गोपनीयता नीति
Last updated: September 4, 2026
This page is written to be genuinely useful whether you're in the EU/EEA/UK (GDPR), California or another US state with a comprehensive privacy law, or anywhere else — it isn't a substitute for legal advice, and if you're unsure how a specific law applies to you, we'd encourage you to consult your own counsel.
1. Overview
This Privacy Policy explains how ELVOROZ collects, uses, discloses, and safeguards information when you visit this website or interact with any product in the ELVOROZ portfolio. We built this policy to be plain and specific rather than long for the sake of it — if anything is unclear, contact us using the details at the bottom of this page. This also serves as our "notice at collection" under CCPA/CPRA: every form on this site that asks for your information links directly here.
2. Information we collect
We collect information in the following ways:
- Information you provide directly — your name, email address, phone number, and message content when you use our contact form, report an issue, or subscribe to our newsletter. None of this is sensitive personal information (health, biometric, precise geolocation, government ID, etc.) — we don't ask for or knowingly collect that category of data.
- Automatically collected information — IP address, browser type, device information, pages visited, and referring URLs, collected through standard server logs and, only if you've consented via the cookie banner, analytics tooling.
- Cookies and similar technologies — used to remember your theme preference, your cookie consent choice itself, and, only with consent, to understand aggregate site usage. See Section 4.
3. How we use your information
- To respond to inquiries submitted through our contact form or issue reports.
- To send newsletter updates to subscribers who have confirmed a double opt-in, and to let them unsubscribe with one click at any time.
- To monitor, maintain, and improve the security and performance of our Services.
- To comply with legal obligations and enforce our Terms of Service.
We do not use your information for automated decision-making or profiling that produces legal or similarly significant effects on you.
4. Cookies and tracking
We use a minimal set of cookies and local storage, primarily to remember interface preferences and your cookie consent choice, and, only where you've opted in via the categories below, to measure aggregate traffic patterns. We do not use cookies to build cross-site advertising profiles, and we do not sell or share data collected through cookies with third parties for cross-context behavioral advertising. If your browser sends a Global Privacy Control (GPC) signal, we automatically treat that as an opt-out of non-essential cookies without asking you to reconsider it.
5. Legal basis for processing (GDPR)
If you're in the EU/EEA or UK, GDPR requires us to have a lawful basis for each way we use your data:
- Consent — for non-essential cookies (analytics, preferences) and newsletter emails, both opt-in and revocable at any time.
- Legitimate interests — for responding to contact form messages and issue reports you send us, and for basic security logging.
- Legal obligation — where we're required to keep or disclose information (e.g. in response to a lawful request).
6. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We may share information with:
- Service providers (subprocessors) who help us operate the Services — see the full, current list on our Security & Trust page. Each is bound by its own data protection obligations to us.
- Legal and safety purposes — where required by law, or to protect the rights, property, or safety of ELVOROZ, our users, or the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to standard confidentiality arrangements.
7. International data transfers
Our service providers are primarily based in the United States, so if you're in the EU/EEA, UK, or elsewhere outside the US, your information is transferred there. Where required, we rely on legally recognized transfer mechanisms — such as the EU-US Data Privacy Framework (for providers certified under it) or Standard Contractual Clauses — to protect that data in transit and at rest. You can request more detail about the safeguards in place for a specific transfer by contacting us below.
8. Data retention
We keep personal information only as long as it's needed for the purpose it was collected for, then delete or anonymize it:
- Contact form messages: deleted after 24 months.
- Issue reports: the ticket is kept for 37 months as support history, but your email address is anonymized off of it after that period.
- Newsletter signups that never confirmed: deleted after 1 month if the confirmation link was never clicked.
- Newsletter subscriptions: kept until you unsubscribe (one click, no login required, in every email), at which point we stop sending to you and, if you'd previously consented, remove the underlying consent record too.
- Cookie consent records: kept for 24 months as proof of what you agreed to, then deleted (a decline is never stored server-side at all — see Section 4).
- Completed data requests (see Section 9): kept as a compliance record for 37 months, then deleted.
These periods are enforced automatically on a schedule, not just written here — you can always ask us to delete your data sooner using the tool in Section 9.
9. Your rights
Regardless of where you live, you can always ask us to access, correct, or delete the data we hold linked to your email address using the tool below. We verify a confirmation link sent to that address before doing anything, so no one else can access, change, or delete your data by claiming to be you.
Access, correct, or delete your data
If you've contacted us, subscribed to our newsletter, or filed an issue report, you can request a copy of what we hold on that email address, ask us to fix something that's wrong, or ask us to delete it. We'll email a confirmation link first — nothing is disclosed, changed, or removed until you click it.
If you're in the EU, EEA, or UK (GDPR)
You have the right to:
- Access the personal data we hold about you, and receive it in a portable format.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten"), subject to limited legal exceptions.
- Restrict or object to certain processing, including direct marketing at any time.
- Withdraw consent at any time, without affecting processing already carried out.
- Lodge a complaint with your local data protection authority.
If you're in California or another US state with a comprehensive privacy law
Laws like the CCPA/CPRA (California), CPA (Colorado), CTDPA (Connecticut), VCDPA (Virginia), and similar statutes in other states generally give you the right to:
- Know what personal information we've collected about you and why.
- Delete personal information we hold about you.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of your personal information, and out of targeted advertising — we don't do either, and we automatically honor Global Privacy Control (GPC) signals as an opt-out regardless. You can also use the "Do Not Sell or Share My Info" link in our footer.
- Not be discriminated against for exercising any of these rights.
We don't sell personal information and don't meet the CCPA's revenue/volume thresholds that trigger every obligation in that law, but we apply these rights to all California visitors regardless.
Everywhere else
Even where no specific statute requires it, we extend the same core rights — access, correction, and deletion — to every visitor, everywhere, through the same tool above.
10. Security measures
We apply industry-standard safeguards to protect information in transit and at rest, including encrypted connections (HTTPS), hashed credential storage for administrator accounts, two-step email verification for admin logins, and access-controlled infrastructure. No method of transmission or storage is 100% secure, and we continuously work to improve our practices — see our Security & Trust page for specifics.
11. Children's privacy
Our Services are not directed at children, and we do not knowingly collect personal information from anyone under 16 (which covers the US COPPA threshold of 13 as well as the higher age some EU member states set for consent). If you believe a child has provided us with personal information, contact us using Section 9's tool or the email below and we'll remove it.
12. Changes to this policy
We may update this Privacy Policy periodically. Material changes will be reflected by updating the "last updated" date at the top of this page.
13. Contact us
Questions about this policy or your data can be sent to customer@elvoroz.com, or to our privacy-specific inbox at support@elvoroz.com.