Skip to main content

Trust

GDPR and the EU AI Act

Evolve Simulations is built and hosted in Australia. This page sets out how the platform stands against the EU General Data Protection Regulation and the EU Artificial Intelligence Act: what is in place today, and what we put in place for a customer whose people are in the European Union.

Last updated

Where we stand

Evolve Simulations is an Australian company. Our privacy and AI controls apply to every customer, and were designed to meet the stricter of the Australian and European requirements. The consent layer on this website, for example, asks before any analytics loads for every visitor, not only for visitors in the European Union.

This page is our own assessment of the platform against the General Data Protection Regulation (GDPR) and the EU Artificial Intelligence Act. It is not legal advice and it is not a certification. We will complete a GDPR or AI Act questionnaire on request, and can take a privacy officer, works council or procurement team through any control in detail.

GDPR: roles

An organisation that uses Evolve to train its people is the controller of its employees' and participants' personal data. It decides who is trained, on what, and how results are used. Evolve is the processor. We handle that data to provide the platform, on the organisation's instructions, under a data processing agreement containing the terms Article 28 requires. Our Data Processing page sets out those commitments.

We are a controller only for visitors to this website and for our direct customer relationships, such as billing contacts. Our Privacy Policy covers that processing.

GDPR: what is in place

Each of the following operates in the product today, for every customer.

  • Transparency (Articles 13 and 14). A collection notice is shown before a person's first simulation, on both the signed-in and the account-less entry points. The notice is versioned, and the version each participant saw is recorded against their session.
  • Access, correction, erasure and portability (Articles 15 to 17 and 20). A person can download everything held about them from their account settings at any time, including the record of every automated scoring decision made about them. Correction and deletion requests are logged against a 30-day deadline set by the system, within the one month the GDPR allows.
  • Automated decision-making (Article 22). Our Terms prohibit using a score as the sole basis for an employment decision. An administrator can override or void any score with a reason, a participant can challenge any result, and both routes are built into the product. Every decision is stored with the model, prompt version and rubric version that produced it, and that record is part of the person's own export.
  • Data minimisation (Article 5(1)(c)). The AI assessor receives the transcript of the session being scored and the rubric for that simulation, and nothing about the person. There is no camera. A participant's speech is transcribed in real time and the audio is not kept.
  • Storage limitation (Article 5(1)(e)). Transcripts and results are deleted on a schedule: 24 months by default, adjustable by each organisation between one and 84 months. A session is held back only while a challenge to its score is open.
  • Security (Article 32). Tenant isolation enforced in the database, role-based permissions in the application, a second authentication factor that an organisation can require of its administrators, encryption in transit and at rest, and dependency and secret scanning on every change.
  • Records and sub-processors (Articles 28(2) and 30). Every provider that supports the platform is published with the region in which it processes and stores data and what it retains. We give notice before adding one so that a customer can object.
  • Cookies. No optional cookie loads until a visitor chooses. The two choices carry equal weight, and the choice can be changed at any time from the Cookie Policy.

Where data is processed

The database holding accounts, simulations, transcripts and results is in Sydney. AI inference, including persona responses, scoring, speech-to-text and text-to-speech, runs in Microsoft Azure's Australia East region on a regional deployment. Error monitoring and product analytics are hosted in the European Union. Every provider and its regions are listed on our Subprocessors page. An organisation can switch off the one optional feature whose provider is outside both Australia and the EU.

Australia does not hold an adequacy decision from the European Commission. A transfer of personal data from the EU to our Australian infrastructure therefore relies on the appropriate safeguards in Article 46, set out below.

For a customer with people in the EU

Our customers today are in Australia. For an organisation with people in the European Union or the United Kingdom, the following are part of onboarding:

  • The European Commission's Standard Contractual Clauses, controller-to-processor module, incorporated into that customer's data processing agreement, with the UK Addendum where the customer's people are in the United Kingdom.
  • A transfer impact assessment for the Australian processing chain, prepared and shared with the customer.
  • A representative in the European Union under Article 27, appointed and named in our Privacy Policy.
  • The material a customer needs for its own data protection impact assessment under Article 35: a description of the processing, the sub-processor register, and the record kept of each automated decision.
  • Notice of a personal data breach affecting the customer's data without undue delay after we become aware of it, with what we know at the time, so that the customer can meet its 72-hour obligation under Article 33.

