Privacy Policy
Last updated: 26 July 2026
Effective date: 26 July 2026
1. Introduction
This Privacy Policy explains how Randova Ltd ("Randova", "Evora", "we", "us", or "our") collects, uses, stores, protects, and discloses personal data when you use the Evora mobile application, associated websites, customer-support channels, and related services collectively referred to as the "Service".
Evora provides artificial intelligence-assisted facial analysis, appearance insights, personalised recommendations, progress-tracking features, and related self-improvement tools. The Service may process photographs of your face and information derived from those photographs. We recognise that facial images and related analysis data can be highly sensitive, and we apply enhanced safeguards to this information.
This Privacy Policy is intended to comply with applicable privacy and data-protection laws, including, where relevant:
- the UK General Data Protection Regulation;
- the Data Protection Act 2018;
- the Data (Use and Access) Act 2026;
- the EU General Data Protection Regulation;
- the Privacy and Electronic Communications Regulations;
- the California Consumer Privacy Act, as amended by the California Privacy Rights Act;
- other applicable United States state privacy laws; and
- other applicable international privacy and consumer-protection laws.
Under UK and European data-protection law, facial information may constitute biometric data where it results from specific technical processing of physical characteristics. Biometric data receives additional protection where it is used to identify an individual. Information inferred from a facial image may also constitute sensitive or special-category data depending on its nature and intended use.
Please read this Privacy Policy carefully before using Evora.
2. Data Controller
For the purposes of UK and European data-protection law, Randova Ltd is the controller responsible for personal data processed through Evora, except where this Privacy Policy states otherwise.
Privacy enquiries may be directed to:
Email: [email protected]
Where legally required, additional details concerning our registered office, local representative, or data-protection representative will be made available through the Service or upon request.
3. Scope of This Privacy Policy
This Privacy Policy applies to personal data processed through:
- the Evora mobile application;
- Evora account and onboarding processes;
- facial-image upload or camera functionality;
- artificial intelligence analysis;
- personalised recommendations;
- subscriptions and purchase verification;
- customer-support communications;
- analytics, diagnostics, and security systems;
- notifications and marketing communications; and
- websites or online pages that link to this Privacy Policy.
This Privacy Policy does not apply to third-party services, websites, or applications that are governed by their own privacy notices.
4. Categories of Personal Data We Collect
The personal data we collect depends on how you use Evora, the permissions you grant, your device settings, and the features made available to you.
4.1 Account and identity information
We may collect:
- your name or chosen display name;
- email address;
- account identifier;
- authentication credentials or authentication tokens;
- sign-in provider information;
- age range or confirmation that you meet the minimum age requirement;
- country or general region; and
- account preferences.
Where anonymous or guest access is available, we may assign an anonymous user identifier to maintain your session and associate your app data with your device or account.
We do not intentionally collect government identification numbers unless required for a specific legal, security, or age-verification purpose and separately disclosed to you.
4.2 Onboarding and profile information
We may collect information you provide during onboarding or while using the Service, including:
- age range;
- beauty, appearance, skincare, or self-improvement goals;
- areas of concern;
- skin-related information;
- lifestyle and routine information;
- sleep, hydration, exercise, or wellness-related responses;
- personal preferences;
- motivations for using the Service;
- free-text responses; and
- information used to personalise recommendations.
Some responses may reveal or permit inferences about health, ethnicity, physical characteristics, or other sensitive matters. You are not required to provide optional information.
4.3 Photographs, images, and camera data
When you choose to use facial-analysis features, we may collect or process:
- photographs uploaded from your device;
- photographs captured using your device camera;
- facial images;
- image metadata, where available;
- image orientation, quality, lighting, and framing information;
- cropped or resized versions of submitted images; and
- temporary image files generated during processing.
Evora will request access to your camera or photo library only where needed for a feature you select. You may withdraw these permissions through your device settings, although doing so may prevent certain features from functioning.
You must only upload images that you own or are legally authorised to use.
4.4 Facial-analysis and derived information
Evora may use automated systems to analyse a facial image and generate data such as:
- facial landmarks and relative measurements;
- facial proportions;
- facial symmetry estimates;
- apparent skin characteristics;
- visible texture, tone, redness, blemishes, or similar appearance-related observations;
- feature-specific assessments;
- image-quality or pose information;
- generated scores, classifications, or confidence values;
- personalised recommendations;
- analysis summaries; and
- changes or trends shown across multiple assessments.
These outputs are estimates generated from images and user-provided information. They may be inaccurate, incomplete, or affected by lighting, camera quality, makeup, facial expression, angle, image editing, or other factors.
4.5 Biometric and sensitive information
Facial images and technical measurements derived from facial images may constitute biometric information under some laws.
Unless we clearly tell you otherwise and obtain any legally required consent, Evora does not use facial information to:
- verify your identity;
- authenticate access to your account;
- recognise you across unrelated services;
- identify you from a database of individuals;
- conduct surveillance; or
- determine whether you are a specific known person.
The purpose of Evora's facial processing is to provide appearance-related analysis and personalised insights requested by you.
Even where facial information is not processed to identify you, it remains personal data and may be considered sensitive personal information in certain jurisdictions. Processing remains regulated even where information is held only briefly or deleted soon after analysis.
We do not intend to infer or determine:
- race or ethnicity;
- religious or philosophical beliefs;
- political opinions;
- sexual orientation;
- genetic information;
- medical diagnoses;
- disability status; or
- emotional or psychological conditions.
Our systems may nevertheless produce unintended correlations or inferences. We seek to limit this risk through data minimisation, testing, access controls, and restrictions on permitted use.
4.6 Subscription and transaction information
If you purchase a subscription or other paid service, payments are generally processed by Apple, Google, or another authorised payment platform.
We may receive:
- purchase and subscription identifiers;
- product purchased;
- subscription status;
- renewal and expiry information;
- trial status;
- transaction date;
- refund or cancellation status;
- storefront or country;
- limited billing-related metadata; and
- entitlement information.
We do not ordinarily receive or store your full payment-card number, bank-account details, or payment security code.
4.7 Device, technical, and usage information
We may automatically collect:
- device type and model;
- operating-system version;
- app version;
- device or installation identifiers;
- language and regional settings;
- time zone;
- IP address;
- approximate location derived from IP address;
- network information;
- session timestamps;
- screens viewed;
- buttons or features used;
- onboarding and feature-completion events;
- subscription events;
- crash logs;
- performance and diagnostic information;
- error reports; and
- security-related events.
We do not collect precise GPS location unless a specific feature requires it, you are clearly informed, and you grant permission.
4.8 Communications and support information
When you contact us, we may collect:
- your name and email address;
- the content of your message;
- screenshots or attachments;
- device and account information;
- support history; and
- information required to investigate and resolve your enquiry.
Please avoid sending facial images, medical information, passwords, or other highly sensitive information through ordinary email unless necessary.
4.9 Notification information
If you enable notifications, we may process:
- push-notification tokens;
- notification preferences;
- delivery status;
- interaction with notifications; and
- reminder settings.
The operating-system provider may also process information relating to notification delivery under its own privacy policy.
4.10 Information from third parties
We may receive information from:
- Apple or Google;
- authentication providers;
- subscription-management providers;
- cloud-hosting providers;
- artificial-intelligence service providers;
- analytics and crash-reporting providers;
- customer-support providers;
- fraud-prevention providers; and
- other service providers acting on our instructions.
5. How We Collect Personal Data
We collect personal data:
- directly from you;
- when you create or use an account;
- when you answer onboarding questions;
- when you upload or capture an image;
- when you request an analysis;
- when you contact customer support;
- automatically from your device and use of the Service;
- from app stores and payment providers;
- from authentication providers; and
- from service providers supporting the operation of Evora.
We do not collect facial images in the background without your action. Facial processing begins only when you use a feature that requires an image and provide or capture that image.
6. Purposes for Which We Use Personal Data
We may use personal data for the following purposes.
