AI transparency

AI you can question.

What EVA does, where people remain responsible, and which evidence to ask for.

Legal informationContact EVALast revised: 10 September 2026

1. The system and its purpose

EVA combines conversational collection, competency frameworks, team and leadership analysis, workforce planning and talent matching. It helps organisations compare information and review options. Public Talk to EVA is an AI enquiry service; its instant responses can be wrong and do not themselves make employment decisions or approve customer access.

AI-generated content should be identified as such. The organisation using EVA must explain the AI-supported steps in its own process and the information and rights that apply to participants.

2. Reviewable matching criteria

EVA Talent Matching compares people with agreed role or mission criteria. With the same inputs, criteria, weights and configuration/version, the matching calculation produces the same result. This describes the configured matching calculation, not the wording generated by a language model.

The decision owner can review the criteria, weights, evidence and gaps. A score is not a probability of success, and a high total must not override a mandatory eligibility requirement. Employee and manager assessments are separate perspectives; agreement alone is not independent verification.

3. Human responsibility and oversight

EVA supports people accountable for workforce decisions. The customer agrees how recommendations enter its workflow, who reviews consequential recommendations and which actions require approval. A configured workflow is not evidence that every decision was meaningfully reviewed; the organisation must operate and check that process.

Where significant decisions are made solely by automated processing, the relevant legal rules and safeguards apply. Participants must be told what applies to their process and how to make representations, seek human intervention and contest the decision. Public examples do not authorise an employer to introduce automated decision-making.

4. Role-based access and data boundaries

Access is configured for the client and the use case. Employees, managers, HR and other authorised viewers can be given access to individual assessments and analyses where this is agreed. EVA and Customer Success configure role-based permissions accordingly. The customer’s notice and agreed access rules should explain who can see each kind of response and analysis.

Hosting, model providers, data transfers, retention and support access depend on the agreed deployment and processing arrangements. Request the applicable architecture, data processing agreement and sub-processor list. Vendor logos or a sample’s aggregate threshold do not establish a universal processing location or access rule.

EVA does not use customer personal data to train models for other organisations. This commitment does not mean that approved service providers never process data to deliver the agreed service.

5. Uses outside EVA’s design

EVA does not infer emotional state, analyse faces or voices for character, or score people on unrelated social behaviour. The customer’s use of any AI-supported process must comply with the applicable prohibitions and other legal requirements.

6. Assurance and procurement evidence

Certification, attestation, testing and procurement frameworks are different forms of evidence. Ask for the scope, date and applicable documentation for your assessment.

ISO/IEC 27001:2022 certified.
Certifying body INTERCERT, registration IC-IS-2412002. Certified since December 2024, current through the 2027 recertification cycle. Independently verifiable at iafcertsearch.org.
SOC 2 Type II attested.
Our report covers all five Trust Service Criteria. It is confidential under the auditor's terms and available under NDA on request.
Penetration testing.
Independently tested against the OWASP Top 10 (2025). All findings remediated.
Public-sector procurement.
Ask EVA to confirm the applicable procurement route and current listing for your purchase. A procurement listing is separate from security certification.
GDPR: by design.
A design commitment we engineer against, not a certification; our Article 50 transparency posture is described above.

Security reports may be shared under NDA. A listing or certificate does not establish that every customer deployment or workforce decision complies with every applicable law.

7. Deployment responsibilities

  • EVA: the system’s design, agreed documentation and technical controls, and its obligations under the applicable customer and data processing agreements.
  • The customer: the purpose, lawful basis, decision criteria, authorised users, participant notices, review responsibilities and actual use of the system.
  • Both parties: agree the relevant evidence, instructions, configuration, data boundaries and responsibilities before deployment.

EU AI Act classification depends on intended purpose and use. Qualifying recruitment and worker-management use cases can be high-risk. The European Commission’s current guidance places the relevant Annex III obligations from 2 December 2027; AI conversation-transparency requirements apply from 2 August 2026. These dates do not suspend existing data protection, employment or anti-discrimination duties. See the European Commission’s framework and timeline.

8. Questions and rights

If you are a candidate or employee in a customer deployment, contact the organisation identified in its notice about the criteria, information and review route relevant to your outcome. If you contact EVA, we can help identify the responsible organisation and assist it as required.

If you used public Talk to EVA, contact ben@eva.ai about your information or a response. See our privacy policy, complaint procedure and notice for EVA’s own recruitment.

If you are evaluating EVA, ask for the relevant instructions, matching documentation, architecture, data processing agreement, sub-processor information and security evidence. Availability and scope of each document should be confirmed for your proposed deployment.