1. Who we are
Evidara ("we", "us", "our") operates the Evidara pharmaceutical evidence intelligence platform at evidarabio.com and associated services. Data controller contact: celldna1@gmail.com. DPO contact: celldna1@gmail.com.
2. What data we collect
Account data: Email address, name, and organization name provided at registration. Stored in Supabase.
Usage data: Query metadata (run IDs, timestamps, token counts, chain used). We do not store raw query text in plaintext after processing is complete.
Billing data: Subscription tier, Stripe customer ID. Payment card details are processed by Stripe and never stored on Evidara infrastructure.
Audit data: Every analysis produces an audit row: agent IDs, timestamps, input hash, output hash, HMAC signature. Audit rows cannot be modified or deleted by design.
Technical data: IP address (for rate limiting), browser type, session token. Not used for tracking or profiling.
3. What we do not collect
- Protected Health Information (PHI). Our PHI scanner blocks and rejects any input containing patient identifiers before processing.
- Sensitive personal data as defined by GDPR Art. 9 (health, biometric, genetic data about natural persons).
- Third-party tracking data. We do not use Google Analytics, Facebook Pixel, or similar third-party trackers.
- Data from users under 18. The platform is designed for professional pharmaceutical researchers.
4. How we use your data
- Service delivery: Processing your evidence synthesis requests, maintaining your account, and returning structured outputs.
- Security and fraud prevention: Rate limiting, abuse detection, and audit trail integrity.
- Billing: Processing subscription payments via Stripe and managing your subscription tier.
- Service improvement: Aggregate, anonymized usage statistics to understand platform performance. No individual profiling.
- Legal compliance: Maintaining audit records as required by 21 CFR Part 11 and applicable law.
We do not sell your data. We do not use your queries to train AI models. We do not share data with third parties except as described in Section 6.
5. Legal basis for processing (GDPR)
- Contract (Art. 6(1)(b)): Account data and usage data necessary to provide the service you subscribed to.
- Legitimate interests (Art. 6(1)(f)): Security monitoring, rate limiting, and audit trail maintenance.
- Legal obligation (Art. 6(1)(c)): Audit records required by applicable regulations.
- Consent (Art. 6(1)(a)): Non-essential cookies and marketing communications. Withdrawable at any time.
6. Third-party processors
We share data with the following processors who are contractually bound to process data only on our instructions:
- Supabase — database, authentication (AWS us-east-1)
- Anthropic — AI evidence synthesis via Claude API (US)
- Railway — backend compute hosting (AWS us-east-1)
- Cloudflare — CDN and edge compute (global)
- Stripe — payment processing (US/EU)
- GitHub — source code hosting and CI/CD (US)
The current sub-processor list is published on our Security page. You will be notified 30 days before any new sub-processor is added.
7. Data retention
- Account data: retained for the duration of your account plus 30 days after deletion.
- Chat conversations and uploaded documents: 24 months from creation.
- Saved queries: retained until you delete them or request erasure. Because you choose what to save, these are not deleted on a schedule.
- Usage events: 36 months from creation.
- Audit trail rows: 10 years, as required by EU AI Act Art. 12. Rows are append-only and cannot be edited. One exception to deletion: where an analysis is still referenced by an approved correction, it is retained beyond 10 years — approved corrections are consulted by every subsequent analysis, so removing the underlying record would silently change future behaviour rather than prune a historical one.
8. Your rights (GDPR)
If you are in the EEA, UK, or Switzerland, you have the following rights:
- Access (Art. 15): Request a copy of all personal data we hold about you.
- Rectification (Art. 16): Correct inaccurate personal data.
- Erasure (Art. 17): Request deletion of your personal data. Note: audit trail rows cannot be deleted by regulatory design — we will inform you of this limitation.
- Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Objection (Art. 21): Object to processing based on legitimate interests.
- Complaint: Lodge a complaint with your local supervisory authority.
To exercise any right: celldna1@gmail.com. We respond within 30 days.
9. Cookies
We use only essential cookies required for authentication and session management. No advertising or tracking cookies. You can disable cookies in your browser settings — this will prevent you from logging in.
10. International transfers
Data is processed primarily in AWS us-east-1 (United States). Transfers to the US from the EEA are covered by Standard Contractual Clauses with each sub-processor. EU data residency is available for Enterprise customers on request.
11. Security
We implement technical and organizational measures including AES-256 encryption at rest, TLS 1.3 in transit, PHI firewall, HMAC-signed audit trail, and role-based access controls. See our Security page for full details.
12. Changes to this policy
We will notify registered users by email at least 14 days before material changes to this policy. The effective date at the top of this page reflects the most recent update.
13. Contact
Privacy questions: celldna1@gmail.com
Data Protection Officer: celldna1@gmail.com
Security reports: celldna1@gmail.com
© 2026 Evidara. This policy is governed by applicable data protection law. For HIPAA-specific terms, see your Business Associate Agreement.