6.1 Providing the Service
We use personal data to:
- create and maintain your account;
- authenticate sessions;
- deliver onboarding;
- process submitted images;
- generate facial-analysis results;
- provide personalised recommendations;
- display previous assessments or progress;
- synchronise data across supported devices;
- provide premium features;
- restore purchases; and
- maintain your preferences.
6.2 Personalisation
We may use your answers, activity, previous assessments, and preferences to:
- tailor the content shown to you;
- prioritise relevant recommendations;
- adapt reminders;
- personalise educational information; and
- improve the relevance of future analysis.
6.3 Safety, security, and fraud prevention
We may use information to:
- protect accounts and infrastructure;
- detect suspicious activity;
- prevent misuse and fraud;
- enforce usage limits;
- investigate security incidents;
- prevent automated abuse;
- protect our users, personnel, and rights; and
- comply with legal obligations.
6.4 Service improvement and quality assurance
We may use limited data to:
- diagnose technical problems;
- monitor reliability and performance;
- assess feature usage;
- test user-interface changes;
- investigate inaccurate outputs;
- improve accessibility;
- evaluate system performance; and
- improve the safety and quality of the Service.
Where reasonably possible, we use aggregated, de-identified, or pseudonymised information for these purposes.
6.5 Artificial intelligence operation and improvement
We may transmit the information necessary to process your request to contracted artificial-intelligence service providers.
We will not use identifiable facial images to train general-purpose artificial-intelligence models operated by us without:
- clearly informing you;
- identifying the relevant purpose;
- establishing a lawful basis;
- obtaining explicit consent where required; and
- providing an appropriate method to withdraw consent.
Our third-party processors are contractually permitted to process information only to provide services to us, subject to their agreed data-use and retention terms.
Where a provider offers settings that prevent customer data from being used for general model training, we seek to use those settings.
6.6 Communications
We may use your contact information to:
- respond to support requests;
- send service and security notices;
- notify you of material changes;
- provide purchase or subscription information;
- send reminders you have requested; and
- send promotional communications where permitted.
You may opt out of promotional email at any time. You may disable push notifications through your device settings.
6.7 Legal and compliance purposes
We may process personal data to:
- comply with laws and lawful requests;
- establish, exercise, or defend legal claims;
- respond to regulators and courts;
- enforce our terms;
- protect legal rights;
- maintain required records; and
- support corporate transactions.
7. Lawful Bases for Processing
Where UK or European data-protection law applies, we rely on one or more of the following lawful bases.
7.1 Performance of a contract
We process information where necessary to provide the Service you request, including:
- maintaining your account;
- processing submitted images;
- generating requested analysis;
- providing recommendations;
- managing subscriptions and entitlements; and
- providing customer support.
7.2 Consent
We may rely on consent for:
- accessing your camera or photo library;
- processing optional sensitive information;
- certain facial or biometric processing;
- marketing communications;
- non-essential analytics;
- notifications; and
- other purposes where consent is legally required.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that took place before withdrawal.
7.3 Explicit consent for special-category data
Where information constitutes special-category data under UK or European law, we may rely on your explicit consent under Article 9.
Processing special-category information ordinarily requires both a lawful basis under Article 6 and a separate condition under Article 9. Explicit consent is often the most appropriate condition for optional biometric processing.
Where explicit consent is required, we will present a clear consent request before the relevant processing begins.
You may refuse or withdraw such consent. Where the processing is essential to a facial-analysis feature, refusing or withdrawing consent will mean that the relevant feature cannot be provided.
7.4 Legitimate interests
We may process information where necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights. These interests may include:
- protecting the Service;
- preventing fraud and abuse;
- improving performance and reliability;
- understanding general feature usage;
- defending legal claims;
- maintaining business operations; and
- providing non-intrusive service communications.
We do not rely on legitimate interests where consent is legally required.
7.5 Legal obligation
We may process information where necessary to comply with legal, regulatory, accounting, tax, or law-enforcement obligations.
