मुख्य सामग्री पर जाएँ

कानूनी

गोपनीयता नीति

यह गोपनीयता नीति बताती है कि जब आप हमारी वेबसाइट देखते हैं, जब आपका संगठन हमारा कॉर्पोरेट ट्रेनिंग प्लेटफ़ॉर्म उपयोग करता है, और जब आप AI रोलप्ले सिमुलेशन में भाग लेते हैं, तब Evolve Simulations व्यक्तिगत जानकारी कैसे संभालता है।

आखिरी अपडेट

यह दस्तावेज़ अंग्रेज़ी में आधिकारिक है।

1. Who we are

Evolve Simulations(“Evolve”, “we”, “us”) provides an AI-powered corporate training platform where employees practise workplace conversations with realistic AI personas and receive scored feedback. We serve organisations internationally and are headquartered in Australia. We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and apply equivalent standards for customers and participants in other jurisdictions.

Evolve sells to organisations for the training of their workforce. In most cases your employer or training provider is the organisation that decides how the platform is used. Where we handle personal information on behalf of a customer organisation, that organisation is generally the controller of that information and we act as its processor. See our Data Processing overview for how these roles work.

2. Information we collect

Account and organisation data

When an account is created or you are invited to a workspace, we collect names, work email addresses, role and team membership, and organisation details. Invitations are sent by email on behalf of your organisation.

Simulation and learning data

When you take part in a simulation we process the spoken and typed input you provide, transcripts of the conversation, the AI persona's responses, and the scores and AI-generated feedback produced for each attempt. We also record learning events (such as starting, completing or being assigned a simulation) in an xAPI-style activity log so your organisation can understand training progress.

Voice and audio

Simulations support spoken conversation. Audio is processed in real time to produce a text transcript (speech-to-text) and to generate the persona's voice (text-to-speech). We use this audio to deliver the conversation and create the transcript and feedback for that session. We do not keep the audio itself; what is kept is the transcript it produced.

Records of the automated decision

Where a simulation is scored, we keep a record of how that score was produced alongside the score: which AI model deployment and version generated it, which version of the scoring instructions and rubric were used, and whether the score came from the AI assessor, from a fallback, or was not generated because your organisation had switched scoring off. This exists so a result can be explained and, if you disagree with it, examined. See section 4.

Security records

To keep accounts safe we record security events: sign-ins and sign-outs, the IP address and browser used, whether a second authentication factor was presented, and refusals where someone was denied access to something. We also record privileged administrative actions in an audit log. These records exist to detect and investigate misuse, and they are kept separately from — and for longer than — your training data. See section 7.

Notice records

When you take part in a simulation we record which version of the collection notice and the AI disclosure you were shown, and when. This is how we can later demonstrate what a participant was told, rather than asserting it.

Creator and Sim Library data

If you build simulations, deliver them to other people, or submit them to the Sim Library, we collect the content you create and the information needed to deliver, moderate and publish it.

Billing data

Subscription and usage billing is handled through Stripe. We receive billing contact details, subscription, invoice and usage records. Payment card details are entered directly into Stripe and are not stored by Evolve.

Technical and diagnostic data

We collect standard technical data such as device and browser information, IP address, and usage metrics, and we use privacy-aware error monitoring (with a scrubber that removes message content and credentials) to keep the platform reliable and secure. Analytics are loaded only where you have consented, and never on the simulation runner — see our Cookie Policy.

3. How we use information

  • To provide the platform: running simulations, producing transcripts, scoring and AI-generated feedback, and recording learning progress.
  • To manage accounts, invitations, teams and role-based access.
  • To operate the Sim Library and creator delivery, including moderating submitted content.
  • To process subscriptions, usage and billing, and to apply quotas and usage controls.
  • To provide support, diagnose issues and keep the service secure and reliable.
  • To detect, investigate and respond to security incidents and misuse of accounts.
  • To communicate with you about your account, the service and important changes.
  • To meet legal, regulatory and contractual obligations.

We do not use your transcripts, scores or feedback to train AI models. The provider running the AI that powers the personas, the scoring and the speech does not use this data to train its models or OpenAI's — see our Subprocessors page, which records what each provider retains.

