Sub-processors
Last updated: 2026-10-01
This is the list of third parties that process personal data for Elevay. It also names the third-party services your browser contacts directly while you use Elevay, such as the ones that serve logos and profile photos. The page is generated from src/data/dpas.json in our application source, which is maintained alongside the code and checked by an automated test. Where a fact depends on how Elevay is configured, or has not been verified, the entry says so.
Notification policy. We notify every customer in the app, with a notice at the top of the Elevay workspace, at least 30 days before a new sub-processor starts processing Customer Data. We do not send it by email. A notice is given on the date it is posted, dated, on this page and shown in the app: the notice period and the time to object run from that date. Anyone else finds each change on this page, with the date it takes effect.
CLOUD Act column. "yes" means the sub-processor is headquartered in a jurisdiction (mainly the United States) whose law allows extraterritorial data requests regardless of where data is stored. Data residency in the EU does not eliminate CLOUD Act exposure when the operator is US-headquartered. This distinction is documented openly because it matters for sovereignty-sensitive customers.
DPA column. What each status means:
- available: The provider publishes a data processing agreement for its customers; the link opens it.
- to sign: The provider's agreement takes effect only once we sign it, and we have not signed it yet.
- to confirm: We have not yet confirmed a data processing agreement with this provider.
- on request: The provider gives its agreement on request; we have not confirmed one yet.
- none published: The provider publishes no data processing agreement.
- none (public service): Not our processor: your browser contacts this public service directly, under its own terms.
- none (public download): Not our processor: your browser downloads files from it directly, under its own terms.
- not covered by the Microsoft DPA: Microsoft processes these requests under its own terms, not under our agreement with it (see AI processing in our Privacy Policy).
- n/a: Software we run ourselves; no third party is involved.
| Provider | Purpose | Data residency | Operator jurisdiction | CLOUD Act | DPA |
|---|---|---|---|---|---|
| Anthropic Fallback provider, and a few features call it directly. Production runs on Microsoft Azure OpenAI Service, and most model calls go to Azure. Where Elevay's Anthropic key is set, meeting preparation, mapping the columns of an imported file, voice-of-customer analysis and the nightly knowledge-base analysis call api.anthropic.com in the United States directly. Where Azure is not configured, other requests go there too, including Anthropic's web search and web fetch tools. Anthropic's commercial terms do not allow it to train its models on this data. | Fallback large language model (chat, scoring, drafting, web research), and direct calls from a few features, depending on which of Elevay's keys are set | United States (api.anthropic.com) | United States (Anthropic PBC) | yes | available |
| Apify Used only when Elevay's Apify token is configured. Elevay sends it a contact's LinkedIn profile address, and a third-party profile reader from Apify's store returns the profile's positions. Apify's data processing addendum is part of its terms and allows transfers to the United States. | Reading a contact's public LinkedIn profile to check their current role, where configured | Czech Republic and United States (Apify's data processing addendum allows transfers to the United States) | Czech Republic (Apify Technologies s.r.o., Prague) | unknown | available |
| Apollo.io Runs when a user asks for it and in scheduled background jobs that follow the customer's ideal customer profile, for example a daily check for new people in target roles at target accounts. | People and company search and enrichment (B2B contact and firmographic data), used to build and refresh target account lists | United States | United States | yes | available |
| Calendly The "Talk to Martin (founder)" link opens the booking page with nothing filled in. The demo form on the previous home page (elevay.app/landing-v2) stores nothing at Elevay: it opens Calendly with the name and work email you typed in the booking link, so Calendly receives them when the booking page opens, even if you do not book. Calendly holds the booking details you enter as Elevay's processor. For the cookies and technical data its booking page collects, Calendly is a controller under its own privacy notice. | Booking a call with Elevay: the "Talk to Martin (founder)" link on the elevay.app home and FAQ pages, and the demo form on the previous home page (elevay.app/landing-v2), open Elevay's Calendly booking page | United States | United States (Calendly LLC) | yes | available |