7.6 Vital interests
In exceptional circumstances, we may process information where necessary to protect a person's life or physical safety.
8. Automated Processing and Artificial Intelligence
Evora uses automated systems and artificial intelligence to analyse images and generate insights.
Automated processing may:
- identify facial landmarks;
- calculate relative proportions;
- categorise visible features;
- estimate appearance-related characteristics;
- produce scores or summaries;
- compare current and previous user-submitted assessments; and
- generate recommendations.
These results are informational estimates. They are not professional medical, dermatological, psychological, or healthcare assessments.
Evora does not intend to make solely automated decisions that produce legal effects or similarly significant effects concerning you.
You should not rely on Evora to:
- diagnose or treat a medical condition;
- determine suitability for medical treatment;
- assess your mental health;
- make employment, insurance, credit, educational, housing, or legal decisions; or
- confirm your identity.
If you believe an automated result is inaccurate or harmful, you may stop using the feature, delete the relevant information, or contact us.
Where applicable law gives you rights concerning automated decision-making, you may request information about the processing, express your point of view, contest a decision, or request human review.
Solely automated decision-making using special-category data that has legal or similarly significant effects is subject to heightened restrictions under UK data-protection law.
10. Sale, Sharing, and Targeted Advertising
We do not sell facial images, facial-analysis data, or sensitive personal information in exchange for money.
We do not use facial-analysis data for third-party targeted advertising.
We do not knowingly share facial data with data brokers.
If our practices change in a way that constitutes a "sale", "sharing", or use for targeted advertising under applicable United States privacy laws, we will update this Privacy Policy and provide legally required opt-out mechanisms before commencing that activity.
We will not use or disclose sensitive personal information for purposes beyond those reasonably necessary to provide the Service, maintain security, comply with law, or fulfil purposes clearly disclosed to you.
11. Facial Data Retention and Deletion
We seek to retain facial images and derived data only for as long as reasonably necessary for the disclosed purpose.
11.1 Temporary processing
Where an image is required only to generate an analysis and is not intended to be saved as part of your account, we seek to delete the source image or render it non-identifiable after processing and any limited operational retention required for secure transmission, error recovery, and abuse prevention.
11.2 Saved assessments
Where Evora permits you to save photographs, results, or progress history, the relevant information may remain associated with your account until:
- you delete the individual item;
- you delete your account;
- the feature is discontinued;
- the retention period expires; or
- continued retention is no longer necessary.
11.3 Derived facial data
Facial landmarks, measurements, analysis results, and other derived data may be retained where required to provide saved results, comparisons, personalisation, or progress tracking.
Derived facial data is not necessarily anonymous merely because the original image has been deleted.
11.4 Processor retention
Our service providers may temporarily retain information in accordance with their contractual retention schedules, security requirements, and backup processes.
We require processors to delete or return personal data after the relevant services end unless retention is legally required.
11.5 Backups
Deleted information may remain temporarily in encrypted or access-restricted backups until the relevant backup is overwritten or securely deleted.
Backup information is not used for ordinary product purposes and will be restored only where necessary for disaster recovery, security, or legal compliance.
12. General Data-Retention Periods
We determine retention periods by considering:
- the purpose for which the information was collected;
- whether the information is needed to provide an active account;
- user expectations;
- legal, accounting, and tax requirements;
- security and fraud-prevention needs;
- limitation periods for legal claims;
- sensitivity and risk;
- whether the information can be aggregated or de-identified; and
- whether you request deletion.
Typical retention categories may include:
- Account information: for the lifetime of the account and a limited period afterwards;
- Saved assessments and facial-analysis data: until deleted by you, your account is deleted, or retention is no longer necessary;
- Temporary image-processing files: only for the processing period and limited operational recovery period;
- Transaction records: for the period required by tax, accounting, consumer-protection, and financial laws;
- Support correspondence: for as long as reasonably necessary to resolve the matter and maintain relevant records;
- Security logs: for a limited period appropriate to detecting and investigating abuse;
- Consent records: for as long as needed to demonstrate compliance; and
- Aggregated or irreversibly de-identified information: potentially indefinitely, where it can no longer reasonably identify you.
