Data Residency & Privacy
EvidAI provides flexible data residency options and comprehensive privacy controls to meet global regulatory requirements.
Data Residency Options
Available Regions
| Region | Location | Use Case |
|---|---|---|
| US East | Virginia, USA | US-based organizations, FDA submissions |
| US West | Oregon, USA | US backup, disaster recovery |
| EU West | Ireland | GDPR compliance, EMA submissions |
| EU Central | Frankfurt | German data sovereignty requirements |
| UK | London | UK MHRA, post-Brexit compliance |
| APAC | Sydney | Australian TGA, regional requirements |
Data Isolation Guarantee
Your Data Stays Put: When you select a region, ALL your data—documents, decisions, audit trails, backups—remains in that region. No exceptions.
GDPR Compliance
Data Subject Rights
EvidAI fully supports GDPR data subject rights:
| Right | Implementation |
|---|---|
| Access | Self-service data export |
| Rectification | Edit personal data anytime |
| Erasure | Account deletion with data purge |
| Portability | Standard format exports |
| Restriction | Suspend processing on request |
| Objection | Opt-out of non-essential processing |
Data Processing
| Category | Legal Basis | Retention |
|---|---|---|
| Account Data | Contract | Account lifetime + 30 days |
| Review Data | Contract | Customer-defined |
| Audit Logs | Legal obligation | 7 years minimum |
| Analytics | Legitimate interest | 2 years |
Data Processing Agreement
Enterprise customers receive a comprehensive DPA:
- Sub-processor list
- Technical and organizational measures
- Breach notification procedures
- Audit rights
- Transfer mechanisms (SCCs)
HIPAA Compliance
Protected Health Information
For customers handling PHI in systematic reviews:
| Requirement | EvidAI Implementation |
|---|---|
| Access Controls | Role-based, MFA required |
| Audit Controls | Comprehensive logging |
| Integrity Controls | Checksums, immutable logs |
| Transmission Security | TLS 1.3 mandatory |
| Encryption | AES-256 at rest |
Business Associate Agreement
BAA available for all Enterprise plans:
- Covers all EvidAI services
- Includes sub-processor coverage
- Annual renewal and review
- Breach notification within 24 hours
Data Classification
Sensitivity Levels
| Level | Description | Handling |
|---|---|---|
| Public | Published studies, public databases | Standard protection |
| Internal | Review protocols, team discussions | Encrypted, access-controlled |
| Confidential | Unpublished data, commercial studies | Enhanced encryption, audit |
| Restricted | Patient data, proprietary methods | Maximum protection, PHI controls |
Automatic Classification
DOCUMENT CLASSIFICATION: Detected
File: "Phase3_Trial_Results_Confidential.pdf"
AI Classification: CONFIDENTIAL
├── Reason: Contains "confidential" marker
├── Additional signals: Unpublished trial data detected
└── Recommended handling: Enhanced audit logging
Manual Override: [Accept] [Downgrade] [Upgrade to Restricted]
International Transfers
Transfer Mechanisms
| Destination | Mechanism | Status |
|---|---|---|
| EU → US | EU-US Data Privacy Framework | ✅ Certified |
| EU → UK | UK Adequacy Decision | ✅ Covered |
| EU → Other | Standard Contractual Clauses | ✅ Available |
| Within Region | No transfer | ✅ Default |
Transfer Impact Assessment
For sensitive transfers, EvidAI provides TIA documentation:
- Destination country assessment
- Supplementary measures implemented
- Risk analysis
- Safeguard effectiveness
Backup & Recovery
Backup Architecture
| Backup Type | Frequency | Retention | Location |
|---|---|---|---|
| Continuous | Real-time | 7 days | Same region |
| Daily | Every 24h | 30 days | Same region |
| Weekly | Every 7 days | 90 days | Same region |
| Monthly | Every 30 days | 1 year | Same region |
| Annual | Yearly | 7 years | Same region (archive) |
Disaster Recovery
| Metric | Target | Actual |
|---|---|---|
| RPO (Recovery Point Objective) | 1 hour | < 15 minutes |
| RTO (Recovery Time Objective) | 4 hours | < 2 hours |
| Availability | 99.9% | 99.95% |
Privacy by Design
Data Minimization
We collect only what's necessary:
| Data Type | Collected | Purpose |
|---|---|---|
| Yes | Authentication, notifications | |
| Name | Yes | Display, audit trails |
| Organization | Yes | Billing, access control |
| Usage Analytics | Anonymized | Product improvement |
| Review Content | Yes | Core service |
| Location | No | Not collected |
| Device ID | Session only | Security |
Anonymization Options
For research and analytics:
- De-identified exports available
- Aggregate statistics only
- Individual data never shared
- Opt-out of all analytics
Privacy First: EvidAI will never sell your data or use your review content for any purpose other than providing our service to you.