Last updated: 6 August 2026.
This Data Processing Agreement ("DPA") forms part of the agreement between Elevale and customers who use the Service where we process personal data as processor (or where the platform infrastructure operator processes personal data as processor or sub-processor for the Service). It supplements our Terms of Service and Privacy Policy, and is incorporated by reference into those documents.
How this DPA is entered: accepting the Terms of Service constitutes acceptance of this standard online DPA. No separate wet-ink or countersigned copy is required unless we agree a custom Enterprise DPA in writing.
{tradingStyleDisclaimer} In this DPA, "Elevale", "we", "us", and "our" mean that registered company trading as Elevale. "Customer" means the organisation or individual that contracts for the Service under the Terms of Service.
1. Definitions
- Personal data: information relating to an identified or identifiable natural person, as defined under UK GDPR and EU GDPR.
- Processing: any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
- Controller: the entity that determines the purposes and means of processing personal data.
- Processor: the entity that processes personal data on the Controller's instructions.
- Subprocessor: a third party engaged by the Processor to process personal data.
- Customer data: personal data contained in workspace content uploaded or generated by Customer and its users.
2. Roles of the parties
- Elevale (we) is Controller for platform account data (registration, billing profile, support communications, and similar account administration data described in our Privacy Policy).
- Elevale (we) is Processor for Customer data uploaded to workspaces, processing only on Customer instructions as set out in the Terms of Service and this DPA.
- Hosting, authentication, storage, security, and related infrastructure may be provided by technology providers acting as Processor or sub-processor under our instructions, including those listed at Subprocessors and integrations.
- Customer is Controller (or joint controller, where applicable) for Customer data and for personal data of its authorised users that Customer decides to collect and process in the Service.
3. Subject matter and duration
Processing is limited to providing the Elevale service: account management, workspace collaboration, AI features (where enabled), integrations, billing, security, support, and compliance. Processing continues for the duration of the subscription and applicable retention periods in Data retention and deletion, then Customer data is deleted or anonymised as documented.
4. Nature and purpose of processing
- Hosting, storing, backing up, and displaying Customer data
- Authenticating users and enforcing role-based access controls
- Generating AI responses, embeddings, and insights when Customer enables AI features
- Syncing data from Customer-authorised third-party integrations
- Maintaining audit logs and security monitoring
- Processing billing and wallet transactions
- Responding to Customer support and data subject requests
5. Types of personal data and data subjects
Categories may include: names, email addresses, job titles, profile photos, workspace content containing personal data, usage logs, billing contacts, and integration-derived data. Data subjects include Customer employees, contractors, invitees, and other users Customer authorises.
6. Processor obligations
Processor shall:
- Process personal data only on documented instructions from the Controller (these Terms, Customer configuration, and lawful requests), unless required by law
- Ensure persons authorised to process personal data are bound by confidentiality
- Implement appropriate technical and organisational measures per Article 32 UK/EU GDPR (see Security and data protection)
- Engage subprocessors only as authorised under section 7, and keep the published subprocessor list current so Controller can review additions and object as set out there
- Assist Controller with data subject requests, DPIAs, and supervisory authority consultations where reasonably possible
- Delete or return Customer data at termination, subject to retention required by law
- Make available information necessary to demonstrate compliance and allow audits on reasonable notice, subject to confidentiality and security constraints
7. Subprocessors
Controller gives general authorisation for Processor to engage current and future subprocessors that are necessary to operate the Service (including new AI providers introduced in the product). Processor (not Controller) selects those subprocessors. The current list is published at Subprocessors and integrations and may include, for example, Supabase, Fly.io, Stripe, AWS SES, OpenAI, Anthropic, Google (Gemini), Perplexity, and ElevenLabs, as applicable to enabled features. Customer does not choose or veto individual platform infrastructure or AI subprocessors while remaining on the multi-tenant Service. Optional features and integrations Customer enables or uses (for example AI or connected apps) constitute authorisation to use the subprocessors needed for those features.
Processor informs Controller of additions or replacements of subprocessors that process Customer personal data by updating the published list at Subprocessors and integrations when the change is introduced in the Service (including when a new AI provider is made available). No separate email or fixed advance notice period is required for that update to count as notice under this DPA. Controller may object on reasonable data-protection grounds after the list is updated. An objection does not require Processor to run a custom stack without that subprocessor for that Customer; if the objection cannot be resolved, Controller's remedy is to terminate the affected services. Continued use of the Service after the list is updated constitutes acceptance of the updated subprocessors where permitted by law.
Processor imposes data protection terms on subprocessors substantially similar to this DPA.
8. International transfers
Personal data may be transferred to the United Kingdom, EEA, United States, and other countries where subprocessors operate. Where transfers occur to countries without an adequacy decision, Processor relies on:
- UK International Data Transfer Agreement (IDTA) and/or EU Standard Contractual Clauses (SCCs) Module Two (Controller to Processor) or Module Three (Processor to Subprocessor), as applicable
- Supplementary measures where required by supervisory authority guidance
Enterprise customers may request executed transfer mechanisms by contacting contact form.
9. Security measures (Article 32)
Processor implements measures including:
- TLS 1.2+ encryption in transit; encrypted storage at rest
- Multi-factor authentication required for platform accounts
- Row Level Security and role-based access on tenant data
- Server-side encryption for OAuth tokens; hashed API keys
- Immutable audit logging; incident response procedures
- Point-in-time database recovery; documented key rotation
Details are in Security and data protection and Audit logging.
10. Personal data breaches
Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Customer data, and in any event within 72 hours where feasible, providing information required under Article 33 GDPR to the extent known. Processor will cooperate with Controller's breach notifications to supervisory authorities and data subjects. See Incident response and data breaches.
11. Data subject rights
Processor assists Controller in fulfilling data subject requests (access, rectification, erasure, restriction, portability, objection) through in-app tools: Profile → Privacy (export and requests) and Profile → Security (account deletion). Controller is responsible for responding to its end users and should establish escalation paths to Processor where platform assistance is needed.
12. Deletion and return of data
Upon termination of the service:
- Customer may export data before access ends
- Grace period continues until end of billing period where applicable
- Personal data is anonymised at 60 days and permanently deleted at 90 days after access ends
- Billing records retained per tax law (typically 6 to 7 years); audit logs retained 2 years
13. Audit and compliance
Processor maintains records of processing activities and security controls. Enterprise customers may request a summary of subprocessors, security documentation, or completion of security questionnaires under NDA. On-site audits may be arranged for Enterprise customers by mutual agreement, no more than once per year unless required by a supervisory authority.
14. Liability
Liability between the parties is governed by the Terms of Service. Each party remains liable for its own compliance obligations under applicable data protection law.
15. Order of precedence
If this DPA conflicts with an executed Enterprise order form or master agreement on data protection matters, the executed agreement prevails. Otherwise, this DPA supplements the Terms of Service.
16. Changes
We may update this DPA to reflect legal or operational changes. Material changes will be notified as described in the Terms of Service. Continued use after the effective date constitutes acceptance where permitted.
Related documents
Contact: contact form