Platform documentation

Privacy Policy

This Privacy Policy explains how Elevale ("we", "us", "our") collects, uses, stores, shares, and protects personal data when you use our platform, marketing website, and related services. It also describes your privacy rights and how to contact us.

{tradingStyleDisclaimer} In this policy, "Elevale", "we", "us", and "our" mean that registered company trading as Elevale.

We are the data controller for account, billing, and marketing personal data described in this policy. For workspace content and other personal data processed within a workspace, we may act as a processor on the instructions of the organisation that administers that workspace. We operate the service; infrastructure providers process data under our instructions (see our Data Processing Agreement and Subprocessors and integrations). The DPA is incorporated into our Terms of Service and applies automatically on acceptance of those Terms; no separate wet-ink signature is required for the standard online DPA.

By creating an account, using Elevale, or submitting information through our marketing site, you acknowledge that you have read this Privacy Policy. Where required by law, we will obtain your consent before processing your data for specific purposes.

Scope

This policy applies to:

  • The Elevale web application and related subdomains
  • Our marketing website and documentation at /help
  • Support, sales, and onboarding communications with us

Third-party providers (for example Xero or Meta) also process data under their own privacy policies. Optional Google Analytics and Google Ads workspace integrations access Google user data under OAuth; see our separate Google user data notice for scopes, use, and deletion.

Personal data we collect

We collect personal data that you provide directly, that we generate when you use the service, and that we receive from third parties where permitted.

Account and profile data

  • Name, email address, and password (stored as a secure hash)
  • Profile photo, job title, timezone, and notification preferences
  • Multi-factor authentication settings (email OTP or authenticator app: required after signup) and session metadata (devices, sign-in times, IP addresses)
  • Organisation and workspace membership, roles, and permissions

Workspace and business content

  • OKRs, KPIs, tasks, business briefs, wiki pages, process maps, and related files you upload
  • Comments, mentions, assignments, and collaboration activity
  • AI chat prompts, responses, and embeddings generated when you use AI features
  • Voice session data when you use voice mode (where enabled)

Billing and commercial data

  • Subscription plan, seat counts, billing contact details, and invoice history (subscriptions billed in GBP; VAT added at checkout where applicable)
  • Payment method metadata processed by Stripe (we do not store full card numbers)
  • Tax identifiers and billing addresses where you provide them
  • AI wallet: prepaid balance, top-up history, auto top-up settings, and per-transaction usage records (model, tokens, cost) for metered AI features; wallet charges are processed in USD, separate from GBP subscription billing

Usage, technical, and security data

  • IP address, browser type, device identifiers, and operating system
  • Log data, error reports, performance metrics, and security events
  • Audit log entries recording changes to workspace data, permissions, exports, and deletions
  • Cookie and consent records (see our Cookie Policy)

Marketing and communications

  • Contact details you provide for newsletters, demos, or enquiries: name, business name, email address, and phone number
  • Contact form submissions, demo requests, sales enquiries, and newsletter sign-ups on our marketing website
  • Marketing engagement data, including email opens, link clicks, and interactions with our marketing messages
  • Website activity on our marketing site, including pages viewed, referral source, campaign parameters (UTMs), device and approximate location (from IP), collected via cookies and similar technologies where you consent
  • Records held in our customer relationship management (CRM) and marketing automation platform, used to manage enquiries, subscriptions, and communications

Data from integrations

When you connect third-party integrations via OAuth or API keys, we receive data authorised by you and needed to deliver the integration (for example advertising metrics, accounting records, or CRM contacts). You control which integrations are enabled per workspace. For Google Analytics and Google Ads OAuth integrations, see our dedicated Google user data notice.

How we use personal data

We use personal data only where we have a lawful basis under UK GDPR, EU GDPR, or equivalent laws.

  • Provide the service: Create and manage your account, authenticate you, store workspace content, and deliver features you request (contractual necessity)
  • Billing and administration: Process subscriptions and seat billing, send invoices, prevent fraud, and comply with tax obligations (contractual necessity and legal obligation)
  • Security and abuse prevention: Monitor for unauthorised access, enforce MFA, maintain audit logs, and protect the platform (legitimate interests)
  • Product improvement: Analyse aggregated usage to fix bugs, improve performance, and develop features (legitimate interests; analytics cookies only with consent on the marketing site)
  • AI features: Process prompts and workspace context you submit to generate responses, summaries, and embeddings when you use AI tools (contractual necessity or legitimate interests, depending on the feature)
  • Communications: Send service messages, security alerts, and (with consent or soft opt-in where allowed) product updates and marketing (contractual necessity, legitimate interests, or consent)
  • Legal compliance: Respond to lawful requests, enforce our terms, and maintain records required by law (legal obligation)

We do not sell your personal data. We do not use personal data for automated decision-making that produces legal or similarly significant effects without human review.

