Privacy Policy
Last updated · Effective
How Evolutions collects, uses, shares, and protects personal information through our website and business relationships — and the choices and rights you have.
1. Overview
Evolutions International Inc., a Delaware corporation (“Evolutions,” “we,” “us,” or “our”), builds operating-system software for global asset management — including our platform for registered investment advisers and our fund-administration tools for private-fund managers. This Privacy Policy explains how we handle personal information in connection with our website at evolutionshq.com (the “Site”) and, when active, our platform and related services (together with the Site, the “Services”), and our dealings with prospective and current business customers, partners, and the people who contact us.
In plain terms: today the Site is a pre-launch page. We do not run advertising trackers, and we do not sell or share your personal information. We do use one analytics tool, PostHog, to understand how this page is used. It is on by default, and we rely on our legitimate interests rather than on your consent — so what we owe you is notice and a real way to object, not a request to agree. We show you a notice saying it is running, and you can turn it off at any time — from that notice, or afterwards using the Cookie preferences link in our footer. If your browser sends a Global Privacy Control signal we treat that as an objection automatically, without you having to do anything. Apart from that, the most we collect from you directly is what you send us through our contact form or by email.
2. Scope of this policy
This policy covers personal information that Evolutions controls — Site visitors, people who contact us, and business contacts at prospective or current customers and partners.
It does not cover data we process on behalf of our business customers when they use our platform (for example, information about a customer’s own clients or funds). We process that data as a service provider under our customer agreements and any applicable data processing addendum, and the customer is responsible for the privacy notices and choices it provides to its own clients. If you are an end-client of one of our customers and want to exercise privacy rights over information in our platform, please contact that customer directly; we will assist them as our agreement and the law require.
3. Information we collect
We collect the following categories of personal information:
- Identifiers and contact details — name, email address, phone number, employer, and job title, when you provide them.
- Professional information — your role, organization, and other professional context you share with us.
- Communications — the content of messages, inquiries, and correspondence you send us.
- Technical and usage data — collected automatically by our hosting provider, such as IP address, browser and device type, pages requested, referring URL, and timestamps, primarily in server logs used for security and reliability.
Sources. We collect this information directly from you, automatically through our hosting infrastructure, and occasionally from third parties such as referrals, business partners, or publicly available professional sources. We retain it as described in Data retention below.
4. Sensitive information
We do not seek to collect “sensitive personal information” (such as government identifiers, financial account credentials, or precise geolocation) through the Site, and we ask that you not send it to us by email. If we inadvertently receive sensitive personal information in your communications, you may direct us to limit its use to what the law permits by contacting us; we do not use it to infer characteristics or for unrelated purposes.
5. How we use information
We use personal information to:
- respond to your inquiries and communicate with you;
- evaluate, establish, and manage business relationships;
- operate, maintain, secure, and improve the Services;
- comply with legal obligations and enforce our agreements; and
- protect the rights, property, and safety of Evolutions, our users, and others.
Our legal bases. If you are in the European Economic Area or the United Kingdom, the GDPR and UK GDPR require a legal basis for each of those purposes. Ours are:
- Legitimate interests — correspondence, business contacts, and security — Article 6(1)(f). Answering your inquiry and replying to you, keeping a record of our business contacts at customers, prospects, and partners, and keeping the Site secure and free of abuse. The law asks us to weigh that interest against your rights: none of this is intrusive or unexpected in a professional context, we collect no more than the exchange needs, and you can object to it.
- Legitimate interests — analytics, including session replay — Article 6(1)(f), weighed on its own rather than under the balance above. Session replay is the most intrusive thing on this page, and it should not shelter under a test written for answering emails. The interest is understanding how this page is used so we can improve it. What tips the balance: it is limited to how the page is used rather than who you are; the identifier is a random value, not derived from anything about you; everything typed into the contact form, and the text around it, is replaced with dots inside your browser before anything is sent, so we cannot read it back; error capture is switched off; and you can stop the whole thing in one click, from the notice or from the footer. That switch is the objection right under Article 21, exercised directly instead of by writing to us and waiting.
- Legal obligation — Article 6(1)(c). Keeping the records we are required to keep for legal, tax, and accounting purposes, and responding to lawful requests from authorities.
- Consent — Article 6(1)(a). Only where we ask you for it and you give it, and only for things not listed above. You can withdraw consent at any time, and withdrawing does not undo what was lawful before you withdrew. Note that analytics is not in this category: it runs on legitimate interests with a one-click objection, as described above and in Cookies & tracking.
We do not treat your inquiry as consent. When you write to us, we reply because answering is in the legitimate interests of both of us — asking you to consent to a reply you asked for would be a fiction. You can object to anything we base on legitimate interests; see Your privacy rights. If you object, we stop, unless we can show compelling legitimate grounds that override your interests or we need the information to establish, exercise, or defend a legal claim.
7. Service providers
We rely on a small number of vendors to operate the Services and our business. They may process personal information only to provide services to us. Our current key providers are:
- Vercel — website hosting and content delivery (United States / global edge).
- Google Workspace — email and productivity; we use it to receive, send, and store our correspondence with you (United States).
- Cloudflare — Turnstile, the anti-spam check on our contact form. The check is invisible: there is no box to tick, and most people will never see it work, because Cloudflare presents a challenge only when it judges one necessary. Invisible is not the same as inactive, so to be plain about what it does: the Turnstile script does not load when our home page opens, but it does load once you scroll near the contact section at the foot of the page, or interact with the form. From that point Cloudflare receives your IP address and browser signals — whether or not you ever submit anything, and whether or not you ever see a challenge. It receives them again when you submit and we verify that submission (United States / global edge). Cloudflare explains what those signals are and how it uses them in its Turnstile Privacy Addendum (opens in new tab).
- Postmark — transactional email; it delivers contact-form submissions to our inbox (United States).
- Upstash — when enabled, a Redis store that briefly holds your IP address to rate-limit contact-form submissions (United States).
- PostHog — product analytics, including session replay, used only where you have allowed analytics. Processed on PostHog’s European Union cloud. Analytics requests are routed through our own domain rather than sent to PostHog directly, so PostHog does not see your requests to this Site unless analytics is on (European Union).
We update this list as our providers change. To request the current list, contact us using the details below.
9. Data retention
We keep personal information only as long as necessary for the purposes described here and to meet legal, tax, and accounting requirements, after which we delete or de-identify it. In practice:
- Server and request logs collected by our hosting provider are kept for a short operational window — typically no more than 90 days — for security and reliability purposes. That window is enforced by the provider, which is why we can put a number on it.
- Email correspondence is kept while we handle your inquiry and afterwards for as long as the exchange still serves the purpose it was collected for — because the conversation is live, because you may return to it, or because it records what we asked or told you.
- Business-contact records are kept while the relationship is active, and afterwards for as long as we could reasonably expect to pick it up again or need to show how it was conducted.
- Records the law requires us to hold — contracts, invoices, and the tax and accounting records behind them — are kept for the period the applicable law sets, which is usually the longest period on this list.
How we decide. Where no system enforces a fixed window, we set the period from the criteria in that list: whether we still need the information for the purpose we collected it for, whether the relationship or conversation is still live, how long the applicable limitation period leaves a claim open, what legal, tax, and accounting rules require us to keep, and whether the record is still the evidence of something — what was agreed, what was asked, or what we told you. We review these against the records we actually hold rather than let them accumulate by default, and you can ask us to delete information sooner; see Your privacy rights.
10. Your privacy rights
Depending on where you live, U.S. state privacy laws may give you the right to know and access, correct, and delete personal information we hold about you; to opt out of any sale, sharing, or targeted advertising; and to not be discriminated against for exercising these rights. Given what the Site collects today, the simplest path is the same for everyone: ask, and we will act on it.
To make a request, contact us using the details in Contact us. We will verify your request using the information we hold and respond within the time the law allows. If we decline a request, we will tell you why, and you may appeal by replying to our response; if you are unsatisfied with the outcome, you may contact your state attorney general or privacy regulator.
If you are in the European Economic Area or the United Kingdom. The GDPR and UK GDPR give you the rights below over information we hold as a controller. Which of them apply in a given case depends on the legal basis we relied on, set out in How we use information.
- Access — ask whether we hold information about you and get a copy of it, together with the details this policy sets out.
- Rectification — have inaccurate information corrected and incomplete information completed.
- Erasure — have information deleted where we no longer need it, where you withdraw the consent it rested on, or where you object and we have no overriding grounds to keep it.
- Restriction — have us pause our use of information rather than delete it, for example while we check an accuracy dispute or weigh an objection.
- Portability — receive information you gave us in a structured, commonly used, machine-readable form, and have it sent to another controller where that is technically feasible. The right covers processing based on consent or a contract and carried out by automated means, so on the bases above it will rarely reach us.
- Objection — object, on grounds relating to your situation, to anything we base on legitimate interests. If you object to direct marketing, we stop; there is nothing to weigh.
- Withdrawal of consent — withdraw consent at any time, where consent is what we relied on. Withdrawal is not retroactive; it does not make earlier processing unlawful.
