Platform documentation

Data Processing Agreement

Last updated: 7 July 2026.

This Data Processing Agreement ("DPA") forms part of the agreement between Saint Financial Group Limited ("Controller" or "Customer", as applicable) and users of Elevale where Saint Financial Group Limited or Saint Financial Group Limited ("Processor") processes personal data on the Customer's instructions. It supplements our Terms of Service and Privacy Policy.

Saint Financial Group Limited (Elevale) operates the Elevale platform infrastructure as Processor or sub-processor on behalf of Saint Financial Group Limited for direct customers, and may act as Processor for agency customers under reseller arrangements described below.

1. Definitions

  • Personal data: information relating to an identified or identifiable natural person, as defined under UK GDPR and EU GDPR.
  • Processing: any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
  • Controller: the entity that determines the purposes and means of processing personal data.
  • Processor: the entity that processes personal data on the Controller's instructions.
  • Subprocessor: a third party engaged by the Processor to process personal data.
  • Customer data: personal data contained in workspace content uploaded or generated by Customer and its users.

2. Roles of the parties

2.1 Direct Elevale customers

  • Saint Financial Group Limited is Controller for platform account data (registration, billing profile, support communications).
  • Saint Financial Group Limited is Processor for Customer data uploaded to workspaces, processing only on Customer instructions as set out in the Terms of Service.
  • Saint Financial Group Limited (Elevale) is Processor or sub-processor providing infrastructure, security, and subprocessors listed at Subprocessors and integrations.

2.2 Agency and white-label customers

Where an agency resells Elevale under its own brand:

  • The agency is typically Controller for end-user and client workspace data.
  • Saint Financial Group Limited and Elevale act as Processor or sub-processor on the agency's instructions.
  • End users may contract with the agency; the agency must publish appropriate privacy terms. See Agency and reseller data responsibilities.

3. Subject matter and duration

Processing is limited to providing the Elevale service: account management, workspace collaboration, AI features (where enabled), integrations, billing, security, support, and compliance. Processing continues for the duration of the subscription and applicable retention periods in Data retention and deletion, then Customer data is deleted or anonymised as documented.

4. Nature and purpose of processing

  • Hosting, storing, backing up, and displaying Customer data
  • Authenticating users and enforcing role-based access controls
  • Generating AI responses, embeddings, and insights when Customer enables AI features
  • Syncing data from Customer-authorised third-party integrations
  • Maintaining audit logs and security monitoring
  • Processing billing and wallet transactions
  • Responding to Customer support and data subject requests

5. Types of personal data and data subjects

Categories may include: names, email addresses, job titles, profile photos, workspace content containing personal data, usage logs, billing contacts, and integration-derived data. Data subjects include Customer employees, contractors, invitees, and other users Customer authorises.

6. Processor obligations

Processor shall:

  • Process personal data only on documented instructions from the Controller (these Terms, Customer configuration, and lawful requests), unless required by law
  • Ensure persons authorised to process personal data are bound by confidentiality
  • Implement appropriate technical and organisational measures per Article 32 UK/EU GDPR (see Security and data protection)
  • Not engage another subprocessor without Controller notification and opportunity to object, as set out in section 7
  • Assist Controller with data subject requests, DPIAs, and supervisory authority consultations where reasonably possible
  • Delete or return Customer data at termination, subject to retention required by law
  • Make available information necessary to demonstrate compliance and allow audits on reasonable notice, subject to confidentiality and security constraints

7. Subprocessors

Controller authorises Processor to engage subprocessors listed at Subprocessors and integrations. Current platform subprocessors include Supabase, Fly.io, Stripe, AWS SES, OpenAI, Anthropic, Google (Gemini), Perplexity, and ElevenLabs, as applicable to enabled features.

Processor will provide at least 30 days' notice before adding a subprocessor that processes Customer personal data, where required by agreement. Controller may object on reasonable grounds relating to data protection. If parties cannot resolve the objection, Controller may terminate affected services.

Processor imposes data protection terms on subprocessors substantially similar to this DPA.

8. International transfers

Personal data may be transferred to the United Kingdom, EEA, United States, and other countries where subprocessors operate. Where transfers occur to countries without an adequacy decision, Processor relies on:

  • UK International Data Transfer Agreement (IDTA) and/or EU Standard Contractual Clauses (SCCs) Module Two (Controller to Processor) or Module Three (Processor to Subprocessor), as applicable
  • Supplementary measures where required by supervisory authority guidance

Enterprise customers may request executed transfer mechanisms by contacting contact form.

9. Security measures (Article 32)

Processor implements measures including:

  • TLS 1.2+ encryption in transit; encrypted storage at rest
  • Multi-factor authentication required for platform accounts
  • Row Level Security and role-based access on tenant data
  • Server-side encryption for OAuth tokens; hashed API keys
  • Immutable audit logging; incident response procedures
  • Point-in-time database recovery; documented key rotation

Details are in Security and data protection and Audit logging.

10. Personal data breaches

Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Customer data, and in any event within 72 hours where feasible, providing information required under Article 33 GDPR to the extent known. Processor will cooperate with Controller's breach notifications to supervisory authorities and data subjects. See Incident response and data breaches.

11. Data subject rights

Processor assists Controller in fulfilling data subject requests (access, rectification, erasure, restriction, portability, objection) through in-app tools: Profile → Privacy (export and requests) and Profile → Security (account deletion). Controller is responsible for responding to its end users; agencies should establish escalation paths to Processor where needed.

12. Deletion and return of data

Upon termination of the service:

  • Customer may export data before access ends
  • Grace period continues until end of billing period where applicable
  • Personal data is anonymised at 60 days and permanently deleted at 90 days after access ends
  • Billing records retained per tax law (typically 6–7 years); audit logs retained 2 years

13. Audit and compliance

Processor maintains records of processing activities and security controls. Enterprise customers may request a summary of subprocessors, security documentation, or completion of security questionnaires under NDA. On-site audits may be arranged for Enterprise customers by mutual agreement, no more than once per year unless required by a supervisory authority.

14. Liability

Liability between the parties is governed by the Terms of Service. Each party remains liable for its own compliance obligations under applicable data protection law.

15. Order of precedence

If this DPA conflicts with an executed Enterprise order form or master agreement on data protection matters, the executed agreement prevails. Otherwise, this DPA supplements the Terms of Service.

16. Changes

We may update this DPA to reflect legal or operational changes. Material changes will be notified as described in the Terms of Service. Continued use after the effective date constitutes acceptance where permitted.

Related documents

Contact: contact form