How we share personal data

We share personal data only as described below.

Subprocessors and infrastructure providers

We use trusted subprocessors to host, secure, and deliver Elevale. They process data on our instructions and under contractual safeguards. Our current platform subprocessors include:

  • Supabase: Database, authentication, and file storage
  • Fly.io: Application hosting
  • Stripe: Payment processing
  • OpenAI, Anthropic, Google Gemini, and Perplexity: AI chat, embeddings, insights, OKR suggestions, and web research (when enabled; separate from Google OAuth integration data: see AI and automated processing)
  • ElevenLabs: Voice mode and text-to-speech (when enabled)
  • AWS SES: Transactional email
  • Cloudflare: Content delivery, security, and performance for our marketing website (processes IP addresses and request metadata)
  • CRM and marketing automation provider: Stores newsletter, enquiry, and marketing contact records and sends marketing communications on our behalf

The authoritative subprocessor list is published at Subprocessors and integrations. We select platform and AI subprocessors needed to operate the Service and update that list when providers are introduced or changed. Separate advance notice or individual customer notifications are not required. Enabling or using optional features (such as AI) authorises the related subprocessors for those features. Objection rights are described in our Data Processing Agreement.

Workspace members

Workspace admins and members with appropriate permissions can access data within that workspace according to roles and permissions set by the organisation that administers the workspace.

Professional advisers and authorities

We may disclose data to lawyers, accountants, insurers, or regulators when required by law, court order, or to protect rights, safety, and security.

Business transfers

If we are involved in a merger, acquisition, or asset sale, personal data may transfer to the successor entity subject to equivalent protections. We will notify you where required by law.

International transfers

Elevale may process and store data in the United Kingdom, European Economic Area, United States, and other countries where our subprocessors operate. Where personal data is transferred outside the UK or EEA to countries without an adequacy decision, we rely on appropriate safeguards such as the UK International Data Transfer Agreement, EU Standard Contractual Clauses, and supplementary measures where needed. Details are set out in our Data Processing Agreement.

Data retention

We retain personal data only as long as necessary for the purposes described in this policy.

  • Active accounts and workspaces: Retained while your subscription or account is active
  • Cancelled workspaces: Grace period until the end of the billing period, then soft anonymisation at 60 days and permanent deletion at 90 days after access ends
  • Audit logs: 2 years, then automatically purged
  • Cookie consent records: 1 year
  • Privacy requests: 3 years after completion (compliance evidence)
  • Billing and tax records: Typically 6 to 7 years, as required by law
  • Backups: Encrypted point-in-time recovery on a rolling schedule, independent of application deletion timelines

Full retention schedules are documented at Data retention and deletion. You can delete your account at any time from Profile → Security.

Security and sessions

We implement technical and organisational measures to protect personal data, including:

  • TLS 1.2+ encryption in transit and encrypted storage at rest
  • Mandatory multi-factor authentication (email OTP or authenticator app) required after signup for all platform accounts
  • Session management via Supabase Auth: you may use multiple devices; sessions expire on sign-out or after inactivity; we may terminate sessions for security
  • Row Level Security and role-based access controls on tenant data
  • Server-side encryption for OAuth tokens and hashed storage for API keys
  • Immutable audit logging for key workspace and admin actions

See Security and data protection and Audit logging for more detail. No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately.

Your rights

Depending on your location, you may have the following rights over your personal data:

  • Access: Know what personal data we hold about you and receive a copy
  • Portability: Receive your data in a structured, commonly used format (JSON export available in-app)
  • Rectification: Correct inaccurate or incomplete data in Profile settings or by contacting us
  • Erasure: Request deletion of your personal data, subject to legal retention requirements
  • Restriction: Ask us to limit how we use your data in certain circumstances
  • Objection: Object to processing based on legitimate interests, including direct marketing
  • Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior lawful processing
  • Complaint: Lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office at ico.org.uk)

How to exercise your rights

  1. Self-service export: Profile → Privacy → Download my data
  2. Self-service erasure: Profile → Security → Delete my account
  3. Privacy request: Profile → Privacy → Submit a request (we aim to respond within 30 days)
  4. Contact us: contact form with the subject line "Privacy request"

We may need to verify your identity before fulfilling a request. Where we act as a processor for workspace content, some requests may need to be coordinated with the organisation that administers your workspace. We do not charge a fee unless a request is manifestly unfounded or excessive.

