All policies

Legal & terms

Data Processing Addendum (DPA)

Version 1.1Effective July 31, 2026Updated 2026-07-21

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Customer," "Controller") and Logethos, a sole proprietorship based in Surat, Gujarat, India ("Evigate," "Processor") and governs Evigate's processing of personal data contained in Customer Content on Customer's behalf.

Summary

For the account/billing data we determine the purposes of, we are the controller (see the Privacy Policy). For Customer Content you upload, you are the controller and we are the processor; we process it only on your documented instructions to provide the service. This DPA sets out our security, subprocessor, transfer, breach-notice, and deletion obligations.


1. Definitions

"Personal data," "processing," "controller," "processor," "data subject," and "personal-data breach" have the meanings given in applicable data-protection law, including the DPDP Act, 2023 (India), the EU/UK GDPR, and CCPA/CPRA (California). "Customer Content" means the evidence, questionnaires, questions, and answers Customer uploads or generates. "Subprocessor" means a third party engaged by Evigate to process Customer Content.

2. Roles and scope

  • For Customer Content, Customer is the controller (or itself a processor for

    its own customers) and Evigate is the processor.

  • For account, authentication, billing, and usage data, Evigate is a

    controller as described in the Privacy Policy.

  • Under CCPA/CPRA, Evigate acts as a service provider and will not "sell" or

    "share" personal data or process it outside the direct business relationship.

This DPA applies to the hosted service. For self-hosted deployments Customer operates the processing environment and is the controller and processor of all data within it; Evigate processes only limited account/support data.

3. Processing details (Annex I)

  • Subject matter: provision of the Evigate questionnaire-automation service.
  • Duration: for the term of the agreement and until deletion per Section 12.
  • Nature and purpose: storage, retrieval (vector + keyword), AI-assisted answer

    drafting, human review, export, and related support.

  • Types of personal data: any personal data Customer chooses to include in

    Customer Content (e.g. names/contact details inside uploaded evidence or questionnaires), plus account identifiers (email, organization name).

  • Categories of data subjects: Customer's personnel and any individuals

    referenced in Customer Content.

  • Special categories: not intended; Customer should not upload special-category

    data unless necessary and lawful.

4. Customer instructions

Evigate processes Customer Content only on Customer's documented instructions, which include this DPA, the Terms, and Customer's use of the product's features (upload, run, review, export, delete). Evigate will inform Customer if, in its opinion, an instruction infringes applicable law. Evigate does not use Customer Content to train AI models and does not process it for its own purposes.

5. Confidentiality

Evigate ensures that personnel authorized to process Customer Content are bound by appropriate confidentiality obligations and access it only as needed to provide and support the service.

6. Security measures (Annex II)

Evigate maintains technical and organizational measures appropriate to the risk, including: encryption in transit (TLS/HSTS) for all data in motion; application-level encryption of secrets at rest (BYOK provider keys held under authenticated encryption; account passwords hashed with scrypt). Customer Content at rest resides on a secure, single-tenant, access-controlled VPS, with sensitive application configuration and BYOK credentials encrypted at rest. Host-level storage encryption is not active by default; customers requiring disk-level encryption are recommended to deploy Evigate using the self-hosted option. Further measures: strict per-organization and per-project isolation tested in CI; hardened HttpOnly session cookies with CSRF protection; strong-password policy, rate limiting, and account lockout; restrictive security headers and CORS; upload size limits and decompression-bomb screening; formula-injection-safe exports; BYOK secrets held with authenticated encryption, never logged or returned to the browser; and a no-document-content/no-prompt logging policy. Full description: Security Overview.

7. Subprocessors

Customer authorizes Evigate to engage the subprocessors listed at Subprocessors. Evigate imposes data-protection obligations on each subprocessor no less protective than this DPA and remains responsible for their performance. Of these, only Anthropic receives Customer Content as a matter of course (and only the minimum, and not at all when Customer uses BYOK), under a signed no-training, zero/low-retention agreement. Google, via its Gemini API, conditionally receives the same category of Customer Content, but only for the specific platform-key request where the Anthropic call itself errors and only when the operator has configured GEMINI_API_KEY; that fallback never applies once Customer uses its own Anthropic key. Google's Gemini API is not under a bespoke signed agreement with Evigate — Evigate relies on Google's stated no-training terms for that API tier instead. Embeddings never leave Evigate's own infrastructure, so no embedding subprocessor exists. Where the operator has enabled "Sign in with Google", Google LLC also acts as a subprocessor for federated authentication only; for users who choose that option it receives account identity data (email + Google profile id) and never Customer Content. Evigate will provide a mechanism to be notified of new subprocessors and a reasonable opportunity to object on data-protection grounds before they begin processing Customer Content.

8. International transfers

Customer Content is hosted in the Mumbai, India region on a Hostinger VPS. Where AI processing involves transfer to subprocessors in the United States (Anthropic, and conditionally Google's Gemini API on the fallback path described in Section 7), such transfers are made under appropriate safeguards, including, for EU/EEA/UK personal data, the European Commission's Standard Contractual Clauses (and the UK Addendum) as incorporated by reference, and equivalent safeguards under the DPDP Act. Customer's use of BYOK keeps these AI transfers on Customer's own provider account. Embeddings are computed on Evigate's own infrastructure in Mumbai, India, and are never transferred to a third party.

9. Data-subject requests

Taking into account the nature of the processing, Evigate will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests (access, correction, erasure, portability, objection). The product's self-serve export and deletion features enable Customer to fulfill most such requests directly. If Evigate receives a request directly from a data subject relating to Customer Content, it will refer them to Customer.

10. Personal-data breach

Evigate will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Content, with the information reasonably available to help Customer meet its own notification obligations (including under the DPDP Act and GDPR), and will take reasonable steps to mitigate and remediate.

*Operator note:* set and honor a concrete maximum notification window (e.g. [BREACH_NOTICE_HOURS] hours). Do not state a number you cannot meet.

11. Audits and information

Evigate will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor it mandates, subject to reasonable confidentiality, scope, frequency, and notice limits, and may satisfy audit requests through documentation and any third-party reports/certifications it holds.

*Operator note:* reference SOC 2 / ISO 27001 reports here only when they exist. None are claimed at this time.

12. Return and deletion

During the term, Customer can export and delete Customer Content using the product. On termination, Customer may export its data for a reasonable period; thereafter, or on Customer's instruction, Evigate will delete Customer Content (database rows and stored files), subject to any retention required by law. Deletion of an organization is irreversible.

13. Liability and term

This DPA is effective for as long as Evigate processes Customer Content. Liability under this DPA is subject to the limitations in the Terms of Service. In case of conflict on data-protection matters, this DPA prevails over the Terms.


*Effective date: July 31, 2026 · Last updated: 2026-07-21 · Version 1.1*