Back to Elevay

Privacy Policy

Last updated: 2026-06-10

1. Data Controller

The data controller for personal data processed through Elevay is:

  • Company: Elevay
  • Country: France
  • Email: privacy@elevay.app
  • Data Protection Officer: privacy@elevay.app
  • Security contact: security@elevay.app

This Privacy Policy explains how we collect, use, store, and protect your personal data when you use Elevay in compliance with the General Data Protection Regulation (GDPR), the French Data Protection Act (Loi Informatique et Libertés), the Swiss Federal Act on Data Protection (nFADP), and other applicable data protection laws.

2. Data We Collect

2.1 Account Data

When you create an account, we collect:

  • Name and email address
  • Authentication credentials (via Google OAuth, Microsoft Entra, or email/password)
  • Profile picture (if provided via OAuth)
  • Company/organization name

2.2 Customer Data (CRM Data)

Data you upload or create within the Service:

  • Contact information (names, emails, phone numbers, job titles, LinkedIn URLs)
  • Company information (names, domains, industry, size, revenue)
  • Deal/opportunity data (names, stages, values, notes)
  • Email content (sent and received through connected mailboxes)
  • Meeting audio, screen keyframes and transcripts (when you start a recording; the capture runs in your browser or companion app — nothing joins the call)
  • Notes, tasks, and activity records
  • Outbound email sequences and templates
  • Chat conversations with the AI assistant

2.3 Usage Data

We automatically collect:

  • Pages visited, features used, and actions taken within the Service
  • Browser type, operating system, and device information
  • IP address and approximate country (via Vercel/Cloudflare geo headers)
  • Timestamps and session duration
  • Error logs and performance data

2.4 Enrichment Data

When you trigger enrichment, we retrieve additional public information about your contacts and companies from third-party providers:

  • Company firmographic data (industry, employee count, revenue, funding)
  • Contact professional data (job title, department, seniority)
  • Social media profiles and public web data

3. How We Process Data

3.1 Core Service Delivery

We process your data to provide the CRM, email sequencing, pipeline management, and analytics features of the Service.

3.2 AI and LLM Processing

Elevay uses AI to power features such as:

  • Email generation: contact data and context sent to the configured LLM provider to generate drafts.
  • Lead scoring: contact and company data analysed by AI models.
  • Deal coaching: deal history and interactions processed for recommendations.
  • Natural language querying: questions and relevant CRM data processed to generate answers with citations.
  • Summarisation: meetings, emails, and activity history summarised by AI.

We minimise the data sent to AI providers to what is strictly necessary. We do not allow AI providers to use your data for model training. By default, requests are routed to the EU endpoint of our primary LLM provider (eu.anthropic.com). Customers who require a fully EU-sovereign LLM may opt into Mistral AI (France) via their workspace settings — see the Security page for details.

3.3 Data Enrichment

Company domains and contact email addresses may be sent to enrichment APIs to retrieve publicly available business information. This processing occurs only when you actively trigger enrichment.

3.4 Google User Data

When you connect a Google account, Elevay accesses the Google user data described below, only with your explicit consent granted through Google's OAuth consent screen, and only for the authenticated user's own account — never another person's mailbox or calendar.

What we access. With gmail.readonly we read messages in your own mailbox over a rolling recent window, including headers, subject, plain-text body, HTML body, attachment metadata and any calendar invitation attached to a message. With calendar.readonly we read events on your primary calendar over a bounded window. With calendar.events we create, update and cancel meetings that you book through Elevay — the same two calendar scopes cover every calendar read and write Elevay performs; we never request broader, calendar-administration access. When you additionally connect a mailbox in Settings → Mail & Calendar, we also request gmail.modify and gmail.send to send email and keep that connected mailbox in sync; we never permanently delete messages or empty trash through this access.

How we use it. Solely to provide features you can see: an in-app inbox showing your conversations, automatic linking of each message to the right contact, company and deal, detection of replies to emails you sent, availability calculation and meeting booking. We do not use Google user data for advertising, and we do not sell it.

How we store it. Message content and calendar event data are stored in our primary database, hosted in the European Union (AWS eu-central-1, Frankfurt), encrypted at rest and in transit. OAuth tokens are encrypted at rest with a dedicated application key. Google user data is isolated per customer workspace and is never readable across workspaces.

How we share it. To generate summaries, suggested replies and search over your own conversations, message content is transmitted to our AI sub-processors — Anthropic for language-model inference and OpenAI for text embeddings (see Section 3.2 for how AI requests are regionally routed) — acting solely as our service providers under Data Processing Agreements, and contractually barred from using it to train their models. Background job orchestration, including passing reply content between processing steps, is performed by Inngest. These sub-processors are listed on the Sub-processors page. We share Google user data with no one else.

