Privacy Policy
Last updated: July 27, 2026
This policy explains how Elevia collects, uses, retains and protects your personal data, and describes the rights available to you.
1. Purpose and scope
This Privacy Policy explains how Elevia collects, uses, retains and protects personal data in connection with the elevia.io website (the “Site”) and the Elevia SaaS platform (the “Service”).
It applies to Site visitors, prospects, customers, Service users and other people interacting with Elevia. It does not replace the privacy information that Elevia customers must provide to individuals whose data they process through the Service.
2. Data controller
The data controller is:
Wabam, a French simplified single-shareholder joint-stock company (SASU) with share capital of €1,000, registered with the Versailles Trade and Companies Register under number 948 378 955, whose registered office is located at 1 B rue Raymond Greban, 78100 Saint-Germain-en-Laye, France.
- Legal representative: Raphaël Ghikh
- Contact: hi@elevia.io
Elevia has not appointed a Data Protection Officer (DPO). Questions about personal data and requests to exercise privacy rights should be sent to the address above.
3. Elevia's two roles under the GDPR
Elevia may act in two distinct capacities:
- As a data controller for data relating to Site visitors, prospects, customers, users, accounts, subscriptions, billing, support, security, communications and audience measurement.
- As a data processor for data customers import into or process through Elevia about their own prospects, customers, contacts, end users, projects, files, proposals or invoices. In this case, the customer determines the purposes and essential means of processing. Such processing is governed by the Data Processing Agreement included in the General Terms and Conditions of Sale and Services.
4. Data we collect
4.1. Data you provide
Depending on how you use the Site or Service, we may collect:
- first and last name;
- professional email address;
- company, job title and profile information;
- credentials and a password stored in hashed form;
- account and subscription information;
- billing information and payment history;
- demo requests, sales communications and support tickets;
- communication preferences;
- data entered into the Service, including customers, contacts, projects, proposals, invoices, files, messages and comments.
Data entered into the Service on behalf of a customer generally falls under the processor role described in Section 3.
4.2. Data collected automatically
We may collect:
- IP address;
- browser type and version;
- operating system and device type;
- pages viewed and browsing journey;
- actions performed in the Service;
- login dates and times;
- technical logs, errors and security events;
- cookie identifiers and product usage data.
4.3. Data from third-party services
We may receive data from:
- an authentication provider, including Google OAuth, when that option is used;
- Stripe for payment and billing management;
- Figma or other connected tools when a customer enables an integration;
- referral and affiliate services;
- other integrations made available through the Service.
We only receive the data required to provide the selected integration, based on the permissions granted by the user.
5. Purposes and legal bases
| Purpose | Main legal basis |
|---|---|
| Account creation and management | Performance of a contract or pre-contractual steps |
| Provision and administration of the Service | Performance of a contract |
| Subscription, payment and invoice management | Performance of a contract and legal obligations |
| Support and request handling | Performance of a contract or legitimate interests |
| Security, logging and fraud prevention | Legitimate interests and legal obligations |
| Product improvement and internal statistics | Legitimate interests |
| Audience measurement using non-essential trackers | Consent where required |
| Product and account communications | Performance of a contract or legitimate interests |
| Newsletters and certain marketing communications | Consent or legitimate interests for reasonable B2B outreach |
| Prospect and demo request management | Pre-contractual steps and legitimate interests |
| Compliance with accounting, tax and legal requirements | Legal obligation |
Where processing relies on our legitimate interests, we ensure that those interests do not disproportionately affect the rights and freedoms of the individuals concerned.
6. Required data
Fields marked as mandatory are required to process your request, create an account or provide the Service. Without them, Elevia may be unable to provide the requested feature or service.
7. Recipients and service providers
Data is available to authorized Elevia personnel on a need-to-know basis and to providers required to deliver, secure and improve the Site and Service.
