Compliance & security
How Evokly protects your data. GDPR compliance is not a burden — it is a competitive advantage.
GDPR compliance
EU hosting
All data is hosted in the European Union with GDPR-compliant providers.
Encryption
Data encrypted in transit (TLS 1.3) and at rest. Passwords hashed with bcrypt.
Data minimisation
We only collect the data strictly needed to run the service.
Right to be forgotten
Complete deletion of data on request. Data export available from your account.
No commercial use
Your photos and videos are never sold, passed to third parties, used for advertising or used to train AI models. They exist only to run the service.
Face matching & biometric data
Explicit consent
Face matching requires an active opt-in from the attendee. No processing without consent.
Secure server-side processing
The selfie is converted on our servers into a mathematical descriptor (a vector that cannot be turned back into an image). Selfies and descriptors are encrypted, never shared with third parties and never used to train models.
Automatic deletion
Facial descriptors are deleted at the end of the event's storage period.
Withdrawing consent
Attendees can withdraw consent at any time, which deletes their descriptors immediately.
Data Processing Agreement (DPA)
For business customers we provide, free of charge, a DPA compliant with article 28 of the GDPR.
Getting the DPA
Send an email to contact@evokly.io and we will send you the DPA ready to sign within 24 hours.
Storage periods
| Plan | Media | Facial data |
|---|---|---|
| Discover (free) | 15 days | 15 days |
| Event (€69) | 6 months | 6 months |
| Pro (€149/month) | 12 months | 12 months |
| Enterprise (on request) | 24 months | Customisable |
Account data is kept for as long as the service is used, plus 3 years. Billing data is kept for 10 years (legal obligation).
Our sub-processors
DPO contact
For any question about data protection:
DPO email:contact@evokly.io
Controller:Prime IT, 55 rue Cartier Bresson, 93500 Pantin, France
Response time: one month at most (GDPR art. 12)
Last updated: July 2026