Privacy Policy
How Evoya AI GmbH processes personal data on its website and AI platform, and what rights you have.
Last updated: September 25, 2026
1. Scope
This privacy policy explains how Evoya AI GmbH ("Evoya AI", "we", "us") processes personal data, in particular in connection with
- our website evoya.ai, including its sub-pages, forms and chat widget,
- our AI platform (available in particular via avaia.io and related subdomains), our APIs and integrations,
- our services such as consulting, workshops, training and development projects, and
- communication with customers, prospects, partners and suppliers.
It is based on the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR). Additional privacy notices or a data processing agreement (DPA) may apply to individual services.
2. Controller and contact
Controller:
Evoya AI GmbH
Brunnenstrasse 27
8610 Uster
Switzerland
UID: CHE-236.338.302
Contact for data protection matters:
Steven Chareonbood, Managing Director
Email: [email protected] (subject "Data protection")
Phone: +41 44 520 16 48
We have not appointed a data protection advisor within the meaning of Art. 10 FADP or a data protection officer within the meaning of Art. 37 GDPR. The contact above is your point of contact for all data protection questions.
3. Our role: controller or processor
As controller, we process personal data whose purposes and means we determine ourselves, e.g. data of website visitors, prospects, contact persons at our customers, account, contract and billing data, and data used for our marketing.
As processor, we process content that our business customers and their users enter into or upload to the platform (e.g. prompts, documents, knowledge bases, chat histories, generated outputs) and data of end users of chatbots operated by customers. We process this data solely on behalf of and on the instructions of the respective customer in accordance with our Terms and our data processing agreement (DPA). The customer is the controller for this processing; in particular, the customer decides which data to enter, which AI models to use and how long content is retained. Data subjects should address requests regarding this data to the respective customer; we forward requests we receive to the customer.
4. Data we process
Depending on the interaction and use, we process in particular the following categories of personal data:
- Master and contact data: name, company, job title, email address, phone number, postal address.
- Account and profile data: username, hashed password, role, organisation, settings.
- Contract and billing data: services booked, licences and credits, billing address, payment method, payment status, contract correspondence.
- Platform content: inputs (prompts), uploaded files, knowledge bases, generated outputs, chat histories.
- Technical and usage data: IP address, date and time of access, pages visited, referrer, browser and device type, operating system, system and error logs, usage statistics (e.g. credits consumed, models used).
- Communication data: content of enquiries via forms, email, phone, chat or support tickets, and appointment bookings.
- Marketing data: newsletter subscription, consents, interactions with our emails, participation in events and webinars.
- Images and recordings: photos and videos of events and workshops (see section 5).
- Application data: information and documents you send us as part of a job application.
We do not deliberately collect sensitive personal data (e.g. health data). Such data only enters our systems if users enter it into the platform themselves. The customer is responsible for the lawfulness of such inputs.
5. Purposes and legal bases
We process personal data for the following purposes:
- Providing the website and platform, including account management, connecting AI models, support and technical operations.
- Concluding and performing contracts, including quotes, invoicing, accounting and enforcement of claims.
- Communication with you, e.g. to answer enquiries and organise appointments.
- Marketing, e.g. newsletters, information about new features, events and references.
- Improving our offering on the basis of aggregated or pseudonymised usage statistics.
- Security and abuse prevention, e.g. spam protection, fraud detection, logging and enforcing our terms of use.
- Compliance with legal obligations, e.g. retention obligations and orders from authorities.
- Events: photos and videos may be taken at events and workshops, which we use on our website, on social media and in publications. We point this out on site. You may object to being recorded or published at any time; we only publish portraits of individual persons with their consent.
Legal bases
Under the FADP, processing is lawful if it complies with the processing principles; where necessary, we rely on a justification under Art. 31 FADP. Where the GDPR applies, we rely on:
- performance of a contract and pre-contractual measures (Art. 6(1)(b) GDPR; Art. 31(2)(a) FADP),
- consent, e.g. for statistics and marketing cookies and the newsletter (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future,
- legal obligation (Art. 6(1)(c) GDPR),
- legitimate interests (Art. 6(1)(f) GDPR), namely in secure and efficient operations, abuse prevention, communication with business contacts, direct marketing to existing customers and the enforcement of legal claims.
Providing personal data is generally voluntary. However, without the information required for a contract or an account, we cannot provide the respective services.
6. Processing on our website
Server log files
When you visit our website, technical data (in particular IP address, date and time, requested URL, referrer, browser and operating system) is stored in log files. This is necessary to deliver the website, for security and for troubleshooting.
