EVORIANT
What it doesHow it worksWhen it fits ↗DeliverableFAQComing soon
Evoriant/Privacy
ESEN

Privacy Policy

How Evoriant processes your personal data on evoriant.com and during a Session — what we collect, on what legal basis, for how long, and with which processors.

01

Data controller

The controller of the personal data collected on evoriant.com and through the Evoriant Service is EVORIANT TECHNOLOGIES, S.L. Data protection contact: privacy@evoriant.com.

02

Scope

This Policy applies to the processing of personal data carried out by the Controller in the context of: access to and use of evoriant.com and its subdomains; use of the Evoriant Service (Free phase and Paid phase); payment processing via Stripe; and, where applicable, supplementary web source search during the Paid phase; and the voluntary post-Session feedback form.

This Policy does not cover processing carried out by third parties (OpenAI, Anthropic, Stripe, etc.) acting as independent controllers under their own privacy policies, as detailed in section 6.

03

Data we process and purposes

The Controller processes personal data exclusively for the purposes listed below. No special categories under Art. 9 GDPR, nor data of minors under 18, are processed.

T1

Service delivery. We process the Session's history, Input and Output to perform the contract and generate the deliverable in the Paid phase (Art. 6(1)(b), contract performance). Retained for the contract term plus 5 years. Processors: OpenAI Ireland Ltd., Anthropic PBC, Vercel Inc. and Supabase.

T2

Free phase. We process the Session Input —no payment or account data— to provide the pre-payment diagnosis, on the basis of our legitimate interest (Art. 6(1)(f)). Retained while the session is active and for up to 30 days after. Processors: OpenAI Ireland Ltd. and Vercel Inc.

T3

Payment and invoicing. We process your email, the amount, the Stripe payment ID, the IP at the time of purchase and the country to handle the charge and issue the invoice (Art. 6(1)(b), contract; and Art. 6(1)(c), legal tax obligation). Retained for 5 years under tax obligations. Processors: Stripe Payments Europe Ltd. and Supabase.

T4

Web source search (Paid phase). When the problem requires it, we send a query synthesised from your Input —not its literal content and without direct identifiers— to retrieve external sources (Art. 6(1)(b)). The query is not retained after the Session. Brave Search acts as a provider, not as a processor (see section 6).

T5

Product analytics. With your consent (Art. 6(1)(a), via the consent management platform) we process a pseudonymised identifier and navigation and conversion events, with no IP (discarded server-side), to understand product usage. Retained for 1 year from the session. Processor: PostHog, Inc. (data in the EU, Frankfurt).

T8

Voluntary feedback. If you choose to fill in and send the post-Session feedback form, we process the responses you provide —NPS rating, reason selection and, if you write it, a free-text comment— on the basis of your consent (Art. 6(1)(a)). Submission is strictly voluntary; it may be skipped with no effect on the Service. Data is retained for up to 12 months or until withdrawal of consent. Processor: Supabase (data in the EU, Frankfurt).

The Input the User enters into the Service (the framing of the decision) may contain personal data of third parties. The Controller processes such Input solely to deliver the Service within the relevant Session and uses it for no other purpose. The User is responsible for ensuring that entering third-party data complies with applicable law.

Note on communications: the Service sends no service or marketing communications of its own. The payment receipt is issued by Stripe directly under its own responsibility (see section 6). The deliverable is obtained by direct download, not by email.

04

Legal basis for processing

  • Contract performance (Art. 6(1)(b)): processing necessary to deliver the Service and process payment. Without this data the Service cannot be provided.
  • Legal obligation (Art. 6(1)(c)): retention of tax data under Spanish law (Law 58/2003 General Tax Act, Commercial Code).
  • Legitimate interest (Art. 6(1)(f)): minimal data processing in the Free phase to enable the pre-payment diagnosis. On balance, the User's rights do not override the Controller's interest in offering a sample of the Service before payment.
  • Consent (Art. 6(1)(a)): product analytics (T5) and voluntary feedback form (T8). Freely given, specific, informed and unambiguous, provided via the CMP. It may be withdrawn at any time without affecting the lawfulness of prior processing.
05

Retention periods

As per section 3, under these criteria: contract-performance data, for the duration of the relationship and the limitation period for bringing or defending claims (5 years, Art. 1964 Civil Code); tax data, 5 years from the close of the financial year (Art. 66 bis General Tax Act); analytics data, 1 year from the session; voluntary feedback form data, up to 12 months or until withdrawal of consent; consent-based data, until withdrawal. Once the periods elapse, data is deleted or irreversibly pseudonymised.

06

Processors, independent controllers and international transfers

The Controller relies on the providers listed below. With those acting as processors it has signed (or will sign before any actual processing begins) the corresponding Data Processing Agreement (DPA), and has verified international transfer safeguards under Chapter V GDPR.

