PRIVACY POLICY

Privacy Policy

How Evolize collects, uses, stores, and protects information when providing its digital-risk scanning and monitoring service.

Document version
1.0
Last updated

This policy has not yet taken effect. Its final details are being completed before it applies.

Scope

This policy explains how Evolize collects, uses, retains, and shares information in connection with the Evolize website, the Evolize application, and the digital-risk scanning and monitoring service they provide. Accessibility is one of the risk categories Evolize evaluates; it is not the whole of the service.

It applies to visitors to the public website, people who submit a domain or URL to be scanned, account holders, paying customers, and anyone who contacts Evolize. Separately, Evolize processes information contained in the public websites it scans, which describes the scanned website rather than the person who requested the scan and is addressed in the section on information observed on scanned websites.

Where this policy refers to "Evolize," "we," or "us," it means the entity that operates the Evolize product and brand and is responsible for the information described here.

Information we collect

Some information reaches us because you provide it — the details you enter into forms, the domain or URL you submit to be scanned, the name and email you use to create an account, and anything you write when you contact us. Some is received automatically when you use the website, such as your device and browser information, network address, the pages you view, and the times of those visits. And some is generated by the service itself, such as the scan evidence captured for each finding.

The section below sets out each category, why it is processed, the legal basis, who receives it, and how long it is kept.

How we use information

The table below summarizes the personal information Evolize processes. Retention is described in full in the Retention section, and the providers named under recipients are described in the Subprocessors section.

How Evolize processes personal information, by data category
Data categoryExamplesPurposeLegal basisRecipientsRetention
Account and organization dataName, work email, organization, role, membership, authentication identifiersAccount creation, authentication, organization administration, access control, supportPerformance of a contract; legitimate interests in securing and administering the serviceWorkOS (authentication); Cloudflare (infrastructure)While the account is active; see Retention
Scan inputsDomain, submitted URL, scan settings, verification stateRun scans, create previews, associate scans with an account, prevent abusePerformance of a contract; legitimate interests in evaluating public digital risk and preventing abuseCloudflare (infrastructure)See Retention
Scan evidenceScreenshots and crops, HTML fragments, selectors, accessibility-tree data, responsive states, rule results, finding metadataReproduce and verify findings, support remediation, maintain history, improve rule reliabilityPerformance of a contract; legitimate interests in verifying findings and improving reliabilityCloudflare (infrastructure)See Retention
Usage, device, and security dataIP address, browser and device information, session events, request and error logs, authentication activitySecurity, fraud prevention, service operation, debugging, performance monitoringLegitimate interests in operating, securing, and debugging the service; legal obligations where applicableCloudflare (infrastructure)See Retention
Billing and transaction dataBilling contact, plan, transaction identifiers, payment status, tax informationTake payment, invoice, meet accounting and tax obligationsPerformance of a contract; compliance with legal obligationsPayment processorAs required for accounting and tax; see Retention
Contact and support dataContact-form and enterprise enquiries, support messages, attachments, feedbackRespond to and manage requests and related communicationsLegitimate interests in responding to enquiries; performance of a contract where applicableCloudflare (infrastructure)See Retention

Account and organization data

Examples
Name, work email, organization, role, membership, authentication identifiers
Purpose
Account creation, authentication, organization administration, access control, support
Legal basis
Performance of a contract; legitimate interests in securing and administering the service
Recipients
WorkOS (authentication); Cloudflare (infrastructure)
Retention
While the account is active; see Retention

Scan inputs

Examples
Domain, submitted URL, scan settings, verification state
Purpose
Run scans, create previews, associate scans with an account, prevent abuse
Legal basis
Performance of a contract; legitimate interests in evaluating public digital risk and preventing abuse
Recipients
Cloudflare (infrastructure)
Retention
See Retention

Scan evidence

Examples
Screenshots and crops, HTML fragments, selectors, accessibility-tree data, responsive states, rule results, finding metadata
Purpose
Reproduce and verify findings, support remediation, maintain history, improve rule reliability
Legal basis
Performance of a contract; legitimate interests in verifying findings and improving reliability
Recipients
Cloudflare (infrastructure)
Retention
See Retention