Where we act as a processor for a customer organisation, we use that organisation's data only to provide the service and as instructed by the organisation under our agreement with it.

4. Automated decisions: how scoring works

This section describes a decision made about you by software rather than by a person, and is written to be read in full rather than summarised. A fuller version, including what an organisation can switch off, is on our AI transparency page.

What is decided, and on what

When you complete a simulation that has scoring enabled, an AI assessor produces a score against the rubric attached to that simulation, together with written feedback. The inputs are the transcript of that session and that rubric. It does not read your other sessions, your profile, your team, or anything your organisation holds about you outside the session being scored.

What it is not

The score is a practice aid. It is not a professional, clinical, psychological or employment assessment, it is not a measure of your competence at your job, and it can be wrong — AI output can be inaccurate, inconsistent between attempts, or miss context a person would catch. It must not be used on its own for hiring, promotion, performance management, discipline or termination. Your organisation, not Evolve, decides how results are used internally, and is responsible for that use.

A person can override it

An administrator in your organisation can override a score with a different one, or void it entirely, with a reason. An override supersedes the AI score wherever the result is shown, and both the original and the override are kept so the change is visible rather than silent.

You can challenge a result

On your own result you can raise a challenge, stating why you think the score is wrong. It goes to the administrators who can act on it. While a challenge is open, the session and its transcript are held back from automatic deletion, so the evidence for the dispute is not destroyed by a retention clock while the dispute is unresolved.

You can see the record

The data export described in section 9 includes an automated-decisions section: every score run held about you, with the model, prompt version, rubric version and whether the score came from the AI assessor, a fallback or a disabled policy. You do not have to ask us for it or wait for it.

5. Disclosure and subprocessors

We do not sell personal information. We share information with trusted service providers who help us run the platform — including hosting, database, AI and speech, payment, email and error-monitoring providers. These providers are listed, with their purpose, the regions they process and store data in, and what each of them retains, on our Subprocessors page. We may also disclose information where required by law or to protect our rights and the safety of users.

Simulation creators

Some simulations on Evolve are made by independent creators, such as a trainer or consultant delivering practice to their clients. What a creator learns about you depends entirely on where you bought or ran the simulation, and never on the fact that they wrote it:

  • You bought or ran it on the creator’s own website (an embedded simulation). You are dealing with that creator directly, so we disclose your email address and your purchase to them, and they may contact you about it. The checkout screen names the creator before you pay.
  • You bought it in the Evolve marketplace — including through a creator’s referral link. You are our customer, not theirs. The creator is told that a sale happened and how much they earned, and is not told who you are. We do not give them your name, email address or account.
  • You ran a simulation through a workshop or delivery link. The person or organisation who created that link receives your details and your score, because they are running the session. The join screen names them before you enter anything.
  • Your results are never disclosed to a creator on the strength of authorship. Someone who wrote or sold a simulation gets no access to how you or your organisation performed on it.

6. Where your information is processed

Training data is held and processed in Australia. This is a specific arrangement rather than a preference:

  • The database holding accounts, simulations, transcripts, scores and usage records is in Sydney (ap-southeast-2).
  • AI persona responses, scoring, speech-to-text, text-to-speech and document extraction run in Microsoft Azure's Australia East region, on a regional deployment rather than a global one, so inference is not routed to other geographies.
  • The application's server-side compute is configured to run in Sydney. Traffic reaches that compute through the nearest network point of presence, which may be outside Australia; that is transit rather than processing.

Some of the services that support the platform — billing, transactional email, error monitoring, website analytics and certain optional features — operate outside Australia. Each one is named on our Subprocessors page, together with the regions in which it processes and stores data, what categories of data it handles and what it retains. Where personal information is processed overseas, we take reasonable steps to ensure it is handled consistently with the APPs and the protections in this policy.

For people in the European Union or the United Kingdom, a transfer of personal data to our Australian infrastructure is made under the European Commission's Standard Contractual Clauses incorporated into your organisation's data processing agreement, as described in section 9 and on our GDPR and the EU AI Act page.

An organisation can also switch off individual AI features for its own workspace, including the optional premium voices, where that better suits its data-handling requirements.

