How Evolize collects, uses, stores, and protects information when providing its digital-risk scanning and monitoring service.
Document version
1.0
Last updated
This policy has not yet taken effect. Its final details are being completed before it applies.
01Scope
This policy explains how Evolize collects, uses, retains, and shares information in connection with the Evolize website, the Evolize application, and the digital-risk scanning and monitoring service they provide. Accessibility is one of the risk categories Evolize evaluates; it is not the whole of the service.
It applies to visitors to the public website, people who submit a domain or URL to be scanned, account holders, paying customers, and anyone who contacts Evolize. Separately, Evolize processes information contained in the public websites it scans, which describes the scanned website rather than the person who requested the scan and is addressed in the section on information observed on scanned websites.
Where this policy refers to "Evolize," "we," or "us," it means the entity that operates the Evolize product and brand and is responsible for the information described here.
02Information we collect
Some information reaches us because you provide it — the details you enter into forms, the domain or URL you submit to be scanned, the name and email you use to create an account, and anything you write when you contact us. Some is received automatically when you use the website, such as your device and browser information, network address, the pages you view, and the times of those visits. And some is generated by the service itself, such as the scan evidence captured for each finding.
The section below sets out each category, why it is processed, the legal basis, who receives it, and how long it is kept.
03How we use information
The table below summarizes the personal information Evolize processes. Retention is described in full in the Retention section, and the providers named under recipients are described in the Subprocessors section.
How Evolize processes personal information, by data category
Data category
Examples
Purpose
Legal basis
Recipients
Retention
Account and organization data
Name, work email, organization, role, membership, authentication identifiers
Account creation, authentication, organization administration, access control, support
Performance of a contract; legitimate interests in securing and administering the service
Domain, submitted URL, scan settings, verification state
Purpose
Run scans, create previews, associate scans with an account, prevent abuse
Legal basis
Performance of a contract; legitimate interests in evaluating public digital risk and preventing abuse
Recipients
Cloudflare (infrastructure)
Retention
See Retention
Scan evidence
Examples
Screenshots and crops, HTML fragments, selectors, accessibility-tree data, responsive states, rule results, finding metadata
Purpose
Reproduce and verify findings, support remediation, maintain history, improve rule reliability
Legal basis
Performance of a contract; legitimate interests in verifying findings and improving reliability
Recipients
Cloudflare (infrastructure)
Retention
See Retention
Usage, device, and security data
Examples
IP address, browser and device information, session events, request and error logs, authentication activity
Purpose
Security, fraud prevention, service operation, debugging, performance monitoring
Legal basis
Legitimate interests in operating, securing, and debugging the service; legal obligations where applicable
Recipients
Cloudflare (infrastructure)
Retention
See Retention
Billing and transaction data
Examples
Billing contact, plan, transaction identifiers, payment status, tax information
Purpose
Take payment, invoice, meet accounting and tax obligations
Legal basis
Performance of a contract; compliance with legal obligations
Recipients
Payment processor
Retention
As required for accounting and tax; see Retention
Contact and support data
Examples
Contact-form and enterprise enquiries, support messages, attachments, feedback
Purpose
Respond to and manage requests and related communications
Legal basis
Legitimate interests in responding to enquiries; performance of a contract where applicable
Recipients
Cloudflare (infrastructure)
Retention
See Retention
04Information observed on scanned public websites
When a website is submitted, Evolize inspects its public surfaces in the same way an ordinary visitor's browser would load the pages. It does not access source-code repositories, does not use credentials to reach private areas, and does not install any agent on the scanned site. For each finding it captures the evidence needed to make the finding verifiable — which can include the page URL, the element and its selector, the relevant markup, a screenshot, the timestamp, and the verification history over subsequent scans.
Scan evidence may incidentally contain information the website's operator has published there, including names, contact details, profile photographs, user-generated content, and other information visible to normal visitors. Evolize processes such information only as part of technical evidence and does not collect it to build personal profiles. To limit exposure, Evolize:
minimizes the content it captures;
prefers cropped or focused evidence where feasible;
restricts access to stored evidence;
applies retention controls; and
responds to legitimate deletion, exclusion, or review requests.
Because a scan can be requested by someone other than a website's owner, the person who submits a domain and the owner may differ. If you are a website owner and want to request exclusion from scanning, removal of personal information, or review of captured evidence, you can use the contact routes on the Company page. We will handle such requests in a way that respects the legitimate interests involved and applicable law.
05Authentication and identity
Evolize uses WorkOS, Inc. to provide account authentication and identity management. Where required to provide these functions, WorkOS may process user identifiers, contact information such as your email address, authentication records, session metadata, and organization membership information. It does not receive website scan data, evidence, or scanner findings. Authentication and session management rely on strictly necessary cookies or tokens that keep you signed in and secure your session; these are not used for analytics or advertising. WorkOS is listed in the Subprocessors section below and on the Security page.
06Legal bases for processing
Evolize relies on the following legal bases, as indicated for each category in the table above:
Performance of a contract — to provide the service you or your organization have requested, including running scans, producing reports, and administering accounts.
