Who we are
Evidra, located in Abuja, Nigeria, operates Evidra, an evidence first platform for RFPs, security questionnaires and due diligence questionnaires. In this policy "we" means Evidra and "you" means a person using the site or the product, or an organization that has an account.
Questions about this policy go to hello@evidra.xyz. Security questions go to security@evidra.xyz.
What we collect
We collect only what the service needs to work.
- Account data: your name, email address and password hash, or the identifier your sign in provider gives us when you sign in with Google or Microsoft.
- Organization data: the organization name, industry, questionnaire types, tone setting, members, roles and invitations.
- Customer content: the documents, questionnaires, answers, evidence links, comments and activity that your organization uploads or creates in the product.
- Usage data: pages processed, chunks embedded, index size, questionnaires completed and questions answered, per organization, per month and lifetime.
- Technical data: server logs with IP address, browser type, the pages requested and timestamps, kept for security and troubleshooting.
- Messages you send through the contact form: your name, email, company, topic and message.
How we use it
Each kind of data is used for one purpose.
- Account and organization data: to sign you in, enforce roles and show the right organization.
- Customer content: to index your documents, draft answers strictly from them, attach evidence, run the verification workflow and export the completed response. Customer content is never used to train or fine tune any model, by us or by our providers.
- Usage data: to show your organization its plan usage and to bill correctly.
- Technical data: to keep the service secure and to investigate faults.
- Contact messages: to reply to you.
- We do not sell personal data and we do not use it for advertising.
Legal basis
Where data protection law requires a legal basis, we rely on the contract with your organization for account, organization, customer and usage data; on our legitimate interest in running a secure service for technical data; and on your request for contact messages. Where consent is required, for example for product emails that are not about your account, we ask for it and you can withdraw it at any time.
Who processes data on our behalf
The providers below process data for us under contracts that restrict them to that purpose. Changes to this list are published on the security page before they take effect.
- Google Cloud: Authentication (Firebase Authentication), application database (Firestore) and file storage (Cloud Storage). Region: European Union multi region.
- Vercel: Web hosting, serverless compute and edge network. Region: Global.
Retention and deletion
Customer content is kept for as long as your organization keeps it. Deleting a document removes its chunks from your search index within minutes and deletes the file from storage. Deleting a questionnaire removes its questions, answers, evidence links, comments and activity. Closing an organization removes all of its data from the database, the index and file storage.
Account data is kept while the account exists and deleted when the account is closed, except where a law requires us to keep a record for longer. Server logs are kept for ninety days. Contact messages are kept until the conversation is closed and for twelve months after.
Where data is processed
Authentication, the application database and uploaded files are held on Google Cloud in the European Union multi region. Vercel serves the site and runs the application from a global edge network. Where data leaves the region in which it was collected, we rely on the transfer mechanisms in our provider contracts.
Security
Connections use TLS. Data at rest is encrypted by the storage providers. The browser never reads the database directly; every query runs on the server scoped to the organization, passages are indexed per organization, and roles are checked on the server for every action. The security page describes these practices in full and states plainly that no certification is held yet.
Your rights
You can access, correct, export and delete the personal data we hold about you. Organization members do this through the product; anyone can email hello@evidra.xyz. Where the law gives you further rights, for example to object to processing or to complain to a supervisory authority, those rights are unaffected by this policy.
Children
The service is for organizations and is not directed at anyone under eighteen. We do not knowingly collect data from children.
Changes
When this policy changes, the new version is published here with a new effective date, and organizations with an account are told by email before a material change takes effect.