We do not make decisions about you by automated means that produce legal effects or similarly significant effects. To make a request, use the details in Contact us. We answer within one month and may extend that by up to two further months for a complex request or a run of requests — if we do, we will tell you why inside the first month. Requests are free unless one is manifestly unfounded or excessive.
Complaints, and why there is no EU or UK representative. You can complain to the supervisory authority in the country where you live or work, or where you think the problem happened. We would rather you came to us first, but you do not have to.
In the EEA, the European Data Protection Board publishes the list of national authorities (opens in new tab). In the United Kingdom, the regulator is the Information Commissioner’s Office (opens in new tab).
We have not appointed a representative under Article 27: our processing of EEA and UK information is occasional, involves no special-category data at scale or data about criminal convictions, and is unlikely to result in a risk to your rights, which is the exemption in Article 27(2). Write to us directly instead.
11. Sale & sharing of personal information
Evolutions does not sell personal information or share it for cross-context behavioral advertising. If that ever changes, we will update this policy and provide a clear “Do Not Sell or Share My Personal Information” mechanism before doing so.
Opt-out preference signals. We treat a Global Privacy Control (GPC) signal, or any other opt-out preference signal your browser or an extension sends, as a valid opt-out request from that browser. We still do not sell or share your personal information, so that part of the signal has nothing to act on. The analytics described in Cookies & tracking is a different matter, and there the signal does act.
When your browser sends GPC we act on it automatically — there is nothing for you to fill in. Analytics does not start, no analytics identifier is created, and any identifier we already held for you is deleted. We do not show you a consent banner in that state, because there is nothing left to ask. We confirm it where you can see it, in the words “Opt-Out Request Honored,” because since January 1, 2026 California has required a business to show that an opt-out request was honored rather than leave you guessing.
12. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information appropriate to its sensitivity, including access controls, encryption in transit, and reputable infrastructure providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If a breach happens. Where the GDPR or UK GDPR applies, we will report a personal-data breach to the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to people’s rights and freedoms. Where a breach is likely to result in a high risk to you, we will tell you without undue delay as well, except in the cases where the law allows us not to — for example, where the data was encrypted and unintelligible to whoever obtained it, or where we have since taken steps that remove the high risk. US state breach-notification laws apply separately, and we will notify affected people and regulators as those laws require. Where the information sits in a business customer’s account, we notify that customer without undue delay and assist with the notices they have to give.
13. International users
Evolutions is based in the United States, and we process and store information there. If you are outside the United States — including in the European Economic Area or the United Kingdom — what you send us is handled in a country whose data-protection laws differ from the ones you live under.
Writing to us is not itself a restricted transfer. When you fill in our form or send us an email, you disclose your information to us directly. Nobody in the EEA or the UK exports it on your behalf, so there is no exporter and Chapter V of the GDPR does not apply to that first step — this follows the European Data Protection Board’s Guidelines 05/2021 on the interplay of Article 3 and Chapter V. What happens next is a different matter: when we pass your information to the providers in Service providers, that onward disclosure is a transfer, and it needs a safeguard.
What we rely on, stated plainly. Where a provider’s data processing agreement already incorporates the European Commission’s Standard Contractual Clauses, we rely on those Clauses; Vercel’s agreement does, and it applies automatically. Not every provider we use is there yet. Where the Clauses are not in place, we are working with that provider to put a transfer addendum in place, and until it is signed we are not going to claim coverage we do not have. In the meantime we keep the exposure small: each provider receives only what its own service needs, and none of them may use it for their own purposes.
Some United States providers also self-certify under the EU-US Data Privacy Framework and its UK extension. Where one does, we treat that as one factor and not the whole answer. The Framework is valid today — the EU’s General Court dismissed the challenge to it in September 2025 — but that ruling is under appeal at the Court of Justice, and the US board that is meant to review the Framework each year has had no quorum since January 2025. That is why we do not lean on it alone.
If you want to know which safeguard applies to a particular provider, or to see a copy of the Clauses we rely on, ask us using the details in Contact us and we will tell you where things stand.
14. Children’s privacy
The Services are intended for businesses and professionals, not for children. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided us personal information, please contact us and we will delete it promptly.
15. Third-party links
The Site may link to third-party websites or services that we do not control. This policy does not apply to them, and we are not responsible for their practices. Review the privacy practices of any site before sharing personal information with it.
16. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes to our data practices, provide more prominent notice — such as a notice on this page or, where we hold contact information, direct communication.
17. Contact us
Questions about this policy, or requests to exercise your rights, may be sent to privacy@evolutionsmail.example.hq.com or by mail to Evolutions International Inc., 2817 Merrimac St, Fort Worth, TX 76107.