This Privacy Policy explains how Evinto Solutions LLC (“Evinto,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with the Optima software-as-a-service platform and related services (the “Services”).
This Privacy Policy applies to users of the Services, including Court Appointed Special Advocate (“CASA”) and Guardian Ad Litem (“GAL”) staff, volunteers, contractors, and other authorized users (“Users”).
If your organization has a separate written agreement with Evinto (including a data processing addendum or “DPA”), that agreement may supplement or override this Privacy Policy for organizational data.
The Policy
1. Roles and Scope
1.1 Organizational Data
In most deployments, your organization is the data controller (or equivalent under applicable law), and Evinto acts as a service provider / data processor with respect to personal data processed on behalf of the organization through the Services.
Evinto processes such data only in accordance with:
- this Privacy Policy,
- the Terms of Use,
- any applicable Contract or DPA, and
- documented instructions from the organization.
1.2 Individual Accounts
Evinto may act as a controller with respect to limited account-level data (e.g., login credentials, support communications, billing contacts).
2. Information We Collect
2.1 User Content (Customer-Provided Data)
The Services are designed to process sensitive CASA/GAL information. Depending on role and permissions, User Content may include:
(a) Volunteer Recruitment and Screening
- Applications and intake forms
- Demographic data (which may include Social Security numbers or other identifiers where permitted by law)
- Background check and screening information
- Interview notes, reference checks, eligibility determinations
- Training records and certifications
- Emergency contact information
- Uploaded documents (PDF, Word, Excel, image files)
(b) Volunteer Management
- Volunteer profiles and contact information
- Case and child assignments
- Activity logs (hours, expenses, mileage)
- Supervisor notes and evaluations
- In-service training records
- Internal administrative notes
(c) CASA / GAL Case Management
- Case identifiers and court information
- Child data, including demographics, placement history, education information, grant eligibility, and service needs
- Family and household data, relationships, and involvement
- Hearing dates, outcomes, court orders, and permanency plans
- Contact logs, narrative reports, and well-being assessments
- Case-related documents and attachments
Evinto does not determine what User Content is entered into the Services. Organizations are responsible for ensuring lawful collection and use of this data.
2.2 Account and Administrative Information
We collect information necessary to operate and secure the Services, such as:
- User names, email addresses, phone numbers
- Organization name and role assignments
- Authentication credentials (hashed)
- Audit logs and access records
- Support requests and communications
2.3 Technical and Usage Information
We automatically collect limited technical data, including:
- IP addresses
- Device and browser type
- Login timestamps
- Usage and performance metrics
- Error logs and diagnostic data
This information is used for security, troubleshooting, analytics, and service improvement.
3. How We Use Information
Evinto uses information solely for legitimate business and operational purposes, including to:
- Provide, maintain, and operate the Services
- Authenticate users and enforce access controls
- Secure the platform and detect/prevent misuse
- Provide customer support and respond to inquiries
- Perform backups, disaster recovery, and system monitoring
- Comply with legal obligations
- Improve functionality, reliability, and performance
Evinto may also use data in deidentified or aggregated form, from which personal information has been removed, for benchmarking, statistics, and service improvement.
4. Legal Bases for Processing (Where Applicable)
Depending on jurisdiction, Evinto processes personal data based on one or more of the following:
- performance of a contract with your organization
- compliance with legal obligations
- legitimate interests in operating and securing the Services
- instructions and authorization from the data controller (your organization)
5. How We Share Information
Evinto does not sell personal data.
We may share information only as follows:
5.1 With Service Providers
With trusted third-party vendors who provide infrastructure or services (e.g., hosting, backups, email delivery, monitoring), under contractual confidentiality and security obligations.
5.2 With Your Organization
With designated administrators and authorized personnel of your organization.
5.3 Legal Requirements
If required by law, subpoena, court order, or governmental request. Where permitted, we provide notice to the organization before disclosure.
5.4 Business Transfers
In connection with a merger, acquisition, reorganization, or sale of assets, subject to confidentiality and continued protection of data.
6. Data Retention
Unless otherwise specified in a Contract:
- Active accounts: Data is retained for the duration of your organization’s use of the Services.
- After termination: User Content is retained for ninety (90) days to allow export or retrieval.
- Deletion: After the 90-day period, User Content is deleted from production systems.
- Backups: Data may persist in encrypted backups for a limited additional period pursuant to standard backup rotation.
Data may be retained longer if required by law or legal hold.
7. Security Safeguards
Evinto maintains commercially reasonable administrative, technical, and physical safeguards designed to protect information, including:
- role-based access controls
- encryption in transit and at rest (where applicable)
- audit logging and monitoring
- least-privilege access practices
- incident response procedures
No system is completely secure. Organizations are responsible for endpoint security, user access management, and appropriate configuration of security features.
8. Security Incidents
Evinto maintains an incident response process. Where required by law or applicable agreements, Evinto will notify affected organizations of confirmed security incidents involving unauthorized access to User Content within a reasonable timeframe and provide information reasonably necessary for compliance obligations.
9. Individual Rights
Privacy rights vary by jurisdiction and role. Where applicable and subject to law:
- Requests regarding User Content (e.g., access, correction, deletion) should be directed to your organization, which controls the data.
- Evinto will assist organizations in responding to verified requests as required by law or contract.
If Evinto receives a direct request relating to User Content, we may refer the request to the relevant organization.
10. Children’s Information
The Services are intended for professional use by CASA/GAL organizations. Evinto does not knowingly collect information directly from children. Any child-related data entered into the Services is provided by authorized users acting on behalf of their organizations.
11. International Data Transfers
The Services are hosted in the United States. If your organization accesses the Services from outside the U.S., you understand that data will be processed and stored in the United States, subject to U.S. law.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will update the “Last Updated” date and provide notice of material changes through the Site or other reasonable means.
13. Contact Us
For questions about this Privacy Policy or Evinto’s data practices, contact: