Legal
Privacy Policy
Last updated
This document is authored in English. The English text is the version that governs.
This policy explains what personal information Evane handles, why, where it is kept and what you can do about it. It covers this website and the Evane application. Evane is operated by WeCarbon Technology Ltd ("we", "us").
1Who holds what
Evane is used by organisations to run events. That gives the information here two different origins, and they are governed differently.
Information about you as a user
Your account — your name, your email address, the sign-in methods you have registered — exists because you have an Evane account. We decide what is held and why, and this policy is the description of that.
Information your organisation puts into Evane
Everything inside a workspace — uploaded documents, contact records, meeting transcripts, chat history, calendar and mail synchronised from a connected Microsoft 365 account — belongs to the organisation whose workspace it is. They decide what goes in, who may see it and when it is removed. We hold and process it on their behalf and under their instructions, and we do not use it to train any model.
If your details appear in someone else's Evane workspace — because you were invited to an event, listed as a participant, or attended a meeting that was recorded — that organisation is the one to approach first. We will help them respond, and you can also contact us directly using the details at the end.
2This website
You can read every page of this website without giving us anything. There is one form, and a small number of things the page loads from elsewhere.
The enquiry form
If you submit an enquiry we receive the fields you filled in: your first and last name, email address, phone number, company, position, the type of enquiry, optionally how you heard about us, and whatever you wrote in the message box. We also receive the language you were browsing in, so the confirmation email comes back in that language.
That enquiry is sent to us by email and a confirmation is sent to you. It is not written into the Evane application or into any customer workspace. We use it to answer you and to keep track of the conversation that follows.
Your IP address
Submitting the form uses your IP address twice: to count submissions so the form cannot be flooded, and as part of the anti-bot check described below. The submission counter holds your IP address for one hour and then discards it. We do not otherwise log your IP address against your identity.
What the page loads from other companies
These requests on this site go somewhere that is not us, and each one lets that company see your IP address and browser details, because that is how an HTTP request works:
- Cloudflare Turnstile — the anti-bot widget on the enquiry form. Loaded on any page carrying the form; when you submit, we also send your IP address to Cloudflare so it can validate the challenge.
- Tencent Cloud Object Storage (Shanghai) — the background video on the home page is served from there.
- Google Fonts — only if you switch the site to Arabic. The Arabic typeface is fetched from Google at that moment. No other language triggers it.
- Microsoft Clarity — only if a Clarity project ID is configured for this deployment. The script is loaded from www.clarity.ms and Clarity receives the same request details any remote script does. It is used for session recordings and heatmaps on the public marketing site only; it is not loaded inside the application.
Cookies and analytics
Apart from the optional Microsoft Clarity script described above, this website sets no analytics or advertising cookies and runs no third-party analytics or session-recording script. The only thing stored in your browser is your language and theme preference, kept so the site does not forget them between visits. The application at global.evane.ai sets one further cookie, described in the next section.
3Your Evane account
An Evane account holds:
- your email address, your name, and a profile picture if you set one;
- the country you selected, and — if you answered them during onboarding — your organisation size, sector, and how you heard about Evane;
- the sign-in methods you have registered.
There is no password. You sign in with your Microsoft work account, with a Google account, with a passkey, or with a six-digit code sent to your email address.
Signing in with Microsoft or Google means that provider confirms your identity to us and passes us your email address and name. For Microsoft we also store the identifiers it gives us for your account and tenant, and — where you have granted it — an encrypted token that lets Evane read the Microsoft 365 data you authorised. If you use a passkey we store only its public key, which cannot be used to sign in as you; the private key never leaves your device.
Being signed in sets one cookie on the application, which identifies your session and expires after seven days. It is strictly necessary for the application to work and is not used for tracking.
If you send feedback from inside the application, we receive your message together with the page you were on, your browser and window size, and a screenshot if you chose to attach one.
4What a workspace holds
A workspace is where an organisation runs an event. Depending on what they use, it may contain:
- Documents — uploaded files, and files synchronised from a connected SharePoint or OneDrive. We store the file itself, its name, size and type, who uploaded it, and a text version extracted so the file can be searched and read by the assistant.
- People — the contacts an organisation tracks for an event: name, honorific, email, phone, organisation, job title, country, role at the event, photograph, notes, and any additional fields that organisation chose to add.
- Meetings — appointments, who attended, and the transcripts described in the next section.
- Conversations — the messages exchanged with the Evane assistant, and the record of what an automated agent did on the workspace's behalf.
- Mail and calendar — where a Microsoft 365 account is connected, the subject, sender, recipients, body and time of synchronised messages, and the details of synchronised calendar events.
- A change history — an entry for each change made to a record, showing who or what made it, when, and the values before and after.
We also record, for each request the assistant makes to an AI model, which model was used, how many tokens it consumed and what it cost. That record contains a one-way fingerprint of the request rather than its text: the contents of your documents and conversations are deliberately kept out of it.
5Meeting recording and transcription
This is the part of Evane that most affects people who are not its users, so it is set out in full.
When a workspace asks Evane to cover a meeting, Evane sends a bot into that meeting. The bot joins as a named participant and is visible in the participant list like anyone else. It captures the meeting audio and produces a transcript, and the workspace can then have that transcript summarised.
The transcript is stored in the workspace as a document, attributed line by line to the speaker the meeting platform identified. It is searchable, and it can be read by the assistant in the same way as any other document in that workspace.
What happens to the audio
The bot runs on infrastructure we operate ourselves — it is not a third-party meeting-notes service, and the meeting does not pass through another company's product.
By default the transcript is built from the live captions the meeting platform itself produces. On that setting the audio is never sent anywhere for transcription: it stays on the machine running the bot. A deployment can instead be configured to transcribe the recorded audio, in which case that audio is sent to a speech-to-text service we run on our own cloud tenancy — described under sub-processors — and not to a public transcription provider.
Evane does not copy the recording into the workspace or into its own storage. Where a recording is offered for playback, it is fetched from the recording service at the moment you ask for it. The transcript, by contrast, is stored in the workspace and stays there until someone deletes it.
Consent is the meeting organiser's responsibility
Recording a conversation without the knowledge of everyone in it is unlawful in many places, and the rules differ by country and sometimes by state or emirate. Evane does not obtain consent on anyone's behalf, and it does not have a feature that does so: the bot's presence in the participant list, together with whatever recording indicator the meeting platform itself displays, is the only notice given automatically.
The organisation that sends the bot is responsible for having whatever consent or notice the law of the meeting requires, from every participant, before the meeting starts. This is stated again as an obligation in our terms.
If you were recorded by an Evane bot and want the recording or transcript removed, ask the organisation that convened the meeting — it is held in their workspace and they can delete it. You can also contact us and we will put you in touch with them and support the request.
6How the AI works
Evane is built around an assistant that reads what is in a workspace and acts on it. Answering a question therefore means sending relevant material — parts of documents, transcripts, contact records, earlier messages in the conversation — to a large language model.
Two commitments about that:
- Your content is not used to train models. It is sent to obtain an answer and for no other purpose.
- It goes only to the model providers named under sub-processors below, under the terms we have with them.
AI output can be wrong. Evane writes drafts, summaries and suggested changes; it does not verify them, and neither the assistant nor this policy makes them accurate. Anything that matters should be checked by a person before it is relied on.
7Who else is involved
Running Evane means other companies handle some of this data on our behalf. We use them for the purposes below and nothing else, and we do not sell personal information to anyone.
Always involved
- Microsoft Azure — hosting. Our servers, databases, file storage and secrets all run on Azure, in the region a workspace belongs to. Effectively everything Evane holds is stored there.
- Azure AI Foundry — the AI models behind the assistant and behind document and meeting summarisation. Document text, transcripts and conversation content are sent here to produce an answer.
- Azure Communication Services — the email we send: sign-in codes, workspace invitations, reminders, comment notifications, and the replies to enquiries from this website. It receives the recipient address and the message.
Involved when you use the relevant feature
- Microsoft 365 — if you connect it. Evane reads the files, mail and calendar you authorised, and can send email on your behalf from the address you connected.
- Google — if you sign in with a Google account, Google confirms your identity and passes us your email address and name. Separately, the Arabic typeface used when you switch either the site or the application to Arabic is fetched from Google Fonts, which lets Google see the request.
- Anthropic — only if you choose it. The assistant's own models all run on Azure AI Foundry; Evane holds no Anthropic account of its own. Anthropic sees your content in two cases, both started by you: if you connect your own AI client (Claude among others) to Evane through our integration endpoint, what that client asks for is delivered into your session and handled by whichever provider runs it; and if someone in your workspace configures an Anthropic API key as the workspace's AI provider, that workspace's conversations run on your account instead of ours.
- Cloudflare — the anti-bot check on this website's enquiry form. It receives your IP address and the challenge token.
- Tencent Cloud — the background video on this website's home page is served from their object storage in Shanghai, which sees the request for it. No personal information is sent, and the application does not use them at all.
- Stripe — where payment is taken online. Card details go from your browser to Stripe directly and never reach our servers; we send them the workspace name and its internal identifier so a payment can be matched to an account.
- Microsoft Clarity — if a Clarity project ID is configured for the marketing site. Clarity records sessions and heatmaps on the public evane.ai pages; it is not loaded inside the application, and a deployment with no project ID does not use it at all.
- Connectors you authorise — Airtable, Fireflies.ai and similar services, each connected with your own credentials and reading only what you granted. Turning one on is a decision your workspace makes, not one we make for you.
The speech-to-text service used when a deployment transcribes recorded audio rather than platform captions runs inside our own Azure tenancy, so it is covered by the Azure entry above rather than being a separate company.
