Data Processing Agreement
Version 1.0 · last updated 30 July 2026
This Data Processing Agreement (“DPA”) forms part of the Everscope Terms when a customer uses Everscope to process personal data on its behalf. The customer is the controller and Deuver, [registered address to be added before public sales], is the processor.
Subject and duration
Processing is limited to operating, securing, supporting and improving the subscribed Everscope service for the duration of the subscription and the documented deletion period.
Nature and purpose
Everscope retrieves Microsoft Power BI and Fabric metadata, stores technical findings and enables governance workflows, ownership, policies, KPI mapping, evidence and exports. Everscope does not retrieve underlying semantic-model business-data rows.
Data and data subjects
Data can include Microsoft identity details, workspace and item metadata, owner and member names, activity aggregates, governance decisions, notes, deadlines, classifications and support information. Data subjects can include customer employees, contractors and other authorised Microsoft users.
Processor obligations
- Process data only on documented customer instructions and applicable law.
- Ensure authorised personnel are bound by confidentiality.
- Maintain risk-appropriate technical and organisational security measures.
- Assist with data-subject requests, security incidents and compliance enquiries.
- Delete or return customer data at the end of the service, subject to legal retention.
- Provide information reasonably needed to demonstrate compliance.
Security measures
Measures include tenant-scoped access control, least-privilege roles, HTTPS, secure HTTP-only sessions, Microsoft OAuth state and PKCE, encrypted Microsoft token caches, hashed passwords and API keys, signed Stripe webhooks, audit logging, distributed rate limiting and retention jobs. Production launch controls require documented backups, restore testing and incident procedures before unrestricted sales are enabled.
Subprocessors and transfers
The customer authorises the providers listed on the Subprocessor page. Everscope will provide reasonable prior notice of material changes and use appropriate contractual transfer safeguards where data can be processed outside the EEA.
Incidents
Everscope will notify the customer without undue delay after confirming a personal-data breach affecting customer data and will provide available information needed for the customer’s legal assessment and notification obligations.
Audit and contact
Audit requests must be proportionate, protect other customers and normally begin with existing documentation. Contact privacy@everscope.app. This DPA should be reviewed with legal counsel before unrestricted public sales.