audit or regulatory request, or for the establishment, exercise or defence of legal claims.
4.5 Controller responsibility for erasure decisions. The Controller is responsible for determining whether a data-subject request requires deletion, restriction, pseudonymisation, objection handling, continued retention or another response. Where the Controller relies on legitimate interests for retention of audit records, the Controller is responsible for carrying out and maintaining any legitimate interests assessment and for assessing any objection under Article 21 of the UK GDPR or EU GDPR, as applicable. The Processor will not independently determine the Controller’s lawful basis for retaining Customer Personal Data.
4.6 Legal hold. The Controller may apply a legal hold to preserve audit records for litigation, anticipated litigation, regulatory enquiry, internal investigation, audit or other legally justified purpose. While a legal hold is active, automatic deletion of the affected records is suspended. The Controller is responsible for applying, reviewing and releasing legal holds and for ensuring that any legal hold remains necessary and proportionate.
4.7 Full-content capture and special-category data. The Controller is responsible for ensuring that it has a lawful basis and, where required, an Article 9 condition and any applicable Data Protection Act 2018 Schedule 1 condition before enabling full-content capture or otherwise submitting special-category data, criminal-offence data, client-confidential material, legally privileged material or other high-risk personal data to the service. The Controller is responsible for carrying out any required data protection impact assessment, providing appropriate notices to users and other data subjects, and configuring capture, redaction, access and retention settings appropriately. The Processor will provide reasonable information and assistance to support the Controller’s assessment.
4.8 Return and deletion on termination. On termination or expiry of the Agreement, the Processor will, at the Controller’s choice, return or delete Customer Personal Data and delete existing copies, unless applicable law requires continued storage by the Processor. Deletion of a workspace is treated as the Controller’s instruction to delete the workspace and its Customer Personal Data after any stated recoverable grace period, unless the parties have separately agreed a post-termination archive or legal-hold arrangement. The Controller is responsible for exporting any audit records it needs to retain before instructing deletion of the workspace.
4.9 Backups. Customer Personal Data may remain in encrypted backups for a limited period until overwritten in accordance with the Processor’s backup lifecycle. During that period, backup data is protected and is not used for any live processing purpose other than restoration, business continuity, security or legal compliance.
5. Subprocessors
The Controller provides general authorisation for the Processor to engage the subprocessors listed at evaident.com/subprocessors. We impose data-protection obligations on each subprocessor no less protective than this DPA and remain responsible for their performance. We will give notice of intended additions or replacements before they begin processing Customer Data, giving the Controller the opportunity to object on reasonable data-protection grounds.
6. International transfers and the optional AI assistant
Customer Data is hosted in the EU by default. The Evaident platform audit record, gateway and connectors do not require Customer Data to be sent to a third-party AI model. The in-app AI assistant is an optional feature. Where the Controller enables or uses the AI assistant, the Processor may send the user’s question and the minimum Customer Data necessary to answer that question to the AI-assistant subprocessor identified on the subprocessors page. Unless the Controller has enabled workspace data access for the assistant, the assistant does not receive workspace audit data. Captured prompt or response content is sent to the AI-assistant subprocessor only where a user expressly asks the assistant to analyse or display a specific event or item containing that content.
Where personal data is transferred outside the United Kingdom, the EEA or Switzerland, the Processor will use an appropriate transfer mechanism, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, an applicable adequacy regulation or decision, or another lawful transfer mechanism, together with supplementary measures where required.
The Processor does not permit subprocessors to use Customer Data to train their models except where the Controller has expressly agreed otherwise in writing.
7. Personal data breach
We will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, and provide information reasonably required for the Controller to meet its own notification obligations.
8. Liability
The liability provisions of the Terms of Service apply to this DPA. Nothing in this DPA limits either party’s obligations or liability under applicable data-protection law to a data subject or supervisory authority.
9. Annex — security measures
- Encryption of Customer Data in transit (TLS) and of credentials and secrets at rest (AES-256-GCM).
- Logical tenant isolation so each customer's data is segregated.
- Role-based access control, single sign-on, and optional two-factor authentication for password accounts.
- A tamper-evident, hash-chained audit record with independent verification.
- Least-privilege access to production, secret management, and monitoring and logging.
- Regular backups and a documented restore capability.
