This DPA forms part of the Everscope Terms when a business customer uses Everscope to process personal data on its behalf. The customer is controller and Everscope is processor.
1. Subject and duration
The customer appoints Everscope as processor for the duration of the Everscope subscription and documented deletion period. Processing is limited to operating, securing and delivering the service on documented customer instructions.
2. Nature and purpose
Everscope retrieves Microsoft Power BI and Fabric metadata, produces deterministic findings and supports ownership, governance workflow and audit evidence. Everscope does not retrieve business-data rows or execute customer data queries.
3. Data and data subjects
Data can include Microsoft identity details, workspace and item metadata, owner and member names, operational metadata, governance decisions, notes, classifications and support information. Data subjects can include authorised customer employees and contractors.
4. Processor obligations
Everscope will process data only on documented instructions and applicable law; bind authorised personnel to confidentiality; maintain risk-appropriate security; assist with data-subject requests and incidents; delete or return data as documented; and provide information needed to demonstrate compliance.
5. Security measures
Measures include tenant-scoped authorisation, least privilege, HTTPS, secure HTTP-only sessions, Microsoft OAuth state and PKCE, encrypted Microsoft token caches, hashed passwords and API keys, signed payment webhooks, audit logging, rate limiting, retention jobs and EU-hosted production workloads.
6. Subprocessors and transfers
The customer authorises the subprocessors published at https://everscope.app/subprocessors. Everscope will publish material changes and use provider contractual transfer safeguards where processing occurs outside the EEA.
7. Incidents
Everscope will notify the customer without undue delay after confirming a personal-data breach affecting customer data and provide available information needed for the customer's legal assessment.
8. Deletion, return and audit
Customers can export machine-readable account and tenant records and delete Everscope-held customer data through self-service controls. Proportionate audit requests normally begin with the public trust documentation and evidence available in the product.