Privacy Policy
Last updated: 2026-06-10
1. Data Controller
The data controller for personal data processed through Elevay is:
- Company: Elevay
- Country: France
- Email: privacy@elevay.app
- Data Protection Officer: privacy@elevay.app
- Security contact: security@elevay.app
This Privacy Policy explains how we collect, use, store, and protect your personal data when you use Elevay in compliance with the General Data Protection Regulation (GDPR), the French Data Protection Act (Loi Informatique et Libertés), the Swiss Federal Act on Data Protection (nFADP), and other applicable data protection laws.
2. Data We Collect
2.1 Account Data
When you create an account, we collect:
- Name and email address
- Authentication credentials (via Google OAuth, Microsoft Entra, or email/password)
- Profile picture (if provided via OAuth)
- Company/organization name
2.2 Customer Data (CRM Data)
Data you upload or create within the Service:
- Contact information (names, emails, phone numbers, job titles, LinkedIn URLs)
- Company information (names, domains, industry, size, revenue)
- Deal/opportunity data (names, stages, values, notes)
- Email content (sent and received through connected mailboxes)
- Meeting audio, screen keyframes and transcripts (when you start a recording; the capture runs in your browser or companion app — nothing joins the call)
- Notes, tasks, and activity records
- Outbound email sequences and templates
- Chat conversations with the AI assistant
2.3 Usage Data
We automatically collect:
- Pages visited, features used, and actions taken within the Service
- Browser type, operating system, and device information
- IP address and approximate country (via Vercel/Cloudflare geo headers)
- Timestamps and session duration
- Error logs and performance data
2.4 Enrichment Data
When you trigger enrichment, we retrieve additional public information about your contacts and companies from third-party providers:
- Company firmographic data (industry, employee count, revenue, funding)
- Contact professional data (job title, department, seniority)
- Social media profiles and public web data
3. How We Process Data
3.1 Core Service Delivery
We process your data to provide the CRM, email sequencing, pipeline management, and analytics features of the Service.
3.2 AI and LLM Processing
Elevay uses AI to power features such as:
- Email generation: contact data and context sent to the configured LLM provider to generate drafts.
- Lead scoring: contact and company data analysed by AI models.
- Deal coaching: deal history and interactions processed for recommendations.
- Natural language querying: questions and relevant CRM data processed to generate answers with citations.
- Summarisation: meetings, emails, and activity history summarised by AI.
We minimise the data sent to AI providers to what is strictly necessary. We do not allow AI providers to use your data for model training. By default, requests are routed to the EU endpoint of our primary LLM provider (eu.anthropic.com). Customers who require a fully EU-sovereign LLM may opt into Mistral AI (France) via their workspace settings — see the Security page for details.
3.3 Data Enrichment
Company domains and contact email addresses may be sent to enrichment APIs to retrieve publicly available business information. This processing occurs only when you actively trigger enrichment.
3.4 Google User Data
When you connect a Google account, Elevay accesses the Google user data described below, only with your explicit consent granted through Google's OAuth consent screen, and only for the authenticated user's own account — never another person's mailbox or calendar.
What we access. With gmail.readonly we read messages in your own mailbox over a rolling recent window, including headers, subject, plain-text body, HTML body, attachment metadata and any calendar invitation attached to a message. With calendar.readonly we read events on your primary calendar over a bounded window. With calendar.events we create, update and cancel meetings that you book through Elevay — the same two calendar scopes cover every calendar read and write Elevay performs; we never request broader, calendar-administration access. When you additionally connect a mailbox in Settings → Mail & Calendar, we also request gmail.modify and gmail.send to send email and keep that connected mailbox in sync; we never permanently delete messages or empty trash through this access.
How we use it. Solely to provide features you can see: an in-app inbox showing your conversations, automatic linking of each message to the right contact, company and deal, detection of replies to emails you sent, availability calculation and meeting booking. We do not use Google user data for advertising, and we do not sell it.
How we store it. Message content and calendar event data are stored in our primary database, hosted in the European Union (AWS eu-central-1, Frankfurt), encrypted at rest and in transit. OAuth tokens are encrypted at rest with a dedicated application key. Google user data is isolated per customer workspace and is never readable across workspaces.
How we share it. To generate summaries, suggested replies and search over your own conversations, message content is transmitted to our AI sub-processors — Anthropic for language-model inference and OpenAI for text embeddings (see Section 3.2 for how AI requests are regionally routed) — acting solely as our service providers under Data Processing Agreements, and contractually barred from using it to train their models. Background job orchestration, including passing reply content between processing steps, is performed by Inngest. These sub-processors are listed on the Sub-processors page. We share Google user data with no one else.
How to revoke and delete. You can disconnect your Google account at any time in Settings → Mail & Calendar, and revoke Elevay's access directly at myaccount.google.com/permissions. Disconnecting or closing your account triggers the deletion described in Section 5.
Limited Use. Elevay's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google Workspace API data to develop, improve or train generalised or non-personalised artificial-intelligence or machine-learning models. Any AI processing of your Google data serves only your own workspace and produces no cross-customer model, prior or benchmark. This is enforced in code, not only by policy: the cross-customer benchmark described in Section 3.5 aggregates outcomes recorded from your own CRM deal stages, and outcomes derived from mailbox or calendar content — a detected reply, a booked meeting — are excluded from that aggregation outright.
3.5 Anonymised Cross-Customer Benchmarks
To tell you whether a buying signal actually predicts won deals, we compute anonymised benchmarks across customers — for example “in software, 51-100 employees, a recent funding round preceded a won deal 34% of the time”. These benchmarks contain no company names, contact names, email addresses, message content or calendar content, and no free-text you authored: only counts and rates, grouped by industry, company-size band and a fixed list of signal families. A group is published only when at least 10 distinct customers and 5 distinct companies contribute to it, so no single customer or company can be read out of it. As stated in Section 3.4, no Google user data feeds this computation. You can opt out of contributing entirely — write to privacy@elevay.app (Section 13) and we will disable the contribution for your workspace; opting out does not remove your access to the benchmarks.
4. Legal Basis for Processing
Under GDPR and nFADP, we rely on:
- Performance of contract (Art. 6(1)(b) GDPR): processing necessary to provide the Service.
- Legitimate interest (Art. 6(1)(f) GDPR): for security, fraud prevention, service improvement and analytics. We maintain a documented Legitimate Interest Assessment.
- Consent (Art. 6(1)(a) GDPR): for optional features (e.g. enrichment, analytics cookies, meeting recording). You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c) GDPR): for accounting and tax record-keeping (10-year retention).
5. Data Retention
- Account data: duration of your account plus 30 days post-deletion (for recovery).
- Customer Data (CRM): duration of your account. Deleted within 30 days of account closure or upon GDPR/nFADP erasure request.
- Usage and analytics data: retained in anonymised form for up to 24 months.
- Email opt-out records: retained indefinitely to ensure ongoing unsubscribe compliance (only the suppressed email address is kept).
- Billing records: 10 years (French Code de commerce, Art. L123-22).
- Inactive prospects: deleted after 3 years from last contact (GDPR retention guidance for B2B prospecting).
6. Your Rights
As a data subject under GDPR or nFADP, you have the rights below. Exercise them at privacy@elevay.app — we respond within 30 days.
- Access (Art. 15): request a copy of all personal data we hold; use the export feature or contact us.
- Rectification (Art. 16): request correction of inaccurate data.
- Erasure (Art. 17): request deletion within 30 days.
- Portability (Art. 20): receive your data in a structured, machine-readable format (JSON).
- Restriction (Art. 18): request that we restrict processing in certain circumstances.
- Objection (Art. 21): object to processing based on legitimate interest, including profiling.
- Withdraw consent: where processing is consent-based, you may withdraw at any time.
- Lodge a complaint: with the CNIL (France), the FDPIC (Switzerland), or your local supervisory authority.
7. Sub-processors
We use the third-party sub-processors below to deliver the Service. The full canonical list, updated as it changes, is published on the Sub-processors page.
| Provider | Purpose | Data residency | Operator jurisdiction |
|---|---|---|---|
| Supabase | Primary PostgreSQL database — customer CRM data, mailbox content, conversation history | EU (AWS eu-central-1, Frankfurt) | United States (Supabase Inc., Delaware) |
| Vercel | Application hosting, edge functions, scheduled crons | Global (US primary, EU edges available) | United States (Vercel Inc.) |
| Anthropic | LLM inference for chat, lead scoring, email drafting | EU (eu.anthropic.com — Frankfurt) | United States (Anthropic PBC) |
| OpenAI | Text embeddings for retrieval and search | United States (no EU inference endpoint available) | United States |
| Mistral AI | EU-sovereign LLM alternative (router-enabled) | EU (Mistral La Plateforme, FR) | France (Mistral AI SAS) |
| Resend | Transactional email (invites, password reset, alerts) | United States | United States (Resend Inc.) |
| Stripe | Payment processing and subscription billing | United States (data flows) / Ireland (EU billing entity, Stripe Payments Europe Ltd) | United States with EU subsidiary (Ireland) |
| Google (OAuth + Gmail API) | Authentication via Google; read access to user mailbox and calendar (gmail.readonly, calendar.readonly, calendar.events); when a mailbox is connected in Settings, also send and mailbox-sync access (gmail.send, gmail.modify) | Global (Google Cloud) | United States (Google LLC) |
| Microsoft (Entra + Graph + Outlook) | Authentication via Microsoft, read-only access to Outlook mailbox + Graph calendar | Global (Microsoft 365) | United States (Microsoft Corp.) |
| Inngest | Background job queue and workflow orchestration | United States | United States (Inngest Inc.) |
| Sentry | Error reporting and performance monitoring | EU (de.sentry.io — Frankfurt) when configured, US by default | United States (Functional Software Inc.) |
| PostHog | Product analytics (page views, feature usage) | EU (eu.i.posthog.com — Frankfurt) | United States (PostHog Inc.) |
| Apollo.io | Contact and company enrichment (B2B firmographic data) | United States | United States |
| EmailEngine (self-hosted) | IMAP sync for connected mailboxes | Self-hosted on Elevay infra | Self (Elevay) |
| Hunter.io / Datagma / Pappers / Firmable | Secondary enrichment (email finding, EU/ANZ data) | Mixed: Hunter (FR), Datagma (FR), Pappers (FR), Firmable (AU) | Mixed |
| Twilio | Outbound voice calls, phone numbers, opt-in call recording | EU (region ie1, Dublin) for voice media when configured | United States (Twilio Inc.) |
| Deepgram | Real-time speech-to-text for live call transcription | United States | United States (Deepgram Inc.) |
| Upstash | Redis cache (rate limiting, transient state) | EU (configured region) | United States (Upstash Inc.) |
| Kaspr | Phone-number enrichment (FR-focused) | EU (France) | France (Kaspr SAS, Cognism group) |
| Lusha | Phone-number and email enrichment (fallback) | United States / Israel | Israel (Lusha Systems Ltd.) |
| FullEnrich | Waterfall contact enrichment (EU mobile/email) | EU (France) | France (FullEnrich SAS) |
| Zeliq | Contact enrichment (async) | EU (France) | France (Zeliq SAS) |
| Crunchbase | Company intelligence (funding, investors) — optional | United States | United States |
We maintain Data Processing Agreements (DPAs) with all sub-processors referenced above. The DPA registry — with current status and links — is on the Sub-processors page. We will notify subscribers at least 30 days in advance of any new sub-processor.
8. International Data Transfers
Several sub-processors are headquartered outside the EEA (mainly in the United States). For each transfer of personal data outside the EEA we rely on:
- European Commission Standard Contractual Clauses (SCCs), 2021 modules
- Adequacy decisions where they apply (e.g. UK, Switzerland)
- Supplementary measures: data minimisation, in-transit and at-rest encryption, regional endpoint pinning where available
We do not rely on the EU-US Data Privacy Framework as a primary transfer basis given ongoing judicial scrutiny in the EU. Our Transfer Impact Assessment is reviewed annually and on each sub-processor change.
Customers who require zero data transfer outside the EU/CH may choose the EU-sovereign profile (Mistral AI for LLM, Brevo for transactional email, Datagma/Pappers for enrichment). See the Security page.
9. Cookies and Tracking
Elevay uses the following types of cookies:
- Strictly necessary: required for authentication and session management. Cannot be disabled.
- Functional: remember your preferences (sidebar state, filter selections).
- Analytics: set only with your consent. We use PostHog EU Cloud.
We do not use third-party advertising cookies. We do not sell your data to advertisers.
10. Data Security
See the Security page for a full description of our technical and organisational measures, including encryption, access control, backups, incident response, and our ISO 27001 / SOC 2 roadmap.
11. Children's Privacy
Elevay is not intended for individuals under 18. We do not knowingly collect personal data from children. If we learn that we have, we delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes at least 30 days in advance by email or in-app notification. The "Last updated" date at the top reflects the current version. Past versions are retained internally for audit purposes.
13. Contact & Data Protection Officer
For privacy-related questions, to exercise your rights, or to contact our Data Protection Officer:
- Email: privacy@elevay.app
- Security: security@elevay.app
- Company: Elevay
- Country: France
You have the right to lodge a complaint with the French data protection authority:
- CNIL — Commission Nationale de l'Informatique et des Libertés
- 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
- Web: www.cnil.fr
Swiss data subjects may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner:
- FDPIC / EDÖB / PFPDT
- Feldeggweg 1, 3003 Bern, Switzerland
- Web: www.edoeb.admin.ch