Skip to content
evolus
app.evolus.ai

Privacy Notice on the processing of personal data

Evolus platform, app.evolus.ai and mobile applications

Version 2.1, published on 26 September 2026, effective from 21 October 2026.

SHA-256 fingerprint: 935174ac61e44049dc90f229b5a9dfc658e5a1bd94b9e0d4dd2ed47f9c613f1b

Download the canonical text (.md)

This is a courtesy translation. In case of discrepancy, the Italian version prevails.

This notice is provided pursuant to articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and describes how the personal data of users who access and use the Evolus platform through the portal app.evolus.ai and through the Evolus and Evo Assistant mobile applications are processed. The processing specific to the Evo Assistant app is described in section 12.

This notice concerns exclusively the Evolus platform and is distinct from the privacy notice of the evolus.ai showcase website.

1. Data controller

The data controller is CodeDesign S.r.l., with registered office at Via Nino Pesce 38, 18018 Taggia (IM), VAT No. IT01739830089 (hereinafter "CodeDesign" or "Provider").

For any request relating to the processing of personal data and for the exercise of the rights provided for by the GDPR, you may write to: privacy@codedesign.it.

CodeDesign has not designated a data protection officer pursuant to art. 37 of the GDPR, having assessed that the conditions for doing so do not apply. The privacy@codedesign.it mailbox is monitored by the data protection contact person.

2. CodeDesign's role and scope of the notice

In providing the Evolus platform, CodeDesign acts in a dual role:

  • a) as data controller, for the data relating to the creation and management of accounts, to authentication, to the use of the platform, to security, to assistance and to compliance with legal obligations;
  • b) as data processor pursuant to art. 28 GDPR, for the personal data that are processed on behalf of the Customer (the organisation that subscribed) through the Employee AI and the platform's features. Such processing is governed by the Data Processing Agreement, which constitutes Annex A to the General Conditions of Use and which the Customer accepts online at the same time as the Conditions, without a separate signature. The Agreement identifies the Customer as the Controller of such data and is published at https://evolus.ai/en/data-processing-agreement; the General Conditions of Use are published at https://evolus.ai/en/terms-of-use.

For the data processed on behalf of the Customer, the notice to data subjects and the collection of any legal bases are the responsibility of the Customer. This notice mainly describes the processing operations for which CodeDesign acts as Controller and provides transparency on the entire processing architecture of the platform.

3. Categories of personal data processed

Depending on the features activated, the following categories of data may be processed:

Account and profile data

Access to the portal and to the mobile applications takes place through the Keycloak identity system (identity.evolus.ai). The following are processed: first name, last name, username, email address, role and groups of membership, preferred language and any profile image (avatar).

Billing data

When an organisation is activated, from the portal or from the Evo Assistant app, the name, the tax country and, depending on the case, the tax code of the natural person not acting as a professional or the VAT number are processed.

Data relating to the acceptance of contractual documents and to consents

When the General Conditions of Use are accepted, from the portal or from the Evo Assistant app, the following are recorded as evidence of the act: name and verified email address of the person accepting, their roles in the organisation, the billing data of the contracting party, date and time, IP address, identifier of the software used (user agent), the text of the statement of powers and the versions of the documents accepted. Any consent to receive commercial communications, and its withdrawal, are recorded as separate acts.

Usage and technical data

Data relating to the use of the Service, technical logs, session identifiers, diagnostic and operational telemetry data, audit trail records of the activities performed on the platform.

Content entered into the platform

  • content of conversations and messages exchanged with the Employee AI via web chat, instant messaging and email;
  • recordings and transcriptions of voice conversations, where the voice feature is activated;
  • documents, files and content uploaded to the Knowledge Base for information retrieval (RAG);
  • identification and contact data present in the address book (verified contacts) and in the content managed by the Employee AI;
  • configurations, instructions and automations defined by the Customer;
  • content processed by the Evo Assistant app, which resides on the user's phone and reaches the platform servers only in the cases described in section 12.

The content may include personal data of third parties (employees, collaborators, customers and contacts of the Customer). The Customer is responsible for the lawfulness of their entry and for the provision of the related notices.

Data relating to purchases made through the stores

For the subscriptions and top-ups purchased in the Evo Assistant app through the App Store or Google Play, the data described in section 13 are processed.

