Privacy Policy
Last updated: September 15, 2026
1. EVRE's role in data processing
EVRE is an enterprise simulation platform that helps organisations rehearse real business situations with AI-supported simulations, assess participant interactions, and produce development feedback. We process personal data according to the nature of the data and the way EVRE is used.
For certain data processed through the website, demo requests, account management, security activities, and our own business operations, EVRE may act as a data controller. When an organisation uses EVRE for its employees, teams, or other users, that organisation may determine the purposes and scope of certain data processed through the platform, and EVRE may process that data on the organisation's behalf.
For enterprise deployments, the parties' roles may be further defined in the applicable customer agreement and data-processing terms. If more specific terms apply to a customer deployment, those terms govern that deployment.
2. Data we process
Depending on how EVRE is used, we may process the following categories of data.
Account and identity data
Name, surname, business email address, organisation, role or title, account membership, authentication, and access information.
Simulation and interaction data
Transcripts created from participant written or spoken responses, simulation history, scenario events, decisions, AI-character interactions, and related session information.
Evaluation data
Behavioural scores, measurement results, feedback, evaluation reasoning, relevant interaction excerpts, and development indicators.
Organisation-provided content
Customers may provide scenarios, competency models, evaluation criteria, training content, or other organisational context to EVRE.
Organisations and users should not submit unnecessary sensitive personal data, trade secrets, or highly sensitive information unless the relevant deployment has been specifically configured for that type of data.
Voice data
In voice simulations, spoken input may be processed and transcribed in real time by the speech-processing infrastructure configured for the active deployment.
Voice-processing architecture may vary by deployment. EVRE Standard Cloud deployments may use managed speech services. Enterprise deployments with stricter data boundaries may use private or local speech-to-text infrastructure.
Generated transcripts may be processed together with other simulation data to run, evaluate, and report on simulations. EVRE does not use biometric identity profiles or voice cloning from employees' voices as a standard product function.
Usage and technical data
IP address, device and browser information, session and security events, feature usage, error information, performance data, and technical metadata needed to operate the service.
Contact data
Information you send to us in connection with demo, sales, support, or other communications may be processed.
3. Why we use data
We may process personal data for the following purposes:
- Provide and operate the EVRE service.
- Manage user accounts and organisational access.
- Create and run simulations.
- Produce behavioural assessments, feedback, and reports.
- Help organisations manage training and development programmes.
- Provide support.
- Maintain security, detect misuse, and protect our systems.
- Analyse product performance and improve EVRE.
- Meet legal and contractual obligations.
- Send commercial communications where permission or another applicable legal basis exists.
Personal data may be processed on the basis of entering into or performing a contract, a legal obligation, legitimate interests, explicit consent, or another legal basis applicable to the relevant processing activity under applicable law.
Optional analytics on EVRE's public website are based on consent. Service security, fraud prevention, and strictly necessary operational measurement may rely on legitimate interests or another applicable legal basis, as appropriate.
4. AI and behavioural assessment
EVRE uses AI systems to analyse behaviour and responses within simulations, generate AI-character responses, and provide feedback to users.
For these purposes, simulation context, transcripts, relevant conversation history, evaluation criteria, and limited technical metadata may be processed by AI services.
EVRE simulation scores are behavioural signals produced against specific training, development, or evaluation criteria. They should be considered in their context and are not designed to be the sole basis for significant employment decisions.
Enterprise customers remain responsible for their purposes of use, assessment processes, and human-review mechanisms.
5. Deployment and data-processing architecture
EVRE can be configured under different deployment models for enterprise requirements.
Standard Cloud
This is EVRE's managed SaaS service. Enterprise cloud and AI service providers may be used for application, data, AI, network, and speech-processing functions.
Private or Regional Deployment
For specific enterprise requirements, private speech processing, regional infrastructure, custom routing, additional data minimisation, or customer-specific provider restrictions may be applied.
Customer-managed or on-premises
Where appropriate for enterprise requirements, certain EVRE components may run in customer-controlled infrastructure, a private-cloud environment, or an on-premises architecture.
Not every deployment uses the same data flow. Processing location, service providers, and data boundaries depend on the deployment selected and technically configured for the customer. Customer-specific data-location or provider restrictions are defined separately in the applicable agreement and deployment documentation.
6. Service providers
EVRE uses third-party infrastructure and technology providers to deliver the service. Depending on the use case, these categories may include:
- Cloud hosting and application infrastructure.
- Database and authentication.
- AI inference and embedding.
- Speech-to-text and text-to-speech.