7. How long we keep it

Training data is deleted on a schedule. It is not kept indefinitely and it does not depend on somebody remembering to ask.

  • Transcripts — the words you actually said — are deleted 24 months after the session, by default.
  • Sessions, scores and feedback are deleted 24 months after the session, by default.
  • An organisation can set either period shorter or longer, between 1 and 84 months, and can set transcripts shorter than results — for example, conversations gone after 6 months with results kept for 24.
  • A session with an open score challenge is held rather than deleted, until the challenge is resolved.

Some records deliberately outlive that schedule, because deleting them would destroy something else: billing and usage records, which the business is separately required to keep; certificates you have earned; and the audit and security logs described in section 2, which are the evidence that the platform was operated properly and are governed by their own policy rather than by the training-data clock.

Account and organisation records are not on this clock — they end with the account, which is section 9. Separately, our AI provider retains prompts and responses for up to 30 days as described in section 6, and deleted data may persist for a limited period in encrypted backups until it is overwritten on the backup cycle.

8. Security

Access to data is enforced in the database itself, so an organisation and team can only reach their own records, and again in the application through role-based permissions. Sign-in supports a second authentication factor, which a customer can make mandatory for its administrators. Privileged actions are audited, security events are logged, and data is encrypted in transit and at rest. Our controls are set out on our Security & Trust page. No system can be guaranteed perfectly secure, but we work to protect your information and to respond quickly to any incident.

9. Your privacy rights

Access — immediate, and self-service

You can download everything we hold about you from your account settings at any time, without asking us and without waiting. The file includes your profile, your memberships, your sessions and transcripts, your scores and feedback, your consent records and the automated-decision records described in section 4. We record the fact that an export was taken, because an export is a disclosure of personal information.

Correction

You can correct your own profile directly. For anything else, you can raise a correction request from your account settings and we will action it.

Deletion

You can request deletion of your account from your account settings. Before you do, the platform shows you anything that stands in the way — for example a published Sim Library entry that other people hold entitlements to, a payout still owed to you, or being the only administrator of an organisation, which would leave that organisation with nobody able to manage it. These are shown up front so you are not told “no” after the fact.

Our deadline

Correction and deletion requests are logged with a 30-day deadline set by the system, not typed by a person. Raising the same kind of request twice returns your existing request rather than creating a second one.

Where your organisation holds the decision

If your employer or training provider manages your account, some questions are properly theirs — whether you are assigned training at all, how your results are used, and how long the organisation chooses to keep them within the limits above. We will tell you when that is the case rather than simply forwarding you on, and your access and export rights above work regardless.

If you are in the European Union or the United Kingdom

The GDPR asks us to state the legal basis for each kind of processing. Where you hold an account with us directly, we process your information to perform our contract with you. We process information about website visitors, and security and error-monitoring data across the platform, on the basis of our legitimate interest in operating a reliable and secure service. Where your employer or training provider has put you through a simulation, the training data is processed on that organisation's basis as controller. We do not rely on your consent for it. The only processing that rests on your consent is optional website analytics, which does not load before you choose.

The rights above work for you in the same way and on the same deadlines. You also have the right to object to or restrict processing, the right not to be subject to a decision based solely on automated processing that significantly affects you — section 4 describes the controls that make that so — and the right to lodge a complaint with the supervisory authority in the country where you live or work. Transfers of your data to Australia are made under the Standard Contractual Clauses described in section 6. Where Article 27 of the GDPR requires it, we appoint a representative in the European Union and publish their details here.

10. Contact us

For privacy questions, or to make a complaint, contact our privacy team at privacy@evolvesimulations.com. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC). If you are in the European Union or the United Kingdom, you may also lodge a complaint with your local supervisory authority.

यह दस्तावेज़ पारदर्शिता के लिए दिया गया एक प्रोडक्ट-रेडी मसौदा है। यह कानूनी सलाह नहीं है और इस पर निर्भर होने से पहले योग्य कानूनी सलाहकार से इसकी समीक्षा करानी चाहिए। अगर यहाँ कुछ अस्पष्ट लगे, तो हमसे संपर्क करें और हम मदद करेंगे।