Legal & terms
Privacy Policy
Summary
Evigate is a tool that drafts cited answers to security questionnaires from evidence you upload. This policy explains what personal data we handle, why, who it is shared with, and the rights you have. The short version:
- We collect the minimum needed to run the service: your account details, the
evidence and questionnaires you upload, the answers produced, and basic operational logs.
- We never use your content to train AI models, and we never sell your data.
- **Embeddings run locally, on our own infrastructure — chunk text never leaves
our server. Only Anthropic, and conditionally Google's Gemini API** as an automatic fallback, ever receive customer-derived content, and only the minimum, and if you bring your own API keys, not even them.
- Your content stays in the Mumbai, India region on a single-tenant VPS until
you delete it. You can export or permanently delete all of it yourself at any time.
1. Who we are
Evigate is operated by Logethos, a sole proprietorship based in Surat, Gujarat, India ("Evigate," "we," "us"). Registered address: B-204, Rajhans Tower, Mota Varachha, Surat, Gujarat, India.
For privacy questions or to exercise your rights, contact privacy@logethos.com. Our Grievance Officer under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") is identified in Section 14.
2. Scope and roles
This policy covers the Evigate hosted service and our marketing site. Where Evigate offers self-hosted deployment, you run the software in your own infrastructure and you are the controller of all data within it; this policy then applies only to limited account, billing, and support interactions with us.
Two distinct relationships apply to the hosted service:
- Account and billing data: name, email, organization name, subscription
state. For this we are the data fiduciary / controller (DPDP Act; GDPR Art. 4(7)).
- Customer content: the evidence documents, questionnaires, questions, and
drafted answers you upload and generate. We process this on your behalf and under your instructions as a data processor (GDPR Art. 4(8); "service provider" under CCPA). Your own privacy notice governs the personal data your content may contain. Our handling of customer content as a processor is set out in the Data Processing Addendum.
3. What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, organization name, hashed password (scrypt); password omitted for accounts created via "Sign in with Google" | You, at signup |
| Authentication data | Server-side session records (only a SHA-256 of the session token is stored), CSRF token, email-verification / password-reset tokens (stored only as hashes) | Generated on login |
| Federated sign-in data | Only if you choose "Sign in with Google": your Google account email and Google profile id (the stable subject identifier), used to create or sign in to your account | Google, when you use Google sign-in |
| Customer content | Uploaded evidence (SOC 2 reports, policies, past questionnaires), incoming questionnaires, extracted questions, drafted answers, your reusable answer library | You, in use |
| Billing data | Subscription plan and status, billing/customer identifiers | Via Paddle (our merchant of record) |
| Usage / metering | Per-organization counts of documents and questions, token/cost ledger of AI and embedding calls | Generated in use |
| Operational logs | Request metadata, a per-request request ID, error events | Generated automatically |
| BYOK keys | Your own AI/embedding provider API keys, if you add them; encrypted at rest, write-only | You, optionally |
We do not collect special-category data deliberately, and we do not log document contents or full AI prompts. Payment card details are handled entirely by Paddle; we never see or store full card numbers.
4. How we use it and our legal bases
We use personal data only to operate the service for you:
| Purpose | Data used | Legal basis (DPDP / GDPR) |
|---|---|---|
| Provide the service (store, retrieve, draft, review, export) | Account, customer content | Performance of contract / legitimate use for the service requested |
| Authenticate and secure accounts | Account, authentication data | Contract; legitimate interests in security |
| Bill and manage subscriptions | Account, billing data | Contract |
| Meter usage and prevent abuse/cost overruns | Usage/metering, logs | Legitimate interests |
| Send transactional email (verification, password reset) | Email address | Contract |
| Maintain, debug, and improve reliability | Logs, error events | Legitimate interests |
| Comply with law | As required | Legal obligation |
We do not send marketing or lifecycle email and run no advertising. We do not make automated decisions producing legal or similarly significant effects about you; the service produces *draft* answers that a human always reviews.
5. AI processing of your content
Evigate is a Retrieval-Augmented Generation (RAG) tool. The detailed, plain-language description of how AI is used, what data leaves your environment, and the human-review guarantee lives in the AI Usage Policy. In summary:
- At ingest, chunk text from your evidence is embedded **locally, on our own
infrastructure** — it is never sent to a third party to produce retrieval vectors. For scanned/image PDF pages only, the page is also sent to Anthropic (vision) at intake to extract the questions on it.
- At answer time, a single question plus the handful of retrieved snippets
(never whole documents, never your full corpus) is sent to our AI provider to draft a grounded, cited answer. If that call to Anthropic errors, a platform-key request may automatically fail over once to Google's Gemini API (only when the operator has configured it); BYOK-Anthropic requests never fail over.
- Your content is never used to train any model. Anthropic operates under a
signed no-training, zero/low-retention agreement; the Gemini fallback relies on Google's stated no-training terms for that API tier rather than a bespoke signed agreement. Embeddings never leave our infrastructure at all.
