Privacy Policy
Last updated: 2026-10-01
Version française : Politique de confidentialité (sections 2, 13, 14, 19, 20 et 24)
1. Who we are
The controller of the personal data described in this policy is:
- Controller: Elevay, société par actions simplifiée à associé unique (SASU)
- Share capital: €1,024
- Registered office: 12 rue Volta, 59130 Lambersart, France
- Companies register: 108 723 537 R.C.S. Lille Métropole
- Privacy contact (also for security): contact@elevay.app
This policy explains how Elevay handles personal data under the General Data Protection Regulation (GDPR), the French Data Protection Act (Loi Informatique et Libertés) and the Swiss Federal Act on Data Protection (nFADP).
2. Who this policy covers, and our two roles
This policy is for:
- people who visit our website;
- people who ask us for a demo, try our AI demo, book a call with us or write to us (see Demo requests, calls and emails);
- people who use Elevay (users) and the companies that pay for it (customers);
- people whom Elevay contacts about its own product (see Elevay's own prospecting);
- people in the LinkedIn network of a member of our team (see If you are connected on LinkedIn with someone at Elevay);
- people whose data our customers process with Elevay (see If a customer of ours holds your data).
Elevay has two roles. For its own purposes (the website, accounts and billing, its own sales and marketing, security, the anonymised benchmarks described below, and the copies left from a former training dataset, described under AI processing, until we delete them) Elevay is the controller. For the data that customers put into Elevay or collect with it (“Customer Data”), the customer is the controller and Elevay is its processor under Art. 28 GDPR: we process that data only on the customer's documented instructions, set out in the data processing section of our Terms of Service.
3. Visiting our website
Vercel hosts our website and application. Our server functions run in Vercel's Frankfurt region (fra1). The first check of each request, which reads whether you are signed in and counts requests per IP address, and the delivery of static files are handled by Vercel's global network, at the location nearest to you. For each request, Vercel's logs hold the page address with its query string, the referring page, the time, the response status, your browser's user agent, your IP address, and the messages our code writes while it handles the request. Some of these messages contain an email address, for example an address typed into the password reset form, even when no account uses it. We use these logs to run the service and to investigate errors and abuse. The logs Vercel shows us are kept for at most 30 days. Vercel does not publish how long it keeps request data for its own purposes. Where error monitoring is on, the warnings and errors among these messages are also sent to Sentry, with email addresses removed; some of them still contain an IP address.
To protect sign-in and our forms against abuse, we count requests per IP address, and per email address for password resets and email verification; these counters expire on their own. Failed sign-in attempts are recorded with the IP address and a hash of the email address, to block password guessing.
Analytics and session recordings run only if you accept them (see Cookies and similar technologies). Our home page, FAQ page and legal pages load nothing from other websites. Where error monitoring is on, every page of our website and app sends error reports to Sentry (see Other services your browser contacts). Our website does not identify the company you work for, and it sets no advertising cookies.
4. Demo requests, calls and emails with us
The “See AI demo” form
“See AI demo” on our home page and our FAQ page opens a demo request form that asks for your work email and, optionally, where you heard about us. Sending it starts our AI demo, described in The AI demo below. If you accepted analytics, we record that the button was clicked and where it sits on the page, that the form opened and was sent, and why an address was refused (for example a personal email address), never what you type in the form.
“Talk to Martin (founder)” and other booking links
“Talk to Martin (founder)” on our home page and our FAQ page opens our Calendly booking page in a new tab, with nothing filled in. Our other booking links open the same page in the same way. A call booked inside our AI demo does not go through Calendly (see The AI demo below). If you accepted analytics, we record which of these buttons was clicked and where it sits on the page.
The form on our previous home page
Our previous home page is still online at elevay.app/landing-v2. Its form asks for your name and work email. When you submit it, your browser opens our Calendly booking page in a new tab, with your name and email added to the page address so that the booking form is already filled in. Calendly receives them when that page opens, even if you do not book. Elevay does not store what you type in this form. If you accepted analytics, we record that the form was submitted, or why it was refused (for example a personal email address), without what you typed.
Booking a call through Calendly
When you book, Calendly collects your name, your email address, your answers to the booking questions and the time you choose. For the booking itself, Calendly acts as our processor. Its booking page is part of Calendly's own website: the cookies Calendly sets there and the technical data it collects, such as your IP address, device and browser, are handled by Calendly as a controller, under its own privacy notice. Calendly is based in the United States, is certified under the EU-US Data Privacy Framework (with its UK Extension and the Swiss-US Data Privacy Framework) and also uses the Standard Contractual Clauses. Calendly adds the booking to our calendar. When that calendar is connected to our own Elevay workspace, calendar sync records the meeting there, with your name and email address as an attendee. Where our Anthropic or OpenAI key is set, our workspace then prepares a briefing for us automatically in the 24 hours before the call: the meeting title and time, your name and email address, and what the workspace holds about your company are sent to Anthropic or OpenAI, both in the United States (see AI processing).
Why, on what basis, and for how long
- Setting up the demo or call you asked for: steps taken at your request before a contract (Art. 6(1)(b) GDPR).
- Following up with you afterwards: our legitimate interest in answering a request you made (Art. 6(1)(f) GDPR). You can object at any time by replying to us or writing to contact@elevay.app, and we stop.
- Preparing our side of the call, including the automatic briefing: our legitimate interest in preparing the calls people book with us (Art. 6(1)(f) GDPR). You can object at any time by writing to contact@elevay.app.
- Recipients: Calendly; Google, which hosts our mailbox and calendar; and our own Elevay workspace with its processors (see Who receives personal data).
- Retention: 3 years from the last contact you initiated (for example your last reply or booking). Deletion at the end of that period is not automated yet, in Calendly, in our calendar or in our workspace.
The AI demo
The AI demo is a guided tour of Elevay led by Elevay's AI agent. The agent is an AI, not a person, and says so in its first sentence. It shows you the real product on a sample workspace: a fictional company and invented people, with real companies shown as sample prospects from public facts. It answers your questions as you type them. Where the demo offers voice, its replies are read aloud from the start (you can turn Sound off at any time), and you can press Talk to speak to it; the text stays on screen. Elevay is the controller of the data described here.
What we process.
- The work email address you enter, which we need to start the demo, and, if you choose one, where you heard about us. We check that the address's domain has mail servers; addresses at personal email providers are refused.
- What you type, the agent's replies, and what you open or approve in the sample workspace.
- If you use Talk, what you say: Deepgram transcribes it, and the transcript becomes your message, like a typed one. We don't record your voice.
- The answers you give when the agent asks about your business, for example what you sell, to whom, in which region, your role and your company.
- If you book a call: your first name, which we need for the booking, and, if you give them, your last name and company.
- Technical data: your browser's language and time zone, to show times in your time zone; when the demo started and ended; and a hash of your IP address and one of its network range (the first three parts of an IPv4 address), made with a key that changes every day (UTC), to limit how many demos and bookings can come from one address and to spot unusual traffic. Because the key changes, the hashes of two different days cannot be matched with each other.
Who receives it.
- Microsoft Azure OpenAI Service writes the agent's replies and, after the demo, the summary described below and, for a sample of demos, an automated check that the agent's replies were supported by what it knows (it receives the conversation after the names of other people have been removed). The demo uses its own EU Data Zone deployment, on a separate Azure resource in Sweden Central: Microsoft processes these requests inside its EU Data Boundary (see AI processing). The replies and the summary never fall back to another provider: when that deployment is unavailable or busy, the demo becomes a pre-written tour. Microsoft does not use them to train its models.
- Microsoft's abuse monitoring. Microsoft checks prompts and replies for harmful content and for patterns of misuse, such as repeated attempts to make the agent break its rules, which a public demo draws. Prompts and replies that its systems flag can be stored in the Azure geography of our resource (Sweden) and reviewed by authorised Microsoft employees located in the European Economic Area. Microsoft does not publish how long it keeps them (its “Data, privacy, and security” and “Abuse monitoring” pages, updated on 5 June 2026).
- Deepgram (Deepgram Inc., United States), where the demo offers voice, on its EU endpoint (
api.eu.deepgram.com). The sound is on from the start, so Deepgram reads the agent's replies aloud unless you turn Sound off; if you press Talk, it also transcribes what you say. Your browser connects to Deepgram directly, with an authorisation that lasts 30 seconds; Deepgram receives your IP address and the text of the replies it reads and, if you use Talk, your voice. Turning Sound off and leaving Talk off stops it. Every request carries Deepgram's model-improvement opt-out (mip_opt_out), so Deepgram does not use them to improve its models. - Vercel, whose server functions run in Frankfurt, and Supabase, whose database is in Frankfurt, host the demo and its record.
- Inngest (United States), our background job service: the demo's own jobs, which end the session, write the summary and clean up each day, receive only the identifier of your demo session. The jobs that later complete the records added to our workspace run through Inngest as for any record there.
- If you book a call: Google, which hosts our calendar, sends you the invitation and hosts the call, and, where our team's Slack alert channel is configured, Slack (United States) receives an alert for our team (see below).
- Our own Elevay workspace and its processors (see Who receives personal data).
After the demo. The summary you see at the end is built from the demo itself, without AI. Then Microsoft Azure OpenAI Service writes an internal summary for Martin, our founder: what you saw, your questions, what the agent could not answer, any objections, and a short note on how well Elevay might fit your company, with its reasons. The same step lists the names of other people you mentioned, and we replace them with “[name]” in the conversation, the questions and the summary that we keep. If that step fails, we delete the conversation after 24 hours and add neither the summary nor your questions to our workspace.
If you sent at least three messages (a suggested reply you click counts), spent at least three minutes between your first and your last message or action in the sample workspace (such as a filter you set or a draft you approve), or booked a call, we add your company to our own Elevay workspace, found from your email's domain, with a record of the demo: the summary and the fit note, the parts of the tour you saw, your answers, the company name you typed, a list written by the AI of what the agent could not answer, and the booking. Your questions, word for word, are copied there only if you book a call; otherwise they stay only in the demo record. If you book, you are also added as a contact, with your name and email address, and Martin gets a task to prepare the call; he also gets a follow-up task when the note says the fit is strong. As for any company or person added to our workspace, the company, and you if you booked, are then completed from our data providers, such as Apollo.io (United States), and scored (see Elevay's own prospecting and Scoring and profiling). The demo does not add you to any email sequence. If you asked us to stop contacting you, we still book the call you ask for: if your address is on our suppression list, we do not add you back as a contact, and if your company is on it, the demo does not add your company or you to our workspace; the meeting itself still appears in our calendar.
Booking a call in the demo. The agent can show you free 30-minute slots in Martin's calendar, but it cannot book: you do, by picking a slot. We then book it on Martin's Google calendar, and Google Calendar sends you the invitation from his account. The invitation carries a Google Meet link, the name of your company or your email domain, and up to three of the questions you asked. When you join, Google hosts the call and receives your IP address, your name as it appears in the call, and your audio and video. Where our team's Slack alert channel is configured, it receives an alert with your first name, your company and the time of the call. The demo sends you no other email.
The call with Martin. Martin may record and transcribe the call with Elevay's meeting capture, which runs in his browser or in an app on his computer (nothing joins the call). The audio is transcribed by Deepgram, in the United States (see AI processing), and the recording, the transcript and the notes are kept in our workspace with the other records of the call. Our invitation mentions recording only when our recording notice is switched on, and that notice is in French. If you prefer the call not to be recorded, tell us before or at the start of the call, and we do not record it. As for any meeting in our calendar, our workspace can also prepare a briefing for Martin automatically in the 24 hours before the call (see Booking a call through Calendly above): where our Anthropic or OpenAI key is set, your name and email address and what our workspace holds about your company, which can include notes from the demo, are sent to Anthropic or OpenAI, both in the United States.
Why, and on what basis.
- Running the demo you asked for, and booking the call you ask for in it: steps taken at your request before a contract (Art. 6(1)(b) GDPR).
- Protecting the demo against abuse (the daily hashes of your IP address and its network range, the limits per email address and the checks against automated scripts): our legitimate interest in keeping the demo available and its cost under control (Art. 6(1)(f) GDPR).
- After the demo (the summary and fit note for Martin, adding your company, and you if you book, to our workspace, preparing the call, following up with you about the demo, and improving the demo from counts across demos and from a review of conversations and of the questions the agent could not answer): our legitimate interest in answering the interest you showed and in improving the demo (Art. 6(1)(f) GDPR). You can object at any time by writing to contact@elevay.app: we then stop, and on request we delete what the demo recorded about you.
AI and decisions. The fit note is written by AI for Martin and decides nothing by itself: it has no legal or similarly significant effect on you (Art. 22 GDPR). The checks that can refuse to start a demo, such as a personal email address or too many demos from one address, only decide whether the demo starts; you can still book a call through the “Talk to Martin (founder)” link.
How long we keep it.
- The conversation (what you typed or said, kept as text, and the agent's replies): deleted automatically 90 days after the demo, or after 24 hours if the removal of other people's names failed.
- The demo record (your email address, names, company, answers, summary and the hashes of your IP address): anonymised automatically 90 days after the demo; only counts remain, such as the number of messages and the length of the demo.
- What we added to our workspace (the record of the demo, your contact record if you booked, the calendar event, any Slack alert and the records of the call): 3 years from the last contact you initiated, as above. Deletion at the end of that period is not automated yet.
- What Microsoft's abuse monitoring keeps: Microsoft does not publish how long.
- Your voice: Elevay never stores it. It exists only in your browser's memory and on its way to Deepgram. Deepgram's model-improvement page says that data from requests with the opt-out is kept only as long as it needs to process them. The request log that Deepgram shows us lists, for each request, technical details only (the settings of the request, the length of the audio, the number of characters read aloud and a one-way fingerprint of that text), not the audio and not the words; that log is served from Deepgram's global service, not from its EU endpoint. What Deepgram itself keeps is still to be confirmed with its data processing agreement (see our sub-processors).
- Our record of each AI request of the demo (model, amount of text, cost and time) holds none of your text.
What the demo does not do.
- We don't record your screen. If you accepted analytics, our session recordings show the demo as an empty block, and the events we send to PostHog (the demo opened, started, went on, led to a booking or ended, or an email address was refused and why) carry no email address, name, company or anything you type.
- We don't record your voice. The microphone stays off until you press Talk, and turns off when you press it again, after a minute without speech, when the demo pauses or ends, or when you leave the tab.
- We do not identify your company from your IP address.
