Authentication
Multi-factor authentication (email or authenticator app) required after signup
- Privileged platform roles (super admin, agency admin) must use MFA
- Password reset and session management via Supabase Auth
Elevale is committed to GDPR, UK GDPR, and global privacy standards. This section explains how we protect your data and where to find our legal documents.
GDPR, data retention, privacy rights, security, audit logging, and legal document links.
Plain-language outcomes from our platform documentation: encryption, access control, audit logging, data rights, and retention, without implementation jargon.
Multi-factor authentication (email or authenticator app) required after signup
In transit: TLS 1.2+ for all connections
Row Level Security (RLS) on all tenant data
Under GDPR, UK GDPR, and many US state laws you have rights over your personal data.
Elevale maintains an immutable audit trail for compliance and security accountability.
Retention timelines are consistent across billing, automated jobs, and this documentation.
Retention periods are consistent across billing, automated jobs, and platform documentation.
View retention policy →Until end of current billing period; full access continues
At grace period end; account closed; deletion schedule begins
Personal data anonymised (soft delete)
Permanent deletion (hard delete)
If Elevale is working for your leadership team, a review on G2 or Capterra helps other business directors discover strategic execution software that fits SMEs and growing teams.
Elevale uses trusted subprocessors to deliver the platform. The authoritative list is published at elevale.app/legal/subprocessors. We provide 30 days notice before adding subprocessors that process personal data.
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, storage (EU/US regions) |
| Fly.io | Application hosting |
| Stripe | Payment processing |
| OpenAI / Google Gemini | AI chat and embeddings (when enabled) |
| ElevenLabs | Voice mode (when enabled) |
| AWS SES | Transactional email |
All content is published from Elevale platform documentation in Supabase.
, agreed at signup
Open document → Legal, agreed at signup
Open document → LegalView the cookie policy.
Open document → LegalView the data processing agreement (dpa).
Open document → LegalView the subprocessor list.
Open document →Last updated: May 2026
Read guide →Retention timelines are consistent across billing, automated jobs, and this documentation.
Read guide →Under GDPR, UK GDPR, and many US state laws you have rights over your personal data.
Read guide →Elevale uses trusted subprocessors to deliver the platform. The authoritative list is published at elevale.app/legal/subprocessors . We provide 30 days notice before adding subprocessors that process personal data.
Read guide →Elevale maintains an immutable audit trail for compliance and security accountability.
Read guide →Agencies using Elevale white-label branding have specific data protection responsibilities.
Read guide →Reach our privacy and security teams directly. Data rights requests are handled within our documented 30-day SLA.