We may retain limited information after an account-deletion request where required by law or necessary to prevent fraud, enforce legal rights, record your request, or protect the security of the Service.
13. International Data Transfers
We and our service providers may process personal data outside your country, including in the United Kingdom, European Economic Area, United States, and other jurisdictions.
These countries may have data-protection laws different from those in your location.
Where UK or European law requires safeguards for an international transfer, we may rely on:
- an adequacy regulation or adequacy decision;
- the UK International Data Transfer Agreement;
- the UK Addendum to the European Commission Standard Contractual Clauses;
- the European Commission Standard Contractual Clauses;
- another legally approved transfer mechanism; or
- an applicable legal derogation.
We may also implement:
- encryption;
- data minimisation;
- pseudonymisation;
- access restrictions;
- contractual audit rights; and
- supplementary technical or organisational safeguards.
You may contact us for further information about applicable transfer safeguards.
14. Security
We use reasonable and appropriate technical and organisational measures intended to protect personal data, particularly facial images and sensitive analysis information.
Measures may include:
- encryption in transit;
- encryption at rest where supported;
- access controls;
- authentication safeguards;
- separation of production and development systems;
- restricted administrative access;
- logging and monitoring;
- secure development practices;
- vulnerability management;
- processor due diligence;
- data minimisation;
- backup protection;
- incident-response procedures; and
- deletion or de-identification controls.
Access to sensitive data is limited to authorised personnel and service providers with a legitimate need to access it.
No internet transmission, storage system, or security measure is completely secure. We cannot guarantee absolute security.
You are responsible for:
- maintaining the security of your device;
- protecting your authentication credentials;
- using an appropriate device passcode;
- keeping your operating system updated; and
- notifying us promptly of suspected unauthorised access.
15. Data-Protection Impact and Privacy by Design
Because facial and derived information can create heightened risks, we seek to apply privacy-by-design principles, including:
- limiting collection to information reasonably necessary;
- using facial information only for clearly disclosed purposes;
- restricting identification-related uses;
- limiting retention;
- separating direct account identifiers from processing data where practical;
- evaluating service providers;
- testing for accuracy and bias;
- implementing appropriate access controls;
- reviewing automated processing;
- providing user deletion controls; and
- conducting data-protection impact assessments where required.
UK guidance states that organisations using high-risk biometric recognition systems should adopt data protection by design and complete a data-protection impact assessment before commencing relevant processing.
16. Accuracy, Bias, and Limitations of Facial Analysis
Automated facial analysis may perform differently depending on:
- skin tone;
- age;
- facial characteristics;
- disability;
- lighting;
- makeup;
- facial expression;
- camera angle;
- camera quality;
- image compression;
- filters or editing;
- partial obstruction; and
- limitations in the underlying models or training data.
We seek to evaluate and reduce unfair or systematically inaccurate outcomes, but we cannot guarantee that results will be accurate or equally reliable for every person.
Evora's outputs:
- are estimates;
- may contain errors;
- should not be treated as objective statements of attractiveness or personal worth;
- do not constitute medical advice;
- should not replace advice from a qualified professional; and
- should not be used to make significant decisions about another person.
You may contact us if you believe a result is materially inaccurate, discriminatory, inappropriate, or harmful.
17. Your Privacy Rights
Depending on where you live, you may have some or all of the rights described below.
17.1 Right of access
You may request confirmation of whether we process your personal data and obtain a copy of that data.
17.2 Right to rectification
You may request correction of inaccurate or incomplete personal data.
17.3 Right to erasure
You may request deletion of personal data, subject to legal exceptions.
Where an in-app account-deletion function is available, you may use it to initiate deletion.
17.4 Right to restriction
You may request that we restrict processing in certain circumstances.
17.5 Right to data portability
You may request certain personal data in a structured, commonly used, machine-readable format and, where technically feasible, request that it be transmitted to another controller.
