Legal

Privacy Policy

Last updated: 01.06.2026

This Privacy Policy explains how personal data is processed when you visit this website, contact EvidenceStack, submit a form, or request an assessment.

1. Controller

The controller responsible for this website is:

Guillermo Carmona

Operating under the EvidenceStack brand

Am Fohlenhof 41

85290 Geisenfeld

Germany

Email: contact@evidencetoscale.com

2. Data we process

Depending on how you use the website, we may process:

Technical data such as IP address, browser type, device type, operating system, pages visited, time of access and similar log data.

Usage data such as page views, traffic sources and aggregated analytics information.

Contact data such as name, email address, company, role and message content.

Form or assessment data submitted by you, including information about your company, technology, readiness level, maturity claims or evidence references.

Communication data from emails, calls or follow-up exchanges.

We do not intentionally collect special categories of personal data through this website.

3. Purposes of processing

We process personal data to:

Operate, secure and improve the website.

Understand website usage and improve content and user experience.

Respond to contact requests and business inquiries.

Process assessment or readiness-review requests.

Prepare, deliver or follow up on potential EvidenceStack services.

Comply with legal obligations and maintain reasonable business records.

The legal basis may include legitimate interest, steps prior to entering into a contract, performance of a contract, consent where required, or legal obligation.

4. Hosting and infrastructure

This website may use cloud infrastructure and technical service providers such as Vercel and Cloudflare for hosting, content delivery, DNS, security, caching, performance monitoring and traffic routing.

These providers may process technical data such as IP addresses, request metadata, device information and log data as required to deliver the website securely and reliably.

5. Analytics

This website may use Google Analytics and similar tools to understand website traffic and improve the site.

Analytics may process information such as page views, approximate location, browser and device information, referral sources and interactions with the website.

Where legally required, analytics cookies or similar technologies are used only after consent. You can manage cookies through your browser settings or through the consent options provided on the website, where available.

6. Forms and lead capture

This website may use form tools such as Fillout to collect contact requests, readiness-assessment inputs or service inquiries.

When submitting a form, only provide information that you are authorized to share. Do not submit confidential, export-controlled, classified or highly sensitive information unless a separate written agreement is in place.

Form submissions may be processed through webhooks, backend services, email or storage systems used to handle your request.

7. Cookies and similar technologies

This website may use cookies, local storage or similar technologies for:

  • Essential website functionality
  • Security and performance
  • Analytics and traffic measurement
  • Form handling and session continuity
  • You can control cookies through your browser settings. Blocking cookies may affect some website functionality.

    8. Recipients and service providers

    Personal data may be shared with service providers that support website operation and business processes, including hosting providers, DNS and security providers, analytics providers, form providers, email providers and professional advisers where necessary.

    We do not sell personal data.

    9. International transfers

    Some service providers may process data outside the European Economic Area. Where this happens, appropriate safeguards are used where required, such as adequacy decisions, standard contractual clauses or equivalent legal mechanisms.

    10. Retention

    We retain personal data only as long as necessary for the purposes described in this Privacy Policy.

    Typical retention periods depend on the type of data:

    Technical logs are kept for a limited period for security and operational purposes.

    Analytics data is retained according to the configured analytics settings.

    Contact and assessment data is retained as long as needed to respond, evaluate the request, provide services, maintain business records or comply with legal obligations.

    11. Your rights

    Subject to applicable legal requirements, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion
  • Restrict processing
  • Request data portability
  • Object to processing based on legitimate interests
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with a competent data protection authority
  • To exercise your rights, contact:

    contact@evidencetoscale.com

    12. No automated decision-making

    We do not use website visitor data for automated decision-making that produces legal or similarly significant effects.

    13. Confidentiality note

    EvidenceStack may receive technical, business or investment-related information through forms or direct communication.

    Unless a separate confidentiality agreement is in place, do not submit highly confidential, sensitive, export-controlled, classified or third-party restricted information through public website forms.

    14. Updates

    This Privacy Policy may be updated from time to time to reflect changes in the website, tools, services or legal requirements.

    The latest version will always be available on this page.