Privacy Policy
Effective date: June 14, 2026
Evalora is operated by Abhijith Warrier, an individual doing business as Evalora, based in Kerala, India. This Privacy Policy explains what personal data we collect, why we collect it, how it is used, and your rights over it.
By creating an account or using Evalora, you agree to the practices described in this policy. If you do not agree, please do not use the service.
1. What Data We Collect
We collect the minimum data necessary to operate the service. Here is what we collect and why.
Account and identity data
When you register, we collect your name, email address, and a hashed password. You may also optionally upload a profile picture from your profile page. Profile pictures are stored on AWS S3. This data is used to authenticate you, display your identity within the workspace, and send you service-related emails (such as campaign notifications and password resets).
Organisation and workspace data
Organisation owners provide a workspace name and optionally upload a logo. Logos are stored on AWS S3. We also store department names, member roles, and invitation records to manage access control.
Feedback form and campaign data
Workspace managers create feedback forms (questions) and campaigns (active feedback cycles). We store these definitions as part of the service.
Feedback responses (submissions)
Contributors submit responses to campaigns. Responses may include text, numerical ratings, yes/no answers, and multiple-choice selections. Responses are stored and made available only to authorised members of the organisation that created the campaign.
Responses are linked to a contributor account to enforce the one-response-per-person rule. Reviewers and managers can see aggregate analytics; individual responses are accessible to managers, admins, and owners depending on their role.
Webcam data
Webcam capture is a core part of every Evalora submission. When a contributor submits feedback, the browser requests webcam access and captures an image at the point of submission. This image is stored on AWS S3 and is displayed alongside the contributor's response in the response viewer, visible only to authorised members of the organisation (managers, admins, and owners, based on their role).
Organisation administrators are responsible for informing contributors that a webcam image will be captured and retained as part of their feedback submission, and for ensuring this complies with applicable employment and privacy law in their jurisdiction.
Usage and technical data
We collect standard server logs including IP addresses, browser type, device information, and request timestamps. This data is used for security monitoring and debugging. We do not use it for advertising or tracking.
Communications
If you contact us by email at support@evalora.pro, we may use that correspondence to respond to your query. Email communication is handled externally via our email provider and is not stored within the Evalora platform itself.
2. How We Use Your Data
We use the data we collect for the following purposes:
- Providing and operating the Evalora platform
- Authenticating users and enforcing access control within workspaces
- Generating analytics and reports for organisation administrators
- Sending service emails — campaign notifications, invitations, password resets
- Generating AI-powered summaries of feedback responses, using the Anthropic Claude API (see Section 4 for details)
- Monitoring for abuse, security incidents, and platform integrity
- Improving the service — fixing bugs and developing new features
We do not use your data for advertising, sell it to third parties, or use it for any purpose beyond operating and improving Evalora.
3. Legal Basis for Processing
If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data under the following legal bases:
- Contract performance — processing your account data and feedback data is necessary to deliver the service you signed up for.
- Legitimate interests — security logging, fraud prevention, and service improvement, where these interests are not overridden by your rights.
- Legitimate interests — webcam capture is a core feature of the platform used to verify the authenticity of feedback submissions. Organisation administrators are responsible for compliance with applicable law when collecting webcam images from their contributors.
- Legal obligation — where we are required to retain or disclose data by applicable law.
For users in India, we process data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act).
4. Third-Party Processors
We share data only with the service providers necessary to operate Evalora. All processors are contractually bound to handle data securely and only for the purposes we specify.
Amazon Web Services (AWS S3)
Stores uploaded files — organisation logos, user profile pictures, and webcam images captured during feedback submissions. CSV, XLSX, and PDF exports are generated on-demand and streamed directly to the requester; they are not stored on S3. Data may be stored in AWS regions including Asia Pacific and US East.
Anthropic (Claude API)
When an authorised user generates an AI summary, the following data is sent to the Anthropic API: the organisation name, campaign titles, question text, and the text-based answer values from submissions. No individual user names or email addresses are included. Anthropic's data use is governed by their API usage policy.
AI summaries are an optional feature. If you do not use the AI summary function, no data is sent to Anthropic.
Vercel
Our frontend and backend are hosted on Vercel's infrastructure. Vercel processes request and response data as part of serving the application.
Zoho (Email delivery)
Transactional emails (invitations, campaign notifications, password resets) are delivered via Zoho Mail SMTP. Email addresses and the content of service emails pass through Zoho.
