Privacy policy

Updated: 21/12/2024

Thank you for using the Workforce Intelligence Platform, a service provided by Everday B.V. ("Workforce Intelligence Platform," "we," "us," or "our"). We value your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR).

By accessing or using the Workforce Intelligence Platform, you agree to the practices described in this Privacy Policy.

1. Information we collect

1.1 Information you provide

We collect personal information that you voluntarily provide, such as when you:

This data may include:

1.2 Information collected automatically

When you use the Workforce Intelligence Platform, we automatically collect certain information:

1.3 Information from third parties

If you integrate external services (e.g., LinkedIn), we may collect data from those platforms based on your granted permissions. This may include:

2. Legal bases for processing

We process your personal data under one or more of the following legal bases:

3. How we use your information

3.1 Data processing purposes

We use the information we collect to:

3.2 Communication

We may use your contact information to:

3.3 Legal and compliance

We may process your data to:

4. Data sharing and subprocessors

We share data with trusted third-party subprocessors who assist in operating, maintaining, and improving our services. Each subprocessor is contractually obligated to handle your data securely and in compliance with GDPR and other applicable data protection laws.

SubprocessorPurposeData ProcessedLocation
ClerkUser authentication & identity managementNames, email addresses, authentication logsEU-based servers
SupabaseHosting of databases & file storagePersonal data (profile details, skill data), logs, uploaded filesFrankfurt, Germany
PostHogProduct usage analyticsAggregated usage data, anonymized event dataEU-based servers
SentryError tracking & performance monitoringError logs and system performance dataEU-based servers
SendGridTransactional & notification emailsEmail addresses, names, message contentEU-based servers
VercelPlatform hosting & deliveryPlatform data (user interactions, page loads)EU-based servers
InngestWorkflow automation & event handlingEvent data related to user actionsEU-based servers
OpenAI APIAI-driven services & functionalitiesUser inputs, interaction data, related metadataGlobal infrastructure

4.1 Legal obligations

We may disclose your personal information:

4.2 Business transfers

In the event of a merger, acquisition, or sale of all or part of our assets, your information may be transferred to the new owner. We will notify you of any such transfer and any subsequent changes in privacy practices.

5. Data storage

We store all data securely on Supabase servers located in Frankfurt, Germany. Supabase provides industry-standard security measures, including encryption at rest and in transit. Access to stored data is restricted to authorized personnel only.

6. Data security

We implement technical and organisational measures to protect your personal data against unauthorized access, misuse, loss, or alteration. These measures include:

7. Data retention

We retain personal data only as long as necessary to provide our services, comply with legal obligations, or fulfill our operational requirements. Retention periods vary based on the data type and purpose:

8. Your rights

Under GDPR and other applicable data protection laws, you have the right to:

To exercise any of these rights, please email hello@ever.day. We may ask you to verify your identity before responding to certain requests.

9. Cookies and tracking technologies

We use cookies, web beacons, and similar technologies to:

9.1 Types of cookies we use

9.2 Managing cookie preferences

You can manage or delete cookies at any time through your browser settings. However, disabling certain cookies may affect functionality or limit certain features of our services.

10. International data transfers

When personal data is transferred outside the European Economic Area (EEA), we implement appropriate safeguards in compliance with GDPR. These may include Standard Contractual Clauses (SCCs) or other mechanisms recognized by the European Commission to ensure adequate data protection.

11. AI use with OpenAI

We use OpenAI exclusively for AI/ML functionalities, such as generating skill insights or assisting in skill assessment conversations. We do not use any other AI or machine-learning service providers.

Note on OpenAI: Because OpenAI's infrastructure may be global, personal data sent to OpenAI for AI-driven features may be transferred outside the EEA. We rely on appropriate contractual safeguards to ensure your data is protected in compliance with GDPR.

12. What data is required vs. optional

Required Data: Some data fields, such as your name, email address, and personal information related to your work experience, education, and certifications, are necessary for basic account creation, operation, authentication, and security.

Optional Data: Other data points, such as skill assessments, feedback submissions, or responses to surveys, are optional. Providing this information can enhance your user experience but you are not obligated to share it.

13. Incident notification

We have an incident response process to address security breaches promptly. In the event of a breach affecting your personal data, we will:

14. Changes to this privacy policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. If any significant updates are made, we will notify you by email or through a prominent notice on our platform.

15. Contact information

Everday B.V.

Stationsplein 45, D3.118

3013 AK Rotterdam

The Netherlands

Email: hello@ever.day

If you believe we are not handling your data in accordance with the law, you have the right to lodge a complaint with the Autoriteit Persoonsgegevens (Dutch Data Protection Authority) or your local supervisory authority.