How to revoke and delete. You can disconnect your Google account at any time in Settings → Mail & Calendar, and revoke Elevay's access directly at myaccount.google.com/permissions. Disconnecting or closing your account triggers the deletion described in Section 5.

Limited Use. Elevay's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google Workspace API data to develop, improve or train generalised or non-personalised artificial-intelligence or machine-learning models. Any AI processing of your Google data serves only your own workspace and produces no cross-customer model, prior or benchmark. This is enforced in code, not only by policy: the cross-customer benchmark described in Section 3.5 aggregates outcomes recorded from your own CRM deal stages, and outcomes derived from mailbox or calendar content — a detected reply, a booked meeting — are excluded from that aggregation outright.

3.5 Anonymised Cross-Customer Benchmarks

To tell you whether a buying signal actually predicts won deals, we compute anonymised benchmarks across customers — for example “in software, 51-100 employees, a recent funding round preceded a won deal 34% of the time”. These benchmarks contain no company names, contact names, email addresses, message content or calendar content, and no free-text you authored: only counts and rates, grouped by industry, company-size band and a fixed list of signal families. A group is published only when at least 10 distinct customers and 5 distinct companies contribute to it, so no single customer or company can be read out of it. As stated in Section 3.4, no Google user data feeds this computation. You can opt out of contributing entirely — write to privacy@elevay.app (Section 13) and we will disable the contribution for your workspace; opting out does not remove your access to the benchmarks.

4. Legal Basis for Processing

Under GDPR and nFADP, we rely on:

  • Performance of contract (Art. 6(1)(b) GDPR): processing necessary to provide the Service.
  • Legitimate interest (Art. 6(1)(f) GDPR): for security, fraud prevention, service improvement and analytics. We maintain a documented Legitimate Interest Assessment.
  • Consent (Art. 6(1)(a) GDPR): for optional features (e.g. enrichment, analytics cookies, meeting recording). You may withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c) GDPR): for accounting and tax record-keeping (10-year retention).

5. Data Retention

  • Account data: duration of your account plus 30 days post-deletion (for recovery).
  • Customer Data (CRM): duration of your account. Deleted within 30 days of account closure or upon GDPR/nFADP erasure request.
  • Usage and analytics data: retained in anonymised form for up to 24 months.
  • Email opt-out records: retained indefinitely to ensure ongoing unsubscribe compliance (only the suppressed email address is kept).
  • Billing records: 10 years (French Code de commerce, Art. L123-22).
  • Inactive prospects: deleted after 3 years from last contact (GDPR retention guidance for B2B prospecting).

6. Your Rights

As a data subject under GDPR or nFADP, you have the rights below. Exercise them at privacy@elevay.app — we respond within 30 days.

  • Access (Art. 15): request a copy of all personal data we hold; use the export feature or contact us.
  • Rectification (Art. 16): request correction of inaccurate data.
  • Erasure (Art. 17): request deletion within 30 days.
  • Portability (Art. 20): receive your data in a structured, machine-readable format (JSON).
  • Restriction (Art. 18): request that we restrict processing in certain circumstances.
  • Objection (Art. 21): object to processing based on legitimate interest, including profiling.
  • Withdraw consent: where processing is consent-based, you may withdraw at any time.
  • Lodge a complaint: with the CNIL (France), the FDPIC (Switzerland), or your local supervisory authority.

7. Sub-processors

We use the third-party sub-processors below to deliver the Service. The full canonical list, updated as it changes, is published on the Sub-processors page.

