- By default, data is stored on US infrastructure, encrypted in transit and at rest.
- Schools that need EU residency can use the EU deployment at eu.evidentk12.com, with student records stored and processed in Frankfurt.
- A signed DPA is available, and its subprocessor list names every vendor, by deployment.
- Row-level security scopes every record to its organization, and school admins have an audit log.
- Any user can Download my data from Settings; Delete Account permanently removes an individual account's students and logs.
Schools reviewing Evident ask the same questions: where does our data live, who can see it, which vendors touch it, and can we get it out or delete it. This article answers them plainly. Evident does not claim a GDPR certification; it offers a signed Data Processing Agreement and access-controlled workflows for your data protection officer or technology team to review.
Where your data is stored
The standard deployment runs on US infrastructure, with data encrypted in transit and at rest through the infrastructure providers. Row-level security scopes each record to its organization, so one school cannot read another's data.
Schools that need EU data residency can be onboarded to the EU deployment at eu.evidentk12.com. There, the database and authentication are in Frankfurt, application compute is pinned to Frankfurt, and records are not replicated to the US.
Translation and AI features
On the US deployment, family translation uses OpenAI and AI progress narratives use Anthropic. On the EU deployment, translation runs in the EU through Mistral AI, and AI progress narratives are not offered. The DPA's subprocessor list names every vendor for each deployment.
For translation, narratives, and note polish, the student's name is replaced with a placeholder before text is sent, and restored afterwards. School admins can turn AI note polish and AI progress narratives off for the organization at /dashboard/admin/settings.
The DPA and subprocessors
A signed Data Processing Agreement is available, whether you use the US or the EU deployment. It sets out what data Evident processes, the purposes, the security measures, and the subprocessors. The current subprocessor list, with the location each vendor processes in, is on the DPA page at /privacy/dpa, and schools with an executed DPA get 30 days' notice of changes.
Evident does not claim a GDPR certification. Schools subject to GDPR or similar laws should review the DPA with their data protection officer. Schools remain responsible for their own FERPA or national data-protection obligations.
Who can see what
Teachers see the students they added or that were shared with them. Note visibility is set per note: Private (the author, school admins, and special education leaders), Staff, Family, or Confidential (support team), which only counselors in the organization can read. Families see only what is shared to their student's portal.
School owners, admins, district admins, and principals can open the Audit Log at /dashboard/admin/audit to review changes to students, charts, and daily logs. Confidential-note changes, confidential exports, and reads of colleagues' confidential narratives are also audited.
Export and deletion
In Settings, Download my data exports the account's profile, students, charts, logs, evidence notes, and packets. Delete Account permanently deletes the account with its students, charts, and logs.
For a single student, Delete Permanently on the student card erases that student and their logs. To delete a whole school organization, an admin contacts support from the Danger Zone in admin settings.
Running your review
Bring your technology lead and your special education or student-support lead into one review. Useful questions: which deployment fits your residency needs, which subprocessors apply, who in your school will hold admin roles, whether AI features should stay on, and how staff departures will be handled.
The security overview at /security summarizes access control and infrastructure, and the pricing page covers purchasing. Contact us for the DPA.
Frequently asked questions
Does Evident comply with GDPR?
Evident offers an EU deployment in Frankfurt, a signed DPA, and export and deletion controls. It does not claim a GDPR certification; review the DPA with your data protection officer.
Where is our data stored?
On US infrastructure by default, or in Frankfurt on the EU deployment (eu.evidentk12.com). Either way, a signed DPA is available.
Is student data sent to AI providers?
Only for features that use them (translation, note polish, progress narratives), and with the student's name replaced first. Admins can turn note polish and narratives off, and narratives are not offered on the EU deployment.
Can we permanently delete a student's data?
Yes. Delete Permanently removes a student and their logs, and Delete Account removes an entire individual account.
Is Evident a safeguarding case management system?
No. Evident documents day-to-day behavior and well-being evidence. Statutory safeguarding concerns belong in your school's designated safeguarding system.