The third-party providers Evaident relies on to deliver the platform — what each does, the data involved and where it’s processed. Provided for your due diligence and to support your data-processing agreement.
| Provider | Purpose | Data processed | Region |
|---|---|---|---|
| Railway | Application hosting and managed PostgreSQL database | All platform data at rest (event records, account and connector data) | EU — Amsterdam (US region available for enterprise) |
| Brevo | Transactional email — invitations, trial notices, assessment reports | Recipient name and email address, message content | EU |
| Stripe | Subscription billing and payment processing | Billing contact and subscription details. Card data is handled solely by Stripe — Evaident never sees or stores it. | EU / US (Stripe global, GDPR-compliant) |
| OpenAI | Powers the optional in-app AI assistant and the website chat assistant — used only to generate an answer when the assistant is used. It is not involved in the platform's evidence, gateway or connectors. | The questions asked, and — only when a workspace owner switches on the assistant's data access — aggregated usage metadata from that workspace. Captured prompt/response content is sent only if a user explicitly asks the assistant to show a specific event. OpenAI does not train on API data. | US |
The AI services you connect — such as OpenAI, Anthropic, Google or Microsoft — are your own accounts under your existing agreements. Evaident reads audit and billing data from them using the credentials you provide; it is not a subprocessor relationship we introduce on your behalf, and your prompt content is never sent to a third-party model. The one exception is the optional AI assistant (off by default, owner-enabled per workspace): when used, it sends your questions and aggregated metadata to OpenAI to generate an answer, and captured content only if you explicitly ask it to show a specific event.
Where use of a subprocessor involves a restricted transfer of personal data outside the United Kingdom, the EEA or Switzerland, we use an appropriate transfer mechanism — such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, an applicable adequacy regulation or decision, or another lawful transfer mechanism — together with supplementary measures where required. We do not permit subprocessors to use Customer Data to train their models except where you have expressly agreed otherwise in writing. This page supports our Data Processing Agreement and Privacy Policy.
We notify customers of material changes to this list before a new subprocessor begins handling customer data. A reference FX-rate feed is also used for currency conversion; no customer or personal data is sent to it.
Our security overview, Data Processing Agreement and full legal terms are all in one place — and we’ll complete your security questionnaire.