Incorporation
This Data Processing Addendum (“DPA”) is part of the Terms of Service between EVRMENT (“Evrment”) and the customer (“Customer”). It applies automatically whenever Evrment processes Customer Personal Data in providing the service. No separate signature is needed for it to take effect, but a countersigned copy is available on request.
Definitions
Capitalized terms not defined here have the meaning given in the Terms.
- Data Protection Laws means all privacy and data protection laws that apply to the processing, which may include the California Consumer Privacy Act as amended (“CCPA”), other US state privacy laws, and, where applicable, the GDPR and UK GDPR.
- Customer Personal Data means personal data within Customer Data that Evrment processes on Customer’s behalf.
- Controller, processor, data subject, personal data, processing, and supervisory authority have the meanings given in the applicable Data Protection Laws. “Business” and “service provider” have the meanings given in the CCPA.
- Subprocessor means a third party Evrment engages to process Customer Personal Data.
- Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
Roles of the parties
For Customer Personal Data, Customer is the controller (and the “business”), and Evrment is the processor (and the “service provider”). Customer decides which data enters the service and why.
Evrment is a separate controller for account data about Customer’s Users, billing data, and website visitor data, as described in our Privacy Policy. This DPA does not cover that data.
Scope and nature of processing
- Subject matter: providing Evrment’s agency operating system, including CRM, calling, messaging, booking, finance, vault, team, and AI features.
- Duration: the term of the Terms, plus the 30-day export period and the backup roll-off period described below.
- Nature of processing: collection, storage, organization, retrieval, transmission, display, analysis, recording, encryption, and deletion, as initiated by Customer and its Users.
- Purpose: to provide, secure, support, and maintain the service for Customer, and as otherwise instructed by Customer in writing.
- Categories of data subjects: Customer’s leads and prospects, clients and policyholders, recruits, team members and downline agents, and people who book appointments or communicate with Customer through the service.
- Categories of personal data: contact details (names, phone numbers, email and postal addresses); demographic information (such as age or date of birth); policy, premium, and commission information; call recordings and call metadata; text and email messages; consent and opt-out records; notes and fact-find information, with any health-related details that Customer records kept to the fields designated for them [DRAFT — counsel review required]; and carrier portal credentials stored by Customer.
- Sensitive data: [DRAFT — counsel review required] Customer may process the sensitive insurance information its business genuinely requires in the fields and workflows Evrment designates for it. Designated protected fields are in development; until they are available, Customer must not enter sensitive identifiers, financial account information or detailed health information into general-purpose notes, team messages, SMS, email or other unstructured fields. Payment card numbers are not processed by Evrment. Evrment is not a HIPAA business associate unless separately agreed in writing, and Customer should not rely on Evrment for HIPAA purposes until HIPAA-regulated workflow support, which is required before general availability, is available.
Our obligations
Instructions
Evrment will process Customer Personal Data only on Customer’s documented instructions. The Terms, this DPA, and Customer’s use and configuration of the service are Customer’s complete instructions. If we believe an instruction violates Data Protection Laws, we will tell Customer, unless the law prohibits it.
Confidentiality
Evrment will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and access it only as needed.
Security
Evrment will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, as summarized in Security measures.
Data subject requests
If Evrment receives a request from a data subject about Customer Personal Data, we will direct the person to Customer and will not respond directly except to confirm the request was passed on. Taking into account the nature of the processing, Evrment will provide reasonable assistance so Customer can respond, largely through features in the service such as search, export, editing, deletion, and do-not-call suppression.
Security Incidents
Evrment will notify Customer of a Security Incident without undue delay, and in any case within [72 hours, for counsel review] of becoming aware of it. The notice will describe, as far as then known, the nature of the incident, the data and data subjects likely affected, likely consequences, and the steps taken or proposed. We will update Customer as more is learned and reasonably assist with any notifications Customer must make. Notice is not an admission of fault.
Other assistance
Evrment will provide reasonable information to help Customer carry out data protection impact assessments and consult supervisory authorities where Data Protection Laws require it.
Customer obligations
Customer is responsible for having a lawful basis and all required notices and consents to collect Customer Personal Data and have Evrment process it. That includes consent for calls, texts, and recordings, and compliance with do-not-call and telemarketing laws, as described in the Acceptable Use Policy. Customer’s instructions must comply with Data Protection Laws.
