Legal
Privacy Policy
Version 1.2 · Effective September 2026 · Last reviewed September 2026
EVIDENCEE DMCC Ltd (“Evidencee”, “we”, “us”, “our”) is committed to protecting the personal data of our customers and their end-users in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy explains how we collect, use, store, and protect personal data when you use the Evidencee platform.
1. Who We Are
EVIDENCEE DMCC Ltd is the data controller for personal data collected through our platform at evidencee.com. We are a UK-based compliance software provider serving subscription businesses subject to the Digital Markets, Competition and Consumers Act 2024.
For data protection queries, contact us at: privacy@evidencee.com
2. What Data We Collect
Account and workspace data
- Name, email address, and password (hashed) for user accounts
- Workspace and brand configuration data
- Integration credentials: payment-platform access tokens and webhook secrets, which Evidencee encrypts (AES-256-GCM) before storing them; and the API keys for your email provider and review platforms, which Evidencee does not yet encrypt
- Billing information (processed by our payment provider; we do not store card numbers)
Compliance and evidence data
- Subscriber event records ingested from Shopify, Stripe, and GoCardless webhooks
- Hashed subscriber identifiers (a keyed SHA-256 hash, HMAC; one-way — plain-text subscriber names or email addresses are not stored in the Evidence Vault)
- Subscriber email addresses, encrypted by Evidencee (AES-256-GCM), where they are needed to send a reminder, a confirmation or a cancellation link
- The IP address and browser details of a subscriber who cancels through a hosted cancellation page
- Notice delivery logs and statuses
- Cancellation journey records and cooling-off case data
- Audit bundle export logs
Usage and technical data
- IP addresses and browser/device information for authentication logs
- Activity logs within the platform (for audit trail purposes)
- Error and performance telemetry
3. How We Use Your Data
- Platform provision: To operate the Evidencee platform, including user authentication, brand management, and compliance automation.
- Legal basis — contract: Processing necessary to fulfil our contract with you (subscription agreement).
- Legal basis — legitimate interests: Security monitoring, fraud prevention, and platform improvement.
- Legal basis — legal obligation: Retaining records as required by applicable law.
- Communications: Sending service emails (account verification, billing receipts, critical alerts). We do not send marketing emails without explicit consent.
4. Data Retention
We retain personal data as follows:
- Account data: closing an account archives it and deletes nothing, so account data is kept after closure until you ask us to erase it (see section 7)
- Evidence vault records: Retained for at least the period set in your workspace's data retention settings (default and minimum: 6 years); nothing deletes them automatically when that period ends
- Activity logs: kept; not deleted automatically
- Billing records: 7 years (legal obligation)
5. Data Security
We implement appropriate technical and organisational measures to protect your data:
- Encryption in transit (HTTPS/TLS) is provided by our hosting platform, Vercel; the database is hosted by Supabase, which encrypts it at rest (AES-256). Those are our providers' measures, not Evidencee's own code
- On top of that, Evidencee itself encrypts subscriber email addresses, payment-platform access tokens and webhook secrets, and multi-factor authentication secrets (AES-256-GCM) before storing them
- Every evidence event carries a SHA-256 hash of its content and is linked in a continuous chain, so a later change to any record can be detected
- Subscribers are matched by a keyed SHA-256 hash (HMAC) rather than by their email address
- Role-based access control limiting data access within your workspace
- Regular security reviews and penetration testing
- UK/EU data processing only
6. Data Sharing
We do not sell personal data. We share data only with the named sub-processors below, each operating under a data-processing agreement with us:
- Vercel Inc. — application hosting and edge delivery (UK / EU regions).
- Supabase — managed Postgres database and storage (UK / EU regions).
- Stripe Payments UK, Ltd. — subscription billing and payment processing (governed by Stripe's privacy policy).
- Resend — transactional and platform notification email delivery.
- Legal compliance: If required by applicable UK law, regulator request, or court order.
A complete, current sub-processor list and our notice mechanism for changes are set out in the Data Processing Agreement.
7. Your Rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Rectification of inaccurate data
- Erasure (right to be forgotten), subject to legal retention requirements
- Portability of your account data in a machine-readable format
- Restriction of processing in certain circumstances
- Object to processing based on legitimate interests
To exercise any of these rights, contact privacy@evidencee.com. We will respond within 30 days.
9. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated by email and/or a notice within the platform. Continued use of Evidencee after changes are published constitutes acceptance of the updated policy.
10. Contact and Complaints
For privacy queries: privacy@evidencee.com
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.