قانوني

اتفاقية معالجة البيانات

آخر تحديث · 6 أكتوبر 2026

This agreement explains how Elastly processes personal data for you when you use the service. It is part of our Terms of Service or of the agreement you signed with us.

VERSION 2026-10-06

1. Parties and roles

You, the customer, are the controller of the personal data in your workspace. Elastly, Inc. is the processor. We process that data only on your documented instructions, which are this agreement, the terms and the settings you choose in the product.

2. Subject matter and duration

We process personal data to provide the Elastly service to you. This agreement lasts as long as we hold your data, which is until the workspace is deleted as described in section 10.

3. Nature and purpose

We store, read and analyze the data you connect or upload so we can price your quotes, explain those prices, track competitors, send you emails about your account and bill you. We do not use your data to benefit another customer, and we do not sell it.

4. Data and data subjects

The personal data we process can include:

  • Your users: name, work email, role and sign-in records.
  • Your customers and their contacts: names, company names, emails and addresses held in your ERP or store, and their quotes and orders.
  • Third parties named inside customer requests you ask us to read, such as names, signatures, phone numbers and addresses in emails, PDFs and images.
  • Billing contacts: name, email and billing address.

We do not ask for special categories of personal data. Please do not send them to us.

5. Sub-processors

You allow us to use the sub-processors on our sub-processor list. Each one is bound by a written contract with data protection terms at least as strict as this agreement. We update the list before a new sub-processor starts handling your data, and we tell workspace Owners by email at least 30 days ahead. You may object in that period. If we cannot address the objection, you may end the service for the affected part.

6. International transfers

Our database and our application servers run in the European Union (Ireland). Some sub-processors are in the United States. When personal data leaves the EEA, the UK or Switzerland, we rely on the Standard Contractual Clauses, or on an adequacy decision where one applies.

7. Security measures

These are the measures in place today:

  • Data is encrypted in transit with TLS and encrypted at rest.
  • Each workspace is isolated in the database with row level security, so one customer cannot read another customer's data.
  • ERP and store credentials are kept in an encrypted secret store, not in ordinary tables.
  • Roles inside a workspace limit who can see and change data, and members can be limited to their own customers.
  • Users can turn on two-step sign-in with an authenticator app.
  • Changes to workspace settings, prices and members are written to an audit log.
  • Errors are monitored so we can find and fix problems quickly.

8. Breach notification

If we become aware of a breach of security that affects your personal data, we will tell you without undue delay and within 72 hours. We will share what we know about what happened, the data involved and what we are doing about it, and we will keep you updated.

9. Data subject requests

If a person asks us directly to access, correct or delete their data, we will pass the request to you. We will help you answer requests that you receive, as far as the service allows and at no extra cost for reasonable requests.

10. Deletion and return

We delete a workspace and all of its data on this schedule:

  • 30 days after a paid subscription or a paid pilot ends.
  • 30 days after the trial or setup period ends, for a workspace that never subscribed.
  • 30 days after it was created, for a workspace that never had a trial and never subscribed.
  • 7 days after an Admin asks us to delete it from Settings.
  • 7 days after we schedule it, when a subscription stays unpaid past the grace period.

We email the workspace Owner at least 7 days before the deletion date. Subscribing again before that date cancels the deletion. Deletion removes every record in the workspace, uploaded files and stored ERP and store credentials. If you want a copy of your data, ask us before the deletion date and we will return it to you. We keep Stripe customer and invoice records for as long as accounting and tax law requires.

11. Audit

We will give you the information you reasonably need to show that we meet this agreement. Once a year, or after a breach, you may audit our compliance. Please give us 30 days' written notice. Audits run during business hours and must not put other customers' data at risk.

12. Contact us

Questions about this agreement? Reach us at privacy@elastly.io.