US state privacy rights

Residents of California, Colorado, Connecticut, Virginia, and other US states with comprehensive privacy laws may have additional rights, including the right to know, delete, correct, and opt out of certain processing.

  • Sale or sharing: Elevale does not sell personal data. On our marketing website we use advertising and retargeting technologies (Google, Meta, LinkedIn) that may constitute "sharing" for cross-context behavioural advertising; you can opt out via our cookie banner or by contacting us
  • Sensitive data: We process account credentials and workspace content only as needed to provide the service
  • Authorised agent: You may use an authorised agent to submit a request where permitted by law; we may require proof of authorisation

Submit US privacy requests via the in-app Privacy Center or contact form. We will not discriminate against you for exercising your rights.

Cookies and similar technologies

We use cookies and similar technologies on the marketing site and platform. Essential cookies are required for sign-in and security. Optional analytics and advertising/retargeting cookies (including Google, Meta, and LinkedIn) on the marketing site are used only with your consent. Full details are in our Cookie Policy.

Children

Elevale is a business software service not directed at children under 16 (or the applicable age of digital consent in your country). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

AI and automated processing

When you use optional AI features, the prompts and workspace context you explicitly submit may be sent to AI subprocessors (OpenAI, Anthropic, Google Gemini, Perplexity, and ElevenLabs for voice) via server-side APIs to generate responses, summaries, embeddings, and insights. This AI processing is separate from Google Ads and Google Analytics OAuth integration data: we do not automatically send raw Google API responses to AI providers. See our Google user data notice for integration-specific practices.

AI usage is metered against your prepaid AI wallet (USD) on applicable plans. Transaction history is retained for billing, support, and compliance. Workspace admins may set spending limits and control which features are available. Commercial terms for wallet top-ups, non-refundability, and forfeiture of unused balance on cancellation are in our Terms of Service.

We configure AI providers not to use your content to train their public models for Elevale API usage, subject to each provider's terms. You must comply with each provider's acceptable use terms. AI outputs may be inaccurate: review important decisions before relying on them. See our Acceptable Use Policy and Terms of Service for AI-specific obligations.

Marketing communications and CRM

If you sign up for our newsletter, request a demo, or contact us, we store your details (name, business name, email, and phone number where provided) in our customer relationship management (CRM) and marketing automation platform. We use this to respond to enquiries, manage subscriptions, and send marketing communications.

We may send product updates, onboarding tips, event invitations, and promotional emails where permitted by law (consent, or soft opt-in for existing customers). Our marketing emails may include tracking that records opens and link clicks so we can measure engagement and improve relevance. You can unsubscribe at any time using the link in any marketing email or by contacting us. Service and security messages (for example password resets, billing notices, and incident alerts) are not marketing and cannot be opted out of while you maintain an account.

Legal basis (UK/EU): consent, or legitimate interests / soft opt-in for existing customers and business contacts, as permitted by applicable law.

Advertising and analytics

On our marketing website we use analytics and advertising technologies to understand how visitors find and use our site and to promote our services. Where required by law, these are enabled only with your consent via our cookie banner. These include:

  • Google Analytics: measures website traffic and usage
  • Google Ads and Google remarketing/retargeting: measure ad performance and show relevant ads to people who visited our site
  • Meta (Facebook/Instagram) Ads: ad delivery, measurement, and retargeting
  • LinkedIn Ads: ad delivery, measurement, and retargeting to business audiences

These platforms may set cookies or similar identifiers and process your data as independent or joint controllers under their own privacy policies. They may combine data with information they already hold. You can manage advertising cookies through our cookie banner and your browser or ad-platform settings. See our Cookie Policy for details.

We do not sell your personal data. Where these technologies constitute "sharing" for cross-context behavioural advertising under certain US state laws, you may opt out via our cookie banner or by contacting us.

Data breaches

If a personal data breach poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours where required and contact affected users without undue delay when the breach poses a high risk. Report suspected security issues to contact form. See Incident response and data breaches.

Changes to this policy

We may update this Privacy Policy to reflect legal, technical, or business changes. We will post the revised policy on this page. Changes are effective immediately when posted, unless we state a later effective date. Where law requires additional notice for a change that affects how we process personal data, we will provide that notice (for example by email or in-app notification). Continued use of Elevale after the effective date constitutes acceptance of the updated policy where permitted.

Contact us

Privacy enquiries: contact form
Security issues: contact form
General contact: contact form

Full company identification: Compliance overview → Legal notice

Related documents