Legal
Privacy Notice
This notice explains how personal data is handled when you use EvidentraIQ. It is a draft. Points marked "To be completed" have not yet been decided and verified, and nothing here should be read as a claim of certification or of compliance with any law.
1. Who is responsible
EvidentraIQ is operated by Global Security Job ApS, Denmark, which acts as data controller for the personal data described here.
EvidentraIQ — A part of Global Security Job ApS · CVR no. 43324934To be completed: A verified privacy contact email, and whether a Data Protection Officer is required.
2. Data we process
- Account data: email address used for passwordless sign-in.
- Organisation data: workspace name, memberships and roles.
- Assessment content: answers, evidence records, findings, actions and history you enter.
- Billing data: package, payment and subscription status. Card details are entered on our payment provider's hosted page and are not stored by EvidentraIQ.
- Report requests: contact details you submit to request a report.
- Technical data: security logs and basic request information needed to operate the service.
The free public assessment demo stores its answers in your own browser and does not send them to us.
3. Purposes and legal basis
Under the GDPR, each processing purpose needs a legal basis. The intended framework is:
- Providing the service and managing accounts and payments — performance of a contract.
- Security, fraud prevention and audit history — legitimate interests.
- Bookkeeping and statutory records — legal obligation.
- Optional communications — consent, where required.
To be completed: Final mapping of each purpose to its legal basis, including any legitimate-interest assessments.
4. Service providers
We use service providers who process data on our behalf under data processing terms, including hosting and database infrastructure, and payment processing for checkout and subscriptions.
To be completed: The named list of subprocessors, their locations and the agreements in place.
5. International transfers
Some providers may process data outside the EU/EEA. Where that happens, transfers will rely on a lawful transfer mechanism under the GDPR, such as an adequacy decision or standard contractual clauses.
To be completed: Which transfers occur and the mechanism used for each.
6. Security
We apply technical and organisational measures appropriate to the risk, including separation of customer workspaces, role-based access, encrypted connections and an audit trail of changes. No system is free of risk, and we make no claim of certification.
7. Retention
We keep personal data only as long as needed for the purposes above, for statutory requirements such as bookkeeping, or to establish or defend legal claims. Data is then deleted or anonymised.
To be completed: Specific retention periods per data category.
8. Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction, data portability, and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time. Send requests to the company identified above; contact details are provided on request.
9. Complaints
You may lodge a complaint with a data protection supervisory authority, in particular in the EU/EEA country where you live, work or where an alleged infringement took place. In Denmark this is Datatilsynet (the Danish Data Protection Agency).
10. Cookies and analytics
The site uses storage that is necessary for sign-in and for the browser-local demo assessment.
To be completed: Confirmation of any analytics or non-essential cookies and, if used, a consent mechanism and cookie list.
11. Changes
We may update this notice. Material changes will be indicated on this page with a new effective date.
To be completed: Effective date and version.
