Privacy Policy

Effective date: April 28, 2026 · Last updated: April 28, 2026

1. Who we are

Evidara ("we", "us", "our") operates the Evidara pharmaceutical evidence intelligence platform at evidarabio.com and associated services. Data controller contact: celldna1@gmail.com. DPO contact: celldna1@gmail.com.

2. What data we collect

Account data: Email address, name, and organization name provided at registration. Stored in Supabase.

Usage data: Query metadata (run IDs, timestamps, token counts, chain used). We do not store raw query text in plaintext after processing is complete.

Billing data: Subscription tier, Stripe customer ID. Payment card details are processed by Stripe and never stored on Evidara infrastructure.

Audit data: Every analysis produces an audit row: agent IDs, timestamps, input hash, output hash, HMAC signature. Audit rows cannot be modified or deleted by design.

Technical data: IP address (for rate limiting), browser type, session token. Not used for tracking or profiling.

3. What we do not collect

4. How we use your data

We do not sell your data. We do not use your queries to train AI models. We do not share data with third parties except as described in Section 6.

5. Legal basis for processing (GDPR)

6. Third-party processors

We share data with the following processors who are contractually bound to process data only on our instructions:

The current sub-processor list is published on our Security page. You will be notified 30 days before any new sub-processor is added.

7. Data retention

8. Your rights (GDPR)

If you are in the EEA, UK, or Switzerland, you have the following rights:

To exercise any right: celldna1@gmail.com. We respond within 30 days.

9. Cookies

We use only essential cookies required for authentication and session management. No advertising or tracking cookies. You can disable cookies in your browser settings — this will prevent you from logging in.

10. International transfers

Data is processed primarily in AWS us-east-1 (United States). Transfers to the US from the EEA are covered by Standard Contractual Clauses with each sub-processor. EU data residency is available for Enterprise customers on request.

11. Security

We implement technical and organizational measures including AES-256 encryption at rest, TLS 1.3 in transit, PHI firewall, HMAC-signed audit trail, and role-based access controls. See our Security page for full details.

12. Changes to this policy

We will notify registered users by email at least 14 days before material changes to this policy. The effective date at the top of this page reflects the most recent update.

13. Contact

Privacy questions: celldna1@gmail.com
Data Protection Officer: celldna1@gmail.com
Security reports: celldna1@gmail.com


© 2026 Evidara. This policy is governed by applicable data protection law. For HIPAA-specific terms, see your Business Associate Agreement.