Evidiam
Privacy Policy

How Evidiam handles personal information.

1. Information we collect

We collect information you provide directly, including name, company, email address, optional phone number, account details, support communications, and access-request submissions.

When a customer uses Evidiam, the platform may process compliance evidence, program documents, operational records, user activity, audit events, and bank-review activity uploaded or connected by that customer.

2. How we use information

We use information to operate Evidiam, respond to access requests, authenticate users, provide customer support, secure the service, maintain audit logs, improve product quality, and comply with legal obligations.

Evidiam does not sell personal information. We do not use customer compliance evidence to advertise to consumers.

3. Customer data

Customer data belongs to the customer. Evidiam processes customer data to provide the service, including evidence ingestion, requirement mapping, packet generation, review workflows, verification, and support requested by the customer.

When we process personal information on behalf of a customer, the customer is responsible for determining whether the data may be provided to Evidiam and for giving required notices to its own users, customers, employees, and counterparties.

4. Sharing and subprocessors

We share information with service providers that help us host, secure, authenticate, operate, and support Evidiam. Current subprocessors are listed on the subprocessors page.

We may also disclose information if required by law, to protect the service, to investigate abuse, or in connection with a corporate transaction such as a merger, financing, or sale of assets.

5. Security and retention

Evidiam uses technical and organizational safeguards designed for a system of record, including tenant isolation, role-based access, token-scoped sharing, audit logging, and tamper-evident event records. No system can be guaranteed perfectly secure.

We retain information for as long as needed to provide the service, comply with legal obligations, resolve disputes, maintain audit history, and enforce agreements. Customers may request export or deletion according to their agreement and applicable law.

6. Your choices

You may contact us to request access, correction, deletion, or export of personal information, subject to applicable law and customer-controlled data restrictions. If your data is controlled by an Evidiam customer, we may direct your request to that customer.

7. Changes and contact

We may update this policy as Evidiam evolves. Material changes will be posted on this page with a new effective date.

Questions may be sent through request access or by email at privacy@evidiam.com.