17.6 Right to object
You may object to processing based on legitimate interests and to direct marketing.
We will stop direct marketing when you object.
17.7 Right to withdraw consent
Where processing is based on consent, you may withdraw consent at any time.
Withdrawal will not affect processing lawfully carried out before withdrawal.
17.8 Rights concerning automated decision-making
Where applicable, you may have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
You may also have rights to request human intervention, express your view, receive meaningful information, or contest a decision.
17.9 Right to complain
You may lodge a complaint with the relevant data-protection authority.
In the United Kingdom, the relevant regulator is the Information Commissioner's Office.
You are encouraged to contact us first so that we may attempt to resolve the issue.
17.10 Right to appeal
Where required by applicable United States state law, you may appeal our refusal to act on a privacy request by replying to our decision or contacting us at [email protected] with the subject line "Privacy Request Appeal".
17.11 Non-discrimination
We will not unlawfully discriminate against you for exercising a privacy right.
18. Exercising Your Rights
To exercise a privacy right, contact:
Please include:
- the right you wish to exercise;
- the email address or account identifier connected to Evora;
- sufficient information to identify the relevant account; and
- the jurisdiction in which you live, where relevant.
We may need to verify your identity before responding. Verification measures will be proportionate to the sensitivity of the information requested.
For requests involving facial images or sensitive information, we may require additional verification to avoid disclosing data to an unauthorised person. We will not request more information than reasonably necessary.
An authorised agent may submit a request where permitted by law. We may require evidence of the agent's authority and direct verification from the user.
We will respond within the period required by applicable law. We may extend the response period where legally permitted, in which case we will inform you.
19. California Privacy Notice
This section applies to California residents where the California Consumer Privacy Act applies.
19.1 Categories collected
During the preceding twelve months, depending on the features used, we may have collected:
- identifiers;
- customer-record information;
- commercial information;
- internet or electronic-network activity;
- device information;
- visual information;
- geolocation information at an approximate level;
- professional or employment information only if voluntarily provided;
- inferences;
- account credentials;
- precise or sensitive information provided in free text;
- biometric or facial information; and
- health-related or appearance-related information that may qualify as sensitive personal information.
19.2 Sources
We collect this information from:
- you;
- your device;
- app stores;
- authentication providers;
- payment and subscription providers; and
- service providers supporting the Service.
19.3 Business and commercial purposes
We use this information for the purposes described in Section 6, including:
- providing requested services;
- maintaining accounts;
- personalisation;
- security;
- debugging;
- analytics;
- customer support;
- subscription management; and
- legal compliance.
19.4 Disclosures
We may disclose these categories to:
- cloud and infrastructure providers;
- artificial-intelligence processors;
- analytics and security providers;
- payment and subscription providers;
- professional advisers;
- corporate-transaction participants; and
- government or legal authorities where required.
19.5 Sale and sharing
We do not sell facial information or facial-analysis data.
We do not share facial-analysis data for cross-context behavioural advertising.
Where legally required, California residents may request:
- access to categories and specific pieces of personal information;
- correction;
- deletion;
- information about collection and disclosure;
- opt-out of sale or sharing;
- limitation of certain uses of sensitive personal information; and
- equal treatment when exercising privacy rights.
20. Children and Minimum Age
Evora is not directed to children under 13 and is not intended for use by anyone below the minimum age displayed in the Service.
We do not knowingly collect personal data from children under 13.
The United States Children's Online Privacy Protection Act generally requires covered online services to provide notice and obtain verifiable parental consent before collecting personal information from children under 13.
Because Evora processes facial images and appearance-related information, users may be required to confirm that they are at least 18 years old or otherwise meet the minimum age applicable to the Service in their region.
If we learn that we have collected personal data from a person who is not legally permitted to use the Service, we will take reasonable steps to delete it.
A parent or guardian who believes a child has provided personal data may contact [email protected].
We do not knowingly profile children for advertising.
21. Camera, Photo-Library, and Device Permissions
Evora may request permission to access:
- the camera;
- the photo library;
- notifications; and
- other device features required for a specific function.