5. Purposes and legal bases of the processing

The data are processed for the following purposes and on the following legal bases:

  • a) provision of the Evolus platform, of the Employee AI features and of the Evo Assistant app, management of the account and of authentication, management of subscriptions and purchases, legal basis: performance of the contract (art. 6.1.b GDPR);
  • b) assistance and technical support to the user, legal basis: performance of the contract and legitimate interest (art. 6.1.b and 6.1.f GDPR);
  • c) security of the platform, prevention of abuse and audit trail (Safety Engine), legal basis: the Provider's legitimate interest in ensuring the integrity and security of the Service (art. 6.1.f GDPR);
  • d) compliance with legal, accounting and tax obligations, legal basis: legal obligation (art. 6.1.c GDPR);
  • e) ascertainment, exercise or defence of a right in legal proceedings, legal basis: legitimate interest (art. 6.1.f GDPR);
  • f) sending of commercial communications from CodeDesign about Evolus, new features, events and offers, legal basis: consent (art. 6.1.a GDPR), optional and revocable at any time from the profile settings in the portal or from the "You" section of the Evo Assistant app;
  • g) diagnostics of the operation of the Evo Assistant app, described in section 12, legal basis: the Provider's legitimate interest in the correct operation of the app (art. 6.1.f GDPR), with the possibility for the user to disable it at any time from the app.

The Customer's data and content are not used by CodeDesign for its own purposes, nor to train, retrain, fine-tune or evaluate artificial intelligence models of its own. On the use of the content by the model providers, see section 7.

6. Processing methods and security measures

The processing is carried out with automated tools and, where necessary, with authorised manual interventions. CodeDesign adopts technical and organisational measures adequate pursuant to art. 32 GDPR, including:

  • access control: centralised identity separate from the application, mandatory verification of the email address, granular permissions checked on every request with fail-closed behaviour, second authentication factor available by means of a one-time code sent by email;
  • encryption of data in transit: all communications between the clients and the platform take place over a channel encrypted with the TLS protocol;
  • application-level encryption of data at rest with the AES 256-bit algorithm in GCM mode, applied to the credentials and access keys of the services configured by the Customer, to the signing secrets of the channels and of the webhooks, to the credentials of the mailboxes and of the workflows, as well as to the transcripts and results of the meetings and to the requests and results of the daily brief processed for the Evo Assistant app. The content of the chat conversations and the documents uploaded to the knowledge libraries are not encrypted at the application level: they are protected by the access controls and by the encryption at rest of the underlying storage;
  • infrastructure: hosting on datacenters located in the European Union;
  • audit log of administrative operations, with the author, subject, date and time of each operation, retained for 24 months and then automatically deleted;
  • Safety Engine: system protecting against prompt injection, data exfiltration and improper use of the AI tools, with protections that the Customer cannot disable;
  • business continuity: hourly backups of the digital employees, encrypted at source before transmission to the remote archive, with an automatic restore check every 6 hours and a documented real restore test.

The complete and up-to-date list of the technical and organisational measures is published in Annex B to the General Conditions of Use, at https://evolus.ai/en/security-measures.

7. Artificial intelligence and model providers

To provide the conversational, synthesis and automation features, the platform transmits the necessary content to providers of artificial intelligence models and voice services (sub-processors indicated in section 8).

The Employee AI is a support and automation tool: it may generate inaccurate or incomplete outputs. The outputs do not replace human judgement and must be verified before relying on them for significant decisions.

Use of the content for training. CodeDesign selects providers whose terms contractually exclude the use of the content transmitted for the training of their own models, and activates, with the providers that allow it, the settings that disable the retention and the use of the content for their own purposes, including the opt-out parameters to be transmitted with each individual request where the provider offers that method. This exclusion is today guaranteed by the contractual terms of the providers and by the settings of CodeDesign's accounts, not by a technical control applied to each individual call by the platform software. The status provider by provider is published on the sub-processors page, at https://evolus.ai/en/subprocessors, and updated with each version of the page.

