Is evasys GDPR compliant? What universities should check for course evaluation
evasys is course evaluation and survey software from evasys GmbH in Lüneburg, Germany, used by universities for teaching evaluations. It can run on the university's own servers or be hosted by evasys. This page sets out what evasys documents publicly about data protection, hosting, subprocessors and AI-supported analysis, and what that means for a university.
Short answer
evasys GmbH is a German company, so it is directly subject to the GDPR. Universities can run evasys on their own servers or have evasys host it; for hosting, evasys names a Microsoft Azure data centre in Germany as its subprocessor. evasys states that the university is always the controller, publishes technical and organisational measures and a dated subprocessor list, and describes an ISO 27001-certified management system. The points to settle are mostly on the university's side: anonymity rules for small courses, retention of evaluation results, and whether the AI-supported comment analysis is switched on and how it works.
What evasys documents publicly
This summary reflects evasys's legal and data protection page, the documents linked from it, its course evaluation and FAQ pages and its imprint, read on 7 October 2026. Numbers in brackets refer to the sources at the end of the page.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented evasys GmbH, Konrad-Zuse-Allee 13, 21337 Lüneburg, Germany, registered at Lüneburg (HRB 1604). | [1] |
| Controller and processor roles | Documented The controller for personal data in an evasys product is always the organisation collecting the data, not evasys GmbH, including when evasys hosts the system. The technical and organisational measures are written for evasys as processor. | [2] [3] |
| Where data is stored | Documented On-premises: data and logs are on the customer's own systems and deletion periods are the customer's responsibility. Hosted by evasys: data is stored on Azure web servers, in a Microsoft Azure data centre in Germany. The newer cloud components (engagement modules and insights) use Azure-based web services. | [2] [4] |
| Data processing agreement | Partly public The legal page publishes the subprocessor list as an annex to the data processing agreement (AVV) and the technical and organisational measures. The full agreement text was not found in public documentation (checked 7 October 2026). | [5] [4] [3] |
| Subprocessors | Documented The list dated September 2025 names Microsoft Ireland Operations Limited (Azure hosting in Germany), TeamViewer Germany GmbH (remote support), evasys Labs Kft in Budapest (only for contracts with evasys+ components), Web Computing GmbH in Münster (learning videos) and Kovai Limited in the UK (AI-supported online help platform). | [4] |
| International transfers | Limited information All named subprocessors are in the EU except Kovai Limited, which is in the United Kingdom, a country covered by a European Commission adequacy decision [13]. A transfer statement for that subprocessor was not found in evasys's public documentation (checked 7 October 2026). As an EU company, evasys does not need the EU-U.S. DPF for its own operations. | [4] |
| AI features | Partly documented The evasys insights module offers dashboards, trend analysis and "AI-supported analysis of open-ended responses", including topic extraction and sentiment analysis. The model, provider and processing location were not found in public documentation (checked 7 October 2026), and no AI model provider appears on the subprocessor list. | [6] [4] |
| Retention and logs | Documented When evasys hosts, IP address and user agent logs for evasys and evaexam are deleted after 365 days and login data is anonymised after 30 days. Logs for the cloud engagement components are kept for four weeks. Hosted user data is backed up daily for 30 days. | [2] [3] |
| Security certifications | Documented evasys describes an ISO 27001-certified information security management system, and says it uses only ISO 27001-certified hosting providers, with certificates available to customers on request. | [6] [3] |
| Institution controls | Documented Single sign-on through a local identity provider or federations such as DFN, HEAnet and the UK federation. Anonymity methods for participants, aggregated reporting with minimum response thresholds, and LTI integration with Canvas, Blackboard, Brightspace, Moodle and ILIAS. | [2] [6] [7] |
evasys deserves credit for publishing concrete, dated documents rather than general assurances: a per-component table of what is logged and for how long, a subprocessor list with addresses and purposes, and detailed technical and organisational measures. The option to run the software on premises is also valuable for institutions with strict hosting rules.
What this means for a university
Validemic's analysis
Choose the hosting model deliberately. On premises, the university takes on hosting, patching and log deletion itself [2]. Hosted by evasys, those tasks move to evasys and its Azure subprocessor in Germany [4], under an Article 28 processor agreement [8]. Either is defensible; what matters is that the records of processing say which model is used, and that IT and the DPO agree on who deletes what.
Course evaluations are personal data about teachers too. Student answers may be anonymous, but evaluation results are usually linked to a named lecturer and may feed into appraisals or promotion. That makes access rules, retention periods and the purposes for which results are used important, and in some countries it involves staff representatives. These questions sit with the university, not the vendor.
Anonymity in small groups. Minimum response thresholds help [6], but open-text comments can still identify students in small seminars through writing style or details. The GDPR treats data as anonymous only if individuals cannot be identified by means reasonably likely to be used (Recital 26) [8]. Set thresholds and decide whether lecturers see raw comments or only summaries.
