SHEET L-01 · PRIVACY POLICY
Privacy Policy
What this website and platform collect, why, where it sits, and how to make us delete it.
1. Who we are
Evidentium is a product of David Reifs, a sole trader established in Spain with NIF NIF of the sole trader, whose registered address is c/ Nyerros, 4, 08500 Vic, Barcelona, Spain. For everything described in this policy we are the data controller unless a section says otherwise.
Data protection contact: privacy contact email. Data protection officer: data protection officer name and contact, or 'not appointed'. Representative in the European Union: not required — we are established in Spain, inside the European Union.
2. Two different roles
We handle personal data in two capacities, and the difference matters because your rights are exercised differently in each.
- As controller, for this website, demo requests, account administration and billing. That is what this policy covers.
- As processor, for the personal data inside a customer's review workspace: the records, criteria, decisions and drafts your team puts there. We act only on that customer's instructions, and the terms are set out in our Data Processing Agreement rather than here.
If you are a researcher whose personal data appears inside someone's review workspace, that organisation is the controller and your request should go to them. We will help them answer it.
3. What we collect on this website
The website has one form. When you request a demo we store exactly the fields you filled in, plus a small amount of technical context.
| What | Where it comes from | Why |
|---|---|---|
| Name and work email | You type it | To reply to you |
| Institution or company | You type it, optional | To prepare a relevant walkthrough |
| Topic of your review | You choose it | Same |
| Your message | You type it, optional | Same |
| Site language | The page you submitted from | To answer in your language |
| Browser user agent and referring page | Your browser sends them | To tell a real enquiry from automated spam |
| Timestamps and a handling status | We add them | To manage the enquiry |
We also record the pages you look at, so we can tell which parts of the site are read and which sources send people here. This is our own measurement, running on our own server; the data is not sent anywhere else.
| What | Where it comes from | Why |
|---|---|---|
| Page visited, and the time | The page you opened | To see what is read |
| IP address | Your connection | To count visits, place them roughly, and spot abuse |
| Browser user agent, and screen width | Your browser sends them | To tell a person from a crawler, and desktop from phone |
| Referring page and any utm_ tags in the link | The link you followed | To know which source or campaign brought you |
| Country | Only if a network in front of us resolves it | To read demand by region |
Those views are grouped under a key we calculate rather than store: your address and browser, mixed with a secret and with today's date, then hashed. It lets us count people instead of clicks and follow one visit through the site. Because the date is part of it, the key changes at midnight UTC and yesterday's visits can no longer be tied to today's. If you then submit the demo form, the same key is saved with your enquiry, which is how we can see the visits that led to it.
If you would rather not be counted, a browser that blocks trackers or sends Do Not Track will not stop this, because it is our own first-party request. Write to us and we will delete the rows for your address.
Your IP address is also used in memory, for a few seconds, to limit how many submissions can arrive from one address per minute.
Our web server keeps access logs, which contain IP addresses, as almost every web server does. Retention for all of it is in section 8.
4. What we do not do
Stated plainly, because these are the things people reasonably assume a website does.
- No third-party analytics. There is no Google Analytics, no advertising pixel, no session recording and no heatmap. The visit counting described in section 3 is our own code writing to our own database, and no other company receives it.
- No tracking across other websites. We can see the page that linked to us, and nothing about where you went next.
- No advertising or tracking cookies, and no cookie banner, because nothing is stored on your device to consent to.
- No third-party requests while you browse. Fonts are served from our own domain, so your visit is not announced to a font provider or a CDN.
- No sale or sharing of personal data for anyone else's marketing.
- No use of your review records, criteria or drafts to train a model, ours or anyone else's.
5. Cookies and local storage
This website sets one cookie, and only after an operator signs in to the administration area:
| Name | Purpose | Lifetime |
|---|---|---|
| rh_admin | Keeps our own staff signed in to the demo request panel. Contains a signed session token, no personal data. | 12 hours, HttpOnly, scoped to /admin |
Counting visits does not add a second one. The key described in section 3 is calculated on our server from the request itself, so nothing is written to your browser and there is nothing for you to clear.
Your browser also stores two appearance preferences locally, rh-theme and rh-skin, so the site remembers whether you chose the light or dark drawing and which accent. They never leave your device and are not read by our servers. Clearing site data removes them.
6. Why we are allowed to hold it
- Demo requests: our legitimate interest in responding to a business enquiry that you initiated. You asked us to get in touch, and we keep only what is needed to do that.
- Account, contract and billing data: performance of the contract with your organisation, and our legal obligations to keep accounting records.
- Server logs, visit counting and rate limiting: our legitimate interest in understanding demand for the site and keeping it available and free of abuse. We use the least identifying method we could find that still gives us a real count, and you can object.
- Marketing email, if we ever send any: your consent, withdrawable in one click. We do not currently operate a newsletter.
7. Where it sits, and who else touches it
The platform runs in three regions: European Union, United States, Australia. A customer chooses the region when the account is created and it is fixed for that workspace. Records, backups and exports stay inside it, and nothing is replicated to another region.
Infrastructure: hosting provider and the region each account sits in. Model provider, for customers who do not connect their own API key: model provider used when a customer does not bring their own key. Handling of demo request correspondence: email or CRM tool used to answer demo requests.
Where a transfer outside the EEA is involved, it is covered by the European Commission's Standard Contractual Clauses together with the technical measures described in our Data Processing Agreement.
Figure rendering receives counts and labels only. No title, abstract or author name from a review reaches a third party.
8. How long we keep it
| Data | Retention |
|---|---|
| Demo request that does not become an account | how long an unconverted demo request is kept |
| Page views in the visit log | 180 days, then deleted automatically |
| Web server access logs | web server log retention, once rotation is configured |
| Workspace data after an account closes | how long workspace data survives account closure |
| Accounting records | As long as tax law requires, then deleted |
You can ask us to delete a demo request before any of these periods elapse and we will, unless we need it to defend a legal claim.
9. Your rights
Under the GDPR and equivalent laws you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, hand it to another provider in a portable format, or object to processing we base on legitimate interest.
Write to privacy contact email. We answer within one month and will tell you if we need longer. There is no charge unless a request is excessive, and we will say so rather than quietly ignore it.
If our answer does not satisfy you, you can complain to your local data protection authority. Ours is the Agencia Española de Protección de Datos (AEPD).
10. Security
Transport is encrypted with TLS. Access to the administration panel requires a password and is limited to a small number of operators, and its session cookie is HttpOnly and short lived. Workspace membership is per project, and larger accounts can require single sign-on and receive audit logs.
Security reports are welcome and are read, not ignored: security contact email, may be the same. No perfect security exists, and any provider who tells you otherwise is selling something.
11. Children
This is a professional research tool. It is not directed at children and we do not knowingly collect their data.
12. Changes
This policy is version 0.1 draft, last updated 2026-08-25. Material changes will be announced to account holders before they take effect, and the previous version will remain available on request.