8. Recipients and sub-processors of the processing

The data may be communicated to external providers appointed as processors or sub-processors of the processing, selected from among entities that offer adequate guarantees regarding data protection and bound by contract with obligations equivalent to those assumed by CodeDesign. The sub-processors belong to the following categories:

  • cloud infrastructure, hosting and storage in the European Union: Microsoft (Microsoft Azure) and Hetzner Online GmbH;
  • routing of requests to language models: OpenRouter, Inc. and the downstream inference providers to which OpenRouter assigns the individual request;
  • voice synthesis, voice agents and speaker diarisation of meetings: ElevenLabs;
  • voice transcription: Deepgram, Inc. as the default provider, alternatively AssemblyAI, Inc. or OpenAI at the Customer's choice;
  • push notifications to the mobile apps: Expo (650 Industries, Inc.), Apple Inc. and Google LLC as the final transport;
  • web search engines used by the agents, when the search feature is activated;
  • payment processing and subscription management: Stripe;
  • third-party services activated by the Customer with its own credentials, such as Microsoft 365, Google Workspace, the Meta Platforms WhatsApp channel, the mail servers indicated by the Customer and the catalogue connectors. These services are not sub-processors of CodeDesign: they are recipients chosen by the Customer, which is answerable for them as controller of the related processing.

To distribute the updates of the code of the Evo Assistant app, CodeDesign uses, as controller, the Expo service of 650 Industries, Inc., United States, which receives only the technical data described in section 12. For purchases made in the Evo Assistant app, Apple and Google act as sellers and process the payment data as independent controllers, according to their own privacy notices (section 13).

The complete, named and up-to-date list of the sub-processors is published at https://evolus.ai/en/subprocessors, indicating for each of them the activity carried out, the country of establishment, the categories of data processed and the legal basis of any transfer. Changes to the list are communicated to the Customer's administrators with at least 30 days' notice, with the right to object on reasoned grounds. The data are not subject to dissemination or sale to third parties.

9. Transfer of data to third countries

The infrastructure for processing and storing the data is located in the European Union: the application services, the database, the file storage, the document search indexes, the identity system and the optical recognition of documents are hosted on European cloud infrastructure; the digital employees and their archives reside on a server in Germany; the backups are kept in Finland.

The provision of the Service nonetheless entails transfers of personal data to third countries, and in particular to the United States of America, for the routing of requests to language models, for the voice services, for voice transcription, for the delivery of push notifications and for the distribution of the updates of the code of the Evo Assistant app. CodeDesign does not represent that the data remain entirely within the European Economic Area.

Each transfer takes place, in the following order:

  • a) on the basis of an adequacy decision of the European Commission (art. 45 GDPR), where applicable to the country of the recipient;
  • b) for recipients established in the United States of America, on the basis of the EU-US Data Privacy Framework, where the entity is certified in the official register and for the categories of data covered by the certification;
  • c) in the absence of the preceding conditions, on the basis of the Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, module 3, incorporated into the agreement with the provider;
  • d) residually, on the basis of one of the derogations provided for by art. 49 GDPR.

The certification status of each recipient is indicated on the sub-processors page, at https://evolus.ai/en/subprocessors, and updated at each change.

Features that reduce transfers. Requests to the language models of the Evo Assistant app are in any case served only by providers that do not retain the content, as indicated in section 12. For Customers on the Enterprise Plan, European routing of the requests to the models, routing solely to zero-retention endpoints, the restriction of the model providers for the individual organisation and the European region of the voice provider are available. These features are activated for the Customers whose accepted commercial proposal provides for them. For the other plans, global routing, the inference providers on the published list and the global voice region apply. The plans are described in the price list published at https://evolus.ai/en/pricing.

10. Retention period

Personal data are retained for the time strictly necessary to achieve the purposes for which they are processed and, in any case:

  • account data and the Customer's content are retained for the duration of the contractual relationship. Upon termination, at the Customer's choice, they are returned or deleted: deletion from the production systems is completed within 60 days of termination and the copies present in the backups are overwritten by the normal rotation cycle within a further 30 days, save for legal retention obligations;
  • chat conversations are retained for the duration of the relationship and deleted at the end of the contract or at the Customer's request;
  • voice conversations are retained according to the period configured by the Customer for each voice agent, and a mode without retention of the content is available;
  • meeting recordings captured by means of the automatic participant are deleted after 30 days;
  • the audio of the meetings sent by the Evo Assistant app is deleted from the servers at the end of the transcription, or when the processing fails definitively; the results of those meetings are deleted after 7 days, reduced to 6 hours from the first consultation;
  • the results of the daily brief processed for the Evo Assistant app are deleted after 7 days, reduced to 6 hours from the first consultation; the content sent from the phone to prepare it is deleted at the end of the processing;
  • the audit log of administrative operations is retained for 24 months;
  • in the consumption detail of the digital employees, after 13 months the identifier and the name of the person interacting with the digital employee and the reference to the conversation are removed; the link to the platform account to which that person may have been traced remains;
  • the notifications in the portal are deleted after 90 days;
  • the temporary files produced by assisted processing are deleted within 24 hours;
  • the data stored on the phone by the Evo Assistant app remain on the phone until the user deletes them, uninstalls the app or deletes the account, as described in sections 12 and 14;
  • data processed for accounting and tax obligations are retained for the terms provided for by applicable law.

