Skip to content

Evacor Suite Data Processing Agreement

Last updated: October 6, 2026

This Data Processing Agreement ("DPA") is part of the Evacor Suite Terms of Service (the "Terms") between Brandsquare LLC, 30 N Gould St, STE N, Sheridan, WY 82801, United States ("Brandsquare", the "Processor") and the customer that accepted the Terms (the "Customer", the "Controller"). It applies when Brandsquare processes Personal Data in Customer Data on the Customer's behalf. It is accepted automatically when the Customer accepts the Terms. A countersigned copy is available on request at product@bsq.agency.

1. Definitions

"Data Protection Law" means the laws that apply to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws such as the California Consumer Privacy Act as amended ("CCPA"). "Personal Data", "Controller", "Processor", "Data Subject", "Processing", "Personal Data Breach", "Service Provider" and "Supervisory Authority" have the meanings in that law. "Customer Data" and "Service" have the meanings in the Terms. "Subprocessor" means a third party that Brandsquare engages to process Personal Data in Customer Data. "SCCs" means the standard contractual clauses in Commission Implementing Decision (EU) 2021/914.

2. Roles and scope

2.1 For Personal Data in Customer Data, the Customer is the Controller (or a Processor acting for its own controllers) and Brandsquare is the Processor (or sub-processor). Annex I describes the processing.

2.2 For account, billing, security and usage data that Brandsquare uses for its own purposes, Brandsquare is an independent controller, as the Privacy Notice explains. This DPA does not apply to that data.

2.3 The Customer is responsible for having a lawful basis, giving notices and obtaining consents needed to process Personal Data through the Service, including from its employees, candidates and customers.

3. Instructions

3.1 Brandsquare will process Personal Data only on the Customer's documented instructions: the Terms, this DPA, and the Customer's configuration and use of the Service (including by its users). Brandsquare will not process it for other purposes, except where law requires, in which case it will tell the Customer first, unless the law forbids that.

3.2 Brandsquare will tell the Customer if, in its opinion, an instruction infringes Data Protection Law. It may suspend the instruction until the Customer confirms or changes it.

3.3 Brandsquare will not sell Personal Data or "share" it for cross-context behavioural advertising, will not retain, use or disclose it outside the direct business relationship with the Customer or for any purpose other than the business purposes in this DPA, and will not combine it with other data, except as the law allows. For CCPA purposes Brandsquare is a Service Provider and certifies it understands and will comply with these restrictions.

4. Confidentiality

Brandsquare ensures that people authorized to process the Personal Data are bound by written confidentiality duties and receive suitable training, and that access is limited to those who need it.

5. Security

Brandsquare implements technical and organizational measures appropriate to the risk, as described in Annex II, and may update them provided it does not materially lower the level of security.

6. Subprocessors

6.1 The Customer gives general authorization for Brandsquare to use the Subprocessors in Annex III.

6.2 Brandsquare will give at least 30 days' notice (by email to the workspace Owner, or by posting on its website with a way to subscribe) before adding or replacing a Subprocessor. The Customer may object on reasonable data protection grounds within that period. The parties will work in good faith to resolve it. If they cannot, the Customer may terminate the affected part of the Service and receive a pro rata refund of prepaid fees for it.

6.3 Brandsquare will bind each Subprocessor to data protection terms no less protective than this DPA and remains responsible for the Subprocessor's performance.

7. International transfers

7.1 The Customer agrees that Personal Data may be processed in the United States and in Bangladesh, and in the locations of the Subprocessors in Annex III.

7.2 Where Personal Data from the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, the SCCs are incorporated into this DPA as follows: Module Two (controller to processor) applies where the Customer is a Controller, and Module Three (processor to processor) where the Customer is a Processor; Clause 7 (docking) applies; in Clause 9 Option 2 (general authorization) applies with the notice period in Section 6.2; in Clause 11 the optional language does not apply; in Clause 17 the law is that of Ireland; in Clause 18 the courts of Ireland; Annex I of the SCCs is Annex I here, Annex II of the SCCs is Annex II here, and Annex III of the SCCs is Annex III here. For the UK, the UK Addendum issued by the Information Commissioner (version B1.0) is incorporated, with the options taken from Annex I; for Switzerland, the SCCs apply with references to the GDPR read as references to the Swiss law, and the Swiss Federal Data Protection and Information Commissioner as the competent authority. If the SCCs conflict with this DPA, the SCCs control.

