Compliance
Privacy Policy
Evalgist Shortlist helps users evaluate resumes and related application documents against stated criteria. Evalgist BV processes account, signup acquisition source, support, security, billing, and product-usage data as controller. For customer-provided candidate documents, Evalgist BV acts as processor for the customer.
Candidate documents may contain names, contact details, employment history, education, qualifications, notes, and other information supplied by or about candidates. This data is processed only to parse files, produce evidence-backed analysis, operate the product, provide support, secure the service, and maintain the billing and audit records needed to run the service.
Extracted document text is deleted after analysis. Original uploaded files are retained for up to 14 days for recovery and support, and can be deleted earlier from the product. Evidence-backed results, quotes, notes, and exports remain until the customer deletes the job, account, or relevant record. Beyond document retention, Evalgist keeps account, billing, security, audit, and legal records for as long as needed to operate the service and meet legal obligations, after which they are deleted.
Document analysis and OCR are routed through OpenRouter with zero data retention enabled, using models from the publishers named in the subprocessors register, currently Anthropic (Claude models, analysis) and Mistral (OCR of scanned documents). OpenRouter selects a zero-data-retention endpoint for the requested model; customer documents are not retained on those endpoints or used for training. AI processing is not limited to the EU; document storage remains in the EU.
Some subprocessors are based in the United States. Where a transfer outside the EEA occurs, Evalgist relies on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-U.S. Data Privacy Framework. The subprocessors register lists each provider's location and data residency.
Shortlist product analytics are configured without analytics cookies, browser persistence, autocapture, session recording, heatmaps, advertising pixels, surveys, or anonymous visitor experiments. When a visitor creates an account from a campaign link, Shortlist stores the campaign source on the authenticated product profile. We do not send resume content, candidate names, qualification text, extracted body text, or full referrer URLs to product analytics. Analytics is provided by PostHog (EU); error monitoring by Sentry (EU), with Session Replay disabled. The subprocessors register lists the infrastructure and AI providers used by the service, including the underlying AI model providers.
You can delete your Shortlist data from the Account page at any time, and can request access, rectification, erasure, export, restriction, or objection by emailing privacy@evalgist.ai. We respond within one month. Candidate requests should normally be handled by the customer as controller; Evalgist will assist the customer where the request concerns data processed in Shortlist.
The account privacy notice covers the shared Evalgist account and waitlist. The Data Processing Agreement sets out processor terms for customer documents. The Security page describes the technical and organisational controls currently in use.
Questions? Email privacy@evalgist.ai.
Last updated 2026-07-22