Who we are and what this covers
Pactify Pty Ltd ("Evolve", "we", "us") operates the Evolve platform. This policy explains what personal data we collect, why, who we share it with, and the rights you have over it.
It covers our website at e-volv.io, the Evolve application, and our APIs. It does not cover the third-party services you connect — GitHub, Jira, a model provider, and so on — which handle data under their own policies.
Our Terms of Service govern use of the Service and incorporate this policy.
Controller and processor
We act in two different roles, and the difference matters for your rights.
- Controller — for account and billing data, your use of our website, and our own security and support records. We decide why and how that data is processed.
- Processor — for the content inside your workspaces: repository content, tickets, prompts, execution records, and anything else your workflows retrieve or produce. We process it on your instructions, as configured by you. If that content includes personal data about your own employees or customers, you are the controller of it.
If you are an individual whose data appears in a customer’s workspace, direct your request to that customer; we will refer you to them and assist them in responding.
Information we collect
You give us
- Account data — name, email address, profile image, workspace names, and membership and role records. Credentials are held by our identity provider; we never receive or store your password.
- Billing data — plan, subscribed seat or workspace count, billing email, invoices, and a payment-processor customer reference. Card numbers go to Stripe and never reach our systems.
- Content and configuration — workflows, agents, prompts, triggers, repository registrations, and the secrets you store. Secrets are encrypted at rest with AES-256-GCM.
- Support correspondence — the messages you send us and our replies.
We collect automatically
- Usage and execution data — executions, step records, agent runs, token counts, durations, and errors.
- Technical data — IP address, browser and device information, and timestamps in server and audit logs.
- Audit events — sign-in, secret access, integration changes, and workspace membership changes, retained as an append-only record for security.
We receive from services you connect
When you authorise an integration we retrieve only what your workflows need: pull requests and diffs, issues and tickets, CI run status and logs, repository metadata, and the identity of the account that authorised the connection. We do not clone or index a repository unless a workflow you run does so.
How we use information, and our legal bases
- To provide the Service — run your workflows, execute agents, store outputs, and show you what happened. Basis: performance of a contract.
- To bill you — process payments, apply plan limits, and issue receipts. Basis: contract and legal obligation.
- To secure the Service — detect abuse, investigate incidents, and maintain audit trails. Basis: legitimate interests in protecting our platform.
- To support and communicate — answer requests and send service notices about outages, security, and material changes. Basis: contract and legitimate interests.
- To improve the Service — aggregate and de-identified usage analysis. Basis: legitimate interests.
- Marketing email — only where you have opted in, and every message carries an unsubscribe link. Basis: consent.
- To meet legal obligations — tax, accounting, and lawful requests. Basis: legal obligation.
AI processing of your content
Running an agent sends prompt content — which can include source code, diffs, ticket text, and any instructions you wrote — to the model provider configured for that agent. Which provider receives it, and where it is processed, depends on the model you select.
You can register your own provider credentials instead of using the models we supply. When you do, the request goes to your account with that provider and is governed by your agreement with them.
We do not use your content to train our own models. For the models we supply, we use the providers’ enterprise API terms and, where a provider offers the setting, exclude submitted content from training.
International transfers
We operate across several regions, so personal data may be processed outside the country you are in — including in the United States, the European Union, India, and Australia. Where data leaves the EEA, the UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with the technical measures described below. A copy of the relevant transfer mechanism is available at privacy@e-volv.io.
How long we keep information
- Account and workspace records — for as long as the account is active, then deleted or anonymised within 30 days of deletion, other than what we must keep by law.
- Execution step outputs — held in a short-lived cache for about 24 hours, then persisted with the execution record.
- Execution and agent-run history — retained on a rolling basis for operational and billing purposes, and removed with the workspace.
- Audit events — retained as a security record for at least 12 months.
- Billing records — retained for the period required by tax and accounting law, typically seven years.
- Backups — expire on their ordinary rotation after deletion from live systems.
Security
We protect data with encryption in transit (TLS), AES-256-GCM encryption of stored secrets, workspace-level access control, least-privilege service accounts, secret management separated from application code, append-only audit logging, and error monitoring.
No system is completely secure, and we cannot guarantee absolute security. If a breach affects your personal data we will notify you and any applicable regulator within the timeframes the law requires. Report a suspected vulnerability to security@e-volv.io.
Your privacy rights
Subject to your location and to our role as controller or processor, you can ask us to:
- give you access to the personal data we hold about you;
- correct data that is inaccurate or incomplete;
- delete your data — the right to erasure, or to be forgotten;
- export your data in a portable, machine-readable form, or send it to another provider;
- restrict or object to a particular processing activity;
- withdraw consent, without affecting what came before.
Email privacy@e-volv.io and we will respond within 30 days, or sooner where the law requires. We may need to verify your identity first. Exercising a right never means worse service or a different price.
EEA and UK residents
If you are in the EEA, the UK, or Switzerland, you have the rights above under the GDPR and UK GDPR, and you may lodge a complaint with your local supervisory authority. We would ask that you raise it with us first at privacy@e-volv.io so we can try to resolve it. Where we process customer content as a processor, we will enter a data processing agreement on request.
California residents
Under the CCPA as amended by the CPRA you may request the categories and specific pieces of personal information we have collected, the purposes, and the categories of parties we disclose to, and you may request deletion or correction. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is nothing to opt out of. You may use an authorised agent, and we will not discriminate against you for exercising a right.
Australian residents
We handle personal information in line with the Australian Privacy Principles. You can request access to or correction of your personal information at privacy@e-volv.io. If you are not satisfied with how we handle a privacy complaint, you may refer it to the Office of the Australian Information Commissioner (OAIC).
Children
The Service is for business use and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact privacy@e-volv.io and we will delete it.
Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means alone. Agents run automatically inside your workspaces, but they act on workflows you configure, and their output is yours to review before it is acted on.
Changes to this policy
We update this policy as the Service changes. For material changes we will give notice by email or in the Service before they take effect and update the effective date at the top of this page. Continued use after that date means you accept the updated policy.
How to contact us
Pactify Pty Ltd, operator of Evolve. Privacy questions, rights requests, and data processing agreements: privacy@e-volv.io.
Security reports go to security@e-volv.io, and anything about billing or your account to support@e-volv.io.