Skip to content

Evacor Suite Privacy Notice

Last updated: October 6, 2026

This notice explains how Brandsquare LLC ("Brandsquare", "we", "us") handles personal information in the Evacor Suite (the console at evacor.app, accounts.evacor.io, evacor.io and the ten products: Evapad, Evalog, Evadoc, Evacal, Evatok, Evasel, Evaple, Evavet, Evabil and Evacas).

Who we are: Brandsquare LLC, a Wyoming limited liability company, 30 N Gould St, STE N, Sheridan, WY 82801, United States, with an operating office at Suite B3, Plot 9, Road 4, Sector 16/A, Uttara, Dhaka 1230, Bangladesh. Contact for privacy: product@bsq.agency, +1 650 250 0350.

1. Two roles, and why they matter

  • Account data: we are the controller. This is the information about you that we need to give you an account, bill you, secure the Service and talk to you. This notice covers it in full.
  • Workspace content: we are the processor. When a company or person (a "workspace") puts data into the Suite, such as employee records, job candidates, customers, invoices, notes or messages, the workspace decides why and how it is used. We process it only on the workspace's instructions, under our Data Processing Agreement. If your data is in someone else's workspace (for example you applied for a job through Evavet, you are an employee in Evaple, or you are a customer using a portal), that workspace is the controller. Ask them first about your data. We will help them answer you.

2. What we collect

Information you give us: name, email address, password (stored only as a one-way hash), phone number if you add one, company name and workspace details, role and permissions, profile photo, billing details, and messages you send us.

Information from your use: sign-in records and session information (session length is up to 15 days), device, browser and IP address, pages and features used, settings, plan and seat counts, usage of AI features (counts and costs, not model training), support requests, and the security and audit events of your workspace (for example sign-ins and permission changes).

Information from payments: our payment provider (Stripe) collects card and bank details directly. We keep the plan, amounts, invoices, tax details and the last four digits of a card, and a payment token. We do not store full card numbers.

Workspace content that you or your users enter into the products, which can include personal information about other people. We do not seek sensitive categories of data, and ask you not to enter them unless the product is meant for it and the law allows. Evavet may process candidate details, documents and assessment or proctoring information that a workspace chooses to collect.

Cookies: see Section 7.

We do not knowingly collect data from children under 16 (or the higher age in your country). Contact us if you believe a child gave us data and we will delete it.

3. How we use it, and our legal bases

PurposeExamplesLegal basis (GDPR/UK GDPR)
Provide the ServiceCreate your account, sign you in across products, run your workspace, store your content, send service emailsContract
Billing and taxCharge plans and seats, send invoices, keep tax recordsContract; legal obligation
Security and abuse preventionRate limiting, virus scanning of uploads, fraud and attack detection, audit logsLegitimate interests; legal obligation
SupportAnswer questions, fix problemsContract; legitimate interests
Improve and developUnderstand usage, fix errors, measure performance (de-identified or aggregated where possible)Legitimate interests
Product and security noticesChanges to the Service, to the Terms, to this noticeContract; legitimate interests
MarketingProduct news by email, only if you opt in or where the law allows; you can unsubscribe at any timeConsent or legitimate interests
LegalRespond to lawful requests, establish or defend legal claimsLegal obligation; legitimate interests

We do not sell your personal information and do not share it for cross-context advertising. We do not use your content to train AI models, and we do not make decisions about you that have legal or similarly significant effects by automated means alone.

4. AI features

Where a workspace uses AI features (for example on the Pro plan), the text and data it chooses to send are passed through our own gateway to OpenAI to produce a result. The gateway applies the workspace's plan limits and records usage and cost per product. Our provider terms do not allow them to use API inputs to train their models by default. Please do not enter personal data into AI features unless you are allowed to and need to. AI output can be wrong, so check it.