- The demo sets no cookie. It keeps one entry,
ads:session, in your browser's session storage, so that reloading the page resumes the demo in the same tab. It is deleted when you close the demo; if you leave the page without closing it, your browser deletes it when you close the tab. It is strictly necessary for the demo you asked for, so it needs no consent (see Cookies and similar technologies). The preferences that the sample pages would save on your device are kept in memory only, and discarded when the demo closes. - Your conversation is not used to train AI models, and it is not kept as an example for later drafts.
Anyone can type an email address into the demo form, and the demo never tells anyone whether an address was used before. If someone used yours, or to have your demo records deleted, write to contact@elevay.app.
When you write to us
When you write to us, for example for support, to exercise a right or about a partnership, we keep your emails and our replies in our mailbox, hosted by Google. Our mailbox can be connected to our own Elevay workspace: your emails are then copied there and processed by its AI features like any connected mailbox (see 6), and when we reply to you, you are added there as a contact, with a company created from your email domain.
- Purpose: answering you. Where our mailbox is connected to our Elevay workspace, also keeping a record of our exchange in our CRM, and extracting from what you write the objections, hooks and questions that shape our sales approach.
- Legal basis: our legitimate interest in answering the people who write to us (Art. 6(1)(f) GDPR), or our legal obligation when you exercise a right (Art. 6(1)(c) GDPR). For the CRM record and the extraction: our legitimate interest in improving how we sell (Art. 6(1)(f) GDPR); you can object at contact@elevay.app.
- Objections sent by email: an email you send us does not put your address on our suppression list by itself, even when you object in it. Only the Unsubscribe link, and a reply to one of our campaign emails that our workspace classifies as a request to stop, do that automatically. When we reply from a mailbox connected to our workspace, you can be added there as a contact, and the workspace then scores you like any other contact (see Scoring and profiling).
- Retention: in our own workspace, the limits set for our own prospects (see How long we keep data). In our mailbox we have not set a fixed period yet.
5. Your Elevay account
When you create or use an account, we process:
- your name and email address; your profile photo if you sign in with Google or Microsoft; a hash of your password if you sign in with an email and password (never the password itself);
- your workspace, its name, your role and your settings;
- the mailboxes, calendars and LinkedIn account you connect; signing in with Google or Microsoft also connects that account's mailbox and calendar (see Google User Data and Microsoft User Data); access tokens and mailbox passwords are encrypted when they are stored;
- your subscription and invoices. Payments are made on Stripe's pages: we do not see or store your card number;
- security records: failed sign-in attempts, with the IP address and a hash of the email address; password reset requests and requests to resend the verification email, each with its time, the IP address and the browser's user agent; and your workspace's audit log, which records sign-ins, sign-outs, invitations (with the invited email address), role and settings changes, two-factor changes, password resets (with the IP address and the browser's user agent), exports from Settings → Privacy & data (with the IP address) and edits to records (see How long we keep data).
To create an account you must give your name and your email address and, unless you sign in with Google or Microsoft, a password. Without them we cannot create your account. Everything else is optional.
If you accepted analytics in the browser you use, our servers also send PostHog a few account events: sign-in completed, onboarding completed, choosing the founder-led plan, the time to your first action, and your accept or dismiss decisions on suggested record updates. They are linked to your user ID, or for the last ones to your workspace ID. Without that consent they are not sent.
6. Customer Data: what Elevay processes for its customers
Customers use Elevay to find, research and contact businesses and the people who work there. For this Customer Data, the customer is the controller and Elevay its processor (see our two roles).
6.1 What it contains
- Companies: names, domains, industry, size, revenue, funding, location, technologies used, open jobs, news and other buying signals.
- People at those companies: names, job titles, seniority, department and sub-department, LinkedIn headline, city, region and country, time zone, career history (up to 20 current and past positions, with employer, title and dates), email addresses (usually work addresses, sometimes personal ones), phone numbers, LinkedIn profile addresses and photos, and job changes. Where LinkedIn profile enrichment runs, also the profile summary, the location and current company shown on LinkedIn, the number of positions and schools listed, whether the person shows as open to work or has an open profile, how many connections they share with the user and how far they are from the user in the LinkedIn network.
- Where that option is on, reactions to and comments on LinkedIn posts: the user's own posts, posts found by keyword and competitors' posts that the customer lists, with the first 300 characters of each comment. Engagement with a competitor's post is recorded as a buying signal on the person's company, when that company is known.
- LinkedIn connections between the customer's team and these people.
- The first-degree LinkedIn connections of each user who connects a LinkedIn account: each connection's name, headline, profile address and LinkedIn member ID, whether or not they work at a target company, and the employer Elevay reads from the headline.
- Interactions: emails sent and received through connected mailboxes, LinkedIn messages and invitations, WhatsApp messages where WhatsApp is enabled, calls, meetings, notes, tasks and deals.
- Meeting audio, screen keyframes and transcripts (when you start a recording; the capture runs in your browser or companion app — nothing joins the call).
- Calls placed through Elevay: numbers, status and outcome (including whether an answering machine picked up), live transcripts and, when call recording is on, the recording. Call recording is off by default.
- Email opens and clicks (see Email opens and clicks) and website visits recorded by a customer's visit pixel (see 6.5).
- Scores, signals and summaries that Elevay computes from the above.
- Conversations with the AI assistant, and the drafts and sequences it prepares.
6.2 Where it comes from
- What the customer uploads, imports or types into Elevay.
- Mailboxes and calendars that users connect: Google, Microsoft, other mailboxes over IMAP and SMTP, calendars connected over CalDAV, and sending mailboxes provisioned through Winnr, including the replies they receive.
- LinkedIn accounts connected through Unipile: conversations and invitations; the list of the user's LinkedIn connections, which Elevay matches to contacts to show who knows whom; LinkedIn and Sales Navigator searches for people and companies that match the ICP, including searches that run in the background, every weekday hour, for people at target accounts and for people who can introduce you; the profiles of the people found, as the connected member's LinkedIn account sees them; authors of LinkedIn posts found by keyword; and, where that option is on, the people who react to or comment on the user's own posts, on posts found by keyword and on competitors' posts that the customer lists, with the first 300 characters of each comment. WhatsApp through Unipile, where WhatsApp is enabled.
- Calls placed through Twilio; meetings captured in the browser or companion app; and video meeting recordings that Infomaniak kMeet saves on the organiser's kDrive.
- Sourcing and enrichment providers: Apollo.io, Ocean.io, Pappers (a commercial provider of French register data) and the other data providers listed in the registry below.
- Public sources: company websites, a public company register (the French government's company directory), public job boards (the Greenhouse, Lever and Ashby job board interfaces) and web pages found by web research (see AI processing).
- Email opens and clicks, and a customer's visit pixel.
6.3 Sourcing and enrichment run automatically
Once a customer sets up its ideal customer profile (ICP) and settings, scheduled jobs run every day, and signal checks several times a day. They find new companies and people that match the ICP, fill in missing facts, look for new buying signals and refresh what is already there. They do not wait for someone to click.
Pausing an ICP profile (Settings → Your TAM) stops the search for new companies for that profile. It does not stop the daily search for people at the companies already in the TAM, which uses the personas of the profiles that are still active, or the LinkedIn searches for people at target accounts that run every weekday hour. To stop these for a company, exclude it or delete it.
6.4 Contact photos
To show a face next to a contact, Elevay uses:
- LinkedIn profile photos obtained through Unipile;
- the photos of your own Google or Microsoft contacts (see Google User Data), served through our servers;
- the photo address that an enrichment provider such as Apollo.io returns;
- for contacts who use a personal email address, such as a Gmail address, their Gravatar image, looked up with a SHA-256 hash of the email address.
We keep a copy in our own database of LinkedIn photos, of the photos Apollo.io returns, and of the photos of your Google or Microsoft contacts. A photo we have not copied, and every Gravatar image, is loaded by your browser from its source (see Cookies and similar technologies).
6.5 Website visits recorded by a customer's pixel
A customer can put Elevay's visit pixel on its own website. The pixel sets a cookie named _eve_v (a random visitor ID, 90 days) and sends us the pages visited, the referring page and campaign parameters. We store them with the browser's user agent, a SHA-256 hash of the IP address and a SHA-256 hash of its network range (the first three parts of an IPv4 address). The IP address itself is not stored in the visit record: it passes through our background job service (Inngest, United States) to a company-identification provider where one is configured (Snitcher, RB2B or Clearbit), which receives the IP address and, depending on the provider, the browser's user agent and the page address, and returns the visiting company. That company can be added to the customer's accounts and enriched, and the visit can start the customer's outreach to people at that company where the customer's settings do so. The customer must ask its visitors for consent before loading the pixel. The pixel is not used on elevay.app.
6.6 How long it is kept
While the customer's account is open, the customer decides: it can edit its records and delete them. Deleting a contact or a company in Elevay archives it: the record leaves the lists, can be restored, and keeps its activities and notes until the account is closed. To erase a person's data for good, the customer writes to contact@elevay.app.
We then erase that person's data from the workspace as we do for our own prospects (see Elevay's own prospecting). The workspace keeps the person's address on its suppression list, and their email address and LinkedIn profile address, without their name, on its do-not-import list, so that it does not contact or import them again. The person's own phone numbers stay on that suppression list too, and the workspace does not add the person again from a calendar invitation, a web form, an import, a data provider's search, its WhatsApp account or by hand. An erased record cannot be restored. Deals stay, as the customer's records, without the link to the person, and we tell the customer where a deal's name or summary still names the person, so that it can edit it. A meeting or an email in which other people also took part stays in the workspace for them, and so does Elevay's copy of that email from the customer's mailbox: we remove from it the person's name, email address, phone number, LinkedIn profile and the link to their record, including from its list of participants, its transcript and the notes, summaries and memory Elevay made from it, and we delete the audio and screen images of its recording; what the person said stays, without those identifiers. A meeting or an email with only the person and the customer's own users is erased. So are the assistant threads opened on the person's record or on their meetings, the actions Elevay's agents prepared about them, the deal suggestions made from their replies and the records of the Elevay recording notices shown to them in a meeting, with any click or sign-up that followed. We erase the copies Elevay took from the customer's connected mailboxes and LinkedIn accounts, and Elevay no longer copies the person from them under the email addresses and LinkedIn identifiers it knew for them; we tell the customer which copies it still holds at their source, such as the messages in its own mailbox, and we erase in a second step what the first step could not remove: the records of the automatic checks of the workspace's messages to the person, the person's identity links, the records of the data providers through which the workspace found the person, and the records of automated work that may contain one of the person's identifiers. For the workspace's recent emails to the person (those sent, bounced, reported as spam or answered in the 31 days before the erasure), it keeps only when each one was sent and whether and when it bounced, was reported as spam or was answered, without the person's address, name or the message, so that its sending protection keeps counting them. It also keeps which sequence each one was part of, and when a meeting booked from a sequence was booked, so that the check that pauses a sequence nobody answers counts the same; and, with each email, pseudonymous keys (a keyed hash of each identifier the message was sent under, never the identifier itself), so that a bounce or spam report about it that arrives after the erasure is still counted. They are deleted automatically within 33 days of the erasure or, for an email whose bounce or spam report arrives after the erasure, within 33 days of the last such report.
When a customer's subscription ends, the customer can ask for an export of its Customer Data for 30 days. The account is then closed, and we delete its Customer Data within 30 days of the closure. A daily job is set to delete the workspace's Customer Data. It first deletes, in steps it resumes the next night when one fails, the data kept beside the main records, such as the copy of synced mailbox messages, meeting captures, LinkedIn data, the records of contact photos, visit records, the people found at accounts, the examples kept for later drafts (see AI processing), and the workspace's suppression list, do-not-call list and meeting-recording opt-outs; then, in one step that deletes nothing if it fails, the main records: contacts, companies, deals, activities, notes, tasks, sequences, emails sent through Elevay, chat conversations and call records. That job does not yet cover every kind of Customer Data: it keeps contacts and companies as rows emptied of the person and the account, the records our system keeps of its own writes, of where field values came from and of meetings, the list of accounts and people the workspace removed, which stops them from being added again, contact photo files that other workspaces may share, the opt-outs and spam complaints on the suppression list, which our database protects against any deletion, and the domains, mailboxes, phone numbers and accounts bought or connected for the workspace until we release them. We therefore complete each deletion ourselves and confirm it to the customer in writing. We keep the workspace audit log and invoices as described in How long we keep data.
7. Google User Data
When you sign in with Google or connect a Google account, Elevay requests the permissions below and starts syncing that account's mail, calendar and contact photos. It accesses the Google user data described below only with your explicit consent granted through Google's OAuth consent screen, and only for the authenticated user's own account — never another person's mailbox or calendar.
What we access. With gmail.modify we read the messages in your own mailbox: when you connect, those of the last 3 months (your workspace settings, under Settings → Inbox Management, can choose 1, 6 or 12 months instead), then new messages as they arrive. We read their headers, subject, plain-text body, HTML body, attachment metadata and any calendar invitation attached to a message. When you open an attachment in Elevay, we fetch its content from Gmail and pass it to your browser; we do not store it. The same scope lets us read whether you have already opened a message in Gmail — so Elevay does not show as new something you have already read elsewhere — and, only when you explicitly open or mark a message as read in Elevay, set that same read state back on the message in Gmail. We never mark your mail as read automatically: no background job, scheduled task or AI assistant changes the state of a message in your mailbox. When you send or schedule an email from your Gmail address in Elevay, the same scope lets us send it through Gmail, as you, so that it stays in its conversation and appears in your Sent folder. We send nothing through Gmail that you did not send or schedule yourself; the other emails Elevay sends go out through Resend or the sending mailbox's own SMTP server. gmail.modify does not allow permanent deletion, and we never delete messages or empty your trash. We do not request https://mail.google.com/, which would allow permanent deletion. With calendar.readonly we read the events and the free or busy times of your primary calendar over a bounded window. When an email sent from Elevay carries your booking link, anyone who opens that link sees your open slots, but not your events, and can pick one. With calendar.events Elevay then creates that meeting on your calendar, and it creates, reschedules and cancels the meetings that you or Elevay's AI assistant book. Each time, Google Calendar emails the invitation, update or cancellation to the attendees on your behalf. The same two calendar scopes cover every calendar read and write Elevay performs; we never request broader, calendar-administration access. With contacts.readonly and contacts.other.readonlywe read the email addresses and profile photos of your saved contacts and of the people you have exchanged email with, when you connect the account and then once a day. We keep a copy of each photo in our database, refreshed about every 30 days, so that the inbox can show senders' faces.