Permissions are controlled through your device operating system.
You may revoke permission through your device settings. Revocation will not automatically delete information already submitted to or stored by Evora. You may separately delete relevant content or request deletion.
We do not use camera access to record continuously or collect images in the background.
22. Marketing Communications
Where permitted, we may send promotional emails about Evora.
You may opt out by:
- using the unsubscribe link in the email;
- adjusting available communication settings; or
- contacting [email protected].
Even after opting out of marketing, you may continue to receive non-promotional messages concerning:
- security;
- account administration;
- subscriptions;
- legal notices;
- changes to the Service; and
- responses to your enquiries.
24. De-identified and Aggregated Data
We may generate aggregated or de-identified information that is not reasonably capable of being associated with you.
We may use such information for:
- statistical analysis;
- service improvement;
- safety testing;
- performance measurement;
- research;
- business planning; and
- reporting.
Where information is treated as de-identified under applicable law, we will:
- take reasonable measures to ensure it cannot be associated with an individual;
- maintain and use it in de-identified form; and
- not attempt to re-identify it except where legally permitted to test the effectiveness of de-identification safeguards.
Pseudonymised information remains personal data where it can be linked back to an individual using additional information.
25. Data Breaches and Security Incidents
If a personal-data breach occurs, we will investigate and take reasonable steps to contain, assess, and remediate the incident.
Where required by law, we will notify:
- affected individuals;
- the Information Commissioner's Office;
- another competent supervisory authority;
- consumer-protection authorities; or
- other relevant regulators.
Notifications will be made within the legally required period and will include available information about:
- the nature of the incident;
- the categories of information affected;
- potential risks;
- actions taken; and
- recommended protective measures.
26. Third-Party Services and Links
Evora may contain links to or integrations with third-party services.
Third parties may collect and process data under their own privacy policies. We are not responsible for the privacy practices of independent third parties.
Before using a third-party service, you should review its privacy information.
App stores, device manufacturers, operating-system providers, authentication providers, and payment providers may act as independent controllers for information they collect directly from you.
27. Business Customers and Processor Relationships
Where Evora is provided to an organisation under a separate business agreement, Randova may process certain personal data on behalf of that organisation.
In those circumstances:
- the organisation may be the controller;
- Randova may act as a processor;
- the organisation's privacy notice may also apply; and
- requests concerning data controlled by that organisation may need to be directed to it.
Where we act as a processor, our processing will be governed by the applicable agreement and documented instructions of the controller.
28. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
- changes to the Service;
- new processing activities;
- changes to service providers;
- legal or regulatory developments;
- security improvements; or
- changes to business practices.
The updated policy will display a revised "Last updated" date.
Where changes are material, we may provide additional notice through:
- the application;
- email;
- a website notice; or
- another appropriate method.
Where required, we will obtain renewed consent before beginning materially different processing of sensitive or facial information.
Continued use of the Service after an update does not constitute consent where applicable law requires express consent.
29. Contact Us
Questions, concerns, complaints, and privacy-rights requests may be directed to:
Randova Ltd
Email: [email protected]
Please use the subject line "Evora Privacy Request" for requests involving access, correction, deletion, consent withdrawal, or another privacy right.
30. Consent to Facial-Data Processing
Before using facial-analysis functionality, you may be asked to confirm that:
- you are voluntarily submitting a photograph containing your face;
- you understand that Evora will technically process the photograph and derive facial-analysis information;
- the purpose is to provide the appearance-related analysis and recommendations you request;
- the processing may involve sensitive personal data;
- automated outputs may be inaccurate;
- the output is not medical advice;
- you have the right to withdraw consent and request deletion; and
- withdrawal may prevent Evora from providing facial-analysis functionality.
Where explicit consent is the applicable legal condition, facial processing will not begin until the required consent has been provided.
Consent to facial processing is separate from consent to:
- marketing;
- notifications;
- model training;
- targeted advertising; and
- any other optional secondary use.
Refusing one optional purpose will not be treated as consent to another.