7.1. Service providers and customer business data
| Provider | Function |
|---|---|
| Scaleway SAS | Application hosting and infrastructure |
| Supabase Inc. | Database, storage and authentication — Paris region |
| Stripe Payments Europe Ltd / Stripe Inc. | Payments and billing |
| Vercel Inc. | Front-end hosting and CDN |
| BunnyWay d.o.o. (Bunny.net) | Media storage, streaming and delivery |
| Plus Five Five, Inc. (Resend) | Transactional emails |
| Loops, Inc. | Product and marketing emails |
| Anthropic, PBC | Claude artificial intelligence features |
| OpenAI Ireland Ltd. | OpenAI artificial intelligence features |
| PostHog, Inc. | Usage analytics, emails and session recordings depending on configuration |
| Functional Software, Inc. (Sentry) | Error monitoring and technical diagnostics |
7.2. Site, communication and feedback providers
| Provider | Function |
|---|---|
| Google Ireland Ltd. / Google LLC | Google Analytics audience measurement |
| Microsoft Ireland Operations Ltd. / Microsoft Corporation | Microsoft Clarity audience measurement and session recordings |
This list may change. Where a provider processes personal data on our behalf, we impose appropriate contractual confidentiality and security obligations.
8. Artificial intelligence
Some features may send Anthropic or OpenAI only the information required to generate the requested output. Elevia does not sell Customer Data and does not use it to train general-purpose artificial intelligence models without the customer's separate agreement.
Customers remain responsible for avoiding unnecessary data, special categories of data or information they are not authorized to process.
9. Transfers outside the European Economic Area
Some data may be transferred outside the European Economic Area where required to use certain providers. These transfers are protected by appropriate safeguards, including European Commission Standard Contractual Clauses, applicable adequacy decisions or another mechanism permitted by the GDPR.
Further information about applicable safeguards may be requested from hi@elevia.io.
10. Retention periods
| Category | Indicative period |
|---|---|
| Account and subscription data | For the duration of the contractual relationship |
| Customer Data after termination | 30 days to allow export or recovery, followed by deletion under the Terms |
| Prospects who do not become customers | Up to 3 years after the last contact |
| Data used for B2B outreach | Up to 3 years after the last contact or until objection |
| Consent-based newsletter data | Until consent is withdrawn or after 3 years of inactivity |
| Invoices and accounting records | 10 years |
| Support tickets | During the relationship and up to 3 years thereafter, unless longer retention is needed as evidence |
| Login and security logs | Up to 12 months |
| Persistent consent-based cookies and trackers | No more than 13 months, unless the provider states a shorter period |
Some data may be retained longer where required by law or necessary to establish, exercise or defend legal claims. It is then isolated and access is restricted.
11. Cookies and trackers
The Site and Service may use:
- cookies strictly necessary for authentication, security and operation;
- audience measurement trackers, including Google Analytics, Microsoft Clarity and PostHog depending on the environment;
- communication tools, including Loops depending on the environment.
Where required by law, storing or reading non-essential trackers is subject to your consent. You may withdraw consent at any time as easily as you gave it. You can also configure your browser to block or delete cookies, although some features may no longer work correctly.
Persistent cookies requiring consent have a maximum lifetime of thirteen (13) months. The user's choice must be renewed periodically.
12. Security
Elevia implements appropriate technical and organizational measures, including encryption in transit, logical segregation of each customer's data, access management, logging, backups, restrictions on internal access and incident-management procedures.
No security measure can guarantee absolute protection. If a personal data breach occurs, Elevia applies the documentation, notification and information requirements imposed by applicable law.
13. Your rights
Depending on applicable law and the legal basis used, you have:
- a right of access;
- a right to rectification;
- a right to erasure;
- a right to restriction of processing;
- a right to object, including to direct marketing;
- a right to data portability;
- the right to withdraw consent at any time;
- the right to give instructions about your data after your death under French law.
To exercise your rights, contact hi@elevia.io. We may request proof of identity only where we have reasonable doubts about the requester's identity.
You may also lodge a complaint with:
Commission Nationale de l'Informatique et des Libertés (CNIL) 3 Place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07, France www.cnil.fr
Where data was entered into Elevia by one of our customers, that customer is generally the data controller. We will forward the request or invite you to contact that customer directly.
14. Children
Elevia is intended for professional use and is not intended for children. We do not knowingly collect personal data relating to children.
15. Third-party links and services
The Site or Service may contain links to third-party services. Elevia is not responsible for their privacy practices. We recommend reviewing their privacy policies before providing them with data.
16. Changes to this Policy
We may amend this Policy to reflect changes to the Service, our processing activities or applicable law. The last-updated date appears at the top of this page. If a change is material, we may notify users by email or through the Service.
17. Contact
For questions about this Policy or to exercise your rights:
Wabam — Elevia 1 B rue Raymond Greban 78100 Saint-Germain-en-Laye, France hi@elevia.io