Skip to main content
EvoklyEvokly
Compliance

Compliance & security

How Evokly protects your data. GDPR compliance is not a burden — it is a competitive advantage.

GDPR compliance

EU hosting

All data is hosted in the European Union with GDPR-compliant providers.

Encryption

Data encrypted in transit (TLS 1.3) and at rest. Passwords hashed with bcrypt.

Data minimisation

We only collect the data strictly needed to run the service.

Right to be forgotten

Complete deletion of data on request. Data export available from your account.

No commercial use

Your photos and videos are never sold, passed to third parties, used for advertising or used to train AI models. They exist only to run the service.

Face matching & biometric data

Explicit consent

Face matching requires an active opt-in from the attendee. No processing without consent.

Secure server-side processing

The selfie is converted on our servers into a mathematical descriptor (a vector that cannot be turned back into an image). Selfies and descriptors are encrypted, never shared with third parties and never used to train models.

Automatic deletion

Facial descriptors are deleted at the end of the event's storage period.

Withdrawing consent

Attendees can withdraw consent at any time, which deletes their descriptors immediately.

Data Processing Agreement (DPA)

For business customers we provide, free of charge, a DPA compliant with article 28 of the GDPR.

Obligations of the controller and the processor
Technical and organisational security measures
Conditions for sub-processing
Assistance with data subject requests
Data breach notification within 72 hours
Audit and compliance checks

Getting the DPA

Send an email to contact@evokly.io and we will send you the DPA ready to sign within 24 hours.

Storage periods

PlanMediaFacial data
Discover (free)15 days15 days
Event (€69)6 months6 months
Pro (€149/month)12 months12 months
Enterprise (on request)24 monthsCustomisable

Account data is kept for as long as the service is used, plus 3 years. Billing data is kept for 10 years (legal obligation).

Our sub-processors

SupabaseDatabase & auth (EU)
Cloudflare R2Media storage (EU)
StripePayments (EU/US, DPF)
VercelApplication hosting (EU region)

DPO contact

For any question about data protection:

DPO email:contact@evokly.io

Controller:Prime IT, 55 rue Cartier Bresson, 93500 Pantin, France

Response time: one month at most (GDPR art. 12)

Last updated: July 2026