Evidence privacy policy
This policy explains what Syndicate ApS does with personal data about the people who use Evidence: account holders, the colleagues they invite, and people who apply for early access. Syndicate ApS is the data controller for everything described here.
Who we are
Syndicate ApS, CVR 39592452, Heidesvej 3 A, 8270 Højbjerg, Denmark, trading as Evidence.
For anything in this policy, including any of the rights below, write to mri@syndicate.dk.
We have not appointed a Data Protection Officer; at our size Article 37 does not require one. We are established in the EU, so no Article 27 representative is needed.
What this policy does not cover
If you took part in a research interview run through Evidence, this is not the policy that applies to you. In that case the organisation that invited you is the data controller, and their notice is shown to you before the interview starts. Syndicate ApS only processes that data on their instructions.
The same goes for documents, transcripts and research content that a customer uploads. We process it for them, under our agreement with them; they decide what it is for and how long it is kept.
Your account
What we hold: Your email address, your name, your profile picture if you set one, your password (stored only as a cryptographic hash, never as text we can read), and the times you signed in.
Why: To give you an account, sign you in, and show your colleagues who did what inside a shared workspace.
Our lawful basis: Performance of our contract with you or your employer (Art. 6(1)(b)).
How long: For as long as your account exists. There is no timer on it. When your account is deleted, your email address, name and profile picture are erased and your sign-in record is destroyed, so you can no longer sign in. See "Deleting your account" below.
Inviting colleagues, and being invited
What we hold: The email address an invitation was sent to, the invitation link, the role it grants, and who sent it. Once you join, we record which workspaces you belong to and when you last visited them.
Why: To let a team work together, and to show an administrator who has access to what.
Our lawful basis: Performance of our contract (Art. 6(1)(b)); our legitimate interest in showing administrators who holds access (Art. 6(1)(f)).
How long: An invitation is deleted 30 days after it expires, whether or not it was ever accepted - an invitation nobody used is an email address held for no reason. Workspace membership lasts as long as the workspace does.
Applying for early access
What we hold: Your first and last name, email address, phone number if you give one, company, anything you write in the comment box, and the IP address and browser you applied from.
Why: To reply to your application and decide whether we can offer you access.
Our lawful basis: Our legitimate interest in responding to people who ask to use the product (Art. 6(1)(f)). You can object at any time using the contact address below, and we will delete your application.
How long: 24 months from the day you applied, then deleted automatically.
Notifications inside the product
What we hold: Messages addressed to you inside Evidence - for example that a research run finished, or that a study's data is about to reach its deletion date - together with who they are for.
Why: To tell you about things that happen in your workspace.
Our lawful basis: Performance of our contract (Art. 6(1)(b)).
How long: 3 months, then deleted automatically.
Our security and audit log
What we hold: A record of significant actions taken in the product - who did what, when, from which IP address and browser. Where the action was answering someone's data-protection request, the record also holds the email address that request was made for.
Why: To investigate security incidents, to show an administrator what happened in their organisation, and to be able to prove that a data-protection request was answered.
Our lawful basis: Our legitimate interest in the security and integrity of the service (Art. 6(1)(f)); for data-protection request records, our legal obligation to demonstrate compliance (Art. 6(1)(c)).
How long: 24 months, then deleted automatically. Records of data-protection requests are kept for 24 months.
Deleting your account
You can delete your account yourself, from your account settings. You do not need to email anyone or ask permission.
Deletion does not happen immediately. We schedule it 24 hours ahead and show you the exact time, so that an accidental click can be undone. Until that moment you can cancel it. After it, you cannot: your sign-in record is destroyed and there is no way for us to identify you or restore the account.
When it runs, we delete your sign-in record - your email address, your password and your sessions - and we erase your email address, name and profile picture from your profile. Your workspace and organisation memberships are removed, any invitations you sent or received are deleted, and your notifications and private chats are deleted.