ProviderPurposeData residencyOperator jurisdiction
SupabasePrimary PostgreSQL database — customer CRM data, mailbox content, conversation historyEU (AWS eu-central-1, Frankfurt)United States (Supabase Inc., Delaware)
VercelApplication hosting, edge functions, scheduled cronsGlobal (US primary, EU edges available)United States (Vercel Inc.)
AnthropicLLM inference for chat, lead scoring, email draftingEU (eu.anthropic.com — Frankfurt)United States (Anthropic PBC)
OpenAIText embeddings for retrieval and searchUnited States (no EU inference endpoint available)United States
Mistral AIEU-sovereign LLM alternative (router-enabled)EU (Mistral La Plateforme, FR)France (Mistral AI SAS)
ResendTransactional email (invites, password reset, alerts)United StatesUnited States (Resend Inc.)
StripePayment processing and subscription billingUnited States (data flows) / Ireland (EU billing entity, Stripe Payments Europe Ltd)United States with EU subsidiary (Ireland)
Google (OAuth + Gmail API)Authentication via Google; read access to user mailbox and calendar (gmail.readonly, calendar.readonly, calendar.events); when a mailbox is connected in Settings, also send and mailbox-sync access (gmail.send, gmail.modify)Global (Google Cloud)United States (Google LLC)
Microsoft (Entra + Graph + Outlook)Authentication via Microsoft, read-only access to Outlook mailbox + Graph calendarGlobal (Microsoft 365)United States (Microsoft Corp.)
InngestBackground job queue and workflow orchestrationUnited StatesUnited States (Inngest Inc.)
SentryError reporting and performance monitoringEU (de.sentry.io — Frankfurt) when configured, US by defaultUnited States (Functional Software Inc.)
PostHogProduct analytics (page views, feature usage)EU (eu.i.posthog.com — Frankfurt)United States (PostHog Inc.)
Apollo.ioContact and company enrichment (B2B firmographic data)United StatesUnited States
EmailEngine (self-hosted)IMAP sync for connected mailboxesSelf-hosted on Elevay infraSelf (Elevay)
Hunter.io / Datagma / Pappers / FirmableSecondary enrichment (email finding, EU/ANZ data)Mixed: Hunter (FR), Datagma (FR), Pappers (FR), Firmable (AU)Mixed
TwilioOutbound voice calls, phone numbers, opt-in call recordingEU (region ie1, Dublin) for voice media when configuredUnited States (Twilio Inc.)
DeepgramReal-time speech-to-text for live call transcriptionUnited StatesUnited States (Deepgram Inc.)
UpstashRedis cache (rate limiting, transient state)EU (configured region)United States (Upstash Inc.)
KasprPhone-number enrichment (FR-focused)EU (France)France (Kaspr SAS, Cognism group)
LushaPhone-number and email enrichment (fallback)United States / IsraelIsrael (Lusha Systems Ltd.)
FullEnrichWaterfall contact enrichment (EU mobile/email)EU (France)France (FullEnrich SAS)
ZeliqContact enrichment (async)EU (France)France (Zeliq SAS)
CrunchbaseCompany intelligence (funding, investors) — optionalUnited StatesUnited States

We maintain Data Processing Agreements (DPAs) with all sub-processors referenced above. The DPA registry — with current status and links — is on the Sub-processors page. We will notify subscribers at least 30 days in advance of any new sub-processor.

8. International Data Transfers

Several sub-processors are headquartered outside the EEA (mainly in the United States). For each transfer of personal data outside the EEA we rely on:

  • European Commission Standard Contractual Clauses (SCCs), 2021 modules
  • Adequacy decisions where they apply (e.g. UK, Switzerland)
  • Supplementary measures: data minimisation, in-transit and at-rest encryption, regional endpoint pinning where available

We do not rely on the EU-US Data Privacy Framework as a primary transfer basis given ongoing judicial scrutiny in the EU. Our Transfer Impact Assessment is reviewed annually and on each sub-processor change.

Customers who require zero data transfer outside the EU/CH may choose the EU-sovereign profile (Mistral AI for LLM, Brevo for transactional email, Datagma/Pappers for enrichment). See the Security page.

9. Cookies and Tracking

Elevay uses the following types of cookies:

  • Strictly necessary: required for authentication and session management. Cannot be disabled.
  • Functional: remember your preferences (sidebar state, filter selections).
  • Analytics: set only with your consent. We use PostHog EU Cloud.

We do not use third-party advertising cookies. We do not sell your data to advertisers.

10. Data Security

See the Security page for a full description of our technical and organisational measures, including encryption, access control, backups, incident response, and our ISO 27001 / SOC 2 roadmap.

11. Children's Privacy

Elevay is not intended for individuals under 18. We do not knowingly collect personal data from children. If we learn that we have, we delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes at least 30 days in advance by email or in-app notification. The "Last updated" date at the top reflects the current version. Past versions are retained internally for audit purposes.

13. Contact & Data Protection Officer

For privacy-related questions, to exercise your rights, or to contact our Data Protection Officer:

  • Email: privacy@elevay.app
  • Security: security@elevay.app
  • Company: Elevay
  • Country: France

You have the right to lodge a complaint with the French data protection authority:

  • CNIL — Commission Nationale de l'Informatique et des Libertés
  • 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
  • Web: www.cnil.fr

Swiss data subjects may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner: