Written for security, privacy and procurement reviewers. You are the controller for personal data in your workspace; Evergrowth is the processor, acting on your instructions under Article 28. Terms follow the Evergrowth Data Processing Agreement. Where this summary and the agreements differ, the agreements prevail.
See security and certifications3 things enter the workspace. 4 categories of sub-processor receive something from it, and each receives only what its function needs.
Processing rests on legitimate interest under the GDPR, Regulation (EU) 2016/679. Both the basis and the reason it applies to a given person are recorded rather than asserted.
The basis for processing business contact data in the platform. It is balanced against the rights of the individual, which the qualification gates are built to respect.
The Regulation contemplates direct marketing as a legitimate interest expressly, so the question is never whether the basis exists in principle, only whether it holds for this person.
Can you document the legitimate interest for processing this person's data?
Not a policy that covers everyone. This person. Article 14(2)(b) of the GDPR obliges the controller to be able to answer it, and a contact database or a browser extension delivers a record without a reason, so the answer has to be reconstructed by hand afterwards.
Evergrowth can.
2 qualification gates run before anything is requested from an external source. They are enforced in the pipeline, not stated in a policy.
Data is processed only for the purpose you set, which is finding and qualifying people against the personas and profiles you approved.
Nothing is requested for anyone who has not passed both gates, so minimisation is applied at the point of collection rather than afterwards.
For people who match the customer's approved profile. The platform neither requests nor requires payroll, employee, health or payment card data at any point.
| Category | Fields | Where it comes from |
|---|---|---|
| Contact identifiers | Full name, job title, email address, phone number, LinkedIn profile | Data providers, verification, customer CRM or import |
| Professional profile | Employment history, education, skills, languages, profile summary, location, profile photograph, follower and connection counts | Data providers |
| Qualification record | The persona and profile match result, with the reasoning behind it | Generated by Evergrowth |
| Article | What has to be stated | Who supplies it |
|---|---|---|
| 14(1)(a) | The identity and contact details of the controller | You |
| 14(1)(b) | The contact details of the data protection officer, where applicable | You |
| 14(1)(c) and 14(2)(b) | The purposes of processing, the lawful basis, and the legitimate interest relied on | Recorded per contact by Evergrowth |
| 14(1)(d) | The categories of personal data concerned | Recorded per contact by Evergrowth |
| 14(1)(e) | The recipients, or categories of recipient | You, from the sub-processor register |
| 14(2)(a) | The retention period, or the criteria used to determine it | You, from your own policy |
| 14(2)(c) | The rights of access, rectification, erasure, restriction, objection and portability | You, wording in our guide |
| 14(2)(e) | The right to lodge a complaint with a supervisory authority | You, wording in our guide |
| 14(2)(f) | The source the data came from, and whether it was publicly accessible | Recorded per contact by Evergrowth |
| 14(3)(b) | Delivered by your first communication at the latest | You, in the first message |
4 categories of sub-processor. Each is named, with its country of processing, in the sub-processor register, which we provide on request and during a security review.
| Category | What leaves the workspace, and why |
|---|---|
| Data providers | A company name, a job title and a country, to identify people holding that role. For a contact the customer already holds, the identifier for that person, to retrieve business contact information. |
| Verification | A single email address or phone number, to confirm it is valid and deliverable before use. Runs only when the customer enables verification. |
| Model providers | Prompt contents, which include account and contact context, for inference. |
| Platform services | Hosting, monitoring of processing including AI processing, support and billing, together with product and session analytics in the customer's browser. |
4 providers, each operating under published terms that prohibit training on data submitted through their APIs.
| Provider | Training | Retention |
|---|---|---|
| AWS Bedrock | Inputs and outputs are not used to train Amazon or third-party models | Prompts and completions are not stored or logged. This is the default routing for Evergrowth agents, in eu-west-1. |
| Microsoft Azure OpenAI | Prompts and completions are not used to train models | Retained up to 30 days for abuse monitoring. Modified abuse monitoring, which removes storage, is available on approved application. |
| OpenAI | API inputs and outputs are not used for training | Retained for abuse monitoring. Zero data retention is available to eligible API customers. |
| Google Gemini API | On paid services, prompts and responses are not used to improve Google products | Logs retained up to 55 days by default, configurable to 7, 14 or 28. Zero data retention available on approved request. |
Individuals keep every right the GDPR gives them. Collecting data indirectly does not reduce any of them.
See what is held, where it came from, and why it is held.
Correct what is wrong, or have the record deleted.
Pause processing, or receive the data in a portable form.
Object to processing based on legitimate interest, including for direct marketing.
Default model routing runs in the EU. Some processing takes place outside the EEA and the UK, always under appropriate safeguards.
Agent inference runs on AWS Bedrock in eu-west-1, Ireland, which does not store prompts or completions. Other processing may take place outside the EEA and the UK where necessary, under Chapter V safeguards.
Processing pinned to EU regions, for customers with a data residency requirement. Scoped with you and recorded as a written amendment to the Data Processing Agreement.
The equivalent arrangement for customers who require processing to remain in the United States. Same mechanism, same written amendment.
Where a transfer outside the EEA and the UK is necessary, it takes place under Standard Contractual Clauses or other appropriate safeguards. Sub-processors outside the EEA and UK are required to provide equivalent safeguards.
Every record carries a company identifier, and access to any account or contact is validated against the requesting organisation before the record is returned.
In transit and at rest, under AWS KMS.
Role-based, with unique user IDs, authenticated through a dedicated identity provider rather than credentials managed in the application. Two-factor authentication by authenticator app or emailed code.
Access and processing are logged and monitored. Every enrichment step is recorded per record, per source, with its outcome.
On expiry of the agreement, personal data is returned or deleted at the customer's choice, and sub-processors are required to do the same.
Every claim on this page maps to a specific article. All references are to the GDPR, Regulation (EU) 2016/679.
| What we say | Where it comes from |
|---|---|
| Lawful basis for processing | Article 6(1)(f), with Recital 47 on direct marketing |
| Duty to inform where data was obtained indirectly | Article 14 |
| Categories of data, and the legitimate interest, to disclose | Article 14(1)(d) and 14(2)(b) |
| The source the data came from, and when to give it | Article 14(2)(f) and 14(3)(b) |
| Purpose limitation and data minimisation | Article 5(1)(b) and 5(1)(c) |
| Data subject rights | Articles 15 to 21 |
| Right to object | Article 21 |
| Controller and processor obligations | Article 28 |
| Transfers outside the EEA and the UK | Chapter V |