Subprocessors
Customer gives general authorization for Evrment to engage Subprocessors. Evrment currently uses Subprocessors in these categories:
- cloud hosting and database;
- authentication;
- telephony and messaging carriers;
- email delivery;
- payment processing;
- AI model providers;
- error monitoring.
Evrment will impose data protection terms on each Subprocessor that are at least as protective as this DPA, and remains responsible for its Subprocessors’ performance. We do not permit our AI model providers to train on Customer Personal Data.
A current list of named Subprocessors is available on request at support@evrment.com. Evrment will give at least 30 days’ notice before adding or replacing a Subprocessor. Customer may object on reasonable data protection grounds within that period. The parties will then work in good faith to find a solution. If none is found, Customer may terminate the affected part of the service and receive a refund of prepaid fees for the unused term.
CCPA service provider terms
When Evrment processes Customer Personal Data as a service provider under the CCPA, Evrment will not:
- sell or share Customer Personal Data, including for cross-context behavioral advertising;
- retain, use, or disclose Customer Personal Data for any purpose other than the business purposes of providing the service under the Terms, or as otherwise permitted for service providers under the CCPA;
- retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer;
- combine Customer Personal Data with personal data received from other sources or collected from its own interactions with consumers, except as the CCPA permits.
Evrment will comply with applicable CCPA obligations, provide the same level of privacy protection the CCPA requires, and notify Customer if it can no longer meet these obligations. Customer may take reasonable steps to stop and remediate unauthorized use. Evrment certifies that it understands these restrictions.
International transfers
Evrment and its Subprocessors primarily process data in the United States. Where Data Protection Laws require a transfer mechanism for personal data leaving the EEA, UK, or Switzerland, the parties agree that the applicable Standard Contractual Clauses (and the UK addendum where relevant) are incorporated by reference, with Customer as data exporter and Evrment as data importer.
Security measures
Evrment maintains the following measures. Items marked as planned are not yet in place and are described so Customer has an accurate picture.
- Encryption in transit: connections to the service use TLS.
- Encryption at rest: databases and backups encrypted at rest by our hosting provider.
- Credential vault: carrier portal credentials are masked in the interface and every reveal is recorded in the audit log. Stored credentials are protected with envelope encryption.
- Audit logging: actions in the workspace are recorded with actor, time, and change detail, and Customer administrators can review and export them.
- Access control: individual accounts with role-based access for Users; and (planned for hosted launch) least-privilege access for Evrment personnel, limited to what is needed for support and operations.
- Tenant isolation (in progress): server-side checks that restrict each request to the Customer’s own workspace data.
- Backups (planned for hosted launch): regular, encrypted backups to support recovery.
- Communications safeguards: do-not-call suppression, quiet-hours enforcement for automation, and call recording that is off by default.
- Independent certification (planned): Evrment does not currently hold a SOC 2 report, ISO 27001 certification, or similar attestation. An independent security audit is planned.
Evrment may update these measures over time, provided the overall level of protection is not materially reduced. More detail is on our security page.
Audits
On Customer’s reasonable written request, no more than once a year (or after a Security Incident, or when a supervisory authority requires it), Evrment will provide documentation reasonably necessary to demonstrate compliance with this DPA, such as security questionnaire responses, policy summaries, and, once available, third-party audit reports.
If that documentation is not enough to meet a requirement of Data Protection Laws, the parties will agree in good faith on further reasonable steps, including scope, timing, confidentiality, and cost, before any on-site or third-party audit.
Return and deletion
When the Terms end, Customer’s workspace remains available for export for 30 days. After that period, Evrment will delete Customer Personal Data from the live service. Our intended practice is that remaining copies in backups roll off within a further 35 days. Evrment may keep data only where the law requires, and will continue to protect it under this DPA for as long as it is kept.
Customer may also delete individual records at any time using the service.
Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms. Nothing in this DPA limits either party’s liability where the law does not allow it to be limited.
Order of precedence
If documents conflict, this order applies, to the extent of the conflict:
- Standard Contractual Clauses, where they apply;
- this DPA, for matters relating to Customer Personal Data;
- the Terms of Service and any order form.
Requesting a signed copy
This DPA applies without signature. If your agency needs a countersigned copy for its records, or a current list of named Subprocessors, email support@evrment.com with your agency’s legal name, address, and the name and title of the signer.