Authentication
Multi-factor authentication (email or authenticator app) required after signup
- Privileged platform roles (super admin, agency admin) must use MFA
- Password reset and session management via Supabase Auth
Elevale is committed to GDPR, UK GDPR, and global privacy standards. This section explains how we protect your data and where to find our legal documents.
GDPR, data retention, privacy rights, security, audit logging, and legal document links.
Plain-language outcomes from our platform documentation: encryption, access control, audit logging, data rights, and retention, without implementation jargon.
Multi-factor authentication (email or authenticator app) required after signup
In transit: TLS 1.2+ for all connections
Row Level Security (RLS) on all tenant data
Under GDPR, UK GDPR, and many US state laws you have rights over your personal data.
Elevale maintains an immutable audit trail for compliance and security accountability.
Retention timelines are consistent across billing, automated jobs, and this documentation.
Retention periods are consistent across billing, automated jobs, and platform documentation.
View retention policy →Until end of current billing period; full access continues
At grace period end; account closed; deletion schedule begins
Personal data anonymised (soft delete)
Permanent deletion (hard delete)
If Elevale is working for your leadership team, a review on G2 or Capterra helps other business directors discover strategic execution software that fits SMEs and growing teams.
Elevale uses trusted subprocessors to deliver the platform. The authoritative list is published at elevale.app/legal/subprocessors. We provide 30 days notice before adding subprocessors that process personal data.
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, storage (EU/US regions) |
| Fly.io | Application hosting |
| Stripe | Payment processing |
| OpenAI / Google Gemini | AI chat and embeddings (when enabled) |
| ElevenLabs | Voice mode (when enabled) |
| AWS SES | Transactional email |
All content is published from Elevale platform documentation in Supabase.
agreed at signup
Open document → Legalagreed at signup
Open document → Legalbranded for Elevale; explains essential and analytics cookies
Open document → LegalView the acceptable use policy.
Open document → LegalView the data processing agreement (dpa).
Open document → LegalView the subprocessor list.
Open document →Last updated: 6 August 2026.
Read guide →This Privacy Policy explains how Elevale ("we", "us", "our") collects, uses, stores, shares, and protects personal data when you use our platform, marketing website, and related services. It also describes your privacy rights and how to contact us.
Read guide →This Acceptable Use Policy ("AUP") applies to all users of Elevale . It is incorporated into our Terms of Service . Violations may result in suspension, account disabling, or termination.
Read guide →Last updated: 6 August 2026
Read guide →Retention timelines are consistent across billing, automated deletion jobs, backups, and this documentation. This page explains what we keep, for how long, and how you can delete data yourself.
Read guide →These Terms of Service ("Terms") govern your access to and use of Elevale . By creating an account, clicking to accept these Terms at signup, or using Elevale, you agree to these Terms, our Privacy Policy , our Cookie Policy , our Acceptable Use Policy , and our Data Processing Agreement (each incorporated by reference). The DPA applies automatically as the processing terms where we (or our infrastructure providers under our instructions) process personal data as processor or sub-processor for your organisation; no separate wet-ink signature is required for the standard online DPA. If you do not agree, do not use the service.
Read guide →Last updated: 6 August 2026.
Read guide →Elevale protects your data with layered authentication, encryption, access controls, and operational safeguards. This page summarises the technical and organisational measures we apply across the platform.
Read guide →Elevale maintains an immutable audit trail for compliance, accountability, and security investigations. This page describes what we log, who can see it, and how long records are kept.
Read guide →Partners and agencies using Elevale white-label branding have specific data protection responsibilities.
Read guide →Last updated: 20 July 2026. Saint Financial Group Limited is committed to making Elevale accessible to people with disabilities. This page explains our approach, the standards we meet, and how to report barriers you encounter.
Read guide →Elevale maintains an incident response process to contain threats, protect users, and meet regulatory notification obligations. This page describes our commitments and your role.
Read guide →Last updated: 6 August 2026. This Referral Agreement (the "Agreement") governs your participation in the Elevale Referral programme (the "Programme"). Elevale is a trading name of Saint Financial Group Limited. In this Agreement, "Elevale", "we", "us", and "our" mean that registered company trading as Elevale. By enrolling in the Programme and accepting this Agreement (acceptance is recorded with a termsAcceptedAt timestamp and a terms_version ), you agree to be bound by it. If you do not agree, do not enrol or continue in the Programme.
Read guide →Reach our privacy and security teams directly. Data rights requests are handled within our documented 30-day SLA.