If you are in the EU or the UK

The access, export, correction and deletion rights described above apply to you on the same terms. You also have the right to object to or restrict processing, the right not to be subject to a decision based solely on automated processing that significantly affects you, and the right to lodge a complaint with the supervisory authority in the country where you live or work. The Article 22 controls above are how the second of those is met. Where your employer or training provider manages your account, some questions are for that organisation to answer, and we will tell you when that is the case.

The AI Act: what applies today

Transparency: Article 50, in force since 2 August 2026

A person who converses with an AI system must be told so. Before a participant speaks in a simulation, on both the signed-in and the account-less entry points, a disclosure states that they will be speaking with an AI character that is fictional and represents no real person, that the conversation is recorded and assessed automatically, and that a person can review any score. A badge remains on screen throughout, and written feedback is labelled as AI-generated on every result. The version of the disclosure each participant saw is recorded. The disclosure text is reproduced on our AI transparency page.

Prohibited practices: Article 5, in force since 2 February 2025

The Act prohibits inferring the emotions of people in the workplace from their biometric data. The platform does not infer a participant's emotions. There is no camera. A participant's voice is used for transcription and for nothing else, and the audio is not retained. The engine that animates the character's expression reads the character's own line of dialogue, not the participant.

How we classify the platform

Annex III of the AI Act classes AI used to monitor or evaluate the performance of workers as high-risk. The platform scores practice conversations and shows the score to the participant and, where an organisation chooses, to its managers, so the question applies.

The platform's intended purpose is practice. It is not supplied to evaluate people's performance in their jobs, our Terms prohibit using a score as the sole basis for any employment decision, and every result states that limitation. On that intended purpose and those terms, our assessment is that the platform as we supply it sits outside the employment category in Annex III. Classification also depends on use. An organisation that uses results in decisions about individuals takes on a deployer's obligations for that use, and we ask to be told so that we can support it.

What is built to the high-risk standard

The obligations for high-risk systems in Annex III apply from 2 December 2027. We make no claim of conformity with them. Most of what they require of a provider is already in place, because it is how a system that scores people should be built:

  • Record-keeping (Article 12). Every scoring decision is stored with the model deployment, prompt version and rubric version that produced it, and with whether the score came from the assessor, a fallback, or a policy that had scoring switched off.
  • Transparency to the deploying organisation (Article 13). What the assessor decides, what it is given, where it runs and what it is not are published on our AI transparency page and stated on every result.
  • Human oversight (Article 14). Override with a reason, a participant challenge route, per-organisation switches that can turn scoring off, and human review of any consequential decision assigned to the customer in our Terms.
  • Data governance (Article 10). The assessor's only inputs are the transcript of the session being scored and the rubric written for that simulation.
  • Technical documentation (Articles 11 and 17). A control register maintained alongside the code and checked by test, stating each control's status and the artefact that evidences it. Available to customers on request.
  • Incident handling. An incident register in which AI incidents are recorded as their own category.

Questions and requests

For a data processing agreement, the Standard Contractual Clauses, a transfer impact assessment, or a GDPR or AI Act questionnaire, contact privacy@evolvesimulations.com. For a security questionnaire, contact security@evolvesimulations.com. We acknowledge every request within five business days.

Keeping this current

This page is reviewed as each stage of the AI Act applies and whenever the platform changes in a way that affects it. The date above is the last substantive revision. Where your organisation has a signed agreement with us, that agreement and its data processing terms take precedence over this page.

This document is a product-ready draft provided for transparency. It is not legal advice and should be reviewed by qualified legal counsel before being relied upon. If anything here is unclear, contact us and we'll help.