Usage, device, and security data

Examples
IP address, browser and device information, session events, request and error logs, authentication activity
Purpose
Security, fraud prevention, service operation, debugging, performance monitoring
Legal basis
Legitimate interests in operating, securing, and debugging the service; legal obligations where applicable
Recipients
Cloudflare (infrastructure)
Retention
See Retention

Billing and transaction data

Examples
Billing contact, plan, transaction identifiers, payment status, tax information
Purpose
Take payment, invoice, meet accounting and tax obligations
Legal basis
Performance of a contract; compliance with legal obligations
Recipients
Payment processor
Retention
As required for accounting and tax; see Retention

Contact and support data

Examples
Contact-form and enterprise enquiries, support messages, attachments, feedback
Purpose
Respond to and manage requests and related communications
Legal basis
Legitimate interests in responding to enquiries; performance of a contract where applicable
Recipients
Cloudflare (infrastructure)
Retention
See Retention

Information observed on scanned public websites

When a website is submitted, Evolize inspects its public surfaces in the same way an ordinary visitor's browser would load the pages. It does not access source-code repositories, does not use credentials to reach private areas, and does not install any agent on the scanned site. For each finding it captures the evidence needed to make the finding verifiable — which can include the page URL, the element and its selector, the relevant markup, a screenshot, the timestamp, and the verification history over subsequent scans.

Scan evidence may incidentally contain information the website's operator has published there, including names, contact details, profile photographs, user-generated content, and other information visible to normal visitors. Evolize processes such information only as part of technical evidence and does not collect it to build personal profiles. To limit exposure, Evolize:

  • minimizes the content it captures;
  • prefers cropped or focused evidence where feasible;
  • restricts access to stored evidence;
  • applies retention controls; and
  • responds to legitimate deletion, exclusion, or review requests.

Because a scan can be requested by someone other than a website's owner, the person who submits a domain and the owner may differ. If you are a website owner and want to request exclusion from scanning, removal of personal information, or review of captured evidence, you can use the contact routes on the Company page. We will handle such requests in a way that respects the legitimate interests involved and applicable law.

Authentication and identity

Evolize uses WorkOS, Inc. to provide account authentication and identity management. Where required to provide these functions, WorkOS may process user identifiers, contact information such as your email address, authentication records, session metadata, and organization membership information. It does not receive website scan data, evidence, or scanner findings. Authentication and session management rely on strictly necessary cookies or tokens that keep you signed in and secure your session; these are not used for analytics or advertising. WorkOS is listed in the Subprocessors section below and on the Security page.

Sharing

We do not sell personal information. We share it only where necessary to run the service and only with parties bound to handle it appropriately:

  • subprocessors that provide infrastructure, authentication, payment, and similar functions, as listed below;
  • other Authorized Users of your organization, where your account belongs to one;
  • authorities or others where required to comply with the law or protect our rights, users, or the security of the service; and
  • a successor entity in a merger, acquisition, or similar transaction, subject to this policy.

Subprocessors

Evolize uses the providers below to operate the service. This list is maintained together with the disclosure on the Security page and is updated when the set of providers changes.

Subprocessors Evolize uses to provide the service
ProviderFunctionData involvedRegionDocumentation
CloudflareHosting, edge delivery, browser rendering, processing and storageScan inputs, generated evidence and operational metadataGlobal infrastructure; storage and processing locations depend on the configured Cloudflare services and account settingsSecurity documentation
WorkOS, Inc.Authentication, identity and organization managementUser identity data, authentication identifiers, session metadata and organization membership data where applicable.United States; international transfers may applySecurity and privacy documentation

Cloudflare

Function
Hosting, edge delivery, browser rendering, processing and storage
Data involved
Scan inputs, generated evidence and operational metadata
Region
Global infrastructure; storage and processing locations depend on the configured Cloudflare services and account settings

WorkOS, Inc.