One thing is deliberately kept: the work you created inside a shared workspace - research, evidence, projects, reports - stays with the team, marked as created by an account that no longer identifies anybody. We keep only an internal identifier, which after deletion points to no name, no email address and no person. This is what lets us honour your erasure without deleting your colleagues' work along with it.
If you are the only administrator of an organisation that still has other members, we will ask you to make someone else an administrator first, so that your colleagues are not locked out of their own organisation. If you are the only member, your workspaces and their contents are deleted with your account.
An administrator of your organisation can also delete an account belonging to someone in that organisation. The same 24-hour window applies.
Two things are not erased at that moment, and we would rather say so than let you assume otherwise. Our security and audit log keeps its record of what was done in the product, including the IP address and browser it was done from; we need it to investigate security incidents and to show an administrator what happened, and it deletes itself on the 24 months schedule described above. And the shared work you created keeps an internal identifier of who made it - an identifier that, once your profile is erased, no longer leads to your name, your email address or you.
Your rights
You have the right to ask for a copy of the personal data we hold about you, to have it corrected, to have it deleted, to object to processing we base on our legitimate interests, and to ask us to restrict how we use it. Write to mri@syndicate.dk and we will answer within one month.
Deletion you can also do yourself, immediately, from your account settings - see above.
If you think we have handled your personal data wrongly, you can complain to the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk), or to the supervisory authority where you live or work.
Who else sees your data
We do not sell personal data and we do not use it for advertising. We share it only with the service providers we need to run Evidence, listed below, each under a contract that limits them to processing it on our instructions.
Supabase - Hosts our database and handles sign-in. European Union (Ireland).
Vercel - Runs and serves the application; its request logs record your IP address and browser. United States, under the European Commission's standard contractual clauses.
Anthropic - Provides the AI models that answer what you type to the assistant. United States, under the European Commission's standard contractual clauses.
Resend - Sends invitation emails, when email delivery is switched on. United States, under the European Commission's standard contractual clauses.
Slack - Receives a notification when someone applies for early access (name, email, phone, company). United States, under the European Commission's standard contractual clauses.
PostHog - Measures how the product is used and records application errors, without cookies and never with interview or evidence content. European Union (Frankfurt, Germany). The company is based in the United States, so its own access is covered by the European Commission's standard contractual clauses.
Trigger.dev - Runs our scheduled background jobs, including account deletion. European Union (Frankfurt, Germany). The company is based outside the EU, so its own access is covered by the European Commission's standard contractual clauses.
Where a provider is outside the European Economic Area, the transfer relies on the European Commission's standard contractual clauses; a copy is available on request from mri@syndicate.dk. The list of companies that process customer data for us is public at /subprocessors.
People who appear in public sources
Evidence's market-intelligence feature reads public web pages about the companies a customer tracks: news, blogs, review sites, careers pages and social posts. Those pages can mention people. We keep what is professional and public: the names and roles of executives named in a company's own materials, and quotes from public reviews with the reviewer described by type (for example "Mortgage customer"), never by name. We do not collect reviewers' or posters' names, handles or contact details: the fields that could carry them are never stored. The model that writes a review excerpt is instructed to replace any name inside the quoted text with a placeholder; that instruction is not a mechanical guarantee, so if a name still reaches a quote, the contact route below applies and we remove it.
Because we learn of these people only through public pages, and the customer holding the data is the controller, contacting each person individually would be a disproportionate effort (GDPR Art. 14(5)(b)). This section is the information instead. If you appear in a public source we have processed and want it corrected or removed, write to mri@syndicate.dk and we will handle it within one month, with the customer where the data sits in their workspace.
Automated decisions
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you.
Evidence does use AI models to generate text. Text written by a model is marked as such, both in the page you read it on and in files you export. How that marking works is published at /ai-content.
Changes to this policy
If we change what we do with personal data, we change this policy and update the version date at the foot of the page. The version history is kept in our source repository.
Version 2026-09-06 · Syndicate ApS · CVR 39592452 · mri@syndicate.dk