Privacy Policy

Last updated: May 2026

1. Who We Are

Elvanis is an AI-powered business diagnostic platform. We are committed to protecting your personal data and being transparent about how we use it. This Privacy Policy explains what data we collect, why we collect it, and how we use it.

2. Data We Collect

We collect information you provide directly: your name, email address, business name, and account credentials. We collect business data from tools you connect to the Platform (Shopify, Jira, GA4, Intercom, Trustpilot) for the purpose of generating diagnostic signals. We collect usage data such as pages visited and features used to improve the Platform.

3. How We Use Your Data

We use your data to provide and improve the Platform, generate diagnostic signals and recommendations, send service communications such as scan results and account notifications, and respond to support requests. We do not use your data for advertising purposes.

4. Third-Party Tool Data

When you connect a third-party tool (Shopify, Jira, GA4, Intercom, Trustpilot), we request read-only access to specific data from that tool. We only request the minimum permissions necessary to generate diagnostic signals. We do not modify or write data to your connected tools.

5. Data Storage and Security

Your data is stored securely on Supabase infrastructure hosted in the EU. We use industry-standard encryption for data in transit and at rest. Access tokens for connected tools are encrypted before storage. We do not store your third-party passwords.

6. Data Sharing

We do not sell your personal data or business data to third parties. We share data with service providers who help us operate the Platform (Supabase for database, Groq for AI analysis, Vercel for hosting, Resend for email). These providers are bound by data processing agreements.

7. AI Processing

Your business data is processed by AI models (Groq/Llama) to generate diagnostic signals. This processing is done on a per-request basis and your data is not used to train AI models. Diagnostic signals are stored in your account and are only visible to you.

8. Data Retention

We retain your account data for as long as your account is active. If you deactivate your account, your data is retained for 30 days before permanent deletion. You may request immediate deletion by contacting us. Connected tool access tokens are deleted immediately upon disconnection.

9. Your Rights (GDPR)

If you are located in the UK or EU, you have the right to access your personal data, correct inaccurate data, request deletion of your data, restrict processing of your data, and data portability. To exercise these rights, contact us through the support section of your profile.

10. Cookies

We use essential cookies for authentication and session management. We use analytics cookies to understand how the Platform is used. You can control cookie preferences through your browser settings. Disabling essential cookies will prevent you from logging in.

11. International Transfers

Your data may be processed in countries outside the UK and EU by our service providers. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.

12. Children's Privacy

The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email. The date at the top of this page indicates when the policy was last updated.

14. Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us through the support section of your profile or via the chat widget on the Platform.

© 2026 Elvanis. All rights reserved. · Terms of Service