The AI analysis needs its own check. Sentiment and topic analysis of student comments is useful, but the public documents do not say which AI service performs it or where [6] [4]. Before enabling it, ask for the model provider, processing location and contractual position, and whether comment text leaves the Azure environment.
DPIA likelihood. Routine anonymous course evaluation is unlikely to reach the Article 35 threshold of likely high risk on its own [8]. Linking results to staff performance management, or applying AI analysis to comments at scale, would justify at least a documented screening. Our DPIA screening tool gives a first view.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask evasys before approving it
- Can we receive the full data processing agreement (AVV) and confirm which version of the subprocessor list applies to our contract?
- For hosting: which Azure region in Germany is used, and do backups and support access stay in the EU?
- Which AI model or provider performs the topic and sentiment analysis in evasys insights, where is it processed, and can we switch it off?
- Is any customer personal data processed through Kovai Limited's online help platform, and on what transfer basis?
- How is TeamViewer remote support initiated and logged, and can we require approval for each session?
- Can we see the ISO 27001 certificate and its scope?
- What default retention applies to evaluation results and raw comments, and can we set our own deletion rules?
- How are minimum response thresholds and anonymity settings configured for small courses?
The EU AI Act angle
Course evaluation sits close to the education uses listed as high-risk in Annex III, but it is not the same thing. Annex III covers AI systems used to evaluate learning outcomes, determine admission, assess the appropriate level of education or monitor students during tests [9]. AI that summarises students' comments about a course evaluates teaching rather than students' learning outcomes, so it does not obviously fall within those categories. If AI-generated summaries feed into decisions about staff, the employment-related categories of Annex III would be worth reading as well [9]. Article 5(1)(f) prohibits AI systems that infer the emotions of people in education institutions, with narrow medical and safety exceptions [10]. Sentiment analysis of written course comments is a different technique, but universities should confirm with evasys exactly what the feature does. The obligation that applies now is Article 4 on measures to support staff AI literacy [11]. High-risk obligations for Annex III systems apply from 2 December 2027 under the amended Article 113 [12].
Sources
- Imprint, evasys GmbH, retrieved 7 October 2026
- General and overall data security topics (status October 2025), evasys GmbH, retrieved 7 October 2026
- Technical and organizational measures (status February 2024), evasys GmbH, retrieved 7 October 2026
- Liste der Unterauftragsverarbeiter (status September 2025), evasys GmbH, retrieved 7 October 2026
- Legal and data protection documents, evasys GmbH, retrieved 7 October 2026
- Course evaluation software for higher education, evasys GmbH, retrieved 7 October 2026
- Frequently asked questions, evasys GmbH, retrieved 7 October 2026
- Regulation (EU) 2016/679 (GDPR), Recital 26 and Articles 28 and 35, text read from the Publications Office copy, retrieved 7 October 2026
- AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744), retrieved 7 October 2026
- AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
- Adequacy decisions, European Commission, retrieved 7 October 2026
About this page
We read evasys's imprint, legal and data protection page, its data security overview (October 2025), technical and organisational measures (February 2024), subprocessor list (September 2025), course evaluation and FAQ pages, and the relevant EU legal texts on 7 October 2026. The German-language product data protection notes (October 2025) match the English overview. Statements about evasys come from those documents; our own interpretation is labelled as Validemic's analysis. "Not found" means we could not find the information in public documentation; it does not mean the vendor lacks it.
This page is not legal advice and does not say whether any particular use of evasys complies with the GDPR. If you work for evasys and see an error, or a document has been updated, please contact us and we will correct it.
Frequently asked questions
Is evasys GDPR compliant?
No tool is GDPR compliant on its own. evasys GmbH is a German company, describes an ISO 27001-certified information security management system, publishes technical and organisational measures and a subprocessor list, and hosts in a Microsoft Azure data centre in Germany when it hosts. Compliance still depends on how the university configures evaluations and handles results.
Who is the controller when a university uses evasys?
evasys's data protection overview says the controller is always the organisation collecting the data, not evasys GmbH, and that this also applies when evasys hosts the system. evasys acts as a processor, and its subprocessor list is published as an annex to its data processing agreement.
Where does evasys store data?
Universities can run evasys on premises, in which case data stays on their own servers. When evasys GmbH hosts the software, its subprocessor list says it uses a Microsoft Azure data centre in Germany, contracted through Microsoft Ireland Operations Limited.
Are evasys course evaluations anonymous?
evasys says it has numerous methods to ensure participant anonymity regardless of medium, and its course evaluation page describes aggregated reporting with minimum response thresholds for small course groups. Whether a specific evaluation is anonymous depends on how the university sets it up, including participant lists and open-text questions.
Does evasys use AI to analyse comments?
The evasys insights analytics module offers AI-supported analysis of open-ended responses, including topic extraction and sentiment analysis. Which AI model or provider is used, and where it runs, was not found in public documentation on 7 October 2026.