| Clearbit (HubSpot) Used only when Elevay's Clearbit key is configured and a workspace's settings choose Clearbit for company identification. It receives the visitor's IP address and returns the company. We have not confirmed that HubSpot's data processing agreement covers this service. | Company identification from a visitor's IP address, for the visit pixel that customers can put on their own websites | United States | United States (HubSpot, Inc.) | yes | to confirm |
| Deepgram Every transcription request Elevay sends to Deepgram carries mip_opt_out=true, which opts the audio out of Deepgram's Model Improvement Program. Live transcription of phone calls runs through Twilio, which uses Deepgram under its own agreement; Elevay's code has no opt-out parameter on that path. No separate DPA was found; the link points to Deepgram's privacy page. The AI demo's voice, where offered, runs on Deepgram's EU endpoint with the Model Improvement Program opted out; Elevay does not store the audio. | Speech-to-text for calls and meetings: live and recorded transcription; speech-to-text and text-to-speech in the AI demo on elevay.app (EU endpoint) | United States (api.deepgram.com) for calls and meetings; EU endpoint (api.eu.deepgram.com) for the AI demo | United States (Deepgram Inc.) | yes | to confirm |
| EmailEngine (self-hosted) Open-source mailbox sync software. Where Elevay deploys it, Elevay runs it itself, so it is not a third-party service. | IMAP sync for connected mailboxes | Self-hosted by Elevay, where deployed | Elevay (self-hosted software) | depends on the host | n/a |
| flagcdn.com (Flagpedia.net) Your browser loads each flag from flagcdn.com, which receives your IP address, your browser details and the country code of the flag. No contact data is sent. | Country flag images in the Accounts table, loaded by your browser | Global (content delivery network) | Czech Republic (Flagpedia.net, Prague) | unknown | none (public service) |
| FullEnrich Started from the app when a user enriches a contact or a list, for example a call list. Results come back through a signed webhook. No separate DPA was found; the link points to FullEnrich's privacy policy. | Phone and email lookups for contacts (waterfall enrichment, EU mobile numbers) | EU (France) | France (FullEnrich SAS) | no | to confirm |
| Google (OAuth + Gmail API) The user's own mailbox and calendar live at Google. Access is not read-only. An email you send or schedule from your Gmail address in Elevay goes out through Gmail, as you; nothing else does: Elevay's other emails go out through Resend or the sending mailbox's own SMTP server. Meetings booked, moved or cancelled through Elevay are announced to the attendees by Google Calendar. Elevay does not request gmail.send or https://mail.google.com/. Once a day it reads your contacts and correspondents and keeps a copy of their photos, refreshed about every 30 days, for sender pictures. | Sign-in with Google; mailbox and calendar access (gmail.modify, calendar.readonly, calendar.events) and sender-photo lookup (contacts.readonly, contacts.other.readonly); where enabled, Gmail change notifications through Google Cloud Pub/Sub on Elevay's own Google Cloud project; Google Meet video calls for meetings booked with the Google Meet option, which calls booked in the AI demo on elevay.app use by default. gmail.modify lets Elevay read messages and set their read/unread state, so that a message already opened in Gmail is not shown as new in Elevay, and so that marking one read in Elevay can be reflected in Gmail on an explicit user action. It also lets Elevay send, through Gmail and as the user, an email the user sends or schedules from their Gmail address in Elevay. It does not allow permanent deletion. | Global (Google Cloud) | United States (Google LLC) | yes | available |
| Google (public favicon service) Where Elevay shows a company logo, your browser requests it from www.google.com/s2/favicons with the company's website domain. Google receives that domain and your IP address. No contact data is sent. | Company logos: your browser loads a company's icon from Google's public favicon service | Global (Google) | United States (Google LLC) | yes | none (public service) |
| Gravatar (Automattic Inc.) Only for addresses at consumer email providers such as gmail.com. Your browser loads www.gravatar.com/avatar/ followed by a SHA-256 hash of the address, so Gravatar receives that hash and your IP address. Business addresses are not looked up. | Profile photos for contacts and senders who use a consumer email address | United States | United States (Automattic Inc.) | yes | none (public service) |
| Hugging Face The first time you use the job-title field of the ideal customer profile editor, your browser downloads the model files (Xenova/multilingual-e5-small) from Hugging Face. Hugging Face receives your IP address and browser details. The model runs in your browser: what you type is not sent to Hugging Face. | Download of the language model behind semantic job-title suggestions, which then runs in your browser | Global (Hugging Face Hub and its download CDN) | United States (Hugging Face, Inc.; EU establishment Hugging Face SAS, Paris) | yes | none (public download) |