11. Rights of the data subject

Data subjects may exercise at any time the rights provided for by articles 15-22 GDPR, and in particular:

  • access to their personal data;
  • rectification of inaccurate data and integration of incomplete data;
  • erasure of data (right to be forgotten);
  • restriction of processing;
  • data portability;
  • objection to processing based on legitimate interest;
  • withdrawal of consent, where the processing is based on consent, without prejudice to the lawfulness of the processing carried out before the withdrawal.

Requests may be sent to privacy@codedesign.it; CodeDesign responds within one month of the request. Where the data subject is an employee, collaborator or contact of the Customer and the data are processed by CodeDesign on behalf of the Customer, the request will be forwarded to the Customer, as Controller, within 5 working days and without undue delay, and the data subject will be informed of this.

Users of the Evo Assistant app can also view, correct and delete from the app the memories stored on the phone. The account can be deleted directly from the app or from the portal, with the effects described in section 14.

The data subject also has the right to lodge a complaint with the competent supervisory authority (in Italy, the Garante per la Protezione dei Dati Personali, the Italian Data Protection Authority, www.garanteprivacy.it).

12. Evo Assistant app

Evo Assistant is the Evolus mobile application for iOS and Android that acts as a personal work assistant. It is used with an Evolus account, within an Evolus organisation. This section describes which data the app stores on the phone, which data it transmits to the platform servers and to which third parties.

Data stored on the phone

The app stores on the phone, in a separate database for each pair of organisation and user: the conversations with the assistant, the memories, the standing instructions (behaviours), the transcripts, summaries and items of the meetings, the outcomes of the daily brief and the log of the operations carried out by the assistant. In the same area of the app, the attachments of the conversations (photos, voice messages, documents generated by the assistant) and the audio of the meetings recorded or imported are stored as files.

These data are not synchronised with the Evolus servers and there is no backup copy managed by Evolus. The database is not encrypted by the app with a key of its own: it is protected by the isolation that the operating system reserves for the data of each app. The database and the attachments are included in the phone backups made by the operating system, if the user has enabled them; the audio of the meetings is excluded from them.

The audio of the meetings remains on the phone until the user deletes it, unless the user has chosen in the settings automatic deletion after a number of days; deleting the audio does not delete the text of the meeting.

Signing out of the account does not delete the data stored on the phone, which become available again at the next sign-in of the same user in the same organisation and are not accessible to another user who signs in from the same phone. Uninstalling the app removes the database and the files of the app from the phone. On iOS the access token and the mail passwords, stored in the system keychain, may survive the uninstallation: the app deletes them at the first launch after a new installation. The deletion of the account is described in section 14.

Data transmitted to the platform servers to generate the answers

To produce each answer, the app transmits to the platform servers the name, language and time zone of the user, the user's message, the recent part of the conversation and its summary, the relevant memories and behaviours, the text of the attached documents, the attached photos and the results of the readings carried out by the assistant while answering, for example the text of an email message, of an event or of a contact. The servers compose the request and forward it, through OpenRouter, to the provider of the language model. Together with the request, a stable session identifier, derived in a non-reversible form from the organisation and the user, is also transmitted to OpenRouter. For searching the memories, the texts of the memories are sent to the servers, and from these to OpenRouter, for the calculation of the numerical representations used in the search. In the same way, without retention by the Evolus servers, the title and summary of the conversations, the extraction and merging of the memories and the proposals of memories and labels derived from the meetings are processed.

The Evolus servers do not record this content in databases or file archives: they process it for the duration of the request. A consumption record remains, with the user, the organisation, the model and the quantities consumed, without the content. The requests to the language models of the Evo Assistant app are served, through OpenRouter, exclusively by providers that do not retain the content received: the constraint is set in the configuration of CodeDesign's account with OpenRouter.

