Giuseppe Martini operates EVA AI. For account administration, billing metadata and the operation of the EVA AI service, the operator may act as data controller. When a customer studio uses EVA AI to communicate with its own WhatsApp contacts, the studio generally determines the purpose of that customer communication and EVA AI processes that data to provide the service under the Data Processing Agreement.
Privacy requests can be sent to support@eva-ai-assistant.com.
Data is processed to provide and secure the service, authenticate users, deliver and reconcile WhatsApp messages, manage bookings, operate subscriptions, support account recovery, diagnose failures and comply with applicable legal obligations. The exact legal basis depends on the role of the parties and the applicable law.
EVA AI relies on third-party services needed to operate the product. Depending on the configured production route, these may include Meta/WhatsApp for messaging, Stripe for billing, MongoDB Atlas for database storage, Anthropic and/or OpenAI for language-model processing, Resend for transactional account email, and Emergent for application hosting.
Configured production processing-location information: Switzerland, European Economic Area, and United States, depending on the configured subprocessors. The operator must keep this information aligned with the actual deployed infrastructure and provider arrangements.
Some providers may process data outside Switzerland or the country of the customer. Where cross-border safeguards are legally required, the operator and/or relevant provider arrangements must supply the required transfer mechanism. This policy does not claim a specific transfer mechanism unless it is actually configured and documented for production.
EVA AI does not publish a blanket automatic 90-day deletion promise. Operational data is retained only for as long as needed for the service, security, dispute handling or applicable legal obligations, with different categories and backups potentially following different lifecycles. Until a self-service export/deletion workflow is available, verified requests are handled through the contact address above.
EVA AI uses access controls, tenant scoping, password hashing, JWT/session revocation controls, webhook signature checks, security logging and authenticated application-level encryption for stored tenant WhatsApp access tokens. Network and infrastructure protections also depend on the configured hosting, database and third-party providers. No online service can guarantee absolute security.
Depending on the applicable law and the role of the requesting party, rights may include access, correction, deletion, restriction, objection or data portability. A studio remains responsible for handling requests from its own WhatsApp customers when it acts as controller; EVA AI will provide reasonable processor assistance under the DPA.
The version and effective date shown at the top identify the policy presented by EVA AI. Material updates may require updated notice or acceptance depending on the change and applicable law.
Contact: support@eva-ai-assistant.com · Bernstrasse 57b, 6003 Luzern, Switzerland