7.3 If a transfer mechanism is invalidated, the parties will agree on an alternative lawful mechanism.

8. Assistance

8.1 Data subject requests. Brandsquare will, taking into account the nature of the processing, help the Customer respond to requests from Data Subjects, through the export, edit and delete tools in the Service. If a Data Subject contacts Brandsquare about Customer Data, Brandsquare will refer them to the Customer, unless the law prevents it.

8.2 Impact assessments and consultations. Brandsquare will give reasonable help with data protection impact assessments and prior consultations with a Supervisory Authority, taking into account the information it has. It may charge reasonable fees for help that goes beyond what the Service provides.

8.3 Government requests. If a public authority asks Brandsquare for Personal Data in Customer Data, Brandsquare will refer the authority to the Customer where possible, tell the Customer unless forbidden, challenge requests it reasonably considers unlawful, and disclose only the minimum needed.

9. Personal Data Breach

Brandsquare will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Data. The notice will describe, as far as known, the nature of the breach, the data and Data Subjects concerned, the likely consequences, the steps taken, and a contact point, and Brandsquare will give updates as they become available. Brandsquare will take reasonable steps to contain and fix it. A notice is not an admission of fault.

10. Return and deletion

10.1 During the term the Customer can export Customer Data. After the Terms end or the workspace is closed, Brandsquare will keep Customer Data for 30 days so the Customer can recover it, then delete it, and delete copies in backups in the normal backup cycle (generally within 35 days after that).

10.2 Brandsquare may keep Personal Data where law requires, such as invoices, ledgers and payroll records that the Customer's workspace is set to retain (by default 10 years, configurable), and protects it under this DPA for as long as it is kept. On request Brandsquare will confirm deletion in writing.

11. Audits and information

11.1 Brandsquare will make available the information necessary to show compliance with this DPA, such as its security documentation, its answers to reasonable security questionnaires, and summaries of third-party assessments and penetration tests it has.

11.2 If that is not enough, or a Supervisory Authority requires it, the Customer may audit Brandsquare's compliance once a year (and after a Personal Data Breach), on at least 30 days' written notice, during business hours, subject to confidentiality, at the Customer's cost, without disrupting operations and without access to other customers' data. The Customer may use an independent auditor bound by confidentiality. Brandsquare may meet audit requests by remote means first.

12. Liability and order of precedence

Each party's liability under this DPA is subject to the limits in the Terms, except where law says otherwise (for example liability to Data Subjects under the GDPR, or under the SCCs). If this DPA conflicts with the Terms about Personal Data, this DPA controls.

13. Term and law

This DPA lasts as long as Brandsquare processes Personal Data for the Customer. It is governed by the law that governs the Terms, except where the SCCs or Data Protection Law require otherwise.

14. Contact

Brandsquare LLC, 30 N Gould St, STE N, Sheridan, WY 82801, United States
Suite B3, Plot 9, Road 4, Sector 16/A, Uttara, Dhaka 1230, Bangladesh
product@bsq.agency, +1 650 250 0350


Annex I: Description of the processing

Parties. Data exporter (Controller): the Customer. Data importer (Processor): Brandsquare LLC. Contact for data protection questions: product@bsq.agency.

Data subjects: the Customer's users (employees, contractors, administrators), its job candidates and applicants (Evavet), its employees and their dependants or contacts where the Customer enters them (Evaple), its customers, leads, prospects and their contacts (Evasel, Evabil, Evacal, Evatok), its suppliers, and anyone else whose data the Customer or its users enter into the Service.

Categories of Personal Data: identification and contact details (name, email, phone, address, job title, company); account and sign-in data; calendar, meeting and message content; documents, notes and files; HR and payroll data that the Customer chooses to enter (such as contract terms, pay, leave, performance records); recruitment data (CVs, application answers, assessment results, interview notes, proctoring information the Customer configures); billing, invoice and ledger data (amounts, tax identifiers, payment status; not full card numbers); technical data (IP address, device and log data); and any other data in content the Customer submits.

Sensitive data: the Service is not designed for special categories of data (such as health, biometric, religion or criminal records). If the Customer chooses to enter any, it is responsible for having a lawful basis and for applying appropriate configuration, and may not enter any in AI features. Applicant and proctoring information may include images, audio or video if the Customer turns those features on.