Legitimate interests — to operate and secure the service, evaluate publicly accessible digital risk, prevent abuse, improve scanner reliability, and communicate with business users. Where we rely on legitimate interests, we balance them against your interests and rights.
Compliance with legal obligations — to meet accounting, tax, and other legal requirements.
Consent — where consent is the appropriate basis, such as certain non-essential cookies. We do not use consent as a catch-all basis, and you may withdraw it at any time.
07Sharing
We do not sell personal information. We share it only where necessary to run the service and only with parties bound to handle it appropriately:
subprocessors that provide infrastructure, authentication, payment, and similar functions, as listed below;
other Authorized Users of your organization, where your account belongs to one;
authorities or others where required to comply with the law or protect our rights, users, or the security of the service; and
a successor entity in a merger, acquisition, or similar transaction, subject to this policy.
08Subprocessors
Evolize uses the providers below to operate the service. This list is maintained together with the disclosure on the Security page and is updated when the set of providers changes.
Subprocessors Evolize uses to provide the service
Provider
Function
Data involved
Region
Documentation
Cloudflare
Hosting, edge delivery, browser rendering, processing and storage
Scan inputs, generated evidence and operational metadata
Global infrastructure; storage and processing locations depend on the configured Cloudflare services and account settings
We keep information only for as long as it is needed for the purposes described in this policy, and then delete or de-identify it. Different categories are kept for different periods.
How long Evolize retains each category of information
Category
Retention
Unclaimed scan previews
Deleted or de-identified when no longer needed to provide a preview, unless claimed, required for security, or legally retained
Claimed scan and finding history
Available for the history period included in your plan (up to 12 months on standard plans; custom on Enterprise), subject to plan and contract terms
Deleted account data
Removed from active systems when no longer needed and from routine backups as they age out of the backup rotation, subject to legal and security exceptions
Security and authentication logs
Kept only as long as needed for security and service operation, then deleted or de-identified
Support requests
Kept as long as needed to handle the matter and maintain a record of the exchange
Billing and tax records
Kept as long as required to meet accounting and tax obligations
Website-owner exclusion requests
Kept as long as needed to apply and honor the request
Unclaimed scan previews
Retention
Deleted or de-identified when no longer needed to provide a preview, unless claimed, required for security, or legally retained
Claimed scan and finding history
Retention
Available for the history period included in your plan (up to 12 months on standard plans; custom on Enterprise), subject to plan and contract terms
Deleted account data
Retention
Removed from active systems when no longer needed and from routine backups as they age out of the backup rotation, subject to legal and security exceptions
Security and authentication logs
Retention
Kept only as long as needed for security and service operation, then deleted or de-identified
Support requests
Retention
Kept as long as needed to handle the matter and maintain a record of the exchange
Billing and tax records
Retention
Kept as long as required to meet accounting and tax obligations
Website-owner exclusion requests
Retention
Kept as long as needed to apply and honor the request
When information is deleted, residual copies may remain in routine backups until they age out of the backup rotation; backups are used only for disaster recovery and are not restored into active use. Anonymized or aggregated information that no longer identifies a person may be retained to operate and improve the service.
10Your rights and choices
Depending on where you live and the applicable law, you may have rights over the information we hold about you, which can include:
access to it;
correction of it;
deletion of it;
restriction of certain processing;
objection to certain processing;
portability of it;
withdrawal of consent, where processing is based on consent; and
complaint to a supervisory authority.
Account holders can review and update much of their information by signing in. For other requests, or if you do not hold an account, you can use the contact routes on the Company page. We may need to verify your identity and, where you act for someone else, your authority, before we act on a request. Information about the safeguards for international transfers is set out below.
11International transfers
Evolize and its providers may process information in countries other than the one in which you are located. As indicated in the Subprocessors section, some providers operate in the United States and on global infrastructure, so information may be transferred across borders.
Where information is transferred to a country that does not provide an equivalent level of protection, we rely on appropriate safeguards required by applicable law, such as standard contractual clauses, so that it continues to be protected in line with this policy. You can use the contact routes on the Company page to request more information about the safeguards that apply.
12Security
We take reasonable technical and organizational measures to protect information against loss, misuse, and unauthorized access, disclosure, or alteration, including access controls and protecting information in transit. By design, scans are confined to public surfaces: Evolize does not collect source code, does not use credentials to reach private areas, and does not install any agent, which deliberately limits the sensitivity of what a scan can gather. No method of transmission or storage is completely secure, but we work to protect information in a manner appropriate to its sensitivity. The Security page describes our approach in more detail.
13Children
Evolize is a business tool intended for organizations and the people who work for them. It is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can review the matter and take appropriate action.
14Changes to this policy
We may update this policy as the service develops or as legal requirements change. When we make a material change, we will update the effective date shown with this policy and, where appropriate, provide a more prominent notice. We encourage you to review it periodically.
15Contact
If you have questions about this policy or how Evolize handles information, you can reach us using the details below. Additional contact routes are available on the Company page.