This list changes as the product does. When we add a sub-processor that handles personal information, this section is updated and the date at the top changes with it.
8Where your data is kept
Evane runs in more than one region, and a workspace is assigned to one when it is created. That assignment is permanent: there is no way to move a workspace to another region afterwards, and the workspace's contents physically live in that region's own database and storage, separate from every other region's.
A workspace created for an organisation in the United Arab Emirates is assigned to the UAE region. Everything else is assigned to the global region.
The exception, which matters
Accounts are not regional. Your user record, your registered sign-in methods, the encrypted token for a connected Microsoft account, and the assistant's notes about your personal preferences are all held in the global region regardless of which region your workspaces are in — there is one identity per person across the whole service, so there is one place it can live. The register of which workspaces exist and who belongs to them, in-application feedback, and Help Centre feedback are held globally for the same reason.
A practical consequence: when you use a workspace in the UAE region, that region looks up your account in the global region to confirm who you are. Your workspace content stays in its region; your identity is read across regions on every request.
Our infrastructure and the AI providers we use are described under sub-processors above. Some of them operate across borders, so where the region matters to you, read that section together with this one.
9How long we keep it, and how to remove it
We do not delete workspace content on a timer. What an organisation puts into Evane stays there until someone removes it, or until the workspace itself is deleted. That is deliberate — an event record is often needed years later — but it means deletion is something you do, not something that happens.
A few things do expire on their own:
- your sign-in session, after seven days;
- an upload you started and abandoned, together with the partial file, after twenty-four hours;
- the counter behind the enquiry form's rate limit, one hour after your first submission in a window.
Deleting a single item
Deleting a document, a contact, a meeting or a message removes the record itself rather than hiding it, and deleting an uploaded file also deletes the stored file and the text extracted from it. Comments are the one exception: deleting a comment hides it, and the text remains in the database until the workspace is deleted.
Deleting a workspace
A workspace owner can delete the whole workspace. That removes its records across every table and deletes its stored files. It cannot be undone and we cannot restore it for you, so export first.
Deleting your account
You can delete your own account from within the application. Doing so removes your user record, your registered passkeys, the link to your Microsoft account and any stored Microsoft token, your feedback, and your personal settings — in every region where you had workspaces, not just one.
Content you contributed to a workspace shared with other people is not deleted, because it is theirs as much as yours — files you uploaded, contacts you created, comments you wrote and shared chats stay in the workspace, with your name detached from them. Workspaces you alone owned and alone belonged to are deleted with the account.
Two situations block deletion until they are resolved: being the sole owner of a workspace that still has other members (transfer ownership first), and being the last administrator of the platform. In both cases we tell you which one it is.
Exporting
Any member of a workspace can export it as a structured file, with credentials and tokens removed. Use it before deleting anything you may want back.
Backups
Our databases are backed up, and a deleted record can persist in those backups for a period after it has gone from the live service. Backups are encrypted, are used only to restore the service after a failure, and roll off on their own schedule.
10Your rights
Depending on where you live, you may have the right to ask what personal information we hold about you, to have it corrected, to have it deleted, to receive a copy in a portable form, and to object to or restrict some uses of it. Where we rely on your consent, you can withdraw it.
For your account, the application itself is the fastest route: your profile is editable, your workspaces are exportable and your account is deletable, all without asking us.
For information held inside an organisation's workspace, that organisation decides. Ask them first; if you cannot reach them, or you do not know which organisation holds your details, contact us and we will identify them and pass the request on.
Exercising a right costs nothing and we will not treat you differently for it. If we cannot do what you ask we will say why. You may also complain to the data protection authority where you live.
11Security
What we actually do:
- Traffic between you and Evane is encrypted in transit, and stored data is encrypted at rest by our cloud provider.
- There are no passwords to steal: sign-in is through your Microsoft work account or a passkey, and a passkey's private key never leaves your device.
- The token that lets Evane read your Microsoft 365 data is encrypted before it is stored, and is never shown back to anyone.
- Each region's workspace data is in its own database, and access to a workspace is enforced on the server for every request rather than in the interface.
- Changes to records are written to a change history showing who made them and what they were before.
- Our own administrative actions are logged separately.
We hold no security certification and this policy claims none. No service is perfectly secure, and we cannot guarantee that yours will never be compromised.
If a breach affects your personal information we will act on it and notify those who need to be notified as the applicable law requires.
12Children
Evane is a business product and is not intended for children. We do not knowingly collect information from a child. If you believe a child's information has reached us, tell us and we will remove it.
13Changes to this policy
We update this policy when what we do changes. The date at the top says when it last changed. Where a change materially affects how we handle your personal information, we will give notice — by email or in the application — rather than relying on you to re-read the page.
14Contact us
Questions about this policy, or a request about your personal information, go to WeCarbon Technology Ltd, info@we-carbon.com, 3F DIFC Innovation One, Dubai, UAE. You can also use the enquiry form on this site.

