Privacy Policy
Last updated: August 4, 2026
This Privacy Policy explains how Evidio ("we", "our", or "us") collects, uses, stores, and protects your personal data when you use our document management platform.
We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws.
1. Data Controller
The controller responsible for processing your personal data is:
Please replace the above information with your legal business or personal details before publishing this policy.
2. What Is Personal Data?
Personal data means any information relating to an identified or identifiable natural person. This includes information such as your name, email address, online identifiers, authentication information, or any other information that can identify you directly or indirectly.
3. Personal Data We Collect
Depending on how you use Evidio, we may collect and process the following categories of personal data:
| Category | Examples |
|---|---|
| Account Information | Name, email address, profile image. |
| Authentication | Session identifiers, authentication tokens, login sessions. |
| Application Data | Folder names, archive information, document metadata, QR code references, transfer information and related records. |
| Company Information | Company memberships, company owner, employee assignments and permissions. |
| Technical Information | IP address, browser type, operating system, device information, request timestamps and security logs. |
We only collect information that is necessary to provide, secure, improve and maintain the Evidio platform.
4. How We Use Your Personal Data
We process your personal data for the following purposes:
- Create and manage user accounts.
- Authenticate users securely.
- Maintain active login sessions.
- Store and organize folders and archive data.
- Generate and manage QR codes.
- Allow collaboration between company members.
- Protect the application against abuse and fraud.
- Provide customer support.
- Monitor application stability and security.
- Comply with legal obligations.
5. Legal Basis for Processing
We process personal data under one or more of the following legal bases provided by Article 6 of the GDPR:
Performance of a Contract (Article 6(1)(b))
Processing is necessary to provide your Evidio account, manage folders, authenticate users, and deliver the services requested by you.
Legal Obligation (Article 6(1)(c))
We may process personal data where required to comply with applicable laws or requests from competent authorities.
Legitimate Interests (Article 6(1)(f))
We process certain technical information to ensure the security, reliability and proper functioning of the platform, prevent unauthorized access, detect abuse and improve the service.
6. Hosting & Infrastructure
Evidio is hosted on Vercel Inc., which provides the infrastructure required to deliver the application over the internet.
When you access Evidio, Vercel may process technical information necessary to securely deliver the application, including:
- IP address
- Browser and device information
- Request timestamps
- HTTP request metadata
- Error logs
- Security-related logs
This information is processed solely for hosting, security, performance optimization and ensuring the reliable operation of the Service.
7. Database Provider
User data is securely stored in a PostgreSQL database hosted by Neon.
Neon acts as our database infrastructure provider and processes personal data only for securely storing and retrieving information required for the operation of Evidio.
8. Authentication & User Sessions
Evidio uses secure authentication to verify user identities and provide access to protected features.
During authentication we may process:
- User account identifiers.
- Email address.
- Encrypted session tokens.
- Session expiration information.
- Login timestamps.
- IP address and browser information for security purposes.
This information is processed solely for authentication, authorization, fraud prevention and account security.
9. Cookies
Evidio uses only cookies that are strictly necessary for the proper operation of the Service.
These cookies are used for:
- Keeping users signed in.
- Maintaining authenticated sessions.
- Protecting user accounts.
- Preventing unauthorized access.
- Security purposes.
We do not use advertising cookies and we do not sell or share cookie data with advertisers.
If optional analytics or marketing cookies are introduced in the future, this Privacy Policy will be updated and, where required by law, your consent will be requested before they are used.
10. Third-Party Services
We use trusted third-party providers to operate the Service.
| Provider | Purpose |
|---|---|
| Vercel | Application hosting and infrastructure. |
| Neon | PostgreSQL database hosting. |
| Cloudinary (if enabled) | Storage of uploaded images and QR code images. |
Each provider processes personal data only to the extent necessary for delivering its services to Evidio.
11. International Data Transfers
Some of our service providers may process personal data outside your country of residence.
Whenever personal data is transferred outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place as required by the GDPR. These safeguards may include:
- European Commission adequacy decisions.
- Standard Contractual Clauses (SCCs).
- Other legally approved transfer mechanisms.
12. Sharing of Personal Data
We do not sell, rent or trade your personal data.
Personal data may be shared only:
- With service providers necessary for operating Evidio.
- When required by applicable law.
- To protect our legal rights or prevent fraud and abuse.
- If required by courts or competent governmental authorities.
We never sell your personal information to third parties.
13. Data Retention
We retain your personal data only for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.
In general:
- Account information is retained while your account remains active.
- Folder and company data is retained until you delete it or your account is removed.
- Authentication sessions are automatically removed after they expire.
- Technical logs are retained only for the period necessary for security, troubleshooting, and legal compliance.
When personal data is no longer required, it will be securely deleted or anonymized unless applicable law requires a longer retention period.
14. Security of Personal Data
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, alteration, disclosure, or destruction.
These measures include, where appropriate:
- Encrypted HTTPS connections.
- Secure authentication and session management.
- Access controls and authorization.
- Database security provided by Neon.
- Infrastructure security provided by Vercel.
- Regular dependency and security updates.
Although we strive to use commercially acceptable means to protect your information, no method of electronic transmission or storage is completely secure.
15. Your Rights Under the GDPR
If you are located within the European Economic Area (EEA), you have the following rights regarding your personal data:
- Right to access your personal data.
- Right to rectify inaccurate or incomplete data.
- Right to erasure ("Right to be Forgotten").
- Right to restrict processing.
- Right to object to processing.
- Right to data portability.
- Right to withdraw consent at any time where processing is based on consent.
- Right to lodge a complaint with your local supervisory authority.
If you wish to exercise any of these rights, please contact us using the contact information provided below.
16. Children's Privacy
Evidio is not intended for children under the age of 16.
We do not knowingly collect personal information from children. If you believe that a child has provided us with personal data, please contact us immediately so that we can delete the information.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the functionality of Evidio.
The latest version will always be available on this page. We encourage you to review this Privacy Policy periodically.
18. Contact Information
If you have any questions regarding this Privacy Policy or wish to exercise your rights under the GDPR, please contact us:

