Privacy Policy
last updated: 29 July 2026
Everday B.V. ("Everday", "we", "us", "our") builds and operates a platform that does the preparatory work behind people decisions. This policy explains what personal data we handle, why, on what legal basis, and what rights you have. It is written to comply with the GDPR.
1. Two roles, and which one applies to you
Everday handles personal data in two distinct capacities, and which parts of this policy apply to you depends on which one you fall under.
As a processor, on behalf of a client. Most personal data we handle is not ours to decide about. Where an employer, a staffing or reskilling firm, or one of our partners uses the platform, that organisation decides what is collected and why. We act on their documented instructions under a data processing agreement. This covers candidates, employees, and other people whose data is in a client workspace. If you are one of those people, the organisation that invited you is your first point of contact, and this policy tells you what we do with the data on their behalf. Where our client is itself acting for its own client, we are a sub-processor.
As a controller, for our own purposes. We decide about a narrow set of data: our website visitors, people who contact us, people we deal with commercially, and the account and log data we need to run and secure the platform.
2. Personal data we handle
2.1 In a client workspace, as processor
Not every client workspace contains all of these categories. What is present depends on what the client configures and connects.
- Identity and account data — name, email address, system-generated identifiers, role and permissions, team or organisational unit, sign-in and authentication events.
- Work and career history — job titles, employers, dates, descriptions of responsibilities and achievements.
- Education and certifications — qualifications, institutions, fields of study, certifications and their issue dates.
- Application and recruitment data — CVs and résumés, applications, vacancy and role data, pipeline status, reviewer notes, rejection reasons, and recorded sign-offs.
- Skills and proficiency data — assessed skill levels, the evidence each level rests on, and how it changes over time.
- Assessment data — responses to and scores from validated instruments covering personality, interests, work styles and AI fluency, stored per administration so that repeat measurements over time stay comparable. Where a client uses a third-party assessment provider, that provider's results flow in through the same route.
- Conversations and submissions — answers to structured conversations and surveys, including voice notes where a person chooses to record one rather than type. Voice is transcribed to text and used as text.
- Feedback about a person — comments from managers, peers, direct reports, or external assessors, where a client operates such a process.
- Optional profile details — country or city, and other fields a person chooses to complete.
- Data from connected systems — records synchronised from a client's HR system, applicant tracking system, document store, or communication tools, limited to what the client connects.
- Publicly available professional information — where a client instructs the market intelligence agent to research a company, a role or a person, information retrieved from public sources through a search provider.
Assessment results, feedback about a person, and inferred proficiency levels are sensitive in effect even where they are not special category data under Article 9, and we treat them accordingly. We do not seek to collect special category data, and clients are instructed not to route it into the platform.
2.2 As controller
- Website and product usage — pages visited, features used, device and browser information, and IP address, collected through analytics.
- Contact and commercial data — the details you give us when you get in touch, and the contact data we keep about client and partner personnel.
- Operational logs — records needed to run, secure, debug and audit the service.
2.3 What we do not do
We do not perform emotion recognition in the workplace. Behavioural profiling uses validated instruments with deterministic scoring, not a model's impression of a person. We do not conduct covert monitoring of individual behaviour or productivity: patterns across many people can become organisational insight, an individual's behaviour does not. We do not build profiles from personal data bought on the open market.
3. Why we handle it, and on what basis
As processor, the purpose and legal basis are the client's to determine. Our instruction is limited to delivering the service: ingesting and normalising records, matching identities, deriving skills and proficiency with their evidence, administering assessments and conversations, researching where instructed, producing evidence and rankings for a person to decide on, and writing results back into the client's systems.
As controller, we rely on:
- Contract — to provide and administer the service to our clients and their users.
- Legitimate interests — to secure, debug and improve the service, and for limited business communication with professional contacts. We balance this against your interests and you may object.
- Consent — for non-essential cookies and for marketing where consent is required. You may withdraw it at any time.
- Legal obligation — where law requires us to retain or disclose.
4. Decisions about people
The platform prepares, evidences and ranks. Everday does not build, operate or stand behind automated decision-making about people. Nothing Everday configures or operates produces a decision with legal or similarly significant effect on a person, within the meaning of Article 22 GDPR, without meaningful human involvement. Where the platform prepares a decision, the sign-off is recorded as an act by an identified person, with the evidence that was in front of them.
Clients can build and configure their own agents on the platform. Our terms prohibit them from configuring the platform to produce or execute such a decision without meaningful human review. Where a client does so anyway, that client acts as controller and deployer on its own instruction, and the decision is theirs.
Every fact we hold carries its source, and every recommendation carries its reasoning. If you want to know how a conclusion about you was reached, the organisation that holds your data can show you, and we support them in doing so.
5. AI providers and how we use models
We use large language models and other AI services to derive skills from evidence, structure conversations, research where instructed, and produce summaries and recommendations.
Anthropic supplies the model behind the conversational engine and the agents. OpenAI supplies models used for document and CV extraction, matching, embeddings and summarisation. Deepgram transcribes voice notes. Content that identifies a person can reach these providers, because deriving skills from a CV or a conversation requires the content itself.
Our commitments on model use:
- No training on your data. We do not train models on client data, and our agreements with model providers prohibit them from doing so.
- Minimisation per task. A model receives what the task requires, not the record.
- No retention for the provider's own purposes. Prompts are processed for the duration of the request.
6. Who we share it with
We share personal data with subprocessors that help us run the service. Each is bound by a data processing agreement, is assessed before use, and processes data only on our instructions. The Trust Center holds the authoritative list.
6.1 Platform subprocessors
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Clerk | Authentication and identity, and delivery of authentication emails | Names, email addresses, authentication and sign-in logs | EU |
| Supabase | Primary database and file storage | Profile, skills, assessment and application data, uploaded files including CVs | Frankfurt, Germany |
| Railway | Hosting for backend services, job queue and graph store | All categories processed by those services | EU |
| Vercel | Hosting and delivery of the web applications | Request data, user interactions | Frankfurt and Paris |
| Inngest | Background jobs and event orchestration | Event data relating to processing steps | EU |
| Anthropic | Model behind the conversational engine and agents | Prompt content: evidence, conversation content, role context | US, global infrastructure |
| OpenAI | Models for document and CV extraction, matching, embeddings and summarisation | Document and CV content, skills evidence, conversation content | US, global infrastructure |
| Deepgram | Speech to text for voice notes | Voice recordings and their transcripts | EU |
| Resend | Transactional and notification email | Email addresses, names, message content | EU |
| PostHog | Product analytics and model tracing | Pseudonymised usage and event data | EU Cloud |
| Tavily | Research queries for the market intelligence agent | Company, role and person queries | EU |
Error tracking and performance monitoring run on our own self-hosted infrastructure, so no third party receives that telemetry.
Client systems that we connect to on a client's instruction, such as HR systems, applicant tracking systems, document stores and communication tools, are the client's own processors rather than ours. We read from and write to them only as instructed.
6.2 Our own business tools
As controller, we use Twenty (self-hosted), Notion, Slack, Linear, Cal.com (self-hosted), GitHub and Vercel Analytics to run our business. These process the contact details of client and partner personnel and of prospects, not the data in client workspaces.
We also disclose personal data where law requires it, and to a successor in the event of a merger or acquisition, in which case we notify affected clients.
7. Where data is stored and transferred
Client data is stored and processed in the European Economic Area. The database and file storage run in Frankfurt, Germany, and the web applications run in Frankfurt and Paris.
AI model providers operate globally, so prompt content is processed outside the EEA. Where personal data is transferred outside the EEA we rely on Standard Contractual Clauses or another lawful transfer mechanism, together with measures limiting what is transferred.
8. How long we keep it
- Client workspace data — for as long as the client's agreement runs. On termination, data is exportable for 30 days and then deleted or anonymised, unless the client instructs otherwise or law requires retention.
- Usage and analytics data — anonymised or deleted within 12 months.
- Financial and contractual records — 7 years, as Dutch tax law requires.
Raw ingested source material is kept immutably so that the record can be re-derived and evidence stays auditable. Erasure reaches that layer too, through a documented procedure completed within the statutory period.
9. Your rights
You have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, to receive it in a portable format, and to withdraw consent where processing rests on it.
If your data sits in a client workspace, send your request to that organisation. They decide, and we support them within the timelines in our data processing agreement. If you do not know who holds your data, contact us at privacy@ever.day and we will identify the controller and pass the request on.
If we are the controller, contact privacy@ever.day directly. We respond within one month.
You may lodge a complaint with the Autoriteit Persoonsgegevens or your local supervisory authority.
10. Security
We encrypt data in transit and at rest, isolate each client workspace at the platform's core rather than at each surface, restrict access to authorised personnel, require multi-factor authentication on sensitive systems, and log access. Full detail is in the Trust Center.
We notify affected clients of a personal data breach without undue delay, and support them in meeting their own obligations.
11. Cookies
Our website uses strictly necessary cookies, and analytics cookies where you consent. You can manage cookies through your browser or our consent banner. Detail is in the Cookie Policy.
12. Children
The platform is not intended for children and we do not knowingly collect their data.
13. Changes
We update this policy as our practices change. For material changes we notify clients in advance and record the date above.
14. Contact
Everday B.V. Stationsplein 45, Unit D3.118 3013 AK Rotterdam The Netherlands
Privacy: privacy@ever.day · Data protection officer: dpo@ever.day · General: hello@ever.day