How we use it. To provide features you can see: an in-app inbox showing your conversations, automatic linking of each message to the right contact, company and deal, adding the people you email to your CRM as contacts, with their company created from the email domain (you can change this in Settings → Inbox Management), summaries and sentiment and intent labels for incoming messages, detection of replies to emails you sent, buying signals and deal details drawn from each conversation (such as objections, competitors mentioned, budget and timing), the fields you ask the AI to fill in, a sales playbook built from the objections and questions in the replies you receive, a memory of your workspace that the AI assistant cites, built by extracting the people, companies and facts each email mentions and by indexing message text for search, a knowledge base rebuilt each night from excerpts of your most recent emails (what you sell, common objections, competitors mentioned), sender photos, availability calculation and meeting booking. Our code also keeps some message text as examples for later drafts in the same workspace, and until this version of this policy it also copied some into a training dataset (see Limited Use below). We do not use Google user data for advertising, and we do not sell it. We do not import your Google address book into your CRM.
How we store it. Message content and calendar event data are stored in our primary database, hosted in the European Union (AWS eu-central-1, Frankfurt), encrypted at rest and in transit. OAuth tokens are encrypted at rest (AES-256-GCM) with an application key kept outside the database; tokens stored before we introduced this encryption stay as they were stored until our backfill rewrites them. Google user data is stored per customer workspace. In the application it is shown to that workspace's members, as described under How we share it, and to Elevay staff only as described under Human access.
How we share it. Inside your workspace: Elevay records emails from your mailbox in your workspace, with their full text. Every member of your workspace, whatever their role, can read an email recorded this way, and an email linked to a contact appears on that contact's record. The inbox itself shows your mailbox only to you, unless you share the mailbox with the workspace.
To generate summaries, suggested replies, search over your own conversations, the workspace memory and the nightly knowledge base, message content is transmitted to our AI sub-processors — Microsoft Azure OpenAI Service, our primary provider, and Anthropic and OpenAI as fallbacks that a few features call directly (see AI processing). Their terms do not allow them to use it to train their models. We also share Google user data with the service providers that store and process it for us: Supabase (our database, Frankfurt), Vercel (our hosting, Frankfurt), Inngest (our background jobs, which pass content such as replies between processing steps) and Resend, which delivers the other emails Elevay sends for a Google mailbox (an email you send from your Gmail address goes through Gmail). Where automatic qualification of new contacts is switched on (it is off by default), the name and email address of a person added to your CRM from your mail are sent to Apollo.io to enrich the contact. The Sub-processors page lists each of them, with its data processing agreement where one is published. One more service receives data derived from your Google mail: for senders who use a personal address, such as a Gmail address, your browser loads their Gravatar image from Automattic (United States) with a SHA-256 hash of their address, and Gravatar receives your IP address (see 6.4). Our team's alert channel on Slack receives contacts' names and message excerpts only from Elevay's own workspace, never from yours. We share Google user data with no one else.
Human access. Elevay staff do not read your Google user data unless you agree to it for the specific messages concerned, it is needed to investigate abuse or a security incident, or the law requires it. Our read-only support mode does not yet enforce this: it shows what the workspace's users see, including the content of synced emails on contact records, and it does not ask the customer or the mailbox owner first. We therefore open it on a workspace only when the customer asks us to.
How to revoke and delete. You can disconnect your Google account at any time in Settings → Inbox Management. This stops syncing and deletes the access tokens we hold. It does not delete the messages, contacts and photos already copied into your workspace, and it does not revoke Elevay's access at Google: do that at myaccount.google.com/permissions. To have the Google user data already copied deleted while your account stays open, write to contact@elevay.app. When your account is closed, we delete the Google user data it holds within 30 days. Our daily deletion job does not yet cover the copy of your synced messages or the sign-in record that holds your Google access tokens, so we delete those ourselves (see 6.6 and How long we keep data).
Limited Use. Elevay's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google Workspace API data to develop, improve or train generalised or non-personalised artificial-intelligence or machine-learning models. Until this version of this policy, our code copied some message text, which can come from Gmail, into the training dataset described under AI processing. That copy has stopped, and we will not use the copies already made to train any model. The cross-customer benchmark described under Anonymised Cross-Customer Benchmarks aggregates outcomes recorded from your own CRM deal stages, and outcomes derived from mailbox or calendar content — a detected reply, a booked meeting — are excluded from that aggregation in its code.
Our code also contains a prompt optimiser that could learn across workspaces from the traces of AI requests, which can include text from your mail. It is off unless we switch it on. Using it on Google user data would breach the Limited Use requirements, so we will keep it off for as long as it can read that data.
8. Microsoft User Data
When you sign in with Microsoft or connect an Outlook mailbox, Elevay requests these delegated permissions, for your own account only, and starts syncing that account's mail, calendar and contact photos:
openid,email,profile: your identity, to sign you in.offline_access: a refresh token, so that syncing continues without asking you to sign in again.Mail.ReadWrite: to read the messages in your mailbox (when you connect, those of the last 3 months, or 1, 6 or 12 months as your workspace settings choose, then new messages as they arrive), including whether you have already read them, and to mark a message as read in Outlook only when you open it or mark it read in Elevay. When you open an attachment in Elevay, we fetch its content from Outlook and pass it to your browser; we do not store it. Nothing in Elevay deletes your messages.Mail.Send: when you send or schedule an email from your Outlook address in Elevay, to send it through Microsoft, as you, so that it stays in its conversation and appears in your Sent Items. We send nothing through Microsoft that you did not send or schedule yourself.Calendars.ReadWrite: to read your calendar events and free or busy times over a bounded window. When an email sent from Elevay carries your booking link, anyone who opens that link sees your open slots, but not your events, and can pick one; Elevay then creates that meeting on your calendar. It also creates, reschedules and cancels the meetings that you or Elevay's AI assistant book. Each time, Outlook sends the invitation, update or cancellation, with any note you add, to the attendees from your mailbox.Contacts.Read: to read your saved Outlook contacts and their photos when you connect and then once a day, and keep a copy of each photo, refreshed about every 30 days, to show senders' faces in the inbox.
We use, store and share Microsoft user data in the same way as Google user data above, including the examples, the copies left from the former training dataset, what every member of your workspace can read and the staff access described there: for the features listed there, stored in the EU, processed by our AI sub-processors, never used for advertising and never sold. You can disconnect in Settings → Inbox Management. This stops syncing and deletes the access tokens we hold. It does not delete the messages, contacts and photos already copied into your workspace, and it does not remove Elevay's access at Microsoft: do that in the app permissions of your Microsoft account. To have the data already copied deleted while your account stays open, write to contact@elevay.app.
9. AI processing
Elevay uses language models to draft emails and messages, summarise conversations and meetings, answer questions about your data with citations, classify replies, extract facts, score leads, and turn text into embeddings for search.
- Primary provider: Microsoft Azure OpenAI Service. Our resource is in Sweden Central. Requests, including embeddings, use Data Zone Standard deployments: Microsoft processes those prompts and responses inside its EU Data Boundary, which covers the EU and can include EFTA countries such as Norway and Switzerland.
- One exception: preparing sequences. Planning the approach to an account, writing the messages and checking them against the facts we hold use a Global Standard deployment. For those requests Microsoft can process the prompt in any region where the model runs, including outside the EU; what Microsoft stores stays in our EU resource.
- Microsoft's abuse monitoring. Microsoft checks the prompts and responses we send to Azure OpenAI Service for harmful content and for patterns of misuse. Those that its systems flag can be stored in the Azure geography of our resources (Sweden) and reviewed by authorised Microsoft employees located in the European Economic Area. Microsoft does not publish how long it keeps them. The modified abuse monitoring that Microsoft offers some customers, without this storage, is not in place for our resources.
- The AI demo on our website runs on its own EU Data Zone deployment, on a separate Azure resource in Sweden Central. Its replies and its end-of-demo summary never fall back to another provider or to a model outside that deployment: when it is unavailable, the demo becomes a pre-written tour (see The AI demo).
- Fallbacks: Anthropic (United States) and OpenAI (United States). They are used as fallback providers and by a few features that call them directly, not through Microsoft, depending on which of our keys are set. Meeting preparation, including the briefing prepared automatically before each meeting, mapping the columns of an imported file, voice-of-customer analysis and the nightly analysis that builds your workspace's knowledge base call Anthropic, or OpenAI. Where our Anthropic key is not set, the inbox's AI tools, the summaries and intent labels computed for each incoming email, deal summaries, call-script translation and the extraction of people, companies and facts from emails, notes and call transcripts call OpenAI. Separately, where transcription is enabled, OpenAI transcribes meeting recordings that are uploaded or retrieved from Infomaniak kDrive, unless a self-hosted transcription server is configured.
- Mistral AI (France) is available on request as the language model of a deployment. It is a setting of the whole deployment, not a switch in your workspace.
- No training. Under the terms we use them on, Microsoft (Azure OpenAI Service), Anthropic and OpenAI do not use our requests to train their models.
- Transcription: Deepgram (United States). Live meeting capture and call transcription use Deepgram. Every transcription request we send carries Deepgram's model-improvement opt-out (
mip_opt_out), so Deepgram does not use the audio to improve its models. When a call uses Twilio's built-in live transcription, Twilio sends the audio to Deepgram under Twilio's own terms. The voice of the AI demo on our website, where it is offered, uses Deepgram's EU endpoint instead, with the same opt-out (see The AI demo). - Web research: Microsoft Bing. To find facts and dated events about companies, Elevay uses the web search tool of Microsoft's Azure AI Foundry, which runs on Grounding with Bing Search. The searches describe a company: its name, its domain and facts we already hold about it. The pages found can name people, for example a newly appointed executive. Microsoft processes these searches under its Grounding with Bing terms and the Microsoft Privacy Statement, not under our data processing agreement with Microsoft, and they can leave the EU.
In AI data handling (/settings/inbox-ai-profile, listed under Settings for workspace admins), a user can turn off some of the AI tools they start themselves in the inbox: Ask, reply drafts, grammar fixes and scheduling drafts. It does not stop rewriting or translating a draft, the summaries and the sentiment and intent labels computed for incoming mail, the thread summary, the follow-up drafts prepared each day, the extraction of people, companies and facts from each email into the workspace memory, or the nightly knowledge-base analysis.
Examples kept for later drafts. When a user approves a draft without changing it or edits a draft before sending it, when a user confirms or corrects how Elevay classified a reply, and when a message sent from Elevay draws a positive answer, Elevay keeps the text concerned as an example for later drafts in the same workspace. Where our quality cycle runs (every week where it is switched on, or when we start it), Elevay also keeps AI results that our quality checks score highly, with the start of the request that produced them, which can quote an email, as examples for later drafts in the same workspace. In both cases email addresses and phone numbers are replaced; examples kept by the quality cycle before this version of this policy can still contain them. Our daily deletion job deletes these examples when the workspace is closed, except older examples that do not record their workspace, which we delete ourselves (see 6.6).
A former training dataset. Until this version of this policy, our code also copied these examples, and AI results that our quality checks scored highly, into a separate dataset that it described as material for training AI models later. In that copy, email addresses, phone numbers, web addresses and the names of the workspace's contacts and companies were replaced by placeholders; other details remained, so the copy is not anonymous. It can contain text from connected mailboxes and is kept with the workspace's identifier. No legal basis supported this copy, so we have stopped it and closed the export that Elevay staff with platform access could use. No feature of Elevay reads the copies already made. We will delete them; until then they are deleted with the workspace's Customer Data. We will not use them to train a model.
10. Anonymised Cross-Customer Benchmarks
To tell you whether a buying signal actually predicts won deals, we compute anonymised benchmarks across customers — for example “in software, 51-100 employees, a recent funding round preceded a won deal 34% of the time”. These benchmarks contain no company names, contact names, email addresses, message content or calendar content, and no free-text you authored: only counts and rates, grouped by industry, company-size band and a fixed list of signal families. A group is published only when at least 10 distinct customers and 5 distinct companies contribute to it, so no single customer or company can be read out of it. As stated under Google User Data, no Google user data feeds this computation. You can opt out of contributing entirely — write to contact@elevay.app and we will disable the contribution for your workspace; opting out does not remove your access to the benchmarks.
11. Email opens and clicks
Campaign emails are sent by one of two jobs that share the same queue; which one sends a given email depends on which picks it up first. Our main sending job adds a tracking pixel (a tiny invisible image) and makes the links pass through our servers before they reach their destination, whether it sends the email through Resend or through a mailbox's own SMTP server. Both carry a signed code that identifies the email. The Unsubscribe link is not tracked. The job that sends directly through a mailbox's own SMTP server adds neither: the emails it sends are not tracked.
- Opens: when the recipient's email program loads the pixel, we record the time, the program's user agent, the time since the email was sent, and whether the open looks like a person or an automated security scanner.
- Clicks: when a link is clicked, we record the link, the time and the same details, then send the reader on to the page.
- These records are kept on the recipient's contact record with the Customer Data. They feed engagement scores (see Scoring and profiling) and, where a sequence branches on engagement, decide its next step. We do not store the IP address with them; our host's request logs hold it for their retention period.
Who is responsible. For a customer's campaigns, the customer is the controller: it must inform its recipients (Art. 14 GDPR) and obtain their consent for this tracking where the law requires it. For Elevay's own prospecting, Elevay is the controller. Reading an open pixel or a tracked link involves your device, so Art. 82 of the French Data Protection Act applies: the CNIL considers that it requires your prior consent, even between businesses (recommendation of 12 March 2026). We do not ask for that consent today, and our emails can carry this tracking.
How to avoid it. Blocking remote images in your email program stops the open pixel. Not clicking the links avoids click tracking. You can object at any time: for Elevay's own emails, click Unsubscribe or write to contact@elevay.app; for a customer's emails, contact that customer. Once you unsubscribe, no more emails are sent to you. Opening or clicking an email you received before is still recorded, because our tracking does not check the opt-out list yet.
12. Scoring and profiling
Elevay scores companies and people for fit (how closely they match the ICP) and intent (recent buying signals and engagement). The scores order lists and suggest whom to contact first. This is profiling. Elevay takes no decision that has legal effects on you or affects you in a similarly significant way (Art. 22 GDPR): the most a score leads to is being contacted as part of a sales campaign. You can object to this profiling at any time (see Your rights).
After our AI demo, an AI also writes a note for Martin, our founder, on how well Elevay might fit the visitor's company. It decides nothing by itself (see The AI demo).
13. Elevay's own prospecting
We use Elevay, from our own workspace, to find and contact businesses that could need it. For this, Elevay is the controller. As we do not collect this data from you, this section gives you the information required by Art. 14 GDPR.
- Data: your name, job title, seniority, department and sub-department, company, your LinkedIn headline, your city, region and country, your time zone, your career history (up to 20 current and past positions, with employer, title and dates), email address (usually your work address, sometimes a personal one), phone numbers, LinkedIn profile address and photo, job changes; where LinkedIn profile enrichment runs, your profile summary, the location and current company shown on your profile, whether you show as open to work or have an open profile, how many connections you share with us and how far you are from us in the LinkedIn network; where that option is on, your reactions to and comments on LinkedIn posts we follow, including our competitors' posts, with the first 300 characters of your comment; whether you are connected on LinkedIn with someone at Elevay, facts and buying signals about your company, the scores we compute for you (see Scoring and profiling), our messages to you and your replies, and whether you opened or clicked our emails.
- Sources: the sources listed in 6.2: data providers such as Apollo.io and Ocean.io, LinkedIn through Unipile, company websites, public company registers, job postings and web research.
- Purpose: to contact you about Elevay, in your professional capacity.
- Legal basis: our legitimate interest in offering Elevay to businesses (Art. 6(1)(f) GDPR).
- Recipients: the processors of our own workspace (see Who receives personal data).
- Retention: 3 years from collection or from the last contact you initiated (for example a reply), whichever is later. Deletion at the end of that period is not automated yet.
Our emails name Elevay as the sender. Those sent by our main sending job carry an Unsubscribe link in their footer; those sent directly through a mailbox's own SMTP server carry it in their plain-text version, where they have one. All carry a one-click unsubscribe header that most email programs show next to the sender. Our emails do not link to this section yet, and they do not yet say where we found your details or remind you, in the email itself, of your right to object.
Your right to object to prospecting. You can object at any time, without giving a reason, to our use of your data for prospecting, including the profiling linked to it (Art. 21(2) and 21(3) GDPR). Click Unsubscribe in any of our emails or write to contact@elevay.app. Unsubscribing stops our emails and messages to you at once: your address goes on our suppression list with the reason and the date. It does not delete the rest of your record. An objection you send by email is not added to that list automatically: it takes effect when we handle your email.
Having your data erased. To have your record erased too, write to contact@elevay.app. We first put your email address on our suppression list, so that we stop contacting you while the erasure runs. The identifier of your LinkedIn profile goes on that list too, so that our LinkedIn messages stop as well. Your own phone numbers go on it too, so that our calls and WhatsApp messages stop as well; a number someone else in our workspace also has, or that our workspace records as your company's own number, such as a switchboard, does not. We then erase your personal data from our workspace: your record and its history, including the entries of our audit log about it, the emails, messages, notes, tasks and calls linked to it, your photo, the copies of our emails with you that our workspace takes from our own mailbox, your entry in the list of our team's LinkedIn connections, and the other copies made from it. From then on, our workspace does not copy you again from our mailbox or from our team's LinkedIn accounts, under the email addresses and LinkedIn identifiers it knew for you. Nor does it copy you again from our WhatsApp account under your phone numbers, or add you again from a calendar invitation, a web form, an import, a data provider's search or by hand: those additions are refused. A deal you were part of stays in our workspace without the link to you; where its name or summary names you, we edit it. A meeting or an email in which other people also took part stays in our workspace for them, and so does our copy of that email from our mailbox: we remove from it your name, email address, phone number, LinkedIn profile and the link to your record, including from its list of participants, its transcript and the notes, summaries and memory made from it, and we delete the audio and screen images of its recording. What you said in it stays, without your name. A meeting or an email with only you and our team is erased. What remains of your record is an empty placeholder that holds only technical identifiers, codes and dates, and it cannot be restored.
We keep your address, the reason and the date on our suppression list, and your email address and LinkedIn profile address, without your name, on a do-not-import list, so that we never contact you or add you to our workspace again (see How long we keep data). Your own phone numbers stay on the suppression list too, with the identifier and member IDs of your LinkedIn profile. We also keep our correspondence about your request, as proof that we handled it, with a record of the request and of what we did (see When you write to us).
For our recent emails to you (those sent, bounced, reported as spam or answered in the 31 days before the erasure), we keep only when each one left our mailbox and whether and when it bounced, was reported as spam or was answered, without your address, your name or the message, so that the protection that pauses our sending when too many emails bounce or are reported as spam keeps counting them. We also keep which of our sequences each one was part of, and when a meeting you booked from one was booked, so that the check that pauses a sequence nobody answers counts the same. With each email we keep pseudonymous keys (a keyed hash of each identifier our email was sent under, never the identifier itself), so that a bounce or spam report about it that arrives after the erasure is still counted. They are deleted automatically within 33 days of the erasure or, for an email whose bounce or spam report arrives after the erasure, within 33 days of the last such report.
Some copies are erased in a second step, and we tell you when that is done: records that our application cannot change today, such as the history of earlier values of your record, meeting records and messages captured from our mailbox, the records of the automatic checks our workspace ran on the messages it sent you, and the identity links it keeps between your record and your email address or LinkedIn profile; the records of the data providers through which we found or bought your details, such as their search results and the responses that gave us your work email; mentions of you in the text of other records, which we look for and edit; messages from you that our workspace kept without linking them to your record, which we look for and erase; the records of our workspace's automated work, such as run logs, traces and the inputs of AI and tool calls, which may contain one of your identifiers and which we look for and erase; and any copy that the first step could not remove. Copies in our database provider's backups disappear when those backups expire.
If you are connected on LinkedIn with someone at Elevay
When a member of our team connects their LinkedIn account to our own workspace, Elevay stores the list of their first-degree LinkedIn connections: each connection's name, headline, profile address and LinkedIn member ID, whether or not they are a prospect. The list is updated when the account is connected again and, where that option is on, every week. Elevay reads each connection's current employer from the headline and matches it to the companies in our workspace, to show which of us knows someone at a company we want to reach. On weekdays, once an hour during the day, it also searches LinkedIn for people at those companies and for our connections who know them and could introduce us.
- Source: our team member's LinkedIn account, through Unipile.
- Purpose: knowing who in our network can introduce us to a company. People found at a target company can become prospects, covered by this section; a member of our team can ask one of their connections for an introduction.
- Legal basis: our legitimate interest in knowing who in our network can introduce us (Art. 6(1)(f) GDPR). You can object at any time by writing to contact@elevay.app.
- Recipients: Unipile (France), which connects the LinkedIn account, and the processors of our own workspace (see Who receives personal data).
- Retention: we keep a team member's list while their LinkedIn account stays connected to our workspace, and we delete it within 30 days after they disconnect it. Nothing deletes it automatically yet, so we do it ourselves. Updates of the list add and change connections but do not remove one you have ended on LinkedIn: write to contact@elevay.app and we delete you from the list.
We do not inform each connection individually: this notice is how we make this information available to you (Art. 14(5)(b) GDPR).
14. If a customer of ours holds your data
If you received a message from a company that uses Elevay, that company is the controller of your data. It decides why and how your data is used, it must have a legal basis, and it must give you the information required by Art. 14 GDPR. To exercise your rights, contact that company.
The footer that our main sending job adds to these emails currently reads “Sent by Elevay via Elevay”, whichever company wrote to you: the company responsible is the one named in the From line.
Every campaign email carries a one-click unsubscribe header that most email programs show next to the sender, and an Unsubscribe link in its footer or, for emails sent directly through a mailbox's own SMTP server, in its plain-text version where it has one. Using either records your opt-out in that company's workspace and stops the sequences it runs to you. If you write to us instead, we forward your request to the company concerned without delay and help it answer.
When that company asks us to erase your data, we erase it from its workspace as described in 6.6. Its workspace then keeps your address on its suppression list, and your email address and LinkedIn profile address, without your name, on its do-not-import list, so that it does not contact you or add you again. Your own phone numbers stay on that suppression list too.
15. Legal bases
| Purpose | Legal basis |
|---|---|
| Running and securing the website and accounts: request logs, rate limits, sign-in protection, error reports and performance measurements of our servers | Legitimate interest in a service that is available and secure (Art. 6(1)(f) GDPR) |
| Essential cookies and storage | No consent needed, as they are strictly necessary for a service you ask for (Art. 82 of the French Data Protection Act) |
| Measuring how the website and app are used, finding errors, and linking a sign-up to the visit that led to it (PostHog analytics cookies, session recordings and account events) | Your consent (Art. 6(1)(a) GDPR and Art. 82 of the French Data Protection Act), which you can withdraw at any time in Cookie settings |
| Providing Elevay to customers and users: accounts, workspaces, support | Performance of a contract (Art. 6(1)(b) GDPR) |
| Processing Customer Data | The customer's instructions, as its processor (Art. 28 GDPR); the customer is responsible for the legal basis |
| Setting up a demo or call you asked for | Steps at your request before a contract (Art. 6(1)(b) GDPR) |
| Following up after a demo request or call | Legitimate interest (Art. 6(1)(f) GDPR); you can object at any time |
| Preparing a call you booked with us (automatic briefing) | Legitimate interest (Art. 6(1)(f) GDPR); you can object at any time |
| Running the AI demo you asked for, and booking the call you ask for in it | Steps at your request before a contract (Art. 6(1)(b) GDPR) |
| Protecting the AI demo against abuse: the daily hashes of your IP address and its network range, the limits per email address and the checks against automated scripts | Legitimate interest in a demo that stays available at a bounded cost (Art. 6(1)(f) GDPR) |
| After the AI demo: the summary and fit note for our founder, adding your company (and you, if you book) to our workspace, following up, and improving the demo | Legitimate interest (Art. 6(1)(f) GDPR); you can object at any time |
| Elevay's own prospecting: finding you, our emails and messages | Legitimate interest (Art. 6(1)(f) GDPR); you can object at any time, without giving a reason |
| Knowing who in our team's LinkedIn network can introduce us to a company | Legitimate interest (Art. 6(1)(f) GDPR); you can object at any time |
| Keeping a CRM record of the emails you send us, and extracting from them the objections and questions that shape our sales approach | Legitimate interest in improving how we sell (Art. 6(1)(f) GDPR); you can object at any time |
| Open and click tracking in our own prospecting emails | Art. 82 of the French Data Protection Act requires your consent for it, as the CNIL reads it (recommendation of 12 March 2026). We do not ask for that consent today (see Email opens and clicks). |
| Photos, company logos, country flags and the job-title suggestion model that your browser loads from third-party services in the app | Legitimate interest in showing them (Art. 6(1)(f) GDPR); for Customer Data, the customer's instructions |
| Anonymised cross-customer benchmarks | Legitimate interest in scores that reflect real outcomes (Art. 6(1)(f) GDPR); customers can opt out |
| Billing, accounting and tax records | Legal obligation (Art. 6(1)(c) GDPR) |
| Keeping opt-outs and answering rights requests | Legal obligation (Art. 6(1)(c), Art. 12 and Art. 21 GDPR) |
16. How long we keep data
| Data | How long |
|---|---|
| Your cookie choice | 12 months from your last choice, then we ask again. The CNIL considers 6 months good practice; we keep 12 months so that we ask you at most once a year. |
| Preference cookies | 12 months |
| Sign-in session | 8 hours, renewed while you use Elevay |
| Request logs (Vercel) | At most 30 days in the logs Vercel shows us. Vercel does not publish how long it keeps request data for its own purposes. |
| Error reports (Sentry, where error monitoring is on) | At most 90 days |
| Analytics events (PostHog) | The retention of our PostHog plan: up to 7 years. PostHog does not offer a shorter period. On request, we delete your analytics profile and its events. |
| Session recordings (PostHog) | Up to 90 days |
| Demo requests, bookings and follow-ups | 3 years from the last contact you initiated. Deletion at the end of that period is not automated yet. |
| AI demo conversation (what you typed and the agent's replies) | Deleted automatically 90 days after the demo, or after 24 hours if the removal of other people's names from it failed |
| AI demo record (email address, names, company, answers, summary, daily hashes of the IP address) | Anonymised automatically 90 days after the demo; only counts remain |
| What the AI demo adds to our workspace: the record of the demo, and your contact record if you book | 3 years from the last contact you initiated. Deletion at the end of that period is not automated yet. |
| Prompts and responses flagged by Microsoft's abuse monitoring (Azure OpenAI Service) | Microsoft does not publish how long it keeps them |
| Elevay's own prospects | 3 years from collection or from the last contact you initiated, whichever is later. Deletion at the end of that period is not automated yet. |
| Emails you send us | In our workspace, the limits set for our own prospects. In our mailbox we have not set a fixed period yet. |
| LinkedIn connections of our team members, in our own workspace (name, headline, profile address, LinkedIn member ID) | While the team member's LinkedIn account stays connected to our workspace; we delete the list within 30 days after they disconnect it. This deletion is not automated yet: we do it ourselves. |
| Elevay's own suppression list (the address, the reason and the date; for a person whose data is erased, also their own phone numbers and the identifier and member IDs of their LinkedIn profile), and the do-not-import entries written when a person's data is erased (email address and LinkedIn profile address, without the name) | No fixed end: as long as we prospect. Data providers keep supplying the same people, and these lists are what stop us from contacting or adding again someone who objected or had their data erased. |
| The sending record of the recent emails sent to a person whose data was erased (those sent, bounced, reported as spam or answered in the 31 days before the erasure): when each one was sent and whether and when it bounced, was reported as spam or was answered, the sequence it was part of, when a meeting booked from a sequence was booked, and pseudonymous keys of the identifiers the message was sent under (a keyed hash of each, never the identifier), without the address, the name or the message (Elevay's own workspace and customers' workspaces) | Deleted automatically within 33 days of the erasure or, for an email whose bounce or spam report arrives after the erasure, within 33 days of the last such report. Our sending protection counts bounces and spam reports over the last 30 days at most. |
| Opt-out and suppression records in a customer's workspace: the address, the reason and the date; for a person whose data the customer had erased, also their own phone numbers, the identifier and member IDs of their LinkedIn profile, and the do-not-import entries (email address and LinkedIn profile address, without the name) | As long as the workspace that sent the email is open, so that the opt-out keeps being respected; then deleted with its Customer Data |
| Records of rights requests: the address, the date of the request and what we did (our correspondence about it stays in our mailbox, see Emails you send us) | 3 years from our answer, as proof that we handled the request. Deletion at the end of that period is not automated yet. |
| Account data | While your account is open. Your user profile in the workspace is deleted with the workspace's records (see 6.6). Your sign-in record (name, email address, photo, password hash) and the Google or Microsoft access tokens it holds are not deleted automatically yet: we delete them within 30 days of account closure, or earlier if you ask us. |
| Workspace audit log: sign-ins, sign-outs, invitations, role and settings changes, two-factor changes, password resets (with the IP address and browser user agent), exports from Settings → Privacy & data (with the IP address), and edits to records with the old and new values of the fields changed | After the account is closed, we keep only who did what and when, as evidence of how the account was used: we delete the old and new field values with the rest of the Customer Data, by hand until our deletion job does it. Our code sets 7 years as the period for the rest; no law imposes that period, and deletion at its end is not automated yet. When a person's data is erased at their request, the entries about that person's record are deleted with it. |
| Failed sign-in attempts (IP address and a hash of the email address) | Deleted at the next successful sign-in to that account, or when a later failed attempt is recorded and they are more than 15 minutes old |
| Password reset and email verification requests (time, IP address, browser user agent) | Kept with your sign-in record and deleted with it (see Account data above) |
| Customer Data | While the customer's account is open, under the customer's control. Deleted within 30 days of account closure: our daily deletion job does not yet cover all of it, so we complete the deletion ourselves (see 6.6). |
| Examples kept for later drafts (approved or corrected drafts and replies, and highly scored AI results) | While the workspace is open. Our daily deletion job deletes them when the workspace is closed, except older examples that do not record their workspace, which we delete ourselves (see 6.6) |
| Copies left from the former training dataset (see AI processing) | No longer collected. We will delete them; until then they are deleted with the workspace's Customer Data (see 6.6) |
| Copies in our database provider's backups | Until they expire on that provider's backup schedule, including copies of data erased at a person's request |
| Call recordings (audio) | 90 days after the call by default (a workspace can set another period of at least 7 days); transcripts stay with the Customer Data |
| Billing records | 10 years (French Commercial Code, Art. L123-22) |
17. Who receives personal data
We share personal data only with:
- our processors (sub-processors, for Customer Data), listed in the registry below with what each one does;
- services that receive data under their own terms rather than as our processors, also listed in the registry: Microsoft Bing for web research (see AI processing), and the public services your browser contacts in the app (see Other services your browser contacts);
- people at Elevay who need the data for their work; Elevay staff can open a customer workspace in read-only mode to give support. That mode shows what the workspace's users see, including the content of synced emails, and does not ask the customer first, so we open it on a workspace only when the customer asks us to (see Google User Data);
- authorities, when the law requires it.