- Network and edge infrastructure.
- Observability and security.
- Communications, support, and other operational services.
Only the scope needed to provide the relevant service is transferred to these providers. EVRE does not sell personal data.
EVRE manages provider relationships through contractual and technical controls according to the provider's role, the data processed, and applicable legal requirements.
7. International data processing
EVRE is an enterprise cloud service that may rely on infrastructure and technology providers operating in multiple countries. Personal data may therefore be processed outside the country where the user or customer is located.
For international transfers, applicable data-protection law, customer agreements, and the transfer mechanisms applicable to the relevant deployment govern. Depending on the case, these may include contractual data-protection terms, standard contractual mechanisms, or other transfer tools permitted by law.
The fact that a server, database, or application runtime is located in a particular region does not mean that all EVRE service providers and subprocessors operate only in that region.
Different deployment options may be evaluated for enterprise customers with specific data-residency requirements.
7.1 Google Sign-In
Signing in with Google is optional. When you use it, EVRE requests only the openid, email and profile scopes, and receives your name, email address, profile picture, and Google account identifier. This data is used to create or authenticate your EVRE account and to associate activity with that account. It is not sold, used for advertising, or used to train AI models.
EVRE does not request or receive access to your Gmail messages, Google Drive files, Google Calendar events, or any other Google service. You can revoke EVRE's access at any time from the Google Account permissions page; revoking access ends Google Sign-In for your account but does not by itself delete your EVRE account.
8. Data retention
We retain personal data for as long as necessary to provide the relevant service, perform a customer agreement, maintain security, and meet applicable legal obligations.
Retention periods may vary according to the nature of the data, the purpose of use, customer instructions, the deployment model, and applicable legal requirements.
For enterprise customers, specific retention and deletion periods may be set out separately in the customer agreement or deployment policy.
When data is no longer needed, it is deleted, anonymised, or taken out of use in accordance with applicable technical and legal retention limits.
Backups, security records, and limited operational records held by third-party services may be subject to their own technical lifecycles.
9. Security
EVRE applies technical and organisational security measures to protect personal data against unauthorised access, use, alteration, loss, or disclosure.
Depending on the use and deployment scope, current controls may include:
- Encrypted network communications.
- At-rest encryption controls provided by infrastructure providers.
- Tenant- and role-based access controls.
- Database-level Row Level Security.
- Server-side privileged-credential boundaries.
- Multi-factor authentication for administrator accounts.
- SSO and customer-specific access policies.
- Audit and security-event records.
- Separation of production and development environments.
- Data minimisation and controls designed to limit sensitive fields in logs.
- Regular review of infrastructure and application security controls.
Security certifications and controls of third-party providers used by EVRE belong to those providers and are not presented as EVRE's own certifications.
10. Cookies and analytics
Necessary cookies and browser storage are used for the website to function, to remember essential preferences, and to help keep it secure.
With your consent, EVRE uses its analytics provider, PostHog, on its public website to understand site use, performance, and browser-side technical issues. Analytics does not run before consent and is not enabled on app.evre.ai or enterprise customer subdomains.
Session replay may be enabled. Content entered into form fields is masked and is not recorded through analytics. Random analytics identifiers may be used to distinguish browsers and sessions rather than your name or email address.
You can change your analytics preference at any time through the “Cookie Preferences” link in the page footer.
EVRE does not sell personal data to third-party advertising networks.
11. Your rights
Depending on your country and EVRE's role in the relevant processing activity, you may have rights over your personal data, including access, correction, deletion, restriction, objection, portability, or rights relating to automated-processing outcomes.
You may send requests relating to processing for which EVRE is the direct controller to us.
Where EVRE processes data on behalf of an enterprise customer, that organisation may be primarily responsible for fulfilling the request. If such a request reaches EVRE, we will act with the organisation through the applicable process.
Individuals in Türkiye may exercise the rights provided under Article 11 of the KVKK. Individuals in the EEA, the United Kingdom, or other relevant regions may exercise rights recognised by applicable data-protection law and may contact the competent supervisory authority.
12. Children
EVRE is designed for professional and enterprise use and is generally not directed at individuals under 18.
If we learn that data belonging to a person under 18 has been processed inadvertently, we will take the steps required under applicable obligations.
13. Changes to this policy
We may update this Privacy Policy as EVRE's products, deployment models, service providers, or legal obligations change.
The current version is published on this page, and the last-updated date is shown at the top. Where required by applicable law or agreement, additional notice may be provided for material changes.
14. Contact
For privacy or personal-data processing requests, please contact us using the details below.

