Privacy Policy
DRAFT — for legal review. This document is a working draft. It has not yet been reviewed by a Singapore-qualified solicitor or PDPA practitioner. Do not rely on it as legal advice. Have it reviewed before publishing.
This Privacy Policy explains how the evercom.ai service ("the Service") collects, uses, and protects personal data when end users (prospective students, education agents) sign in and chat with our AI assistant.
The Service is operated under the evercom.ai brand and made available to subscribing educational institutions ("tenants") under their own branding and subdomain. This Privacy Policy applies to all tenants of the Service.
A tenant institution may publish its own additional privacy notice addressing how it handles enquiries it receives via the Service. That tenant notice is in addition to, not in place of, this Policy.
1. Who we are
The Service is operated by evercom.ai, a sole proprietorship based in Singapore. We are the data controller for the personal data described in this Policy.
We expect to incorporate as a Singapore Pte Ltd in due course; that incorporation will not change how your data is handled, and you will be notified of the change in operating entity through this page.
2. What we collect
When you use the Service, we collect:
- Account information — your email address and name (provided directly or via Google Sign-In).
- Your role — whether you indicate you are a prospective student or an education agent.
- The tenant — which tenant institution's subdomain you signed in through.
- Conversation content — the messages you send and the AI assistant's replies.
- Interest signals — facts the AI extracts from the conversation to help the tenant follow up: country of residence, course interest, approximate budget, English proficiency, timeline.
- Technical metadata — IP address, browser user-agent, and timestamps, captured by AWS in standard service logs.
We do not knowingly collect payment information, passport numbers, government IDs, or other sensitive identifiers. If you paste such content into the chat, our safeguards attempt to redact it before storage. Please do not share sensitive personal information in the chat.
3. Why we collect it (and our legal basis)
- To provide the conversation — performance of the implicit contract you enter into when you start the chat.
- To remember your conversation so you can continue it later — same basis.
- To share qualified enquiries with the relevant tenant institution's admissions team — based on your indication of interest in that tenant during the conversation. You can ask us not to share at any time (Section 6).
- To monitor, secure, and improve the Service — our legitimate interest in operating the Service safely.
For users in jurisdictions with stricter consent requirements (e.g., EU/UK GDPR), the lawful bases above apply with the appropriate adjustments, and we will rely on your explicit consent where it is the appropriate basis.
4. Who we share it with
- The tenant institution's admissions team — we share your conversation summary and contact details with the tenant whose subdomain you used only when our analysis indicates you are a qualified prospective student of that tenant. The tenant uses it only to respond to your enquiry. We do not share data across tenants.
- AWS (Amazon Web Services) — our infrastructure provider. Your data is processed and stored in the AWS US East (N. Virginia) region.
- Anthropic Claude (via Amazon Bedrock) — the foundation model serving the AI assistant. AWS's terms prohibit Bedrock providers from training on customer data.
- No other third parties. We do not sell your data, and we do not share it for marketing by any party other than the tenant institution you identified an interest in.
5. Cross-border transfer
Your data is processed in the United States (AWS us-east-1). This is a cross-border transfer for users outside the United States. The transfer is necessary to provide the Service. AWS implements encryption in transit and at rest, and contractual safeguards appropriate for international transfers.
6. How long we keep it
- Conversation history — retained for 180 days, then deleted automatically.
- Contact details shared as a qualified lead — retained by the tenant institution for as long as your enquiry is active, in line with the tenant's own admissions records policy. Ask the tenant directly for their retention policy.
- Technical logs — standard AWS retention, typically 90 days.
7. Your rights
Under the Singapore Personal Data Protection Act 2012 (PDPA), and under EU/UK GDPR where applicable, you can:
- Access — ask what personal data we hold about you.
- Correct — ask us to correct inaccurate data.
- Delete / withdraw consent — ask us to delete your account and all associated conversation history, and to stop sharing your enquiry with any tenant.
- Object / restrict — object to processing or ask us to restrict it.
- Portability (where applicable) — receive your data in a machine-readable format.
To exercise any of these rights, email evercomai01@gmail.com from the email address you used to sign in. We'll respond within 30 days.
If you believe we have not complied with your rights, you can lodge a complaint with the Personal Data Protection Commission of Singapore (www.pdpc.gov.sg) or your local data-protection authority.
8. Security
We use:
- AWS Cognito for authentication, with Google federated sign-in.
- TLS (HTTPS) for all traffic.
- AWS-managed server-side encryption (KMS) for all stored data.
- Tenant-isolated data structures: your data is tagged with the tenant you signed in through and is not visible to any other tenant.
- Access to underlying AWS resources is limited to the operator (evercom.ai).
No system is perfectly secure. If we become aware of a personal-data breach affecting you, we will notify you and the relevant authority in accordance with applicable law.
9. Cookies and local storage
The Service uses a Cognito session cookie to keep you signed in, and local storage to remember your tenant context. We do not use advertising cookies, third-party analytics trackers, or any other cookies that follow you across sites.
10. Children
The Service is intended for prospective higher-education or post-secondary students who are at least 17 years old. If you are younger, please do not use the Service without the involvement of a parent or guardian.
11. AI-assistant disclosure
You are interacting with an AI assistant, not a human counsellor. The AI may produce inaccurate or incomplete information. Material decisions (course choice, fees, visa) should be confirmed with the tenant institution's human admissions team.
12. Changes
If we change anything meaningful, we will update the "Effective date" above and, where appropriate, notify you in the chat the next time you sign in. Material changes affecting how we share your data will be notified at least 14 days in advance where feasible.
13. Contact
Privacy questions, requests, or complaints: evercomai01@gmail.com.