Document coverage
- Privacy policy and GDPR.
- Cookie policy and planned consent management.
- Terms and conditions.
- DPA and subprocessors.
- Security, SLA and support.
- AI policy for EVA AI.
- Acceptable use and accessibility.
Limits of this documentation
Effective compliance requires alignment between documents, contracts, technical configurations, suppliers, cookies actually used, internal processes and organisational measures. This page provides a documentary foundation but does not replace legal advice or a privacy audit.
Recommended next checks
- Cookie banner with granular consent and preference logs.
- Named list of subprocessors and transfers outside the EEA.
- Records of processing activities and an internal retention policy.
- Mapping of AI providers and legal bases.
- Accessibility testing of key workflows.
- Final legal review before definitive publication.