Nature and purpose: hosting, storing, retrieving, displaying, transmitting, backing up, securing and deleting data, and processing it as the Customer's users direct in the products, in order to provide the Service (including AI features, email and notification delivery, virus scanning, search and support).

Duration and frequency: continuous, for the term of the Terms and the deletion period in Section 10.

Retention: as in Section 10.

Annex II: Technical and organizational measures

  • Access control and tenant isolation: every query on workspace data is scoped to the workspace; shared server-side checks on every action and route; role and permission model; automated tests that try to read another workspace's data; database row-level security where data is reached through the database interface.
  • Authentication: single sign-on across the Suite; passwords stored only as salted one-way hashes; two-factor sign-in mandatory for workspace administrators, billing administrators, support staff with customer-data access and anyone with production access; sign-out of all devices; session expiry; rate limiting on public endpoints.
  • Encryption: TLS in transit; encryption at rest by the database and storage providers.
  • File handling: checks on file type and size, private by default with short-lived signed links, antivirus scanning of uploads.
  • Application security: secure development practices, code review, dependency checks, type checking, automated tests and continuous integration; separate test and live keys; payment webhooks verified and processed idempotently; secrets held in a managed vault and not in code.
  • Logging and monitoring: structured logs with request, user and workspace identifiers, no secrets or document content in logs; error tracking; audit logs of sensitive actions; uptime and scheduled-job monitoring.
  • Availability and recovery: managed database with point-in-time recovery and a separate off-platform backup copy; tested restores.
  • Personnel: confidentiality obligations; access limited to those who need it; production access reviewed.
  • Vendor management: due diligence and written data protection terms with Subprocessors.
  • Incident response: a documented process for detecting, assessing, containing and reporting incidents, including customer notification under Section 9.
  • Data minimization and deletion: retention periods as in Section 10; deletion and export tools in the Service.

Annex III: Subprocessors

As of the date above. The set that applies depends on which products and features the Customer uses.

SubprocessorPurposeLocation of processing
Supabase, Inc.Primary database, private file storage, realtimeUnited States (Ohio, AWS us-east-2)
Vercel Inc.Web hosting and serverless functions for all productsUnited States (Ohio, Cleveland)
Upstash, Inc.Cache and rate limitingUnited States (Virginia, AWS us-east-1)
Stripe, Inc. (and Stripe Payments Europe, Ltd.)Payment processing for plansUnited States, EEA
Zoho Corporation (ZeptoMail)Transactional email deliveryUnited States, EU, India (as routed)
Resend, Inc.Transactional email delivery (Evasel, Evabil)United States
Postmark (ActiveCampaign, LLC)Transactional email delivery (Evabil, where the Customer chooses it)United States
Functional Software, Inc. (Sentry)Error and performance monitoringUnited States
PostHog, Inc.Product analytics (Evavet and Evalog, where enabled)United States or EU (as configured)
Trigger.devBackground job processing (for example Evavet)United States
Sanity ASCareers-site job-opening content (Evavet)EU, United States
Fly.io, Inc.Antivirus scanning of uploads (Evavet)Singapore
DigitalOcean, LLCCode execution sandbox for coding assessments (Evavet)Australia (Sydney)
Cloudflare, Inc.DNS, object storage for backup copiesGlobal network
OpenAI, L.L.C.AI features, through the Evacor gatewayUnited States
Twilio Inc.SMS and voice calls through the Customer's own Twilio account (Evasel, where enabled)United States
Better Stack, Inc.Security alert records (Evavet)United States
Langfuse GmbHAI call tracing: model, token counts, cost and latency, never prompts (Evavet, where enabled)EU
Google LLCCalendar, mail and meeting integrations the Customer connects with its own Google account; push notifications and call connection (STUN) services; maps and places search (Evasel)United States, global network
Expo (650 Industries, Inc.)Push notifications to the mobile app (Evatok)United States
Integrations the Customer connects itself (Microsoft, Zoom, Meta, LinkedIn, Apple iCloud)Calendar, mail, meeting, messaging and posting, only when a workspace connects its own accountAs provided by each service
Brandsquare affiliates and personnelOperations and supportUnited States, Bangladesh

Brandsquare will keep this list current and notify changes under Section 6.2.