📋 This privacy policy will be reviewed and updated prior to commercial launch.
Last updated: June 2026 · Version 0.1 (Pilot) · GDPR-aligned
This Privacy Policy explains how Elevate Teams collects, uses, and protects your personal data when you use our platform. We are committed to handling your information responsibly and in accordance with the General Data Protection Regulation (GDPR).
We collect information you provide directly to us when you use the Elevate Teams platform ("Platform"). This includes: Personal Identification Data • Full name and email address provided at account registration or invitation. • Contact details optionally provided in your profile. Usage Data • Log data including IP address, browser type, pages visited, and timestamps. • Actions performed within the Platform (e.g. records created, workflows triggered, content approved). Organisation Data • Information about your organisation entered into the Platform, including property data, campaign details, and team structures. • This data is stored on a per-organisation (tenant) basis and is strictly isolated from other organisations.
We use the information we collect to: • Provide, operate, and maintain the Platform. • Authenticate your identity and manage access controls. • Enforce role-based permissions and organisational boundaries. • Send transactional emails such as invite notifications and platform alerts. • Monitor platform health, detect abuse, and prevent unauthorised access. • Improve platform functionality based on usage patterns (aggregated and anonymised). • Comply with legal obligations. We do not sell, trade, or rent your personal information to third parties for marketing purposes.
Your data is stored on servers located within the European Union (EU) in compliance with GDPR requirements. Tenant data is stored with strict multi-tenant isolation. Each organisation's data is logically separated and cannot be accessed by users of other organisations. We retain your data for as long as your organisation maintains an active account with us, or as required by applicable law. Upon account termination, data will be retained for a period of 90 days before secure deletion, unless a longer retention period is required by law. We employ industry-standard practices for backup and disaster recovery to protect against data loss.
We take the security of your data seriously and implement appropriate technical and organisational measures to protect it, including: • Role-based access control (RBAC) enforced at every layer of the Platform. • Tenant isolation with certified separation of organisation data. • Encrypted data transmission using TLS. • Secure authentication managed by our identity provider. • Comprehensive audit logging of all data access and mutations. • Regular security reviews and penetration testing. Our tenant isolation architecture has been independently certified: 124 tests across 5 phases with zero cross-tenant data leakage or privilege escalation paths confirmed. Despite these measures, no system can guarantee absolute security. You are responsible for maintaining the security of your account credentials.
The Platform uses cookies and similar tracking technologies to operate and improve our services. Essential Cookies Required for authentication, session management, and Platform functionality. These cannot be disabled without affecting your ability to use the Platform. Analytics Cookies Used to understand how users interact with the Platform in aggregate. These are anonymised and do not identify you personally. You can control cookie settings through your browser preferences. Note that disabling essential cookies will prevent you from logging in to the Platform. We do not use cookies for advertising or cross-site tracking purposes.
We use a limited set of trusted third-party services to operate the Platform: • Email Delivery: Used to send transactional emails (invitations, notifications). Your email address may be processed by our email service provider solely for delivery purposes. • Infrastructure & Hosting: Our Platform runs on cloud infrastructure providers operating within the EU. • Authentication: Secure sign-in is managed by our authentication provider. All third-party providers are bound by data processing agreements and are required to handle your data in accordance with GDPR requirements. We do not share your personal data with third parties beyond what is necessary to provide the Platform.
Under the General Data Protection Regulation (GDPR) and applicable data protection law, you have the following rights regarding your personal data: Right of Access — You may request a copy of the personal data we hold about you. Right to Rectification — You may request correction of inaccurate or incomplete data. Right to Erasure — You may request deletion of your personal data, subject to our legal obligations to retain certain records. Right to Restriction — You may request that we restrict processing of your data in certain circumstances. Right to Data Portability — You may request your data in a structured, machine-readable format. Right to Object — You may object to processing of your data for certain purposes. Right to Withdraw Consent — Where processing is based on consent, you may withdraw that consent at any time. To exercise any of these rights, please contact us using the details below. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.
For any privacy-related questions, requests to exercise your rights, or concerns about how we handle your data, please contact our Data Controller: Elevate Teams Email: privacy@elevateteams.es Website: elevateteams.es Data Controller: Elevate Teams Jurisdiction: Spain / European Union We will endeavour to respond to all privacy enquiries within 5 business days, and all formal data subject requests within 30 days.