Aller au contenu principal

Juridique

Aperçu du traitement des données

Cet aperçu explique comment fonctionnent les rôles de protection des données lorsque votre organisation utilise Evolve Simulations, et comment mettre en place un accord de traitement des données (DPA) formel.

Dernière mise à jour le

Ce document fait foi en anglais.

Controller and processor roles

When a customer organisation uses Evolve to train its workforce, the organisation generally acts as the controller of its employees' and participants' personal information — it decides who is trained, why, and how results are used. Evolve Simulationsgenerally acts as the processor, handling that information to provide the platform and following the organisation's instructions under our agreement.

For our own website visitors and for our direct customer-account relationships (such as billing contacts), we act as a controller. Our handling of personal information in that capacity is described in our Privacy Policy.

What we process on a customer's behalf

  • Account, team and role data for the customer's users.
  • Simulation content, transcripts, scores and AI-generated feedback.
  • Learning activity events (xAPI-style) reflecting training progress.
  • Usage and billing records associated with the customer's subscription.

Our commitments as processor

  • Process customer data to provide the service and as instructed under the agreement.
  • Apply the security controls described on our Security & Trust page, including database-enforced tenant isolation and role-based access.
  • Use only the subprocessors listed on our Subprocessors page, under appropriate obligations, and give notice before adding one.
  • Answer data subject access, correction and deletion requests directly, and tell the customer where a request is properly theirs to decide.
  • Tell the customer without undue delay after becoming aware of a personal data breach affecting its data, with what we know at the time, so the customer can meet its own deadlines — the Notifiable Data Breaches scheme, or the GDPR's 72 hours — and assist with the assessment that follows.
  • Make available the information needed to demonstrate these commitments, and support the audits and inspections the customer's agreement provides for — starting with our published control register and evidence bundle.
  • Delete session data on a schedule the customer controls, and return or delete customer data on termination with a record of what was destroyed.

Data subject requests

The platform answers most requests without either of us mediating. An individual can download everything we hold about them from their own account settings, immediately and without asking — including the record of every automated scoring decision made about them, with the model, prompt and rubric versions behind it. Correction and deletion requests are logged against a 30-day deadline imposed by the system rather than typed by a person.

Some questions remain the customer's to answer: whether a person is assigned training, how results are used within the organisation, and how long the organisation keeps them within the limits below. Where that is the case we say so rather than silently forwarding the request on. Details are in our Privacy Policy.

Retention, and what the customer controls

Session data is deleted on a schedule rather than kept indefinitely. Transcripts default to 24 months and sessions, scores and feedback to 24 months; a customer can set each between 1 and 84 months, and can set transcripts shorter than results. A session with an open score challenge is held until the challenge is resolved, so a retention clock cannot destroy the evidence for a dispute.

Billing and usage records, issued certificates, and the audit and security logs are outside that schedule and governed separately — deleting them on a training-data clock would destroy records the customer or the law separately requires.

Export and termination

A customer administrator can export the organisation's data at any time: the organisation and its settings, members, sessions with transcripts, scores and feedback, the audit log, and the automated-decision records.

Termination of a workspace is requested by a customer administrator and executed by Evolve. The customer receives counts of what was destroyed, a confirmation code, and when and by whom — a record they keep. Files uploaded to the platform (knowledge documents and media assets) are not covered by the export or that process and are removed separately on request.

Subprocessor changes

Our subprocessor register is the authoritative list, maintained alongside the platform itself so that what customers read is what the application is held to. Each entry records the date it was last checked against the provider, and the register is reviewed at least every six months.

What we commit to

  • To publish the register, with each provider's processing region, storage region and what it retains — not just its name.
  • To give notice before a new subprocessor begins processing customer data, so a customer has the opportunity to raise an objection under its agreement.
  • To keep the register current, and to date it from its own review records rather than from an unrelated document date.

International transfers

Our primary infrastructure is in Australia, which does not hold an adequacy decision from the European Commission. For a customer whose people are in the European Union or the United Kingdom, the data processing agreement incorporates the Commission's Standard Contractual Clauses in the controller-to-processor module, with the UK Addendum where it applies, and we provide a transfer impact assessment for the Australian processing chain. Each provider's processing and storage region is disclosed on the subprocessor register. Our position under the GDPR and the EU AI Act is set out on our GDPR and the EU AI Act page.

Customer responsibilities

  • Establish a lawful basis for processing employee and participant data, and provide any required notices or consents.
  • Configure roles, assignments and access appropriately within the platform.
  • Use simulation results responsibly, with human review for any significant people decisions.
  • Tell us if results will be used in decisions about individual employees, so the obligations that use attracts under the EU AI Act can be supported.

Getting a DPA

A Data Processing Agreement is available on request and is typically included as part of an enterprise agreement. To request a DPA or discuss specific data-protection requirements, contact privacy@evolvesimulations.com. Where your organisation has a signed agreement with us, that agreement and its DPA terms take precedence over this overview.

Ce document est une version de travail fournie à des fins de transparence. Il ne constitue pas un avis juridique et doit être revu par un conseil qualifié avant de s'y fier. Si quelque chose n'est pas clair, contactez-nous.