evidoria

Privacy policy

Last updated: 19 July 2026 · Controller: C-NAPSE, Lisbon, Portugal

What we collect — and what we deliberately don't

Evidoria runs no analytics scripts, advertising trackers or third-party cookies. Browsing the observatory requires no account and leaves no profile.

  • Evidence alerts: if you subscribe, we store your email address, your chosen filters and verification/unsubscribe tokens. Subscription is double opt-in and every email carries a one-click unsubscribe.
  • Copilot questions: we log the question text, the catalogue and which practices were retrieved — never your identity, IP address or session. These logs exist to find gaps in the evidence base.
  • Suggestions: if you suggest a practice or source, we store the form contents including the contact email you provide, for moderation.
  • Server logs: standard technical logs (status codes, paths) are kept for operations and security; they are rotated and are not used for profiling.

Retention

  • Copilot query logs: deleted after 180 days.
  • Audit records of content changes: kept 24 months (governance and EU-project reporting).
  • Alert subscriptions: kept until you unsubscribe; unverified signups are purged after 30 days.
  • Suggestions: reviewed items are kept as part of the editorial record; rejected items are purged after 12 months.

Processors

Evidoria is hosted on Hetzner (Germany) behind Cloudflare (CDN/TLS). Copilot answers are generated via Anthropic's API (the question text is sent; no identity is attached). Alert emails are delivered through our email provider. Each processor acts under a data-processing agreement.

Your rights

Under the GDPR you may request access, rectification, erasure, restriction or portability of your personal data, and you may lodge a complaint with your supervisory authority. For any request, contact C-NAPSE: c-napse.pt.