Cookies and consent management
We use strictly necessary cookies (e.g. session, language preference, storing your cookie choice). We only load third-party statistics, marketing and functional services after you have consented via our cookie banner. You can change your choice at any time via the "Cookie Settings" link in the website footer. Details can be found in our Cookie Policy.
Google Analytics, Google Tag Manager and Google Ads
With your consent, we use services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, USA ("Google"): Google Tag Manager to manage tags, Google Analytics for statistical analysis of website usage and Google Ads to measure the success of our ads (conversion tracking, e.g. clicks on "Start for Free" or "Book a Demo") and for remarketing, i.e. to show visitors of our website interest-based Evoya AI ads on other websites and Google services. Cookies or identifiers are set and usage data, including a truncated IP address, is transmitted to Google, including to the USA. We use Google Consent Mode; without your consent, these Google services are not loaded. More information: Google Privacy Policy.
Contact form and Google reCAPTCHA
If you contact us via a form, we process your details (e.g. name, company, email, phone number, message) to answer your enquiry. To protect against spam and abuse, we use Google reCAPTCHA on pages with forms. reCAPTCHA analyses your behaviour on the page (e.g. IP address, mouse movements, time spent) and transmits this data to Google, including to the USA. The legal basis is our legitimate interest in preventing abuse. Google's Privacy Policy and Terms of Service apply.
Appointment booking (TidyCal)
For booking demos and introductory calls, we link to the TidyCal service (AppSumo Originals, USA). When you book an appointment, TidyCal processes your details (e.g. name, email, chosen time slot, any message) on our behalf. Data may be stored in the USA.
Newsletter and marketing automation (Vbout)
We use Vbout (Vbout Inc., USA) to send our newsletter. The Vbout sign-up form is only loaded once you have consented to the "Functional" category or actively loaded the form. We use a double opt-in procedure for sign-ups. Vbout measures whether newsletters are opened and links are clicked. With your consent to "Marketing", we also use Vbout tracking on our website to associate website visits with known contacts and improve our communication. You can unsubscribe at any time via the link in every email and deactivate tracking in the cookie settings.
Chat assistant on the website
Our website offers an AI chat assistant that runs on our own platform (chat.avaia.io). The assistant is only loaded after you interact with the page. If you use it, we process your inputs and the generated answers to respond to your question. Please do not enter sensitive personal data in the chat.
Social media profiles
Our website contains links to our profiles on LinkedIn, YouTube, X and Facebook. These are plain links, not plugins; data is only transmitted when you click the link. The privacy policies of the respective operators apply on those platforms.
7. Processing on the AI platform
Account and usage
To provide the platform, we process account, contract and usage data. We use usage statistics (e.g. number of requests, credits consumed, models used) for billing, capacity planning, abuse prevention and the further development of our services.
AI models and storage location
The platform connects AI models from various providers, including models operated in Switzerland or the EU and models from international providers. By default, we store platform content in ISO 27001-certified data centres in Switzerland. When you use a model, your inputs and the content required for the response are transmitted to the provider of the selected model for processing, possibly in that provider's country (see section 9). The platform shows for each model in which country it is operated. The customer or the users it authorises choose the model.
No use for training AI models
We do not use our customers' platform content to train AI models unless the customer has expressly agreed. We connect third-party models via their business interfaces (APIs), for which the providers commit in their own terms not to use API data to train their models. The respective providers are responsible for complying with these commitments.
Content retention and zero data retention
Customers can set on the platform how long chat histories and other content are retained, down to deletion at the end of the session (zero data retention). Some model providers temporarily store inputs and outputs under their own terms, e.g. for up to 30 days for abuse monitoring. Whether a provider offers zero data retention is indicated on the platform or communicated on request.
Integrations and on-premise
If a customer connects the platform to third-party systems (e.g. Microsoft 365, email, databases), the platform accesses these systems to the extent authorised by the customer. If a customer operates the solution on its own infrastructure (on-premise) or with a cloud provider of its choice, it is responsible for operating and securing that environment.
8. Recipients and processors
We only disclose personal data where necessary for the purposes described, to the following categories of recipients:
- IT and hosting providers (data centres, cloud infrastructure, email, backup),
- AI model providers whose models you select on the platform,
- website, analytics and marketing service providers (Google, Vbout, TidyCal),
- payment and accounting service providers and banks,
- partners providing implementation or support services on behalf of a customer, if the customer so wishes,
- advisors such as fiduciaries, auditors and lawyers who are bound by confidentiality,
- authorities and courts, where we are legally obliged to do so or it is necessary to protect our rights,
- acquirers or investors in the context of a corporate transaction, subject to confidentiality.