Payment processors
Subscription payments are processed by Razorpay, a PCI-DSS compliant payment gateway. When you subscribe, your payment details (card number, UPI ID, or bank details) are collected and stored directly by Razorpay — we never store or have access to your raw payment credentials. Razorpay may retain payment data in accordance with their own Privacy Policy. We store only the subscription ID and payment reference ID for billing and support purposes.
5. Data Retention
We retain data only as long as necessary:
- Account data — retained while your account is active. There is no self-service account deletion; to request removal of your account and personal data, contact us at support@evalora.pro. We will process the request within 30 days.
- Feedback responses — retained as long as the campaign exists in the workspace. When a campaign or workspace is deleted, all associated responses are permanently deleted.
- Webcam data — stored for the lifetime of the campaign. Deleted when the campaign is deleted.
- Server logs — retained for up to 90 days for security and debugging purposes.
- Backups — may persist for up to 30 days beyond the deletion of data in active systems.
6. Your Rights
Depending on where you are located, you have the following rights regarding your personal data. To exercise any of these rights, contact us at support@evalora.pro.
Right to access
You can request a copy of the personal data we hold about you.
Right to rectification
You can correct inaccurate data directly through your account settings, or ask us to correct it on your behalf.
Right to erasure
You can request that we delete your personal data. Note that deleting your account removes your identity, but feedback responses you submitted may remain in your organisation's workspace as they belong to the organisation, not to you as an individual. Contact your organisation admin to request deletion of your responses.
Right to data portability
You can contact us to request a copy of the personal data we hold about you (name, email address, and profile picture). Organisation campaign data is owned by the organisation; contact your organisation admin regarding exports of that data.
Right to object
Where we process data based on legitimate interests, you may object to that processing by contacting us. We will assess whether our legitimate interests override yours in each case.
India — DPDP Act rights
If you are an Indian resident, you have the right to access, correct, and erase your personal data under the Digital Personal Data Protection Act, 2023. You also have the right to nominate another person to exercise these rights on your behalf. Grievances can be raised with us at the contact below before escalating to the Data Protection Board of India.
EEA/UK — right to lodge a complaint
If you are in the EEA or UK and believe we are processing your data unlawfully, you have the right to lodge a complaint with your local data protection authority.
7. Cookies and Local Storage
Evalora uses minimal client-side storage. We do not use advertising cookies or third-party tracking pixels.
- Authentication tokens— JWT access and refresh tokens are stored in your browser's localStorage to keep you logged in across sessions. These are not cookies and are only accessible within the Evalora application.
- Maintenance bypass cookie — a session cookie used internally by our team to access the service during maintenance windows. Not set for regular users.
No third-party advertising or analytics cookies are used on Evalora.
8. Data Security
We take reasonable technical measures to protect your data:
- All connections between your browser and our servers are encrypted via HTTPS/TLS
- Passwords are never stored in plain text — they are hashed using a secure algorithm
- Authentication uses short-lived JWTs (15 minutes) with rotating refresh tokens
- File storage on AWS S3 uses server-side encryption
- Administrative access to the platform is restricted and logged
No system is perfectly secure. If you believe you have found a security vulnerability, please contact us immediately at support@evalora.pro before disclosing it publicly.
9. Children
Evalora is a B2B platform designed for use by organisations. It is not directed at children under the age of 18. We do not knowingly collect personal data from individuals under 18. If you believe a minor has submitted data through our platform, please contact the organisation administrator or contact us directly.
10. International Data Transfers
Our infrastructure uses services (AWS, Vercel, Anthropic, Zoho) that may process data in countries outside India, including the United States. Where data is transferred internationally, we rely on the contractual safeguards offered by those processors.
If you are in the EEA, by using Evalora you acknowledge that your data may be transferred to and processed in India and the US, where data protection laws may differ from your country.
11. Changes to This Policy
We may update this policy from time to time. For material changes — changes to how we use your data or who we share it with — we will notify you by email at least 14 days before the change takes effect. Minor changes (grammar, clarifications) may be made without notice.
The effective date at the top of this page reflects the date of the most recent update. Continued use of Evalora after a policy change constitutes acceptance of the updated policy.
12. Contact
For any questions about this policy, to exercise your rights, or to raise a privacy concern, contact us at:
Abhijith Warrier
Operating as Evalora
Kerala, India
Email: support@evalora.pro
We aim to respond to privacy requests within 7 business days.