The registry below is generated from the same file as the Sub-processors page. It shows the status of each data processing agreement (DPA). We notify every customer in the app, with a notice at the top of the Elevay workspace, at least 30 days before a new sub-processor starts processing Customer Data. We do not send it by email. A notice is given on the date it is posted, dated, on this page and shown in the app: the notice period and the time to object run from that date. Anyone else finds each change on this page, with the date it takes effect.
What the DPA column means:
- available: The provider publishes a data processing agreement for its customers; the link opens it.
- to sign: The provider's agreement takes effect only once we sign it, and we have not signed it yet.
- to confirm: We have not yet confirmed a data processing agreement with this provider.
- on request: The provider gives its agreement on request; we have not confirmed one yet.
- none published: The provider publishes no data processing agreement.
- none (public service): Not our processor: your browser contacts this public service directly, under its own terms.
- none (public download): Not our processor: your browser downloads files from it directly, under its own terms.
- not covered by the Microsoft DPA: Microsoft processes these requests under its own terms, not under our agreement with it (see AI processing in our Privacy Policy).
- n/a: Software we run ourselves; no third party is involved.
| Provider | Purpose | Where data is processed | Operator | DPA |
|---|---|---|---|---|
| Anthropic | Fallback large language model (chat, scoring, drafting, web research), and direct calls from a few features, depending on which of Elevay's keys are setFallback provider, and a few features call it directly. Production runs on Microsoft Azure OpenAI Service, and most model calls go to Azure. Where Elevay's Anthropic key is set, meeting preparation, mapping the columns of an imported file, voice-of-customer analysis and the nightly knowledge-base analysis call api.anthropic.com in the United States directly. Where Azure is not configured, other requests go there too, including Anthropic's web search and web fetch tools. Anthropic's commercial terms do not allow it to train its models on this data. | United States (api.anthropic.com) | United States (Anthropic PBC) | available |
| Apify | Reading a contact's public LinkedIn profile to check their current role, where configuredUsed only when Elevay's Apify token is configured. Elevay sends it a contact's LinkedIn profile address, and a third-party profile reader from Apify's store returns the profile's positions. Apify's data processing addendum is part of its terms and allows transfers to the United States. | Czech Republic and United States (Apify's data processing addendum allows transfers to the United States) | Czech Republic (Apify Technologies s.r.o., Prague) | available |
| Apollo.io | People and company search and enrichment (B2B contact and firmographic data), used to build and refresh target account listsRuns when a user asks for it and in scheduled background jobs that follow the customer's ideal customer profile, for example a daily check for new people in target roles at target accounts. | United States | United States | available |
| Calendly | Booking a call with Elevay: the "Talk to Martin (founder)" link on the elevay.app home and FAQ pages, and the demo form on the previous home page (elevay.app/landing-v2), open Elevay's Calendly booking pageThe "Talk to Martin (founder)" link opens the booking page with nothing filled in. The demo form on the previous home page (elevay.app/landing-v2) stores nothing at Elevay: it opens Calendly with the name and work email you typed in the booking link, so Calendly receives them when the booking page opens, even if you do not book. Calendly holds the booking details you enter as Elevay's processor. For the cookies and technical data its booking page collects, Calendly is a controller under its own privacy notice. | United States | United States (Calendly LLC) | available |
| Clearbit (HubSpot) | Company identification from a visitor's IP address, for the visit pixel that customers can put on their own websitesUsed only when Elevay's Clearbit key is configured and a workspace's settings choose Clearbit for company identification. It receives the visitor's IP address and returns the company. We have not confirmed that HubSpot's data processing agreement covers this service. | United States | United States (HubSpot, Inc.) | to confirm |
| Deepgram | Speech-to-text for calls and meetings: live and recorded transcription; speech-to-text and text-to-speech in the AI demo on elevay.app (EU endpoint)Every transcription request Elevay sends to Deepgram carries mip_opt_out=true, which opts the audio out of Deepgram's Model Improvement Program. Live transcription of phone calls runs through Twilio, which uses Deepgram under its own agreement; Elevay's code has no opt-out parameter on that path. No separate DPA was found; the link points to Deepgram's privacy page. The AI demo's voice, where offered, runs on Deepgram's EU endpoint with the Model Improvement Program opted out; Elevay does not store the audio. | United States (api.deepgram.com) for calls and meetings; EU endpoint (api.eu.deepgram.com) for the AI demo | United States (Deepgram Inc.) | to confirm |
| EmailEngine (self-hosted) | IMAP sync for connected mailboxesOpen-source mailbox sync software. Where Elevay deploys it, Elevay runs it itself, so it is not a third-party service. | Self-hosted by Elevay, where deployed | Elevay (self-hosted software) | n/a |
| flagcdn.com (Flagpedia.net) | Country flag images in the Accounts table, loaded by your browserYour browser loads each flag from flagcdn.com, which receives your IP address, your browser details and the country code of the flag. No contact data is sent. | Global (content delivery network) | Czech Republic (Flagpedia.net, Prague) | none (public service) |
| FullEnrich | Phone and email lookups for contacts (waterfall enrichment, EU mobile numbers)Started from the app when a user enriches a contact or a list, for example a call list. Results come back through a signed webhook. No separate DPA was found; the link points to FullEnrich's privacy policy. | EU (France) | France (FullEnrich SAS) | to confirm |
| Google (OAuth + Gmail API) | Sign-in with Google; mailbox and calendar access (gmail.modify, calendar.readonly, calendar.events) and sender-photo lookup (contacts.readonly, contacts.other.readonly); where enabled, Gmail change notifications through Google Cloud Pub/Sub on Elevay's own Google Cloud project; Google Meet video calls for meetings booked with the Google Meet option, which calls booked in the AI demo on elevay.app use by default. gmail.modify lets Elevay read messages and set their read/unread state, so that a message already opened in Gmail is not shown as new in Elevay, and so that marking one read in Elevay can be reflected in Gmail on an explicit user action. It also lets Elevay send, through Gmail and as the user, an email the user sends or schedules from their Gmail address in Elevay. It does not allow permanent deletion.The user's own mailbox and calendar live at Google. Access is not read-only. An email you send or schedule from your Gmail address in Elevay goes out through Gmail, as you; nothing else does: Elevay's other emails go out through Resend or the sending mailbox's own SMTP server. Meetings booked, moved or cancelled through Elevay are announced to the attendees by Google Calendar. Elevay does not request gmail.send or https://mail.google.com/. Once a day it reads your contacts and correspondents and keeps a copy of their photos, refreshed about every 30 days, for sender pictures. | Global (Google Cloud) | United States (Google LLC) | available |
| Google (public favicon service) | Company logos: your browser loads a company's icon from Google's public favicon serviceWhere Elevay shows a company logo, your browser requests it from www.google.com/s2/favicons with the company's website domain. Google receives that domain and your IP address. No contact data is sent. | Global (Google) | United States (Google LLC) | none (public service) |
| Gravatar (Automattic Inc.) | Profile photos for contacts and senders who use a consumer email addressOnly for addresses at consumer email providers such as gmail.com. Your browser loads www.gravatar.com/avatar/ followed by a SHA-256 hash of the address, so Gravatar receives that hash and your IP address. Business addresses are not looked up. | United States | United States (Automattic Inc.) | none (public service) |
| Hugging Face | Download of the language model behind semantic job-title suggestions, which then runs in your browserThe first time you use the job-title field of the ideal customer profile editor, your browser downloads the model files (Xenova/multilingual-e5-small) from Hugging Face. Hugging Face receives your IP address and browser details. The model runs in your browser: what you type is not sent to Hugging Face. | Global (Hugging Face Hub and its download CDN) | United States (Hugging Face, Inc.; EU establishment Hugging Face SAS, Paris) | none (public download) |
| Infomaniak | Video calls for meetings booked through Elevay, on Infomaniak kMeet (the default video host of Elevay's deployment), and retrieval of kMeet recordings from Infomaniak kDrive, for transcriptionMeetings booked through Elevay carry an Infomaniak kMeet link by default: each participant's browser connects to kMeet, which carries their name, audio and video for the length of the call. Elevay also reads the recording that kMeet saves on the organizer's kDrive and sends it to transcription. Operator and infrastructure are in Switzerland, which has an EU adequacy decision. | Switzerland | Switzerland (Infomaniak Network SA, Geneva) | available |
| Inngest | Background job queue and workflow orchestrationRuns Elevay's background jobs and receives their data: the event that starts each job, usually record identifiers, and the result of each step, which can be a whole contact or company record, or content such as an email draft or the first 140 characters of a LinkedIn or WhatsApp message. The AI demo's own jobs receive only the demo session's identifier. No separate DPA was found; the link points to Inngest's privacy policy. | United States | United States (Inngest Inc.) | to confirm |
| Instantly | Warm-up statistics of connected sending mailboxes, and replies of mailboxes imported from Instantly, where configuredUsed only when an Instantly key is configured, Elevay's own or one a workspace adds. Every six hours Elevay sends Instantly the addresses of the connected sending mailboxes and receives their warm-up statistics; for mailboxes imported from a workspace's Instantly account, it also reads the replies they receive. Instantly states that it generally stores data in the United States. Its privacy policy links no data processing agreement. | United States | United States (Foo Monk, LLC dba Instantly.ai, Wyoming) | to confirm |
| jsDelivr | Download of the WebAssembly runtime (onnxruntime-web) for semantic job-title suggestions, which then runs in your browserThe first time you use the job-title field of the ideal customer profile editor, your browser loads the onnxruntime-web runtime from cdn.jsdelivr.net. jsDelivr and the CDN providers that serve its traffic receive your IP address and browser details. What you type is not sent. | Global CDN | United Kingdom (Volentio JSD Limited) | none (public service) |
| Kaspr | Phone-number enrichment (France-focused)One step of the contact-enrichment chain, used when a Kaspr API key is configured. Prospects in France are tried with Kaspr first. | EU (France) | France (Kaspr SAS, Cognism group) | available |
| Lusha | Phone-number and email enrichment (fallback)One step of the contact-enrichment chain, used when a Lusha API key is configured. Lusha's DPA is with Lusha Systems, Inc. (United States); transfers rely on the Standard Contractual Clauses in that DPA. | United States / Israel | United States (Lusha Systems, Inc., Delaware), with an Israeli affiliate (Lusha Systems Ltd.) | available |
| Microsoft (Entra + Graph + Outlook) | Sign-in with Microsoft; Outlook mailbox (Mail.ReadWrite), sending the emails the user sends from that address (Mail.Send), calendar (Calendars.ReadWrite) and contact photos (Contacts.Read)Mail.ReadWrite: Elevay reads your messages and marks a message read in Outlook when you do so in Elevay; it never edits or deletes a message. Mail.Send: an email you send or schedule from your Outlook address in Elevay goes out through Microsoft, as you; nothing else does. Calendars.ReadWrite: Elevay reads your events and creates, reschedules or cancels the meetings you book through Elevay; Outlook then sends the invitation, update or cancellation to the attendees. Contacts.Read: once a day Elevay reads your saved contacts and keeps a copy of their photos, refreshed about every 30 days. | Global (Microsoft 365) | United States (Microsoft Corp.) | available |
| Microsoft Azure OpenAI Service | Primary large language model in production: drafting, classification, extraction, text embeddings and web research; the AI demo on elevay.appChat, classification, embeddings, web research and the AI demo use EU Data Zone deployments: Microsoft processes those prompts and responses inside its EU Data Boundary, which covers the EU and can include EFTA countries such as Norway and Switzerland. Sequence preparation uses a Global Standard deployment, which Microsoft can process in any Azure region. Web searches go to Microsoft Bing. The AI demo has its own resource and no fallback. Microsoft's abuse monitoring can keep flagged prompts and responses in Sweden for review by staff in the EEA; Microsoft does not publish how long. | EU Data Boundary (resources in Sweden Central; can include Norway and Switzerland), except sequence preparation (Global Standard deployment) | United States (Microsoft Corp.) | available |
| Microsoft Bing (Grounding with Bing Search) | Web search queries from Elevay's research agents (company facts and dated buying signals)When Elevay researches a company on the web, the model's web search tool sends search queries to Grounding with Bing Search. The queries are built from company information: name, website, country and LinkedIn company page. Microsoft states that its Data Protection Addendum does not apply to this data and that it leaves the Azure compliance and geographic boundaries (learn.microsoft.com/en-us/azure/foundry/agents/how-to/tools/web-search). The Grounding with Bing terms of use govern it. | Global (outside the Azure EU Data Zone) | United States (Microsoft Corp.) | not covered by the Microsoft DPA |
| Mistral AI | EU large language model, used only where a deployment selects itNot used by default. Elevay can configure a deployment to use Mistral instead of the default provider; Mistral then receives that deployment's model calls and embeddings. French operator, hosted in the EU. | EU (Mistral La Plateforme, FR) | France (Mistral AI SAS) | available |