OpenAI
AI models · Processor · OpenAI Ireland Ltd. (EEA) · SCC for US processing
Anthropic
AI models · Processor · Anthropic PBC (USA) · SCC (Irish law)
Vercel
Hosting and deployment · Processor + independent controller · Vercel Inc. (USA) · SCC + DPF
Supabase
Database and authentication · Processor · Data in the EU (Frankfurt); contracting entity outside the EEA · SCC (sub-processors in Supabase's DPA)
Stripe
Payment processing · Processor + independent controller · Stripe Payments Europe Ltd. (EEA) + Stripe Inc. (USA) · DPF + SCC
PostHog
Product analytics · Processor · PostHog, Inc.; data in the EU (Frankfurt) · EU DPA; SCC for US sub-processors
Brave Search
Web search, Paid phase only · Not a processor · Brave Software (USA) · Server-side query, no direct identifiers

Beyond acting as processors, Vercel and Stripe also process certain data as independent controllers under their own policy (Vercel: service and account data; Stripe: fraud prevention, AML/KYC and sending the receipt to the User). User data on Supabase is hosted in the EU (Frankfurt) and, during the Paid phase, queries to Brave are made server-side without exposing direct identifiers.

Processors are prohibited from using the Controller's data for their own purposes other than delivering the contracted service. The Controller updates this list when adding or changing providers; material changes are notified under section 12. The User may request a copy of the safeguards applicable to international transfers (Standard Contractual Clauses) by writing to privacy@evoriant.com.

07

Cookies and tracking technologies

7.1 — Consent management (CMP)

evoriant.com uses a consent management platform (CMP) deployed locally, with no intermediary server or external processor. The consent cookie is stored exclusively in the User's browser and is not transmitted to third parties.

The modal appears on the first visit; the User can accept, reject or customise. Settings can be changed at any time via "Cookie preferences" in the footer.

7.2 — Cookies used

TypePurposeDurationProvider
NecessaryStores consent preferences365 daysFirst-party
Analytics (consent)Pseudonymised identifier for product analytics1 yearPostHog (EU)

No advertising or cross-site tracking cookies are used. Analytics cookies are written only with prior explicit consent. The IP address is not retained — it is discarded on the analytics server before the event is stored — and the processing does not allow direct personal identification of the User. Full detail is set out in the Cookie Policy.

08

Data subject rights

The User may exercise, free of charge, the rights of access, rectification, erasure, objection, restriction, portability and withdrawal of consent, under the terms of the GDPR. Requests should be addressed to privacy@evoriant.com, identifying the applicant. The Controller responds within one month at most (extendable to two in complex cases, with prior notice).

If the User considers the processing does not comply with the law, they may lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) or with the supervisory authority of their habitual residence.

09

Minors

The Service is intended exclusively for persons over 18. The Controller does not knowingly collect data from minors; if it becomes aware of such data, it will delete it immediately. Notices to privacy@evoriant.com.

10

Security of processing

The Controller applies technical and organisational measures appropriate to the state of the art: encryption in transit (TLS/HTTPS) and at rest for sensitive data; role-based access control; error monitoring; activity logging. Providers are selected requiring equivalent safeguards.

No system is infallible. In the event of a security breach that may affect data subjects' rights, the Controller will notify the AEPD within 72 hours at most (Art. 33 GDPR) and, where appropriate, the affected User (Art. 34 GDPR).

11

Artificial intelligence transparency (AI Act)

The Service integrates third-party AI systems (OpenAI, Anthropic). Under Regulation (EU) 2024/1689 (AI Act), the Controller clearly and visibly informs the User that they are interacting with an artificial intelligence system. Deliverables are identified as content generated with AI assistance.

The Service makes no automated decisions producing legal or similarly significant effects on the User within the meaning of Art. 22 GDPR: the User retains control of, and responsibility for, their decision at all times. The Controller does not use the User's Input to train its own models, nor does it authorise its processors to do so.

12

Changes to this Policy

The Controller may amend this Policy to reflect legal, technical or business changes. Material changes will be notified at least 30 calendar days in advance via an in-product notice or, where one exists, an email to the associated address. The current version is always available at evoriant.com/privacy.

13

Governing law and jurisdiction

This Policy is governed by Spanish and European data protection law (GDPR, LOPDGDD). Any dispute is subject to the Terms of Service, without prejudice to the consumer User's right to lodge a complaint with the AEPD or the supervisory authority of their residence.

EVORIANT TECHNOLOGIES, S.L.evoriant.com/privacy · privacy@evoriant.com
EVORIANT

AI in the Human Loop.

An AI co-reasoning platform for decisions that matter — built on the CoThinker Method.

Product

  • What it does
  • How it works
  • When it fits
  • Deliverable
  • FAQ

Method

  • cothinker.io ↗
  • Sample memo

Company

  • Privacy
  • Terms
  • Cookies
  • Transparency
  • Legal Notice
  • hello@evoriant.com
© 2026 EvoriantAI in the Human Loop.