Data Processing Agreement
Ever Platform · ever.co
Version 2026-10 · In force from · Ever Technologies LTD
This Data Processing Agreement (the “Agreement”) applies when an organization uses the Ever Platform and we process personal data on its behalf. It is agreed between that organization (“you”) and Ever Technologies LTD, a company registered in Bulgaria under company number 204599535, with its registered office at Mladost 2, bl. 211, ent. A, Sofia 1799, Bulgaria (“we”, “us”).
It is the data processing addendum that our Terms of Service refer to, for the Ever Platform, and it forms part of those Terms. It needs no separate signature: it applies from the moment your organization starts using the Ever Platform, and each consent screen through which an integration is enabled links to it. If your procurement process needs a countersigned copy, write to legal@ever.co and we will provide one on these terms.
At a glance
- You are the controller of the personal data your organization manages through the Ever Platform. We process it only on your instructions and never for purposes of our own.
- The Ever Platform runs on servers we own and operate in Spain, in the European Union. Every request reaches us through our edge provider, which may handle it outside the European Union, and our off-site backups are encrypted before they leave our servers.
- An integration moves only the fields it declares, which its consent screen and the product’s scope table show, and it stops as soon as it is revoked.
- We use the sub-processors on our published list, give at least 30 days’ notice before adding or replacing one, and you may object.
- We notify you of a personal data breach without undue delay, and within 72 hours.
- When you stop using the Ever Platform you can export your data, and we then delete it on the timetable in section 14.
1. Definitions
Words defined in our Terms of Service keep their meaning. In this Agreement:
- Ever Platform means the services we operate for organizations: Ever ID, the sign-in service at auth.ever.co; app.ever.co, where organizations, their members and their integrations are managed; the API at api.ever.co; and the integrations that connect an Ever product, whether we host it or you run it yourself, to those services.
- Customer Personal Data means the personal data we process on your behalf through the Ever Platform, as described in section 4. It does not include the personal data we process as an independent controller (section 3).
- Integration means a named flow of data between an installation of an Ever product and the Ever Platform. Each integration declares the exact fields it may move, when they move and what the Ever Platform keeps.
- Sub-processor means a third party we engage to process Customer Personal Data on your behalf.
- Data Protection Law means the General Data Protection Regulation (EU) 2016/679 (the “GDPR”) and every other data protection law that applies to the processing, including the UK GDPR and the Swiss Federal Act on Data Protection where they apply. “Controller”, “processor”, “personal data”, “personal data breach”, “processing” and “supervisory authority” have the meanings given in the GDPR.
- SCCs means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
2. Scope
This Agreement applies whenever we process Customer Personal Data on your behalf, for as long as we do so, and it continues after the Terms end until the data has been returned or deleted under section 14. It does not cover:
- Our own processing as controller, described in section 3 and governed by our Privacy Policy.
- The content of a product we host for you. The data inside your workspace in a hosted Ever product, such as Ever Gauzy Cloud, Ever Teams Cloud or Ever Works Cloud, is covered by that product’s own data processing addendum, published on its website. This Agreement covers the Ever Platform and the data that moves between your product and the Ever Platform through an integration.
- Software you run yourself. We process nothing inside an installation you operate and we are not your processor for it. Such an installation sends nothing to the Ever Platform until you connect it and enable an integration; from then on, this Agreement covers what that integration sends.
- Third-party services you connect yourself. Such a provider processes data under its own arrangement with you and is not our sub-processor.
3. Roles
You are the controller of Customer Personal Data and we are your processor. If you process it on behalf of another organization, you appoint us as your sub-processor on these terms and confirm that your controller has authorized this. You are responsible for the lawfulness of the processing you instruct, including the legal basis for enabling an integration and for informing the people concerned.
We are an independent controller, under our Privacy Policy, for:
- each person’s own Ever ID account (their sign-in identity, credentials, security factors and sign-in records), which belongs to that person rather than to any one organization;
- billing, payment and tax records;
- security, audit and abuse-prevention records, including the record of who enabled or revoked an integration, when, and under which versions of the Terms and of this Agreement; and
- information you choose to make public through the Ever Platform, such as your organization’s public profile and handle, once it is published.
We do not process Customer Personal Data for purposes of our own. We do not sell it, we do not use it for advertising or profiling, and we do not use it to train machine-learning models unless you have expressly opted in. No company in our group other than Ever Technologies LTD processes it.
4. Description of the processing
This section is the description Article 28(3) GDPR requires and, where the SCCs apply, Annex I to them. What each integration moves is shown on its consent screen and, inside the product, in its read-only scope table; for the integrations you enable, that description forms part of this section.
| Subject matter | Providing the Ever Platform to your organization: sign-in with Ever ID for your members, your organization’s account, members, roles and invitations, and the integrations you enable. |
|---|---|
| Nature | Collection, storage, retrieval, transmission, comparison of salted one-way hashes, display, restriction and deletion, and the backups needed to keep the service available. |
| Purpose | Only to provide, secure, support and maintain the Ever Platform for you under the Terms and your instructions, and to meet our legal obligations. |
| Duration | For as long as your organization uses the Ever Platform, and then until the data is deleted under section 14. |
| Frequency | Continuous while the service is in use. Each integration runs only as its consent screen states: when a user acts, once, when something changes, daily, or when an event occurs. |
Categories of data subjects
- the owners, administrators and members of your organization, and the people you invite;
- the users of your Ever product installations whose identifiers pass through an integration you enable; and
- your business contacts, such as clients, suppliers and partners, only where an integration you enable compares their identifiers as salted one-way hashes.
Categories of personal data
| Category | What it covers |
|---|---|
| Membership data | The name, e-mail address and Ever ID identifier of each member, their role in your organization, the invitations sent and their status, and changes to memberships. |
| Installation and connection data | Identifiers and public keys of the installations you connect, the public address of an installation where you consent to share it, the state of each connection, and who connected it. |
| Integration data | Only the fields declared by each integration you enable: typically identifiers, salted one-way hashes (for example of a contact’s VAT number, registration number or e-mail address), the counts used for usage reporting, and status information. |
| Technical data | IP addresses, request metadata and the logs created while requests are processed. |
| Messages | E-mails we send on your organization’s behalf, such as invitations. |
No integration moves the content of your documents, files, messages, tasks or projects. The Ever Platform has no field intended for special categories of personal data or for data about criminal convictions and offences, and you should not put such data into it.
5. Integrations: consent, scope and revocation
- On an installation you run yourself, every integration is off until an owner or administrator of your organization enables it. On an Ever product we host for you, the integrations that product describes as on by default start when your organization is linked to the Ever Platform, under that product’s terms, and you can switch any of them off.
- Integrations are enabled on app.ever.co, or inside the product after a fresh Ever ID sign-in, by an owner or administrator of your organization. Before enabling one, they see its purpose, the exact fields it moves and in what form (in clear, as a salted one-way hash, or as an identifier), when they move, what the Ever Platform keeps and for how long, and links to the Terms, this Agreement and the sub-processor list.
- A field that is not declared cannot be sent: requests are checked against the published schema on both sides. If an integration needs another field, its scope version changes and consent is asked for again before anything new moves.
- Each consent is recorded with the scope version, the versions of the Terms and of this Agreement that were shown, who gave it and when.
- You can revoke an integration at any time, on app.ever.co or in the product. The Ever Platform refuses further transfers at once, and the installation stops sending as soon as it learns of the revocation. What the Ever Platform then deletes is stated on that integration’s consent screen.
- The operator of an installation can block any integration for the whole installation.
6. Instructions
We process Customer Personal Data only on your documented instructions, including for transfers as described in section 13: the Terms, this Agreement, the settings you choose, the integrations you enable (and, in a product we host for you, the integrations its terms describe as on by default), and any further written instruction we accept. If a law of the European Union or of a Member State requires us to process it otherwise, we will tell you before we do, unless that law forbids it. If we believe an instruction infringes Data Protection Law, we will tell you immediately, and we may suspend the affected processing until it is resolved.
7. Confidentiality
Everyone we authorize to process Customer Personal Data is bound by a written duty of confidentiality that continues after their engagement ends. Access is limited to the people whose work requires it, through individual accounts, protected by multi-factor authentication wherever the system supports it.
8. Security
We maintain technical and organizational measures appropriate to the risk, as Article 32 GDPR requires. They include:
- TLS for all traffic to the Ever Platform; encryption at rest for databases and backups; and encryption of every off-site backup on our own servers before it is sent.
- Secrets kept in a dedicated secrets store, never in source code.
- Installations that authenticate with a key pair they generate themselves; the private key never leaves the installation.
- Identifiers that an integration compares are pseudonymized (salted and hashed) on your installation before they are sent. They remain personal data.
- Requests checked against published schemas on both sides, and every consent, revocation and policy change recorded in an audit log on both sides.
- Administrative interfaces that are not open to the public internet: they can be reached only through an access gateway that requires staff sign-in, and staff access is individual, least-privilege and logged.
- Infrastructure changes made through version control and reviewed; automatic backups whose restores are tested.
Our Security page describes these measures in more detail. We may update them, but never in a way that lowers the protection of Customer Personal Data. We do not hold a SOC 2 report or an ISO/IEC 27001 certification, and we do not claim either.
9. Personal data breaches
If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay and in any event within 72 hours. Once we have confirmed that your organization is affected, we aim to make first contact within 24 hours. The notice will describe, as far as we know at the time, what happened, the categories and approximate number of people and records concerned, the likely consequences and the measures taken or proposed, and it will name a contact for follow-up questions. We will add information as the investigation progresses and help you with your own notifications.
Notices go to the owners and administrators of your organization and to any security contact you have given us. To report a security problem to us, write to abuse@ever.co.
10. Sub-processors
- You give us a general written authorization to engage sub-processors. The sub-processors of the Ever Platform are published in the Ever Platform section of our sub-processor list, with what each one does, the personal data it receives, where it processes it and the transfer mechanism.
- Before a sub-processor processes Customer Personal Data, we bind it by a written contract to data protection obligations at least as protective as those in this Agreement. We remain responsible to you for its performance.
- We give at least 30 days’ notice before a new or replacement sub-processor starts processing Customer Personal Data, by updating the list and by e-mail to the addresses registered for notifications. To register an address, write to privacy@ever.co.
- You may object on reasonable data protection grounds within 30 days of the notice, by writing to privacy@ever.co. We will work with you in good faith for 30 days to resolve the objection. If we cannot, you may stop using the affected part of the Ever Platform, or end the Terms, without penalty, and we will refund any fees you have prepaid for the period after the end.
- If a sub-processor has to be replaced urgently, because it has failed, been compromised or stopped providing its service, we may engage the replacement sooner. We will tell you as soon as we can and why, and your right to object then runs from that notice.
11. Assistance
- Requests from individuals. Where the Ever Platform provides a tool for a request, such as removing a member or revoking an integration, it is the fastest route. Otherwise write to privacy@ever.co: we acknowledge within 3 business days and assist within 10 business days, or sooner if your own deadline requires it. If a person asks us directly about Customer Personal Data, we pass the request to you and tell them we have done so.
- Impact assessments and prior consultation. We provide the information about our processing that you need, including answers to a reasonable questionnaire once in any 12 months.
- Supervisory authorities. We cooperate with them, and we tell you when one contacts us about your processing unless the law forbids it.
12. Information and audits
We make available the information needed to demonstrate that we meet Article 28 GDPR. Most of it is published: this Agreement, our Security page and the sub-processor list. Beyond that, you may send us a written questionnaire once in any 12 months, and we will answer it within 30 days.
An on-site audit is available where a supervisory authority requires it, after a personal data breach affecting your data, or where the published information and our answers do not allow you to meet your obligations. It requires 30 days’ written notice, takes place during business hours, is limited to the processing of your data, is carried out by you or by an independent auditor who is bound by confidentiality and is not our competitor, and is at your cost unless it reveals a material breach of this Agreement by us. It never includes access to other customers’ data, or tests against our production systems without our written agreement.
13. Where the data is, and international transfers
- Where the data is. Customer Personal Data is stored and processed on servers we own and operate in Spain, in the European Union. We are established in Bulgaria, so our own processing for you involves no transfer outside the European Economic Area.
- The edge. Every request reaches us through Cloudflare, which ends the TLS connection at the location nearest the person making the request. That location can be outside the European Union, so the content of a request can be processed there while it is in transit.
- Backups. Off-site backups are encrypted on our servers before they are sent, and the storage provider does not have the key. They are held in storage restricted to the EU jurisdiction. Until our move to that storage is complete, encrypted copies are also held in storage located in Western Europe without that jurisdiction restriction.
- Sub-processors outside the European Economic Area. Where a sub-processor is established, or processes data, outside the European Economic Area, the transfer relies on an adequacy decision or on the SCCs in our contract with that sub-processor, with the safeguards described in our Privacy Policy. The sub-processor list names the location and the mechanism for each one.
- If you are outside the European Economic Area. Where personal data we process for you is transferred to you outside the European Economic Area, Module Four of the SCCs applies and is incorporated by reference, with the docking clause (clause 7) included, the law of the Republic of Bulgaria under clause 17, and the courts of Sofia, Bulgaria, under clause 18. For the United Kingdom and Switzerland, the corresponding UK addendum and Swiss adaptations apply.
- Requests from public authorities. We do not give any public authority direct or unrestricted access to Customer Personal Data. If we receive a legally binding request for it, we tell you unless the law forbids it, we challenge the request if it is unlawful or wider than the law allows, and we disclose no more than it requires.
- If a transfer mechanism we rely on is invalidated or replaced, we adopt its replacement, or we stop the transfer and tell you what that means for the service.
14. Retention, return and deletion
- During the term. Removing a member from your organization removes their membership. Revoking an integration triggers the deletion stated on its consent screen. A member’s own Ever ID account belongs to them and is not deleted when they leave your organization.
- At the end. When your organization stops using the Ever Platform, you can export its data, or ask us for a copy, for 30 days. We then delete Customer Personal Data from our live systems within a further 30 days and instruct our sub-processors to do the same. On request, we confirm the deletion in writing.
- Backups. Backups are not edited record by record, so deleted data remains in encrypted backups until they expire on their rolling cycle, at most 35 days later. We use a backup only to restore a whole system after a failure, never to bring back data that was deleted. If we restore a system from a backup, we re-apply every deletion made since that backup was taken before the system is used again.
- Sign-in records. Each person’s Ever ID account and its sign-in records are our own records (section 3); how long we keep them, including after an account is deleted, is described in our Privacy Policy.
- What we must keep. Where a law of the European Union or of a Member State requires us to keep data, we keep only what it requires, for as long as it requires, restrict it to storage and tell you unless the law forbids it. Invoices and the payment and tax records attached to them are our own records, kept for the period Bulgarian accounting and tax law requires, as our Privacy Policy describes.
15. Liability
Each party’s liability under this Agreement is subject to the limitation of liability in the Terms; this Agreement does not create a second cap. Nothing in it limits the rights of data subjects, including the right to compensation under Article 82 GDPR.
16. Versions and changes
- This is version 2026-10 of this Agreement. Every consent to an integration records the version that was shown.
- We may update this Agreement to reflect changes in the law, in the Ever Platform or in our sub-processors. We publish each new version on this page, with its version and date, at least 30 days before it takes effect, unless a change is required by law sooner or only adds to your protection. Earlier versions are available on request.
- If this Agreement conflicts with the Terms on the processing of Customer Personal Data, this Agreement prevails. Where the SCCs apply, they prevail over both.
17. Contact
- This Agreement, a countersigned copy, a due-diligence request or a security questionnaire: legal@ever.co.
- Requests from individuals, sub-processor notifications and objections: privacy@ever.co.
- Security problems: abuse@ever.co.
- By post: Ever Technologies LTD, Mladost 2, bl. 211, ent. A, Sofia 1799, Bulgaria.
- Our lead supervisory authority is the Commission for Personal Data Protection (CPDP) in Bulgaria, https://www.cpdp.bg/.