Privacy Policy
Last updated 22 July 2026
This policy explains what employeeiQ collects, why, who it is shared with, and what rights you have. It covers both this website and the employeeiQ application.
1. Who we are
employeeiQ is operated by EV1 Media. For any privacy question, or to exercise any right described below, contact info@ev1media.com.
2. What we collect
Account and billing information
- Full name, work email address, and company name
- A password, stored only as a salted hash — never in readable form
- The number of employee seats you purchase
- Billing records: plan, amount, invoice history, and subscription status
Card details are entered directly into Stripe and are never transmitted through or stored on our systems.
Content you upload
Documents you add — handbooks, policies, procedures, training material — along with the employee directory records and access levels you configure. These may contain personal data about your staff. You remain the controller of that data; we process it on your behalf.
Usage information
- Questions asked of the assistant and the answers returned, retained so users can see their history and so administrators can audit access
- Sign-in events and security-relevant activity
- Standard server logs, including IP address and browser type
Website analytics
This marketing site uses the Meta Pixel to measure how visitors arrive. It sets third-party cookies and reports page views and button clicks to Meta. It does not load until you accept it in the banner shown on your first visit. If you decline, no pixel is loaded and no data goes to Meta. You can change your decision by clearing this site's data in your browser.
The Meta Pixel is not used inside the employeeiQ application. Your documents and questions are never sent to any advertising network.
3. Why we process it
| Purpose | Lawful basis |
|---|---|
| Providing the service and answering questions from your documents | Performance of a contract |
| Billing and collecting payment | Performance of a contract |
| Security, abuse prevention, and audit trails | Legitimate interests |
| Service and billing notifications | Performance of a contract |
| Website analytics | Consent |
4. Sub-processors
We use the following providers. Each is bound by contract to protect the data they handle, and none is permitted to use it for their own purposes.
| Provider | What it handles |
|---|---|
| Anthropic | Processes document text and questions to generate answers. Content is sent at the time a question is asked. |
| Supabase | Database, authentication, and document storage |
| Stripe | Payment processing and subscription billing |
| Vercel | Hosting for this marketing site |
| Render | Hosting for the employeeiQ application |
| Meta | Website analytics, only with your consent |
We will give notice before adding a sub-processor that handles customer documents.
5. Sharing
We do not sell personal data, and we do not share it for advertising purposes. We disclose it only to the sub-processors above, where required by law or valid legal process, or to a successor entity in the event of a merger or acquisition — in which case this policy continues to apply until you are notified otherwise.
6. Access controls
Within your workspace, documents carry an access level and each employee account carries a clearance level. The assistant only draws on documents a user is authorised to see. Administrators can view their own organisation's audit records. Our staff do not access customer documents except where you ask us to for support, or where necessary to investigate a security incident.
7. Retention
- Documents and directory records: kept until you delete them or close your account
- Question and answer history: retained per your plan's audit-retention period
- Billing records: kept for as long as tax and accounting law requires, typically seven years
- After account closure: customer content is deleted within 30 days, excluding records we are legally required to keep
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and to withdraw consent. Employees of a customer organisation should contact their own employer first, since that organisation controls the data. Write to info@ev1media.com and we will respond within 30 days.
We do not use your data for automated decision-making that produces legal or similarly significant effects.
9. International transfers
Our providers may process data in the United States and other countries. Where data moves from the UK or European Economic Area, transfers rely on Standard Contractual Clauses or another approved safeguard.
10. Security
Data is encrypted in transit with TLS and at rest by our infrastructure providers. Passwords are hashed. Access is restricted by role and clearance level. No system is perfectly secure, but if a breach affects your data we will notify you without undue delay.
11. Children
employeeiQ is a workplace product and is not directed at anyone under 16. We do not knowingly collect their data.
12. Changes
If we make a material change we will update the date above and notify account administrators by email before it takes effect.
← Back to employeeiQ