Voice messages, and the sentences spoken in the voice conversation, are sent to the servers for transcription and from these to the transcription provider configured for the organisation; they are not retained by the Evolus servers. In the voice conversation, the text of the assistant's answers is sent to ElevenLabs for voice synthesis and is not retained by the Evolus servers.

When the assistant reads a web page or carries out a web search, the address of the page or the search is transmitted, through the Evolus servers, to OpenRouter, which reads the page or carries out the search through the engines indicated on the sub-processors page.

Meetings

The user can record a meeting, even with the screen locked, or import its audio. The audio is sent once to the platform servers, together with any names of the participants indicated by the user, the date and the time zone, and is transcribed by ElevenLabs with attribution of the contributions to the participants; the text is then summarised by means of the language models. The audio is deleted from the servers at the end of the transcription. The transcript, the summary and the names of the participants remain on the servers, encrypted, until they are collected by the app and in any case not beyond the terms indicated in section 10; when the app has saved the result on the phone, it requests its deletion from the servers. The notification announcing that the meeting is ready shows the title of the meeting.

Whoever records a meeting should inform the participants of it: the app reminds the user of this in the presentation of the feature and in the recording screen.

Email

The user can connect mailboxes to the app through the IMAP and SMTP protocols. The password is stored in the phone's keychain, is not included in backups and is not transmitted to the Evolus servers. The app connects directly to the mail server indicated by the user, over an encrypted channel, and reads the messages on demand, without saving their text on the phone. The daily brief keeps the subject and the sender of the messages it mentions, and the assistant's answers, saved in the conversation, may report their content. When the assistant reads a message in order to answer, its text is transmitted to the platform servers and to the model provider in the ways described above. A message is sent only after the user's confirmation.

To suggest the mail server parameters, the app may query Mozilla's automatic configuration service, to which it transmits only the domain of the email address.

Calendar, reminders, contacts and photos of the phone

With the permissions granted by the user in the operating system, the app reads on the phone the calendar, the reminders and the address book when the user asks the assistant to; it also reads the calendar and the reminders to prepare the daily brief, and the calendar to suggest the title and participants of a meeting that the user is about to record. It creates, modifies or deletes events, reminders and contacts only after the user's confirmation. Of the photos, it receives only the one chosen by the user with the system picker. What the app reads reaches the platform servers only within a request for an answer, the daily brief or the sending of a meeting. The app does not ask for access to the location and, on Android, does not use the camera.

Daily brief

If the user uses it, the app collects on the phone, from the connected sources, the items of the day (for example titles of events, reminders, subject and sender of messages, memories, meetings) and sends them to the platform servers, which prepare the text by means of the language models and may consult the services connected by the organisation. The content sent and the identity used for the connected services are deleted at the end of the processing; the result remains on the servers, encrypted, for the terms indicated in section 10. The notification announcing that the brief is ready does not show its content.

Services connected by the organisation

If the organisation has connected services from the catalogue, such as Microsoft 365 or Google Workspace, the user's authorisation is granted in the browser and the related tokens are stored on the platform servers, encrypted, and not on the phone. The assistant's requests to these services pass through the platform servers, which do not retain their content. The tokens of a connection not used for 90 days are deleted.

Push notifications

If the user allows notifications, the app registers on the platform servers the notification token of the device, with the operating system and the indication of the app. The token is deleted when the user signs out of the account and when the account is deleted.

App updates

At every launch the app checks for updates of its own code with the Expo service, to which it transmits technical data (platform, version and channel of the app, update in use) and a random identifier generated by the app, without content and without account data.

Diagnostics and reports

The app automatically sends diagnostic data to the observability infrastructure managed by CodeDesign: crashes and errors, of which the type and position in the code are transmitted but not the text; duration and outcome of the app's requests to the platform servers, without their content; usage sessions and screens visited; version of the app; characteristics of the device, including manufacturer, model, operating system, memory, battery level and mobile carrier, and, on Android devices, the name assigned to the device; a random identifier of the installation. The name, the email address and the account identifier of the user are not transmitted, nor is the content of conversations, memories, email, meetings or documents. The user can disable the sending at any time from the "You" section of the app, with immediate effect.

On the phone the app also keeps a technical error log, limited to the last 500 lines, which contains neither content nor the text of the errors and is not sent automatically.