- With BYOK, LLM calls run on your own provider account instead of ours;
embeddings are never BYOK and always run locally.
6. Who we share it with (subprocessors)
We use a small, fixed set of vendors. The authoritative, always-current list, including purpose and exactly what data each receives, is published at Subprocessors and served live from the application so it can never drift from what the system actually does. As of the last-updated date:
| Subprocessor | Purpose | Data shared | Location |
|---|---|---|---|
| Anthropic | AI provider, drafts answers; also reads scanned questionnaire page images at intake | A question + retrieved snippets at answer time; a scanned page image + extracted text at intake | USA |
Google — Gemini API *(conditional: only when GEMINI_API_KEY is configured, and only for the request that failed over)* | Automatic LLM fallback if the Anthropic call errors | Same as the Anthropic call for that request | USA |
| Paddle | Payments (merchant of record) | Billing details only | United Kingdom / global |
| Google *(only if you choose "Sign in with Google")* | Optional federated sign-in | Account email + Google profile id | USA |
| Hostinger | Cloud VPS hosting + self-hosted storage | Your data at rest on the VPS | Mumbai, India |
Embeddings are computed locally on our own infrastructure and never appear in this table — there is no embedding subprocessor.
We do not sell personal data and do not share it for cross-context behavioral advertising (CCPA/CPRA). We may disclose data if required by law, or in connection with a merger or acquisition (you will be notified).
7. International data transfers
Your customer content is hosted in the Mumbai, India region on a Hostinger VPS (if the data region changes, this section will be updated and the analysis below applied to the new region). Our AI subprocessor, Anthropic, and conditionally Google's Gemini API (fallback only), are located in the United States, so a question plus retrieved snippets, and at intake for scanned PDF pages a page image, transit to the US. Embeddings are computed locally on our infrastructure in Mumbai and never transit anywhere.
- DPDP Act: transfers outside India are permitted except to countries the
Government of India may restrict; none of our subprocessors are in a restricted country.
- GDPR (EU/EEA customers): transfers rely on the European Commission's
Standard Contractual Clauses with each importer, as referenced in our DPA.
- BYOK removes us from these AI transfers entirely: the LLM calls then run
on your own provider account.
8. Retention
We retain customer content only as long as you keep it. There is no fixed expiry: your data stays until you delete a document or purge your organization. On deletion, we remove the database rows and the stored files. Account and billing records are retained for the life of the account and for a limited period afterward as required for tax, accounting, and legal purposes. Backups, where maintained, are cycled on a rolling basis. Operational logs are short-lived and never contain document contents or prompts.
9. Security
We protect data with encryption in transit (TLS/HTTPS with HSTS) and application-level encryption of secrets at rest (BYOK keys under authenticated encryption; passwords hashed with scrypt). Stored documents and database records reside on a secure, single-tenant, access-controlled VPS. For customers with specific disk-level encryption requirements, we offer a self-hosted option. We also apply strict per-organization and per-project isolation, hardened HttpOnly session cookies with CSRF protection, a strong-password policy, rate limiting and account lockout, and upload screening. The full technical description is in the Security Overview.
10. Your rights
Subject to the law that applies to you, you have rights to access, correct, update, export (portability), and delete your personal data, to withdraw consent, and to complain to a regulator. Most are self-serve in the product:
- Access / portability: export a portable, secret-free JSON snapshot of your
organization's data from Settings.
- Deletion: delete any document, or permanently purge your entire
organization and all its data, from Settings.
- Correction: edit your account and content in the product, or contact us.
To exercise a right we cannot fulfill in-product, email privacy@logethos.com. We will respond within the timeframe required by applicable law. We will not discriminate against you for exercising a right.
- India (DPDP Act): you may nominate another person to exercise your rights in
the event of death or incapacity, and may escalate to our Grievance Officer and then the Data Protection Board of India.
- EU/EEA/UK (GDPR): you may lodge a complaint with your supervisory authority.
- California (CCPA/CPRA): you have the rights to know, delete, correct, and to
opt out of "sale"/"sharing"; we do neither.
11. Cookies
Evigate uses only strictly necessary cookies (your authentication session and a CSRF token). We set no advertising or third-party analytics cookies. See the Cookie Policy.
12. Children
Evigate is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 18. Under the DPDP Act, processing children's data requires verifiable parental consent; we do not target or knowingly serve children.
13. Changes
We may update this policy as the product evolves. Material changes will be reflected here with a new "last updated" date and noted in our public changelog. Continued use after an update constitutes acceptance.
14. Contact and grievances
- Privacy / data requests: privacy@logethos.com
- Grievance Officer (DPDP Act, s.13): The Grievance Officer, grievance@logethos.com
- EU/UK representative (GDPR Art. 27): [EU_UK_REP], if appointed
- Postal: Logethos, B-204, Rajhans Tower, Mota Varachha, Surat, Gujarat, India
*Effective date: July 31, 2026 · Last updated: 2026-07-21 · Version 1.1*