This policy explains how Evaident Ltd (“Evaident”, “we”) processes personal data. It covers two roles: (a) where we are the controller of data about the people who run and use our accounts; and (b) where we are a processor handling personal data within Customer Data on a customer’s instructions, governed by our Data Processing Agreement.
1. Data we process as controller
- Account data: name, work email, organisation, role and authentication details (including SSO identifiers and, for password accounts, hashed passwords and encrypted two-factor secrets).
- Billing data: subscription and billing contact details. Card details are handled solely by our payment processor; we do not see or store them.
- Usage and support data: logs, device/connection metadata and correspondence needed to operate, secure and support the service.
2. Why we process it and our lawful basis
- To provide, secure and support the service — performance of our contract with you.
- To bill and prevent fraud, and to comply with law — legitimate interests and legal obligation.
- To send service and, where permitted, relevant product communications — legitimate interests; you can opt out of marketing at any time.
3. Customer Data we process as processor
When you use Evaident, the platform records metadata about your organisation’s AI use and — only if you enable it — optional prompt/response content, with PII redaction available. This may contain personal data of your staff or clients. We process it solely to provide the service on your instructions, as set out in the DPA. We never use Customer Data to train AI models, and we never sell it.
4. Hosting, transfers and subprocessors
- Customer Data is hosted in the EU (Amsterdam) by default; a US region is available for enterprise customers on request.
- We use a small set of vetted subprocessors to deliver the service, listed at evaident.com/subprocessors. Where data is transferred outside the UK/EEA, appropriate safeguards (such as the UK IDTA or EU Standard Contractual Clauses) are used.
5. Retention of customer audit records and erasure requests
We keep account, billing and support data (where we are the controller) for as long as you have an account and for a reasonable period afterwards as needed for legal, accounting or dispute purposes.
Evaident provides a tamper-evident audit record of how AI tools are used within a customer organisation. Where you are a member of, or are recorded within, a customer workspace, the customer organisation is normally the data controller for that audit record and Evaident acts as its processor. Evaident processes that record on the customer’s documented instructions, including the customer’s configured retention, capture, redaction and legal-hold settings.
Customer audit records are retained for the period configured by the customer, subject to the minimum and maximum retention periods available within the service (up to the maximum available on the customer’s plan). The service is designed to support customers that need to retain AI-use logs for compliance, audit, governance, regulatory or legal-claims purposes, including customers subject to sector-specific or AI-specific record-keeping requirements. At the end of the configured retention period, audit records are automatically purged, unless a customer-applied legal hold is in effect.
By default, Evaident records metadata only, such as the user, time, AI tool, model, usage volume, risk flags and relevant governance events. Prompt and response content is captured only where the customer enables content capture for the relevant source or route. Captured content may be subject to a shorter retention period than the audit metadata. Where captured content is purged, Evaident may retain a digest, hash, reference or other integrity evidence so that the audit chain can still be verified without retaining the content itself.
You may ask for your personal data to be erased. Where Evaident is the controller of your own account, billing, support or website data, Evaident will assess and respond to that request. Where your personal data is contained in a customer workspace, the relevant customer is responsible for assessing and responding to the request, and Evaident will assist the customer in accordance with the Data Processing Agreement.
A workspace owner or administrator can remove your live access and delete or deactivate your account profile, including your sign-in credentials and directory profile. However, this does not necessarily remove historical audit records showing activity already attributed to you. Those historical records may be retained for the applicable retention period where the customer determines that retention is necessary to comply with a legal or regulatory obligation, to maintain an accountable compliance record, to investigate misuse or security incidents, or for the establishment, exercise or defence of legal claims.
Where the customer relies on a legal obligation or legal-claims basis, the right to erasure may not apply to the relevant audit record under Article 17(3)(b) or Article 17(3)(e) of the UK GDPR or EU GDPR, as applicable. Where the customer relies on legitimate interests, the customer must assess any objection to processing and may continue to retain the record only where it can demonstrate compelling legitimate grounds which override the interests, rights and freedoms of the individual, or where the processing is required for legal claims.
Evaident does not process customer audit records on the basis of consent, and the withdrawal of consent does not by itself require deletion of a historical audit record. The customer remains responsible for choosing the appropriate lawful basis, setting an appropriate retention period, informing its users, and handling data-subject requests. If you believe your data is being retained without a lawful basis, you should raise this with the customer organisation operating the workspace. You may also complain to the Information Commissioner’s Office or your local supervisory authority.
6. Security
We apply technical and organisational measures appropriate to the data, including encryption in transit and at rest, tenant isolation, role-based access, single sign-on and optional two-factor authentication, and a tamper-evident audit record. See our security overview for more.
7. Your rights
Depending on your location you may have rights to access, correct, delete, restrict or port personal data, and to object to certain processing. For account data we are the controller — contact us using the details below. For personal data within Customer Data, the relevant customer is the controller and we will assist them in responding to your request.
8. Cookies
We use strictly necessary cookies to keep you signed in and to secure the service. We do not use advertising cookies. Any analytics we use are privacy-respecting and limited to operating and improving the service.
9. Contact and complaints
For privacy questions contact privacy@evaident.com or our data protection contact at dpo@evaident.com. If you are in the UK and are unhappy with our response you may complain to the Information Commissioner’s Office (ICO).