5. Who we share it with

  • Service providers (subprocessors) that help us run the Suite, under written contracts that limit their use of the data. The current list is in Annex III of our Data Processing Agreement and includes our database and file-storage host (Supabase), web hosting (Vercel), caching and rate limiting (Upstash), payments (Stripe), email delivery (ZeptoMail and Resend), error monitoring (Sentry), product analytics (PostHog), background jobs (Trigger.dev), content management (Sanity), antivirus and sandbox hosting (Fly.io), DNS and backup storage (Cloudflare), and OpenAI for AI features. We will update the list before adding a new one.
  • Your workspace. Owners and administrators of a workspace can see the account data of its members and the workspace's content and audit logs.
  • Legal and safety. When required by law or valid legal process, or to protect rights, safety and security. We tell you first where allowed.
  • Corporate changes. In a merger, financing or sale of our business, with protection no less than this notice.
  • With your direction. For example when you connect a third-party tool.

6. Where your data is processed and transfers

We host primary data in the United States (Ohio) and our team operates from the United States and Bangladesh. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is transferred to countries that may not offer the same protection. We protect transfers with the European Commission's Standard Contractual Clauses (and the UK addendum where needed) in our agreements with customers and subprocessors, and apply technical and organizational safeguards (Annex II of the Data Processing Agreement).

7. Cookies and similar technologies

  • Essential cookies keep you signed in across products, protect against attacks and remember settings. They are needed for the Service and do not need consent.
  • Analytics. Where enabled, some products (currently Evavet and Evalog) use PostHog to understand usage; the marketing site does not. Session replay is off for financial, HR and private content. Where the law requires consent, we ask first. You can block cookies in your browser, but the Service may not work.
  • We do not use advertising cookies.

8. How long we keep data

  • Account data: while your account is active, and then for up to 30 days after closure, except records we must keep.
  • Workspace content: while the workspace is active, and for 30 days after it is closed or cancelled so it can be recovered, then deleted. Backups are overwritten in their normal cycle.
  • Financial records (invoices, ledgers, payroll and related tax records): kept, anonymised where the law allows, for the legal retention period, by default 10 years, and configurable per workspace within the law.
  • Security and audit logs: for a limited period, generally up to 12 months, longer where needed to investigate abuse or meet legal duties.
  • Legal holds: longer where needed to deal with a dispute or a legal duty.

You can export your data and delete your account in the console. When you delete your account, we anonymise your own records in each product, and keep records that a workspace or the law requires, in anonymised form.

9. Your rights

Depending on where you live, you may have the right to: know what we hold about you and get a copy; correct it; delete it; restrict or object to some processing; receive it in a portable form; withdraw consent at any time; and complain to a data protection authority. California residents can also know what we collect, delete, correct, and opt out of the sale or sharing of personal information (we do neither), and will not be treated worse for using these rights. You can use an authorized agent.

To use a right, email product@bsq.agency or use the controls in the console. We may need to verify who you are. We reply within one month (45 days in California), and tell you if we need more time. If your data is in someone else's workspace, we will refer your request to them. You may complain to your local authority (in the EU, the authority in your country; in the UK, the ICO). We would appreciate the chance to fix a concern first.

10. Security

We use encryption in transit, access controls and tenant isolation between workspaces, two-factor sign-in for privileged roles, rate limiting, virus scanning of uploads, logging and backups with point-in-time recovery. No system is perfectly secure. We will tell affected customers and, where required, authorities, without undue delay if a breach affects personal data. Report a security problem to product@bsq.agency.

11. Changes

We may update this notice. For material changes we will notify you by email or in the console before they take effect, and change the date above.

12. Contact

Brandsquare LLC, 30 N Gould St, STE N, Sheridan, WY 82801, United States
Suite B3, Plot 9, Road 4, Sector 16/A, Uttara, Dhaka 1230, Bangladesh
Email: product@bsq.agency. Phone: +1 650 250 0350.

If we are required to appoint a representative in the EU or the UK, we will name them here.