| Infomaniak Meetings booked through Elevay carry an Infomaniak kMeet link by default: each participant's browser connects to kMeet, which carries their name, audio and video for the length of the call. Elevay also reads the recording that kMeet saves on the organizer's kDrive and sends it to transcription. Operator and infrastructure are in Switzerland, which has an EU adequacy decision. | Video calls for meetings booked through Elevay, on Infomaniak kMeet (the default video host of Elevay's deployment), and retrieval of kMeet recordings from Infomaniak kDrive, for transcription | Switzerland | Switzerland (Infomaniak Network SA, Geneva) | no | available |
| Inngest Runs Elevay's background jobs and receives their data: the event that starts each job, usually record identifiers, and the result of each step, which can be a whole contact or company record, or content such as an email draft or the first 140 characters of a LinkedIn or WhatsApp message. The AI demo's own jobs receive only the demo session's identifier. No separate DPA was found; the link points to Inngest's privacy policy. | Background job queue and workflow orchestration | United States | United States (Inngest Inc.) | yes | to confirm |
| Instantly Used only when an Instantly key is configured, Elevay's own or one a workspace adds. Every six hours Elevay sends Instantly the addresses of the connected sending mailboxes and receives their warm-up statistics; for mailboxes imported from a workspace's Instantly account, it also reads the replies they receive. Instantly states that it generally stores data in the United States. Its privacy policy links no data processing agreement. | Warm-up statistics of connected sending mailboxes, and replies of mailboxes imported from Instantly, where configured | United States | United States (Foo Monk, LLC dba Instantly.ai, Wyoming) | yes | to confirm |
| jsDelivr The first time you use the job-title field of the ideal customer profile editor, your browser loads the onnxruntime-web runtime from cdn.jsdelivr.net. jsDelivr and the CDN providers that serve its traffic receive your IP address and browser details. What you type is not sent. | Download of the WebAssembly runtime (onnxruntime-web) for semantic job-title suggestions, which then runs in your browser | Global CDN | United Kingdom (Volentio JSD Limited) | unknown | none (public service) |
| Kaspr One step of the contact-enrichment chain, used when a Kaspr API key is configured. Prospects in France are tried with Kaspr first. | Phone-number enrichment (France-focused) | EU (France) | France (Kaspr SAS, Cognism group) | no | available |
| Lusha One step of the contact-enrichment chain, used when a Lusha API key is configured. Lusha's DPA is with Lusha Systems, Inc. (United States); transfers rely on the Standard Contractual Clauses in that DPA. | Phone-number and email enrichment (fallback) | United States / Israel | United States (Lusha Systems, Inc., Delaware), with an Israeli affiliate (Lusha Systems Ltd.) | yes | available |
| Microsoft (Entra + Graph + Outlook) Mail.ReadWrite: Elevay reads your messages and marks a message read in Outlook when you do so in Elevay; it never edits or deletes a message. Mail.Send: an email you send or schedule from your Outlook address in Elevay goes out through Microsoft, as you; nothing else does. Calendars.ReadWrite: Elevay reads your events and creates, reschedules or cancels the meetings you book through Elevay; Outlook then sends the invitation, update or cancellation to the attendees. Contacts.Read: once a day Elevay reads your saved contacts and keeps a copy of their photos, refreshed about every 30 days. | Sign-in with Microsoft; Outlook mailbox (Mail.ReadWrite), sending the emails the user sends from that address (Mail.Send), calendar (Calendars.ReadWrite) and contact photos (Contacts.Read) | Global (Microsoft 365) | United States (Microsoft Corp.) | yes | available |
| Microsoft Azure OpenAI Service Chat, classification, embeddings, web research and the AI demo use EU Data Zone deployments: Microsoft processes those prompts and responses inside its EU Data Boundary, which covers the EU and can include EFTA countries such as Norway and Switzerland. Sequence preparation uses a Global Standard deployment, which Microsoft can process in any Azure region. Web searches go to Microsoft Bing. The AI demo has its own resource and no fallback. Microsoft's abuse monitoring can keep flagged prompts and responses in Sweden for review by staff in the EEA; Microsoft does not publish how long. | Primary large language model in production: drafting, classification, extraction, text embeddings and web research; the AI demo on elevay.app | EU Data Boundary (resources in Sweden Central; can include Norway and Switzerland), except sequence preparation (Global Standard deployment) | United States (Microsoft Corp.) | yes | available |
| Microsoft Bing (Grounding with Bing Search) When Elevay researches a company on the web, the model's web search tool sends search queries to Grounding with Bing Search. The queries are built from company information: name, website, country and LinkedIn company page. Microsoft states that its Data Protection Addendum does not apply to this data and that it leaves the Azure compliance and geographic boundaries (learn.microsoft.com/en-us/azure/foundry/agents/how-to/tools/web-search). The Grounding with Bing terms of use govern it. | Web search queries from Elevay's research agents (company facts and dated buying signals) | Global (outside the Azure EU Data Zone) | United States (Microsoft Corp.) | yes | not covered by the Microsoft DPA |
| Mistral AI Not used by default. Elevay can configure a deployment to use Mistral instead of the default provider; Mistral then receives that deployment's model calls and embeddings. French operator, hosted in the EU. | EU large language model, used only where a deployment selects it | EU (Mistral La Plateforme, FR) | France (Mistral AI SAS) | no | available |
| Ocean.io Used when Elevay builds and refreshes a customer's target account list, including in background jobs. Elevay sends search filters and, for email lookups, Ocean's own person identifiers; Ocean returns company and contact data. Ocean states that it stores personal data in the EU. No separate DPA is published; the link points to Ocean's privacy statement. | Company and people search to build and refresh target account lists: lookalike companies, account counts, people at target accounts and work-email lookup | EU (per Ocean's privacy statement) | Denmark (Ocean ApS, Copenhagen) | no | to confirm |
| OpenAI Without Microsoft Azure OpenAI Service, OpenAI serves embeddings and is a fallback for model calls. Where Elevay's OpenAI key is set and its Anthropic key is not, these features call it directly: meeting preparation, import column mapping, voice-of-customer analysis, the nightly knowledge-base analysis, the inbox's AI tools, the summaries and intent labels of incoming emails, deal summaries, call-script translation and the extraction of people, companies and facts from emails, notes and transcripts. It also transcribes uploaded or kDrive meeting recordings, unless a self-hosted server is set. | Fallback large language model and text embeddings; direct calls from a few features; speech-to-text for uploaded meeting recordings | United States | United States | yes | available |
| Pappers Used when a Pappers API key is configured. Company registry data includes the names of company officers. No separate DPA was found; the link points to Pappers' legal notice. | French company registry lookups (company search and website domain resolution) | France | France | no | to confirm |
| PostHog Started only after you accept analytics in the cookie banner; its traffic goes through Elevay's path /ingest to PostHog EU Cloud. Session recordings show layout, interactions and link addresses; other text, input values and images are hidden. Clicks are recorded with the element's kind, classes, place and link address, without its text or other attributes. Accepting is recorded as an event. After sign-in, events are linked to your account (email, name, workspace name). PostHog receives your IP address and, where its location lookup is on, stores an approximate location derived from it. | Product analytics, only with your consent: page views, clicks without the text of what you click, session recordings with text and images hidden, and JavaScript errors | EU (PostHog EU Cloud, Frankfurt) | United States (PostHog Inc.) | yes | to sign |
| RB2B (GetEmails, LLC) Used only when Elevay's RB2B key is configured and a workspace's settings choose RB2B for company identification. It receives the visitor's IP address, browser user agent and page address. Elevay asks it only for the company; RB2B's own service can also identify people. Its privacy policy names no data processing agreement. | Company identification from a visitor's IP address, for the visit pixel that customers can put on their own websites | United States | United States (GetEmails, LLC, Texas) | yes | to confirm |
| Resend Resend receives each message it delivers: sender, recipient, subject, content and attachments. Mailboxes connected with their own SMTP server send through that server instead. | Email delivery: account emails (invitations, email verification, password reset) and outbound emails from connected mailboxes that have no SMTP server of their own | United States | United States (Resend Inc.) | yes | available |
| Sentry Runs only in a deployment where a Sentry DSN is set. Elevay has not yet confirmed whether its Sentry project stores data in the EU or in the United States; the browser's content security policy only allows Sentry's US ingestion hosts. Before an error report leaves Elevay, user details, cookies, authorization headers, email addresses and key-like strings are removed. The page address is kept, including any one-time code in it, and server warnings can include an IP address. Server performance measurements (one request in ten) are sent without this filter; browsers send none. | Error reporting, and performance monitoring of our servers, where configured | Not confirmed: EU (Frankfurt) or United States, set by the Sentry project | United States (Functional Software Inc.) | yes | available |