The user can also report a problem from the app. The report is transmitted to the platform servers, linked to the account, with the text written by the user, the photos the user chooses to attach, the version of the app and of the operating system, the language and an excerpt of the technical log kept on the phone, which the user sees before sending and which contains no content. For support purposes, the diagnostic data of the organisation relating to the previous 24 hours may be associated with the report, and the subject and text of the report may be analysed by means of a language model to route it and to prepare a draft reply for the internal use of the support staff.

13. Payments and purchases through the stores

Payments made from the portal are processed by Stripe, indicated in section 8.

In the Evo Assistant app, the Evo Assistant subscription and the credit top-ups can be purchased exclusively through the App Store (Apple) or Google Play (Google). Apple and Google act as sellers: they manage the payment, issue the receipt and process the payment data and the store account data as independent controllers, according to their own privacy notices. CodeDesign does not receive the payment card data nor the name or email address of the user's Apple or Google account, does not retain the price paid nor the country of the store account and, for these purchases, does not issue an invoice.

At the end of the purchase, the app transmits to the platform servers the transaction signed by Apple or the Google Play purchase token. To activate and manage the purchase, CodeDesign extracts from it and retains: the identifiers of the transactions and of the subscription assigned by the store, the product purchased, the store environment, the dates of the purchase and of the period, the status of the automatic renewal, the events communicated by the store (renewals, cancellations, refunds), the organisation for which the purchase was made and the user who made it. The link with the organisation is obtained by means of a random code generated by the platform servers and transmitted to the store at the time of the purchase. To check the status of the purchases, the platform servers query the Apple and Google services, transmitting the identifiers of the transaction.

The cancellation of, and refund requests for, a purchase made through a store are managed in the store settings.

If the General Conditions of Use have not yet been accepted for the organisation, before the purchase the person who signs for the organisation accepts them from the app, with the recording of the data indicated in section 3.

14. Deletion of the account

The user can delete their Evolus account from the Evo Assistant app, from the "You" section, item "Delete account", or from the portal app.evolus.ai, from the profile page, item "Delete account", with the same effects. Before confirmation, a summary is shown of the organisations that will be deleted, of those the user will leave and of the subscriptions concerned. The deletion is final.

On the platform servers the deletion entails:

  • the deletion of the conversations, threads, meetings and daily briefs still present, with the related attachments and audio; of memberships, roles, groups and permissions; of personal API keys, notifications and preferences; of join requests; of the personal connections to the catalogue services with the related tokens; of the notification tokens of the devices;
  • the anonymisation of the user profile: first name, last name, email address, username, telephone, address, company, language and profile image are removed or replaced;
  • the deletion of the organisations of which the user is the sole owner, with the immediate closure, without refund, of the related subscriptions paid through the portal and the switching off of the renewal of Google Play subscriptions. An App Store subscription with automatic renewal active must be cancelled from the store settings before proceeding, and a paid contract managed directly by Evolus must be closed by the Provider at the user's request: while they are active, the deletion cannot be started;
  • the deletion of the account from the identity system, as the last step.

The following are retained, because of legal obligations or because they belong to the organisation, and remain linked to the anonymised profile: the evidence of acceptance of the General Conditions of Use and of the clauses, which contains the data indicated in section 3, including name, email address and IP address; the invoices and payments; the audit log, for the period indicated in section 10; the consumption data; the data of the purchases made through the stores described in section 13; the projects of the organisation; the compliance records of the voice configuration; the support reports. The audit log records the deletion with only the counts of the organisations and subscriptions concerned.

On the phone from which the user deletes the account through the app, the databases of all the user's organisations, the attachments, the audio of the meetings, the mail credentials, the scheduled notifications and, if no other user is signed in on the phone, the technical log are deleted. The preferences of the phone, such as the theme and the diagnostics setting, remain. The other phones on which the user had signed in to the app, and all phones when the deletion takes place from the portal, receive a silent notification and, if they do not receive it, check the status of the account at the first sign-in attempt: in both cases they delete the same data. The data of other users present on the same phone are not affected.

Anyone who cannot access their account can request its deletion by writing to privacy@codedesign.it.

15. Amendments to the notice

CodeDesign reserves the right to update this notice to reflect regulatory, technical or organisational changes. The updated version will be published on this page with an indication of the date of last update. You are invited to consult this page periodically.

CodeDesign S.r.l., Evolus platform. Registered office: Via Nino Pesce 38, 18018 Taggia (IM), VAT No. IT01739830089. Data protection contact: privacy@codedesign.it. Text of the notice: https://evolus.ai/en/privacy-policy.