Function
Authentication, identity and organization management
Data involved
User identity data, authentication identifiers, session metadata and organization membership data where applicable.
Region
United States; international transfers may apply

Retention

We keep information only for as long as it is needed for the purposes described in this policy, and then delete or de-identify it. Different categories are kept for different periods.

How long Evolize retains each category of information
CategoryRetention
Unclaimed scan previewsDeleted or de-identified when no longer needed to provide a preview, unless claimed, required for security, or legally retained
Claimed scan and finding historyAvailable for the history period included in your plan (up to 12 months on standard plans; custom on Enterprise), subject to plan and contract terms
Deleted account dataRemoved from active systems when no longer needed and from routine backups as they age out of the backup rotation, subject to legal and security exceptions
Security and authentication logsKept only as long as needed for security and service operation, then deleted or de-identified
Support requestsKept as long as needed to handle the matter and maintain a record of the exchange
Billing and tax recordsKept as long as required to meet accounting and tax obligations
Website-owner exclusion requestsKept as long as needed to apply and honor the request

Unclaimed scan previews

Retention
Deleted or de-identified when no longer needed to provide a preview, unless claimed, required for security, or legally retained

Claimed scan and finding history

Retention
Available for the history period included in your plan (up to 12 months on standard plans; custom on Enterprise), subject to plan and contract terms

Deleted account data

Retention
Removed from active systems when no longer needed and from routine backups as they age out of the backup rotation, subject to legal and security exceptions

Security and authentication logs

Retention
Kept only as long as needed for security and service operation, then deleted or de-identified

Support requests

Retention
Kept as long as needed to handle the matter and maintain a record of the exchange

Billing and tax records

Retention
Kept as long as required to meet accounting and tax obligations

Website-owner exclusion requests

Retention
Kept as long as needed to apply and honor the request

When information is deleted, residual copies may remain in routine backups until they age out of the backup rotation; backups are used only for disaster recovery and are not restored into active use. Anonymized or aggregated information that no longer identifies a person may be retained to operate and improve the service.

Your rights and choices

Depending on where you live and the applicable law, you may have rights over the information we hold about you, which can include:

  • access to it;
  • correction of it;
  • deletion of it;
  • restriction of certain processing;
  • objection to certain processing;
  • portability of it;
  • withdrawal of consent, where processing is based on consent; and
  • complaint to a supervisory authority.

Account holders can review and update much of their information by signing in. For other requests, or if you do not hold an account, you can use the contact routes on the Company page. We may need to verify your identity and, where you act for someone else, your authority, before we act on a request. Information about the safeguards for international transfers is set out below.

International transfers

Evolize and its providers may process information in countries other than the one in which you are located. As indicated in the Subprocessors section, some providers operate in the United States and on global infrastructure, so information may be transferred across borders.

Where information is transferred to a country that does not provide an equivalent level of protection, we rely on appropriate safeguards required by applicable law, such as standard contractual clauses, so that it continues to be protected in line with this policy. You can use the contact routes on the Company page to request more information about the safeguards that apply.

Security

We take reasonable technical and organizational measures to protect information against loss, misuse, and unauthorized access, disclosure, or alteration, including access controls and protecting information in transit. By design, scans are confined to public surfaces: Evolize does not collect source code, does not use credentials to reach private areas, and does not install any agent, which deliberately limits the sensitivity of what a scan can gather. No method of transmission or storage is completely secure, but we work to protect information in a manner appropriate to its sensitivity. The Security page describes our approach in more detail.

Children

Evolize is a business tool intended for organizations and the people who work for them. It is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can review the matter and take appropriate action.

Changes to this policy

We may update this policy as the service develops or as legal requirements change. When we make a material change, we will update the effective date shown with this policy and, where appropriate, provide a more prominent notice. We encourage you to review it periodically.

Contact

If you have questions about this policy or how Evolize handles information, you can reach us using the details below. Additional contact routes are available on the Company page.