Legal
Public legal notices and customer-facing trust documents for Evitrus on evitrus.io. Technical setup guides live on docs.evitrus.io.
Use the search control in the header (or Ctrl+K / Cmd+K) to find a document by name, statute, or topic.
Binding contracts (signed DPA, MSA) are issued separately by counsel. Pages marked draft are not executable agreements.
Internal ISMS procedures (access reviews, control inventories, staff runbooks) are not published here. They can be shared under NDA during procurement.
Required notices
German and EU website law for this public site:
| Document | Why it is published |
|---|---|
| Impressum | Provider identification, § 5 DDG and § 18 (2) MStV |
| Privacy policy | Information duties, GDPR Arts. 13 and 14; TDDDG |
GDPR & contracting
Who you contract with, how personal data is processed in the product, and who else may see it:
| Document | Status |
|---|---|
| Company information | Public |
| DPA outline (Art. 28) | Draft — counsel finalizes |
| Subprocessors | Public |
| Security contact | Public |
Trust & security
Vendor due-diligence materials for the managed cloud. These answer the usual security and GDPR procurement questions; they are not a SOC 2 report or an ISO 27001 certificate.
| Document | Status |
|---|---|
| Security whitepaper | Public |
| Architecture & data flow | Public |
| Incident response | Public |
| Backup & availability | Public |
Related product docs: Security & residency, Data portability, Scale & SLOs, Compliance packs.