Overview and how this applies
This Data Processing Addendum (“DPA”) forms part of the Terms of Servicebetween you (the “Customer”) and Individual Entrepreneur Yaroslav Volovyi(“EvalLens, ” “we”) and applies where we process personal data on the Customer’s behalf in providing the Service. If a signed agreement between the parties includes different data‑processing terms, that agreement controls. Terms such as “controller,” “processor,” “data subject,” and “processing” have the meaning given under applicable data‑protection law, including the EU/UK GDPR and the Law of Georgia on Personal Data Protection.
Roles of the parties
For personal data contained in submissions and evaluation materials the Customer provides or collects (“Customer Personal Data”), the Customer is the controller and EvalLens is the processoracting on the Customer’s documented instructions. Where EvalLens determines the purposes and means of processing — for example, account administration and securing the Service — EvalLens acts as a controller and its Privacy Policy applies.
Subject-matter, nature and purpose
The processing covers what is needed to provide the Service:
- Subject‑matter and duration: processing of Customer Personal Data for the term of the Service and until deletion or return as described below.
- Nature and purpose:hosting, storing, and running AI‑assisted evaluation of submitted materials to produce advisory, decision‑support reports for the Customer.
- Types of data: account and contact details, and the contents of submissions (which may include founder/team information and any personal data the Customer or its participants include).
- Data subjects:the Customer’s personnel and the participants whose materials are submitted to the Service.
Processing on documented instructions
EvalLens processes Customer Personal Data only on the Customer’s documented instructions — including as set out in this DPA, the Terms, and the Customer’s configuration and use of the Service — unless required to do otherwise by applicable law, in which case we will inform the Customer unless the law prohibits it. We do not use submitted materials to train third‑party foundation models, and we instruct our providers to process this content only to deliver the Service. We will tell the Customer if we believe an instruction infringes applicable data‑protection law.
Confidentiality
We ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and access such data only as needed to provide the Service, following least‑privilege principles.
Security measures
We implement appropriate technical and organizational measures to protect Customer Personal Data, including encryption in transit, access controls, row‑level isolation between customer workspaces, and server‑side handling of secrets. A fuller description is on our Security page. We may update these measures over time provided the level of protection is not materially reduced.
Sub-processors
The Customer authorizes EvalLens to engage the sub‑processors listed on our Sub‑processorspage to help provide the Service. We impose data‑protection obligations on each sub‑processor that are no less protective than those in this DPA and remain responsible for their performance. We will notify the Customer of intended additions or replacements as described on that page, giving the Customer an opportunity to object on reasonable data‑protection grounds.
Data-subject requests
Taking into account the nature of the processing, we will provide reasonable assistance to help the Customer respond to data‑subject requests (such as access, correction, deletion, restriction, portability, and objection). If we receive such a request directly from a data subject about Customer Personal Data, we will direct them to the Customer rather than respond ourselves, unless legally required to act.
Assistance with compliance
Taking into account the information available to us, we will provide reasonable assistance to the Customer with data‑protection impact assessments and prior consultations with supervisory authorities, and with the Customer’s obligations to keep Customer Personal Data secure, to the extent these relate to our processing.
Personal-data breach notification
We will notify the Customer without undue delay after becoming aware of a personal‑data breach affecting Customer Personal Data, and provide information reasonably available to us to help the Customer meet its own notification obligations. Our notice is not an acknowledgment of fault or liability.
Return and deletion
On termination of the Service, or on the Customer’s request, we will delete or return Customer Personal Data in accordance with the retention periods described in our Privacy Policy, except where applicable law requires continued storage. Residual copies in routine backups are purged on our ordinary backup cycle.
International transfers
Where we or our sub‑processors transfer Customer Personal Data across borders, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses and the UK addendum where relevant, or transfers to a jurisdiction recognized as adequate. Further detail is in our Privacy Policy.
Audits and information
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allow for and contribute to audits conducted by the Customer or an independent auditor it mandates. To minimize disruption, the parties will agree on scope, timing, and cost in advance, and we may satisfy audit requests by providing relevant documentation or summaries of third‑party assessments where available.
Contact us
To put a signed copy of this DPA in place, or for any data‑processing question, contact privacy@evallens.io.
Questions about this page? Contact legal@evallens.io.