Privacy
Last updated: 27 December 2025
Evident (“Evident”, “we”, “our”, or “us”) provides a B2B SaaS product that helps teams understand company-level usage signals derived from network and event data. We act as a data controller for personal data processed through our website and application.
- Legal entity: Shaun BROWN — micro-entreprise
- Location: France (European Union)
- Contact: dpo@useevident.com
Our privacy principles
- We focus on company-level identification, not individual profiling.
- We do not sell personal data.
- We do not use data for advertising or cross-site tracking.
- We minimize retention and aggregate data wherever possible.
Some customers outside the EU may choose to associate Evident data with user-level identifiers in their own systems (e.g., CRM). Evident does not perform this re-identification on their behalf.
Personal data we process
3.1 Account and contact data
When you create or manage an account, we may process:
- Name
- Email address
- Company name
- Authentication identifiers (authentication is handled by Clerk)
3.2 Product and technical data
When using the Evident application, we may process:
- IP addresses
- Timestamps (first seen / last seen)
- Event counts and usage metadata
- Derived company, domain, or organization information
- Configuration and preference data
IP addresses are considered personal data under GDPR. We process them primarily to derive company-level insights and apply filtering, aggregation, and retention limits.
3.3 Website analytics data
When visiting our website, we may collect:
- Page views and navigation events
- Approximate location
- Device and browser information
This data is collected via Google Analytics 4 (GA4).
3.4 Billing data
Billing and payments are handled by a Merchant of Record (MoR) provider (planned: Paddle). Evident does not store full payment card details.
What we do not do
- Perform behavioral advertising or ad targeting
- Track users across third-party websites
- Sell or rent personal data
- Use fingerprinting techniques
- Enrich data for individual-level profiling
Purposes of processing
- Provide and operate the Evident service
- Generate company-level analytics and insights
- Authenticate users and secure accounts
- Monitor performance, reliability, and abuse
- Improve product functionality
- Meet legal and compliance obligations
Legal bases for processing (GDPR)
- Contract performance — providing the service you request
- Legitimate interests — security, fraud prevention, product improvement
- Legal obligations — accounting, compliance, and regulatory requirements
We do not generally rely on consent for core product functionality.
Mapping of purposes to legal bases
| Purpose | Data Involved | Legal Basis |
|---|---|---|
| Account creation & authentication | Name, email, authentication identifiers | Performance of a contract |
| Core product functionality & analytics | IP addresses, timestamps, event counts, derived company data | Performance of a contract |
| Security, abuse prevention, fraud detection | IP addresses, logs, technical metadata | Legitimate interests |
| Product improvement & reliability | Aggregated & anonymized usage data | Legitimate interests |
| Billing & accounting | Billing metadata | Legal obligation |
Customer responsibility
Evident is a business-to-business service. Customers are responsible for ensuring they have a lawful basis to process any personal data they submit to the Evident service, including IP addresses, event data, or identifiers derived from their own systems.
Data retention
- Raw technical data (including IP addresses) is retained for a limited period and then aggregated, anonymized, or deleted.
- Account data is retained for the duration of the customer relationship.
- Data may be retained longer where required by law.
- You may request deletion at any time, subject to legal obligations.
Data sharing and subprocessors
We share data only with trusted service providers necessary to operate the service, including:
- Hosting & infrastructure: Railway Corporation (EU region — Amsterdam)
- Authentication: Clerk
- Product analytics: Amplitude
- Website analytics: Google Analytics (GA4)
- Payments: Merchant of Record provider (planned: Paddle)
These providers process data under contractual obligations and appropriate safeguards. We do not share data with advertisers.
International data transfers
Some service providers may process data outside the European Union. Where this occurs, we rely on appropriate safeguards such as:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions where applicable
Your rights (GDPR)
You have the right to:
- Access your personal data
- Request rectification or deletion
- Object to processing based on legitimate interests
- Request restriction of processing
- Request data portability
- Lodge a complaint with a supervisory authority
Where we rely on legitimate interests as our legal basis, you have the right to object to such processing. We will assess any objection and cease processing unless we demonstrate compelling legitimate grounds. To exercise your rights, contact us at dpo@useevident.com.
Changes to this policy
We may update this Privacy Policy from time to time. The latest version will always be available on our website, with the effective date clearly indicated.
For any questions about data handling or removal, contact us at dpo@useevident.com.
Back to home