| Slack (Salesforce) Alerts from Elevay's own workspace can include a contact's name (or email address when no name is known), job title, company and up to 240 characters of their reply or message. Alerts from any other workspace give only that workspace's identifier, without names, addresses or message content. Operating alerts can also name the email address of a connected mailbox whose sync has paused. A call booked in the AI demo on elevay.app posts the visitor's first name, company and meeting time. The Elevay staff who read this channel see these alerts; their reads are not recorded in an audit log. | Internal alert channel of Elevay's team, where Elevay's Slack webhook is configured, including an alert for each call booked in the AI demo on elevay.app | United States | United States (Slack Technologies, LLC, a Salesforce company) | yes | to confirm |
| Snitcher Used only when Elevay's Snitcher key is configured; it is the default provider for company identification. It receives the visitor's IP address and browser user agent, and returns the company. Its privacy policy names no data processing agreement. | Company identification from a visitor's IP address, for the visit pixel that customers can put on their own websites | Not published | Netherlands (Snitcher B.V., Hilversum) | no | to confirm |
| Stripe Card payments and subscriptions. Customers in the EU contract with Stripe Payments Europe Ltd (Dublin). | Payment processing and subscription billing | United States (data flows) / Ireland (EU billing entity, Stripe Payments Europe Ltd) | United States with EU subsidiary (Ireland) | yes | available |
| Supabase The database is stored in Frankfurt. The operator is headquartered in the United States, so the US CLOUD Act applies despite EU storage. | Primary PostgreSQL database — customer CRM data, mailbox content, conversation history | EU (AWS eu-central-1, Frankfurt) | United States (Supabase Inc., Delaware) | yes | available |
| Twilio Call recording is off by default and runs only when enabled for the deployment and the workspace. Where the called number is in Switzerland, France, Canada or one of the US area codes on Elevay's list, recording starts only after an audible disclosure. For other countries, including other EU countries, no disclosure is played: the workspace must inform the other party. Twilio handles calls and recordings in the United States; Elevay deletes recordings after 90 days by default (minimum 7). Live transcripts come from Twilio's real-time transcription, run with Deepgram. | Voice calls, phone numbers, live call transcription and opt-in call recording | United States (Twilio's US1 region; no EU region is configured) | United States (Twilio Inc.) | yes | available |
| Unipile Processes the messages and profiles of the people you exchange with on LinkedIn, and on WhatsApp where it is enabled. French operator and hosting. Unipile does not publish its DPA; it is provided on request. | LinkedIn account connection (messages, conversations, invitations and profiles) and WhatsApp messages where WhatsApp is enabled | France (Scaleway) | France (Unipile, 168 rue de la Rotonde, 42153 Riorges) | no | on request |
| Upstash Used only in a deployment where an Upstash database is configured. It keeps short-lived state (rate-limit counters, locks, cached market-size estimates), not customer records. | Redis cache for rate limits, locks and cached estimates, where configured | Region set on the database, where configured | United States (Upstash Inc.) | yes | available |
| Vercel Every request to elevay.app reaches Vercel, including the visitor's IP address. Server functions run in Frankfurt (fra1). Static files and cached pages are served from the edge location closest to the visitor. | Application hosting: server functions and the content delivery network | EU (fra1, Frankfurt) for server functions; global edge network for content delivery | United States (Vercel Inc.) | yes | available |
| Jitsi public service (meet.jit.si) Not used by Elevay's production deployment, whose video links point to Infomaniak kMeet (see Infomaniak). The code falls back to the public meet.jit.si service, run by 8x8, Inc., only when a deployment sets no video host of its own; each participant's browser would then connect to meet.jit.si, which would carry their name, audio and video for the length of the call. | Fallback video host in Elevay's code: a deployment that sets no video host of its own would put a meet.jit.si link in the invitations of meetings booked through Elevay. Elevay's production deployment sets Infomaniak kMeet instead | United States (meet.jit.si, run by 8x8), only for a deployment that sets no video host of its own; not used by Elevay's production deployment | United States (8x8, Inc.) | yes | to confirm |