We conclude agreements with processors obliging them to process data only on our instructions and to protect it appropriately. Business customers receive a current list of sub-processors for the platform on request (see DPA, Annex 2).
9. International transfers
Recipients of personal data may be located outside Switzerland, in particular in the EU/EEA and the USA, and for international AI models also in other countries.
- We transfer data to countries recognised by the Swiss Federal Council or the European Commission as providing an adequate level of data protection (including the EU/EEA and the United Kingdom) without additional safeguards.
- We transfer data to the USA to recipients certified under the Swiss-U.S. or EU-U.S. Data Privacy Framework, or on the basis of the European Commission's standard contractual clauses with the adaptations required for Switzerland.
- We transfer data to other countries without an adequate level of data protection on the basis of standard contractual clauses or, where none exist, only on the basis of an exception under Art. 17 FADP or Art. 49 GDPR, in particular where the disclosure is necessary to perform the contract with you or you have expressly consented.
Important note on AI models: The platform may offer models from providers whose servers are located in countries without an adequate level of data protection and who do not offer standard contractual clauses. Such models are labelled on the platform. If a customer or user selects such a model, the transfer takes place at their express instruction and responsibility. Customers can restrict the use of such models for their organisation. We recommend not using personal data with them.
10. Retention
We retain personal data only as long as necessary for the respective purpose, as required by statutory retention obligations or where we have a legitimate interest (e.g. to preserve evidence during limitation periods). As a guideline:
- Server log files: generally up to 90 days, longer in the event of security incidents.
- Contact and appointment requests: until resolved, then up to 24 months if no business relationship arises.
- Customer account and platform content: for the term of the contract in accordance with the settings chosen by the customer; after termination, content is deleted within 30 days in accordance with our Terms, and backups no later than 60 days thereafter.
- Contract and accounting records: 10 years (Art. 958f Swiss Code of Obligations).
- Newsletter: until you unsubscribe; proof of consent for up to 3 years thereafter.
- Cookies: according to the lifetimes stated in the Cookie Policy.
- Applications: up to 6 months after the process has ended, unless you consent to longer retention.
11. Data security
We take appropriate technical and organisational measures to protect your personal data, in particular encrypted transmission (TLS), role-based access controls, logging, regular backups, hosting in certified data centres and confidentiality obligations for our staff. However, no provider can guarantee absolute protection against all risks. In the event of a data security breach likely to result in a high risk, we notify the FDPIC, the competent EU supervisory authority where applicable and, where required, the data subjects or our customers in accordance with the law.
12. Automated decisions and profiling
We do not make automated individual decisions that have legal effects on you or significantly affect you (Art. 21 FADP, Art. 22 GDPR). The AI models on the platform provide suggestions, answers and analyses that should be reviewed by humans. If customers use the platform for their own automated decisions or profiling, they are responsible for doing so.
With your consent, we analyse usage behaviour on our website for statistical and marketing purposes (see section 6). No high-risk profiling within the meaning of the FADP takes place.
13. Your rights
Within the scope of applicable data protection law, you have in particular the following rights:
- access to information on whether and which personal data we process about you,
- rectification of inaccurate or incomplete data,
- erasure or destruction of your data, unless retention obligations or overriding interests prevent this,
- restriction of processing,
- receipt or transfer of your data in a common electronic format,
- objection to processing based on legitimate interests on grounds relating to your particular situation,
- withdrawal of consent at any time with effect for the future, e.g. via the cookie settings or the unsubscribe link in the newsletter.
Objection to direct marketing: You may object to the processing of your data for direct marketing at any time without giving reasons. We will then no longer use your data for this purpose.
Please send your request to [email protected] or to our postal address. We may request proof of identity. We generally respond within 30 days. If your request concerns platform content that we process on behalf of a customer, we forward it to that customer.
You also have the right to lodge a complaint with a supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch). In the EEA, it is the supervisory authority at your place of residence, place of work or place of the alleged infringement.
14. Minors and schools
Our website and platform are aimed at companies, organisations and educational institutions. Persons under 16 may only use the platform under a contract with an educational institution or with the consent of their parents or guardians. If a school uses the platform, it is the controller for processing the data of its pupils and teachers and is responsible for obtaining any required consents; we act as its processor.
15. Changes
We may amend this privacy policy at any time, e.g. when introducing new services or following changes in the law. The version published on this website applies. We inform registered customers of material changes in an appropriate manner, e.g. by email or on the platform. In the event of discrepancies between language versions, the German version prevails.