| Ocean.io | Company and people search to build and refresh target account lists: lookalike companies, account counts, people at target accounts and work-email lookupUsed when Elevay builds and refreshes a customer's target account list, including in background jobs. Elevay sends search filters and, for email lookups, Ocean's own person identifiers; Ocean returns company and contact data. Ocean states that it stores personal data in the EU. No separate DPA is published; the link points to Ocean's privacy statement. | EU (per Ocean's privacy statement) | Denmark (Ocean ApS, Copenhagen) | to confirm |
| OpenAI | Fallback large language model and text embeddings; direct calls from a few features; speech-to-text for uploaded meeting recordingsWithout Microsoft Azure OpenAI Service, OpenAI serves embeddings and is a fallback for model calls. Where Elevay's OpenAI key is set and its Anthropic key is not, these features call it directly: meeting preparation, import column mapping, voice-of-customer analysis, the nightly knowledge-base analysis, the inbox's AI tools, the summaries and intent labels of incoming emails, deal summaries, call-script translation and the extraction of people, companies and facts from emails, notes and transcripts. It also transcribes uploaded or kDrive meeting recordings, unless a self-hosted server is set. | United States | United States | available |
| Pappers | French company registry lookups (company search and website domain resolution)Used when a Pappers API key is configured. Company registry data includes the names of company officers. No separate DPA was found; the link points to Pappers' legal notice. | France | France | to confirm |
| PostHog | Product analytics, only with your consent: page views, clicks without the text of what you click, session recordings with text and images hidden, and JavaScript errorsStarted only after you accept analytics in the cookie banner; its traffic goes through Elevay's path /ingest to PostHog EU Cloud. Session recordings show layout, interactions and link addresses; other text, input values and images are hidden. Clicks are recorded with the element's kind, classes, place and link address, without its text or other attributes. Accepting is recorded as an event. After sign-in, events are linked to your account (email, name, workspace name). PostHog receives your IP address and, where its location lookup is on, stores an approximate location derived from it. | EU (PostHog EU Cloud, Frankfurt) | United States (PostHog Inc.) | to sign |
| RB2B (GetEmails, LLC) | Company identification from a visitor's IP address, for the visit pixel that customers can put on their own websitesUsed only when Elevay's RB2B key is configured and a workspace's settings choose RB2B for company identification. It receives the visitor's IP address, browser user agent and page address. Elevay asks it only for the company; RB2B's own service can also identify people. Its privacy policy names no data processing agreement. | United States | United States (GetEmails, LLC, Texas) | to confirm |
| Resend | Email delivery: account emails (invitations, email verification, password reset) and outbound emails from connected mailboxes that have no SMTP server of their ownResend receives each message it delivers: sender, recipient, subject, content and attachments. Mailboxes connected with their own SMTP server send through that server instead. | United States | United States (Resend Inc.) | available |
| Sentry | Error reporting, and performance monitoring of our servers, where configuredRuns only in a deployment where a Sentry DSN is set. Elevay has not yet confirmed whether its Sentry project stores data in the EU or in the United States; the browser's content security policy only allows Sentry's US ingestion hosts. Before an error report leaves Elevay, user details, cookies, authorization headers, email addresses and key-like strings are removed. The page address is kept, including any one-time code in it, and server warnings can include an IP address. Server performance measurements (one request in ten) are sent without this filter; browsers send none. | Not confirmed: EU (Frankfurt) or United States, set by the Sentry project | United States (Functional Software Inc.) | available |
| Slack (Salesforce) | Internal alert channel of Elevay's team, where Elevay's Slack webhook is configured, including an alert for each call booked in the AI demo on elevay.appAlerts from Elevay's own workspace can include a contact's name (or email address when no name is known), job title, company and up to 240 characters of their reply or message. Alerts from any other workspace give only that workspace's identifier, without names, addresses or message content. Operating alerts can also name the email address of a connected mailbox whose sync has paused. A call booked in the AI demo on elevay.app posts the visitor's first name, company and meeting time. The Elevay staff who read this channel see these alerts; their reads are not recorded in an audit log. | United States | United States (Slack Technologies, LLC, a Salesforce company) | to confirm |
| Snitcher | Company identification from a visitor's IP address, for the visit pixel that customers can put on their own websitesUsed only when Elevay's Snitcher key is configured; it is the default provider for company identification. It receives the visitor's IP address and browser user agent, and returns the company. Its privacy policy names no data processing agreement. | Not published | Netherlands (Snitcher B.V., Hilversum) | to confirm |
| Stripe | Payment processing and subscription billingCard payments and subscriptions. Customers in the EU contract with Stripe Payments Europe Ltd (Dublin). | United States (data flows) / Ireland (EU billing entity, Stripe Payments Europe Ltd) | United States with EU subsidiary (Ireland) | available |
| Supabase | Primary PostgreSQL database — customer CRM data, mailbox content, conversation historyThe database is stored in Frankfurt. The operator is headquartered in the United States, so the US CLOUD Act applies despite EU storage. | EU (AWS eu-central-1, Frankfurt) | United States (Supabase Inc., Delaware) | available |
| Twilio | Voice calls, phone numbers, live call transcription and opt-in call recordingCall recording is off by default and runs only when enabled for the deployment and the workspace. Where the called number is in Switzerland, France, Canada or one of the US area codes on Elevay's list, recording starts only after an audible disclosure. For other countries, including other EU countries, no disclosure is played: the workspace must inform the other party. Twilio handles calls and recordings in the United States; Elevay deletes recordings after 90 days by default (minimum 7). Live transcripts come from Twilio's real-time transcription, run with Deepgram. | United States (Twilio's US1 region; no EU region is configured) | United States (Twilio Inc.) | available |
| Unipile | LinkedIn account connection (messages, conversations, invitations and profiles) and WhatsApp messages where WhatsApp is enabledProcesses the messages and profiles of the people you exchange with on LinkedIn, and on WhatsApp where it is enabled. French operator and hosting. Unipile does not publish its DPA; it is provided on request. | France (Scaleway) | France (Unipile, 168 rue de la Rotonde, 42153 Riorges) | on request |
| Upstash | Redis cache for rate limits, locks and cached estimates, where configuredUsed only in a deployment where an Upstash database is configured. It keeps short-lived state (rate-limit counters, locks, cached market-size estimates), not customer records. | Region set on the database, where configured | United States (Upstash Inc.) | available |
| Vercel | Application hosting: server functions and the content delivery networkEvery request to elevay.app reaches Vercel, including the visitor's IP address. Server functions run in Frankfurt (fra1). Static files and cached pages are served from the edge location closest to the visitor. | EU (fra1, Frankfurt) for server functions; global edge network for content delivery | United States (Vercel Inc.) | available |
| Jitsi public service (meet.jit.si) | Fallback video host in Elevay's code: a deployment that sets no video host of its own would put a meet.jit.si link in the invitations of meetings booked through Elevay. Elevay's production deployment sets Infomaniak kMeet insteadNot used by Elevay's production deployment, whose video links point to Infomaniak kMeet (see Infomaniak). The code falls back to the public meet.jit.si service, run by 8x8, Inc., only when a deployment sets no video host of its own; each participant's browser would then connect to meet.jit.si, which would carry their name, audio and video for the length of the call. | United States (meet.jit.si, run by 8x8), only for a deployment that sets no video host of its own; not used by Elevay's production deployment | United States (8x8, Inc.) | to confirm |
| Winnr Software LLC | Sending fleet mailboxes: provisioning, hosting, SMTP delivery of every email sent from them, DKIM/SPF/DMARC and warmupWinnr holds the SMTP credentials of the sending mailboxes it provisions and hosts those mailboxes, including the replies they receive, which Elevay reads to show them in the inbox. Every email Elevay sends from a fleet mailbox goes out through Winnr's SMTP server, so Winnr receives the recipient's address, the subject and the full content of each campaign email, including its tracking links. Winnr publishes no DPA, no sub-processor list and no country of incorporation (checked 2026-08-20). | Not published | Not published (the site names Winnr Software LLC without a country of incorporation) | none published |
| Zeliq | Contact enrichment (async)Started from a contact when a user asks for it. Results come back through a signed webhook. No separate DPA was found; the link points to Zeliq's privacy policy. | EU (France) | France (Zeliq SAS) | to confirm |
| Zoom | Zoom video meetings for meetings booked through Elevay with the Zoom option, where configuredUsed only when Elevay's Zoom account is configured and a meeting is booked with the Zoom option. Elevay sends the meeting title, start time and length to create the meeting on its Zoom account, and Zoom then hosts the call with the participants' names, audio and video. The link points to Zoom's privacy statement; Elevay has not confirmed a data processing agreement. | Not confirmed: set by Zoom's routing and the data center settings of Elevay's Zoom account | United States (Zoom Communications, Inc., San Jose) | to confirm |
Countries
The recipients in the registry are established in, or process personal data in, these countries:
- Czech Republic: Apify, flagcdn.com (Flagpedia.net)
- Denmark: Ocean.io
- France: FullEnrich, Hugging Face, Kaspr, Mistral AI, Pappers, Unipile, Zeliq
- Germany: PostHog, Supabase, Vercel
- Ireland: Stripe
- Israel: Lusha
- Netherlands: Snitcher
- Norway: Microsoft Azure OpenAI Service
- Sweden: Microsoft Azure OpenAI Service
- Switzerland: Infomaniak, Microsoft Azure OpenAI Service
- United Kingdom: jsDelivr
- United States: Anthropic, Apify, Apollo.io, Calendly, Clearbit (HubSpot), Deepgram, Google (OAuth + Gmail API), Google (public favicon service), Gravatar (Automattic Inc.), Hugging Face, Inngest, Instantly, Lusha, Microsoft (Entra + Graph + Outlook), Microsoft Azure OpenAI Service, Microsoft Bing (Grounding with Bing Search), OpenAI, PostHog, RB2B (GetEmails, LLC), Resend, Sentry, Slack (Salesforce), Stripe, Supabase, Twilio, Upstash, Vercel, Jitsi public service (meet.jit.si), Zoom
- Global infrastructure, in several countries: flagcdn.com (Flagpedia.net), Google (OAuth + Gmail API), Google (public favicon service), Hugging Face, jsDelivr, Microsoft (Entra + Graph + Outlook), Microsoft Azure OpenAI Service, Microsoft Bing (Grounding with Bing Search), Vercel
- Location not published by the provider: Snitcher, Winnr Software LLC
- Location set by a configuration we have not confirmed: Sentry (Not confirmed: EU (Frankfurt) or United States, set by the Sentry project); Upstash (Region set on the database, where configured); Zoom (Not confirmed: set by Zoom's routing and the data center settings of Elevay's Zoom account)
18. International transfers
Some recipients are established outside the EU, or process data outside it (see Countries). Where a recipient's data processing agreement is in place, transfers to it rely on one of these:
- an adequacy decision of the European Commission where one exists, for example for Switzerland, the United Kingdom and Israel, and for US companies certified under the EU-US Data Privacy Framework (Calendly is one);
- otherwise, the Standard Contractual Clauses adopted by the European Commission in 2021, included in the recipient's data processing agreement.
For personal data from Switzerland, the equivalent safeguards recognised by the Swiss Federal Council apply, including the Swiss-US Data Privacy Framework for certified US companies. We add measures such as encryption in transit and at rest. The DPA column of the registry shows the status of each recipient's agreement. You can get a copy of these safeguards by writing to contact@elevay.app; where a recipient publishes its data processing agreement, the DPA column links to it.
Web research searches sent to Microsoft Bing are outside these safeguards (see AI processing). The following recipients are established outside the EU or do not publish where they process data, and the registry shows no data processing agreement in place with them, so no transfer safeguard is in place yet for data sent to them: Clearbit (HubSpot), Deepgram, Inngest, Instantly, PostHog, RB2B (GetEmails, LLC), Slack (Salesforce), Snitcher, Jitsi public service (meet.jit.si), Winnr Software LLC, Zoom. These services receive your IP address and browser details directly from your browser, under their own terms: flagcdn.com (Flagpedia.net), Google (public favicon service), Gravatar (Automattic Inc.), Hugging Face, jsDelivr.
20. Your rights
Under the GDPR and the nFADP, you have the rights below. Write to contact@elevay.app. We answer within one month; for complex or numerous requests we can extend this by two more months, and we tell you why within the first month. If we have a reasonable doubt about who you are, we ask for proof of identity.
- Access (Art. 15): a copy of the personal data we hold about you, with the information that goes with it (purposes, recipients, retention and sources): write to us. Workspace admins can also download a JSON copy of the workspace's records (their own profile, contacts, companies, deals, activities, notes and tasks) in Settings → Privacy & data.
- Rectification (Art. 16): correct inaccurate data, in the app or by asking us.
- Erasure (Art. 17): ask us to erase your data. If you are one of our prospects, Elevay's own prospecting says what we erase, what we keep so that we never contact you again, and what we erase in a second step. If your data is in a customer's workspace, we erase it at that customer's request (see 6.6). When an account is closed, we delete its Customer Data within 30 days, completing ourselves what our daily deletion job does not yet cover (see 6.6).
- Restriction (Art. 18): ask us to limit the use of your data while a question is settled.
- Portability (Art. 20): receive the data you gave us in a structured, machine-readable format (JSON), on request or with the export above.
- Objection (Art. 21(1)): object to processing based on legitimate interest, including profiling. We stop unless we have compelling legitimate grounds.
- Objection to prospecting (Art. 21(2)): absolute, without reason (see Elevay's own prospecting).
- Withdraw consent: at any time, with Cookie settings (in the footer of our website and legal pages, on the sign-in and sign-up pages, and in the app in the account menu at the bottom of the sidebar, for every user). It does not affect what was done before.
- Instructions after death: under Art. 85 of the French Data Protection Act, you can tell us what should happen to your data after your death.
- Complaint: with the CNIL (France), with the FDPIC if you are in Switzerland, or with your local supervisory authority (see Contact).
If your data is in a customer's workspace, see If a customer of ours holds your data.
21. Security
See the Security page for our technical and organisational measures.
22. Children
Elevay is not intended for people under 18. We do not knowingly collect personal data from children. If we learn that we have, we delete it.
23. Changes to this policy
The date at the top shows the current version. When we change this policy in a way that matters, we tell users in the app, in a message about those changes only: a notice at the top of the pages of the Elevay workspace that lists what changed and links to this page. It stays until the user closes it. We do not send it by email. This covers a new purpose, a new kind of recipient, a new country outside the EU, a change in how you exercise your rights, and processing this policy did not describe before. The notice appears at least 30 days before the change applies or, for processing that already runs, when the new version is published; a user who does not sign in during that time sees it the next time they do. We do not show notices for corrections of spelling or wording, nor to a user whose account was created after the change. People who are not users, such as our prospects, find the current version and its date on this page. We keep past versions and send them on request.
24. Contact
For privacy questions and to exercise your rights:
- Privacy contact: contact@elevay.app
- Company: Elevay (SASU), 108 723 537 R.C.S. Lille Métropole
- Registered office: 12 rue Volta, 59130 Lambersart, France
You can lodge a complaint with the French data protection authority:
- CNIL — Commission Nationale de l'Informatique et des Libertés
- 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
- Web: www.cnil.fr
If you are in Switzerland, you can lodge a complaint with the Federal Data Protection and Information Commissioner:
- FDPIC / EDÖB / PFPDT
- Feldeggweg 1, 3003 Bern, Switzerland
- Web: www.edoeb.admin.ch
25. Version française
Cette section traduit en français les sections 2, 13, 14, 19, 20 et 24 de cette politique. Les autres sections n’existent pour l’instant qu’en anglais, ci-dessus.
2. À qui s’adresse cette politique, et nos deux rôles
Cette politique s’adresse :
- aux personnes qui visitent notre site ;
- aux personnes qui nous demandent une démonstration, essaient notre démo IA, réservent un appel avec nous ou nous écrivent (section 4, en anglais) ;
- aux personnes qui utilisent Elevay (les utilisateurs) et aux entreprises qui paient pour l’utiliser (les clients) ;
- aux personnes qu’Elevay contacte au sujet de son propre produit (section 13 ci-dessous) ;
- aux personnes du réseau LinkedIn d’un membre de notre équipe (section 13 ci-dessous) ;
- aux personnes dont nos clients traitent les données avec Elevay (section 14 ci-dessous).
Elevay a deux rôles. Pour ses propres finalités (le site, les comptes et la facturation, sa propre prospection et son marketing, la sécurité, les statistiques anonymisées entre clients décrites à la section 10, et les copies d’un ancien jeu de données d’entraînement décrites à la section 9, jusqu’à leur suppression), Elevay est responsable de traitement. Pour les données que les clients mettent dans Elevay ou collectent avec lui (les « Customer Data »), le client est responsable de traitement et Elevay est son sous-traitant au sens de l’article 28 du RGPD : nous ne traitons ces données que sur les instructions documentées du client, fixées dans la section sur le traitement des données de nos conditions d’utilisation (en anglais).
13. La prospection d’Elevay pour elle-même
Nous utilisons Elevay, depuis notre propre espace de travail, pour trouver et contacter des entreprises qui pourraient en avoir besoin. Pour cela, Elevay est responsable de traitement. Comme nous ne collectons pas ces données auprès de vous, cette section vous donne les informations exigées par l’article 14 du RGPD.
- Données : vos nom, intitulé de poste, niveau hiérarchique, département et sous-département, entreprise, le titre de votre profil LinkedIn, vos ville, région et pays, votre fuseau horaire, votre parcours professionnel (jusqu’à 20 postes actuels et passés, avec l’employeur, l’intitulé et les dates), votre adresse e-mail (le plus souvent professionnelle, parfois personnelle), vos numéros de téléphone, l’adresse et la photo de votre profil LinkedIn, vos changements de poste ; lorsque l’enrichissement des profils LinkedIn est actif, le résumé de votre profil, la localisation et l’entreprise actuelle qui y figurent, le fait que vous vous affichiez ouvert à de nouvelles opportunités (open to work) ou que votre profil soit ouvert, le nombre de relations que vous avez en commun avec nous et votre distance à nous dans le réseau LinkedIn ; lorsque cette option est active, vos réactions et commentaires sur les publications LinkedIn que nous suivons, y compris celles de nos concurrents, avec les 300 premiers caractères de votre commentaire ; le fait que vous soyez en relation sur LinkedIn avec une personne d’Elevay, des faits et des signaux d’achat sur votre entreprise, les scores que nous calculons pour vous (section 12), nos messages et vos réponses, et le fait que vous ayez ouvert nos e-mails ou cliqué sur leurs liens.
- Sources : celles de la section 6.2 : des fournisseurs de données comme Apollo.io et Ocean.io, LinkedIn via Unipile, les sites des entreprises, des registres publics d’entreprises, des offres d’emploi et des recherches sur le web.
- Finalité : vous contacter au sujet d’Elevay, dans votre cadre professionnel.
- Base légale : notre intérêt légitime à proposer Elevay aux entreprises (article 6(1)(f) du RGPD).
- Destinataires : les sous-traitants de notre propre espace de travail (section 17).
- Durée de conservation : 3 ans à compter de la collecte ou du dernier contact venu de vous (par exemple une réponse), la date la plus tardive étant retenue. La suppression à l’issue de ce délai n’est pas encore automatisée.
Nos e-mails indiquent Elevay comme expéditeur. Ceux qu’envoie notre tâche d’envoi principale portent un lien « Unsubscribe » dans leur pied de page ; ceux envoyés directement par le serveur SMTP d’une boîte le portent dans leur version texte, lorsqu’ils en ont une. Tous portent un en-tête de désinscription en un clic, que la plupart des logiciels de messagerie affichent à côté de l’expéditeur. Nos e-mails ne renvoient pas encore à cette section, et ils ne disent pas encore où nous avons trouvé vos coordonnées ni ne vous rappellent, dans l’e-mail lui-même, votre droit d’opposition.
Votre droit de vous opposer à la prospection. Vous pouvez vous opposer à tout moment, sans avoir à vous justifier, à l’utilisation de vos données pour la prospection, y compris au profilage qui y est lié (article 21(2) et 21(3) du RGPD). Cliquez sur « Unsubscribe » dans l’un de nos e-mails ou écrivez à contact@elevay.app. La désinscription arrête immédiatement nos e-mails et nos messages : votre adresse est inscrite sur notre liste d’opposition, avec le motif et la date. Elle ne supprime pas le reste de votre fiche. Une opposition envoyée par e-mail n’est pas ajoutée automatiquement à cette liste : elle prend effet quand nous traitons votre e-mail.
Faire effacer vos données. Pour faire aussi effacer votre fiche, écrivez à contact@elevay.app. Nous inscrivons d’abord votre adresse e-mail sur notre liste d’opposition, afin de ne plus vous contacter pendant l’effacement. L’identifiant de votre profil LinkedIn y est inscrit aussi, afin que nos messages LinkedIn cessent également. Vos propres numéros de téléphone y sont inscrits aussi, afin que nos appels et nos messages WhatsApp cessent également ; un numéro qu’une autre personne de notre espace de travail a aussi, ou que notre espace de travail enregistre comme le numéro de votre entreprise, comme un standard, ne l’est pas. Nous effaçons ensuite vos données personnelles de notre espace de travail : votre fiche et son historique, y compris les entrées de notre journal d’audit qui la concernent, les e-mails, messages, notes, tâches et appels qui y sont liés, votre photo, les copies de nos e-mails avec vous que notre espace de travail reprend de notre propre boîte, votre entrée dans la liste des relations LinkedIn de notre équipe et les autres copies qui en ont été faites. Dès lors, notre espace de travail ne vous recopie plus depuis notre boîte ni depuis les comptes LinkedIn de notre équipe, sous les adresses e-mail et les identifiants LinkedIn qu’il connaissait pour vous. Il ne vous recopie pas non plus depuis notre compte WhatsApp sous vos numéros de téléphone, et ne vous ajoute plus depuis une invitation d’agenda, un formulaire web, un import, la recherche d’un fournisseur de données ou à la main : ces ajouts sont refusés. Une opportunité qui vous concernait reste dans notre espace de travail, sans le lien vers vous ; si son nom ou son résumé vous nomme, nous le modifions. Une réunion ou un e-mail auquel d’autres personnes ont aussi pris part reste dans notre espace de travail pour elles, de même que notre copie de cet e-mail reprise de notre boîte : nous en retirons votre nom, votre adresse e-mail, votre numéro de téléphone, votre profil LinkedIn et le lien vers votre fiche, y compris de sa liste de participants, de sa transcription et des notes, résumés et mémoire qui en ont été tirés, et nous supprimons l’audio et les images d’écran de son enregistrement. Ce que vous y avez dit reste, sans votre nom. Une réunion ou un e-mail entre vous et notre seule équipe est effacé. Il ne reste de votre fiche qu’un emplacement vide, qui ne contient que des identifiants techniques, des codes et des dates, et qui ne peut pas être restauré.
Nous conservons votre adresse, le motif et la date sur notre liste d’opposition, ainsi que votre adresse e-mail et l’adresse de votre profil LinkedIn, sans votre nom, sur une liste de personnes à ne pas importer, afin de ne plus jamais vous contacter ni vous ajouter à notre espace de travail (section 16, en anglais). Vos propres numéros de téléphone restent aussi sur la liste d’opposition, avec l’identifiant de votre profil LinkedIn et ses identifiants de membre. Nous conservons aussi nos échanges sur votre demande, comme preuve que nous l’avons traitée, avec une trace de la demande et de ce que nous avons fait.
Pour nos e-mails récents à votre adresse (ceux qui ont été envoyés, ont rebondi, ont été signalés comme spam ou ont reçu une réponse dans les 31 jours précédant l’effacement), nous ne gardons que la date à laquelle chacun est parti de notre boîte, et si et quand il a rebondi, a été signalé comme spam ou a reçu une réponse, sans votre adresse, votre nom ni le message, afin que la protection qui suspend nos envois quand trop d’e-mails rebondissent ou sont signalés comme spam continue de les compter. Nous gardons aussi la séquence dont chacun faisait partie, et le moment où vous avez pris un rendez-vous depuis l’une d’elles, pour que le contrôle qui suspend une séquence sans réponse compte de la même façon. Avec chaque e-mail, nous gardons des clés pseudonymes (une empreinte, par une clé secrète, de chaque identifiant sous lequel notre e-mail a été envoyé, jamais l’identifiant lui-même), pour qu’un rebond ou un signalement comme spam qui arrive après l’effacement soit encore compté. Ils sont supprimés automatiquement dans les 33 jours qui suivent l’effacement ou, pour un e-mail dont un rebond ou un signalement comme spam arrive après l’effacement, dans les 33 jours qui suivent le dernier de ces signalements.
Certaines copies sont effacées dans un second temps, et nous vous prévenons quand c’est fait : des enregistrements que notre application ne peut pas encore modifier, comme l’historique des valeurs antérieures de votre fiche, des fiches de réunion et des messages capturés depuis notre boîte, les traces des contrôles automatiques que notre espace de travail a faits sur les messages qu’il vous a envoyés, et les liens d’identité qu’il garde entre votre fiche et votre adresse e-mail ou votre profil LinkedIn ; les traces des fournisseurs de données par lesquels nous avons trouvé ou acheté vos coordonnées, comme leurs résultats de recherche et les réponses qui nous ont donné votre adresse professionnelle ; les mentions de vous dans le texte d’autres fiches, que nous recherchons et modifions ; les messages de vous que notre espace de travail a gardés sans les rattacher à votre fiche, que nous recherchons et effaçons ; les traces du travail automatique de notre espace de travail, comme les journaux d’exécution et les entrées des appels à l’IA et aux outils, qui peuvent contenir l’un de vos identifiants et que nous recherchons et effaçons ; et toute copie que la première étape n’a pas pu retirer. Les copies qui figurent dans les sauvegardes de notre hébergeur de base de données disparaissent quand ces sauvegardes expirent.
Si vous êtes en relation sur LinkedIn avec une personne d’Elevay
Quand un membre de notre équipe connecte son compte LinkedIn à notre propre espace de travail, Elevay enregistre la liste de ses relations LinkedIn de premier degré : le nom, le titre du profil, l’adresse du profil et l’identifiant LinkedIn de chaque relation, qu’elle soit ou non un prospect. La liste est mise à jour quand le compte est connecté de nouveau et, lorsque cette option est active, chaque semaine. Elevay lit l’employeur actuel de chaque relation dans le titre de son profil et le rapproche des entreprises de notre espace de travail, pour savoir qui d’entre nous connaît quelqu’un dans une entreprise que nous voulons joindre. Les jours ouvrés, une fois par heure en journée, il cherche aussi sur LinkedIn des personnes dans ces entreprises, et celles de nos relations qui les connaissent et pourraient nous présenter.
- Source : le compte LinkedIn du membre de notre équipe, via Unipile.
- Finalité : savoir qui, dans notre réseau, peut nous présenter à une entreprise. Les personnes trouvées dans une entreprise cible peuvent devenir des prospects, couverts par cette section ; un membre de notre équipe peut demander à l’une de ses relations de le présenter.
- Base légale : notre intérêt légitime à savoir qui, dans notre réseau, peut nous présenter (article 6(1)(f) du RGPD). Vous pouvez vous y opposer à tout moment en écrivant à contact@elevay.app.
- Destinataires : Unipile (France), qui connecte le compte LinkedIn, et les sous-traitants de notre propre espace de travail (section 17).
- Durée de conservation : nous conservons la liste d’un membre de l’équipe tant que son compte LinkedIn reste connecté à notre espace de travail, et nous la supprimons dans les 30 jours qui suivent sa déconnexion. Rien ne la supprime encore automatiquement : nous le faisons nous-mêmes. Les mises à jour de la liste ajoutent et modifient des relations mais n’en retirent pas une que vous avez rompue sur LinkedIn : écrivez à contact@elevay.app et nous vous retirons de la liste.
Nous n’informons pas chaque relation individuellement : cette notice est la façon dont nous mettons ces informations à votre disposition (article 14(5)(b) du RGPD).
14. Si l’un de nos clients détient vos données
Si vous avez reçu un message d’une entreprise qui utilise Elevay, cette entreprise est responsable du traitement de vos données. Elle décide pourquoi et comment vos données sont utilisées, elle doit disposer d’une base légale et vous donner les informations exigées par l’article 14 du RGPD. Pour exercer vos droits, contactez cette entreprise.
Le pied de page que notre tâche d’envoi principale ajoute à ces e-mails indique actuellement « Sent by Elevay via Elevay », quelle que soit l’entreprise qui vous a écrit : l’entreprise responsable est celle qui figure dans le champ « De ».
Chaque e-mail de campagne porte un en-tête de désinscription en un clic, que la plupart des logiciels de messagerie affichent à côté de l’expéditeur, et un lien « Unsubscribe » dans son pied de page ou, pour les e-mails envoyés directement par le serveur SMTP d’une boîte, dans sa version texte lorsqu’il en a une. L’un comme l’autre enregistre votre opposition dans l’espace de travail de cette entreprise et arrête les séquences qu’elle vous adresse. Si vous nous écrivez plutôt, nous transmettons sans délai votre demande à l’entreprise concernée et l’aidons à y répondre.
Lorsque cette entreprise nous demande d’effacer vos données, nous les effaçons de son espace de travail comme le décrit la section 6.6 (en anglais). Son espace de travail conserve alors votre adresse sur sa liste d’opposition, ainsi que votre adresse e-mail et l’adresse de votre profil LinkedIn, sans votre nom, sur sa liste de personnes à ne pas importer, afin de ne plus vous contacter ni vous ajouter. Vos propres numéros de téléphone restent aussi sur sa liste d’opposition.
19. Cookies et technologies similaires
Les cookies et le stockage du navigateur (stockage local, stockage de session et cache du navigateur) permettent à un site de conserver des informations sur votre appareil. Nous utilisons des traceurs essentiels, qui ne demandent pas de consentement parce qu’ils sont strictement nécessaires à un service que vous demandez, et la mesure d’audience de PostHog, qui ne fonctionne qu’avec votre consentement. Nous n’utilisons aucun cookie publicitaire. Notre démo IA ne dépose aucun cookie : la seule chose qu’elle conserve sur votre appareil est l’entrée du stockage de session décrite dans le tableau.
Vous pouvez modifier votre choix à tout moment avec « Cookie settings » : le bouton ci-dessus, le pied de page de notre site et de ces pages légales, les pages de connexion et d’inscription, et dans l’application, pour chaque utilisateur, le menu du compte en bas de la barre latérale. Les administrateurs d’un espace de travail le trouvent aussi sous Settings → Privacy & data → Cookies and analytics.
Le tableau « What we store on your device » de la section 19 donne le nom, la finalité et la durée de chaque cookie et de chaque stockage, et dit s’il demande votre consentement. Sur elevay.app, seuls les stockages de PostHog, dont le nom commence par ph_, le demandent.
Ce que PostHog enregistre si vous acceptez. Avant que vous acceptiez, le code de PostHog n’est même pas téléchargé. Après votre accord, votre navigateur envoie des données à PostHog EU Cloud (Francfort) par notre propre adresse /ingest. Nous nous en servons pour voir comment notre site et notre application sont utilisés, pour trouver les erreurs et les endroits où les gens bloquent afin de les corriger, et pour savoir quelle visite a mené à une inscription. Nous ne l’utilisons pas pour la publicité et nous ne le vendons pas. PostHog enregistre :
- les pages que vous consultez, avec leur titre, et le moment où vous les quittez, avec la page d’où vous venez et les paramètres de campagne ;
- les clics, les envois et les modifications de formulaires, enregistrés comme le type d’élément, ses classes, sa place dans la page et l’adresse vers laquelle pointe un lien, sans le texte de l’élément ni ses autres attributs, et jamais ce que vous tapez dans les champs ;
- votre navigateur, votre système d’exploitation, le type d’appareil, la taille de l’écran et de la fenêtre, la langue et le fuseau horaire ;
- les erreurs JavaScript, avec leur message et leur pile d’appels ;
- des enregistrements de session qui montrent la mise en page, vos interactions et l’adresse des liens de la page, secrets retirés, par exemple l’adresse du profil LinkedIn d’un contact affiché à l’écran : tout le texte, toutes les valeurs saisies et les autres textes portés par les attributs de la page sont masqués ; les images, les vidéos et les canevas sont remplacés par des blocs vides ; ni le contenu ni les en-têtes des requêtes réseau, ni les journaux de la console du navigateur ne sont enregistrés ; l’adresse, le statut et la durée des requêtes de la page sont enregistrés ;
- un événement « consent granted » quand vous acceptez.
PostHog reçoit ces requêtes avec votre adresse IP. Lorsque sa recherche de localisation est active, PostHog en déduit une localisation approximative (ville, région, pays et coordonnées) et la conserve avec les événements et votre profil d’analyse, même lorsqu’il ne conserve pas l’adresse elle-même.
Avant tout envoi, les secrets et ce que vous tapez ou choisissez et que l’application place dans l’adresse des pages, comme des jetons, des codes, des adresses e-mail, des termes de recherche et les filtres de colonnes des tableaux, sont retirés. Après votre connexion, Elevay rattache le profil d’analyse de ce navigateur à votre compte : votre identifiant d’utilisateur, votre adresse e-mail, votre nom et le nom de votre espace de travail. Les événements enregistrés auparavant dans ce navigateur, avant votre connexion, sont fusionnés dans ce profil. Nos serveurs n’envoient les événements de compte décrits à la section 5 qu’avec ce consentement.
Si vous refusez ou retirez votre consentement. Rien ne cesse de fonctionner dans Elevay, et rien vous concernant n’est envoyé à PostHog, ni par votre navigateur ni par nos serveurs. Si vous n’avez jamais accepté, PostHog n’a jamais fonctionné et n’a rien stocké. Si PostHog fonctionnait, il s’arrête, supprime son cookie et son stockage local, et laisse dans le stockage local un marqueur nommé __ph_opt_in_out_<project key>, qui enregistre le refus, ne contient aucun identifiant et reste jusqu’à ce que vous l’effaciez ; ses entrées de stockage de session disparaissent à la fermeture de l’onglet. Le retrait ne remet pas en cause ce qui a été enregistré avant ; pour le faire supprimer, écrivez-nous.
Votre choix est enregistré dans ce navigateur : vous choisissez donc séparément sur chaque navigateur et chaque appareil. Quand vous acceptez, PostHog enregistre aussi un événement « consent granted » lié à l’identifiant d’analyse de ce navigateur, conservé comme les autres événements d’analyse (section 16). Un refus n’est enregistré que dans votre navigateur. Nous conservons votre choix 12 mois, puis nous vous le redemandons. Si vous avez choisi avant cette version de la politique, nous vous le redemandons une fois, parce que l’information a changé : elle décrit désormais les enregistrements de session et le lien avec votre compte après la connexion.
Autres services que votre navigateur contacte.
- Sentry (Functional Software Inc., États-Unis), lorsque la surveillance des erreurs est active : sur chaque page de notre site et de notre application, votre navigateur envoie à Sentry un signal de session, et les erreurs JavaScript avec les étapes qui y ont mené. Sentry reçoit ces requêtes avec votre adresse IP. Avant l’envoi d’un rapport d’erreur, un filtre retire les informations sur l’utilisateur, les cookies, les adresses e-mail et les clés ; l’adresse de la page est envoyée telle quelle, y compris le code à usage unique d’un lien que nous vous avons envoyé par e-mail (réinitialisation du mot de passe, vérification de l’adresse, invitation), avec la page d’où vous venez et l’agent utilisateur de votre navigateur. Votre navigateur ne mesure pas le chargement des pages pour Sentry. Sentry ne stocke rien sur votre appareil.
- Twilio (Twilio Inc., États-Unis), quand vous passez un appel depuis Call Mode : votre navigateur se connecte à Twilio pour acheminer l’appel. Twilio reçoit votre adresse IP, le son de votre micro, le numéro appelé, le numéro affiché et des informations de connexion.
- Deepgram (Deepgram Inc., États-Unis), quand vous enregistrez une réunion dans votre navigateur et que la transcription en direct est configurée : votre navigateur envoie le son de la réunion directement à Deepgram pour le transcrire. Deepgram reçoit votre adresse IP et le son.
- Deepgram (Deepgram Inc., États-Unis), sur son point d’accès dans l’UE, là où la démo IA de notre site propose la voix : votre navigateur reçoit les réponses de l’agent lues à voix haute (le son est activé dès le départ) et, si vous appuyez sur Parler, envoie ce que vous dites à Deepgram pour le transcrire. Deepgram reçoit votre adresse IP, le texte qu’il lit et, si vous utilisez Parler, votre voix. Nous n’enregistrons pas votre voix.
- Hébergeur de visioconférence : les réunions réservées via Elevay portent par défaut un lien de réunion Infomaniak kMeet (Infomaniak Network SA, Suisse). Quand vous rejoignez la réunion, votre navigateur se connecte à kMeet, qui reçoit votre adresse IP, le nom que vous saisissez, ainsi que votre son et votre image pendant l’appel. Un déploiement qui ne fixerait pas son propre hébergeur utiliserait le service public meet.jit.si, exploité par 8x8, Inc. (États-Unis) ; le nôtre fixe kMeet.
- flagcdn.com (Flagpedia.net, République tchèque) : les drapeaux des pays du tableau Accounts en sont chargés. Il reçoit votre adresse IP, des informations sur votre navigateur et le code pays du drapeau.
- Gravatar (Automattic, États-Unis) : la photo des contacts et des expéditeurs qui utilisent une adresse e-mail personnelle est chargée depuis Gravatar, avec une empreinte SHA-256 de leur adresse dans l’adresse de l’image. Gravatar reçoit votre adresse IP.
- Hébergeurs de photos de profil : une photo de contact que nous n’avons pas copiée dans notre propre stockage est chargée depuis l’adresse fournie par sa source, par exemple les serveurs d’images d’Apollo.io ou de LinkedIn. Ils reçoivent votre adresse IP.
- Le service d’icônes de sites de Google (Google LLC, États-Unis) : les logos des entreprises en sont chargés. Il reçoit le domaine de l’entreprise et votre adresse IP.
- Hugging Face et jsDelivr : la première fois que vous utilisez le champ d’intitulé de poste de l’éditeur de profil client idéal, votre navigateur télécharge un petit modèle de langage depuis Hugging Face et son moteur depuis jsDelivr. Ils reçoivent votre adresse IP et des informations sur votre navigateur ; ce que vous tapez reste dans votre navigateur.
20. Vos droits
Au titre du RGPD et de la nLPD, vous disposez des droits ci-dessous. Écrivez à contact@elevay.app. Nous répondons dans un délai d’un mois ; pour des demandes complexes ou nombreuses, nous pouvons le prolonger de deux mois, et nous vous en donnons la raison dans le premier mois. Si nous avons un doute raisonnable sur votre identité, nous vous demandons un justificatif.
- Accès (article 15) : une copie des données personnelles que nous détenons sur vous, avec les informations qui les accompagnent (finalités, destinataires, durée de conservation et sources) : écrivez-nous. Les administrateurs d’un espace de travail peuvent aussi télécharger une copie JSON des fiches de l’espace (leur propre profil, les contacts, les entreprises, les opportunités, les activités, les notes et les tâches) dans Settings → Privacy & data.
- Rectification (article 16) : corriger des données inexactes, dans l’application ou en nous le demandant.
- Effacement (article 17) : nous demander d’effacer vos données. Si vous êtes l’un de nos prospects, la section 13 ci-dessus dit ce que nous effaçons, ce que nous conservons pour ne plus jamais vous contacter et ce que nous effaçons dans un second temps. Si vos données sont dans l’espace de travail d’un client, nous les effaçons à la demande de ce client (section 6.6, en anglais). À la clôture d’un compte, nous supprimons ses Customer Data dans les 30 jours, en complétant nous-mêmes ce que notre tâche quotidienne de suppression ne couvre pas encore (section 6.6).
- Limitation (article 18) : nous demander de limiter l’utilisation de vos données le temps qu’une question soit réglée.
- Portabilité (article 20) : recevoir les données que vous nous avez fournies dans un format structuré et lisible par machine (JSON), sur demande ou avec l’export ci-dessus.
- Opposition (article 21(1)) : vous opposer à un traitement fondé sur l’intérêt légitime, y compris au profilage. Nous l’arrêtons, sauf motifs légitimes et impérieux.
- Opposition à la prospection (article 21(2)) : absolue, sans justification (section 13 ci-dessus).
- Retrait du consentement : à tout moment, avec « Cookie settings » (en pied de page de notre site et des pages légales, sur les pages de connexion et d’inscription, et dans l’application, dans le menu du compte en bas de la barre latérale, pour chaque utilisateur). Il ne remet pas en cause ce qui a été fait avant.
- Directives après le décès : en vertu de l’article 85 de la loi Informatique et Libertés, vous pouvez nous indiquer le sort de vos données après votre décès.
- Réclamation : auprès de la CNIL (France), du PFPDT si vous êtes en Suisse, ou de votre autorité de contrôle locale (section 24 ci-dessous).
Si vos données sont dans l’espace de travail d’un client, voir la section 14 ci-dessus.
24. Contact
Pour toute question sur vos données et pour exercer vos droits :
- Contact vie privée : contact@elevay.app
- Société : Elevay (SASU), 108 723 537 R.C.S. Lille Métropole
- Siège social : 12 rue Volta, 59130 Lambersart, France
Vous pouvez introduire une réclamation auprès de l’autorité française de protection des données : la CNIL (Commission Nationale de l’Informatique et des Libertés), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr.
Si vous êtes en Suisse, vous pouvez introduire une réclamation auprès du Préposé fédéral à la protection des données et à la transparence (PFPDT), Feldeggweg 1, 3003 Berne, Suisse, www.edoeb.admin.ch.