| Winnr Software LLC Winnr holds the SMTP credentials of the sending mailboxes it provisions and hosts those mailboxes, including the replies they receive, which Elevay reads to show them in the inbox. Every email Elevay sends from a fleet mailbox goes out through Winnr's SMTP server, so Winnr receives the recipient's address, the subject and the full content of each campaign email, including its tracking links. Winnr publishes no DPA, no sub-processor list and no country of incorporation (checked 2026-08-20). | Sending fleet mailboxes: provisioning, hosting, SMTP delivery of every email sent from them, DKIM/SPF/DMARC and warmup | Not published | Not published (the site names Winnr Software LLC without a country of incorporation) | unknown | none published |
| Zeliq Started from a contact when a user asks for it. Results come back through a signed webhook. No separate DPA was found; the link points to Zeliq's privacy policy. | Contact enrichment (async) | EU (France) | France (Zeliq SAS) | no | to confirm |
| Zoom Used only when Elevay's Zoom account is configured and a meeting is booked with the Zoom option. Elevay sends the meeting title, start time and length to create the meeting on its Zoom account, and Zoom then hosts the call with the participants' names, audio and video. The link points to Zoom's privacy statement; Elevay has not confirmed a data processing agreement. | Zoom video meetings for meetings booked through Elevay with the Zoom option, where configured | Not confirmed: set by Zoom's routing and the data center settings of Elevay's Zoom account | United States (Zoom Communications, Inc., San Jose) | yes | to confirm |
Changes to this list
- 2026-10-01: Google and Microsoft: when you send or schedule an email from your Gmail or Outlook address in Elevay, it is now sent through Gmail or Microsoft, as you, instead of through Resend. Elevay asks Microsoft for the Mail.Send permission for this; for Gmail, the permission you already gave covers it. No new sub-processor.
- 2026-09-30: We now announce a new sub-processor with a notice at the top of the Elevay workspace and a dated entry on this page, at least 30 days before it starts processing Customer Data, and we no longer send it by email. The notice is given on the date it is posted here and shown in the app, and the time to object runs from that date (Terms, section 8.8).
- 2026-09-29: Deepgram's entry now covers the voice of the AI demo on elevay.app, where it is offered: speech-to-text and text-to-speech on Deepgram's EU endpoint (api.eu.deepgram.com), with the Model Improvement Program opted out. Elevay does not store the audio. Our data processing agreement with Deepgram is still to be confirmed.
- 2026-09-26: Microsoft Azure OpenAI Service now also runs the AI demo on elevay.app, on its own EU Data Zone deployment and its own Azure resource, with no fallback to another provider. We now describe Microsoft's abuse monitoring, which applies to our requests, the AI demo's included. Where Elevay's Slack alert channel is configured, Slack receives an alert for each call booked in the AI demo. Google's entry now covers Google Meet calls, which calls booked in the AI demo use by default. Inngest's entry now says that the results of job steps, which can be whole records, pass through it. We confirmed that meetings booked through Elevay use Infomaniak kMeet, in Switzerland, for their video calls: Infomaniak's entry now covers hosting those calls, and the Jitsi entry now describes only the public meet.jit.si service that a deployment without a video host of its own would use, which Elevay's does not.
- 2026-09-25: Added Slack (Salesforce), the alert channel of Elevay's team, where configured. It had received, for every workspace, the name, job title and company of contacts who replied positively or sent a message, with an excerpt. From this version it receives these details only from Elevay's own workspace. Clarified that emails sent from Winnr fleet mailboxes go out through Winnr's SMTP server.
- 2026-09-25: Added entries for services our code already used before they were listed: Ocean.io, Microsoft Bing (Grounding with Bing Search), the video meeting host behind the Jitsi links of meetings booked through Elevay, and the public services your browser contacts directly (flagcdn.com, Google's favicon service, Gravatar, Hugging Face and jsDelivr). Ocean.io, Microsoft Bing and the video meeting host receive Customer Data, and customers did not receive the 30-day notice for them.
- 2026-09-25: Added Apify, Clearbit (HubSpot), Instantly, RB2B (GetEmails, LLC), Snitcher and Zoom, each used only where its key is configured. We have not confirmed which of these keys are set in production.
- 2026-09-25: Removed Crunchbase: Elevay's code no longer calls it.
Following sub-processor changes
Customers see a notice at the top of the Elevay workspace at least 30 days before a new sub-processor starts processing Customer Data. We do not send it by email. Anyone else finds each change on this page, with the date it takes effect, and can ask contact@elevay.app for earlier versions of the list.
See the Privacy Policy for legal bases, retention and data subject rights, and the Security page for technical controls.