Where your data goes, and where it stops

Written for security, privacy and procurement reviewers. You are the controller for personal data in your workspace; Evergrowth is the processor, acting on your instructions under Article 28. Terms follow the Evergrowth Data Processing Agreement. Where this summary and the agreements differ, the agreements prevail.

See security and certifications
SOC 2 Type 2No exceptions identified
ISO 27001:2022Certified
GDPREU data protection

The path data takes

3 things enter the workspace. 4 categories of sub-processor receive something from it, and each receives only what its function needs.

CUSTOMER SYSTEMS EVERGROWTH WORKSPACE SUB-PROCESSORS CRM recordsUploaded listsWorkspace configuration accounts, contactsCSV importsICP and persona profiles Tenant data storeAgent runtimeOutputs isolated per customerresearch and qualificationexports, CRM write-back BOTH GATES MUST PASS 1 Company matches the ICP profile 2 Person matches the persona profile Model providersData providersVerificationPlatform services prompt contentscompany name, job title, country1 email address or 1 phone numberhosting, monitoring, billing green = only after both gates pass
The 2 qualification gates sit inside the workspace and run before any contact data is requested. Green arrows carry data only after both gates pass. Model providers are not gated in the same way, because the qualification decision is itself made by a model, and receives only the name, job title, LinkedIn profile and employer that decision requires.

The lawful basis, and what makes it hold

Processing rests on legitimate interest under the GDPR, Regulation (EU) 2016/679. Both the basis and the reason it applies to a given person are recorded rather than asserted.

Legitimate interest Article 6(1)(f)

The basis for processing business contact data in the platform. It is balanced against the rights of the individual, which the qualification gates are built to respect.

Direct marketing Recital 47

The Regulation contemplates direct marketing as a legitimate interest expressly, so the question is never whether the basis exists in principle, only whether it holds for this person.

Recital 47 of the GDPR says may. The distance between may and does is documentation. The interest is specific to the individual and recorded at qualification, before any data leaves the workspace.
The question worth putting to any vendor, including us

Can you document the legitimate interest for processing this person's data?

Not a policy that covers everyone. This person. Article 14(2)(b) of the GDPR obliges the controller to be able to answer it, and a contact database or a browser extension delivers a record without a reason, so the answer has to be reconstructed by hand afterwards.

Evergrowth can.

How the limit is enforced

2 qualification gates run before anything is requested from an external source. They are enforced in the pipeline, not stated in a policy.

Account enters name, domain Gate 1: the company does it match the profile the customer approved? No: processing halts no contacts are ever sought Contact discovery by role, not by person Gate 2: the person do they match a buyer persona the customer set? No: processing halts no contact data retrieved Enrichment runs external sources called for this person only YES YES Contact discovery asks for a role at a qualified company, never for a named individual. The query sent to a data provider is a company name, a job title and a country. Contacts already in the workspace are never sent out.
Both gates run before any external source is called. An account that fails the profile check stops before a contact is sought. A contact at an unqualified account stops before any contact data is retrieved.

Purpose limitation Article 5(1)(b)

Data is processed only for the purpose you set, which is finding and qualifying people against the personas and profiles you approved.

Data minimisation Article 5(1)(c)

Nothing is requested for anyone who has not passed both gates, so minimisation is applied at the point of collection rather than afterwards.

Business contact and professional profile data

For people who match the customer's approved profile. The platform neither requests nor requires payroll, employee, health or payment card data at any point.

CategoryFieldsWhere it comes from
Contact identifiersFull name, job title, email address, phone number, LinkedIn profileData providers, verification, customer CRM or import
Professional profileEmployment history, education, skills, languages, profile summary, location, profile photograph, follower and connection countsData providers
Qualification recordThe persona and profile match result, with the reasoning behind itGenerated by Evergrowth
What Article 14 asks of you, in full. Where personal data was obtained from somewhere other than the person, Article 14 asks the controller for 9 pieces of information, and sets a deadline for delivering them. Most are facts about your own organisation. 3 are facts about the individual record, and those are the ones that cannot be reconstructed later.
ArticleWhat has to be statedWho supplies it
14(1)(a)The identity and contact details of the controllerYou
14(1)(b)The contact details of the data protection officer, where applicableYou
14(1)(c) and 14(2)(b)The purposes of processing, the lawful basis, and the legitimate interest relied onRecorded per contact by Evergrowth
14(1)(d)The categories of personal data concernedRecorded per contact by Evergrowth
14(1)(e)The recipients, or categories of recipientYou, from the sub-processor register
14(2)(a)The retention period, or the criteria used to determine itYou, from your own policy
14(2)(c)The rights of access, rectification, erasure, restriction, objection and portabilityYou, wording in our guide
14(2)(e)The right to lodge a complaint with a supervisory authorityYou, wording in our guide
14(2)(f)The source the data came from, and whether it was publicly accessibleRecorded per contact by Evergrowth
14(3)(b)Delivered by your first communication at the latestYou, in the first message
The 3 in bold are the difficult ones. Everything else is a fact about your own organisation that you already know. Why you held this particular person, what you held about them, and where it came from are facts about a single record, and a contact database or a browser extension does not capture them. Evergrowth records all 3 at the moment the contact qualifies.
Delivering the notice. The Play Agent that writes your outreach can carry it, once your own organisation's details are in its instructions. Our guide gives the wording and the layered format that delivers all 9 items.

Who receives data, and what they receive

4 categories of sub-processor. Each is named, with its country of processing, in the sub-processor register, which we provide on request and during a security review.

CategoryWhat leaves the workspace, and why
Data providersA company name, a job title and a country, to identify people holding that role. For a contact the customer already holds, the identifier for that person, to retrieve business contact information.
VerificationA single email address or phone number, to confirm it is valid and deliverable before use. Runs only when the customer enables verification.
Model providersPrompt contents, which include account and contact context, for inference.
Platform servicesHosting, monitoring of processing including AI processing, support and billing, together with product and session analytics in the customer's browser.

No provider trains on customer data

4 providers, each operating under published terms that prohibit training on data submitted through their APIs.

ProviderTrainingRetention
AWS BedrockInputs and outputs are not used to train Amazon or third-party modelsPrompts and completions are not stored or logged. This is the default routing for Evergrowth agents, in eu-west-1.
Microsoft Azure OpenAIPrompts and completions are not used to train modelsRetained up to 30 days for abuse monitoring. Modified abuse monitoring, which removes storage, is available on approved application.
OpenAIAPI inputs and outputs are not used for trainingRetained for abuse monitoring. Zero data retention is available to eligible API customers.
Google Gemini APIOn paid services, prompts and responses are not used to improve Google productsLogs retained up to 55 days by default, configurable to 7, 14 or 28. Zero data retention available on approved request.
What actually reaches a model. The personal data in a prompt is limited to what the qualification decision requires: the person's name, job title, LinkedIn profile and employer. The bulk of what the agents process is company level research, which is not personal data. No profile photograph, no employment history and no special category data is sent to a model.

Rights are unaffected

Individuals keep every right the GDPR gives them. Collecting data indirectly does not reduce any of them.

Access Article 15

See what is held, where it came from, and why it is held.

Rectification and erasure Articles 16 and 17

Correct what is wrong, or have the record deleted.

Restriction and portability Articles 18 and 20

Pause processing, or receive the data in a portable form.

Right to object Article 21

Object to processing based on legitimate interest, including for direct marketing.

Requests come to you. You are the controller, so a request reaches you first, and the Data Processing Agreement commits us to assist you in giving effect to it. Because every contact carries the reason it qualified and the source it came from, the answer already exists.

Where data is processed

Default model routing runs in the EU. Some processing takes place outside the EEA and the UK, always under appropriate safeguards.

Standard default

Agent inference runs on AWS Bedrock in eu-west-1, Ireland, which does not store prompts or completions. Other processing may take place outside the EEA and the UK where necessary, under Chapter V safeguards.

EU-only on request

Processing pinned to EU regions, for customers with a data residency requirement. Scoped with you and recorded as a written amendment to the Data Processing Agreement.

US-only on request

The equivalent arrangement for customers who require processing to remain in the United States. Same mechanism, same written amendment.

Transfers Chapter V

Where a transfer outside the EEA and the UK is necessary, it takes place under Standard Contractual Clauses or other appropriate safeguards. Sub-processors outside the EEA and UK are required to provide equivalent safeguards.

How a regional configuration is agreed. Because the platform runs on AWS, region pinning is available for the components AWS serves. We scope the configuration with you, confirm what each sub-processor can support, and record the commitment in a written amendment to the Data Processing Agreement. Scope, timeline and any commercial impact are agreed in writing before the commitment is made.

One customer's data is never returned to another

Every record carries a company identifier, and access to any account or contact is validated against the requesting organisation before the record is returned.

Encryption

In transit and at rest, under AWS KMS.

Access control

Role-based, with unique user IDs, authenticated through a dedicated identity provider rather than credentials managed in the application. Two-factor authentication by authenticator app or emailed code.

Logging

Access and processing are logged and monitored. Every enrichment step is recorded per record, per source, with its outcome.

Return and deletion

On expiry of the agreement, personal data is returned or deleted at the customer's choice, and sub-processors are required to do the same.

Check any of this against the Regulation

Every claim on this page maps to a specific article. All references are to the GDPR, Regulation (EU) 2016/679.

What we sayWhere it comes from
Lawful basis for processingArticle 6(1)(f), with Recital 47 on direct marketing
Duty to inform where data was obtained indirectlyArticle 14
Categories of data, and the legitimate interest, to discloseArticle 14(1)(d) and 14(2)(b)
The source the data came from, and when to give itArticle 14(2)(f) and 14(3)(b)
Purpose limitation and data minimisationArticle 5(1)(b) and 5(1)(c)
Data subject rightsArticles 15 to 21
Right to objectArticle 21
Controller and processor obligationsArticle 28
Transfers outside the EEA and the UKChapter V