What is processed, why it is processed, and who controls it.
This pre-launch notice describes the platform’s implemented and intended processing. It is not a substitute for the final controller identity, data-processing agreement, subprocessor review, retention schedule or professional legal approval.
LIVE SEQUENCE · 01/03CONTEXT
Pre-launch version24 July 2026B2B platform
01
Controller and privacy contact
The controller will be the legal entity that operates Elarvio. Its final registered identity has not yet been supplied. Privacy requests can currently be directed to support@elarvio.com. The controller disclosure must be completed before production publication.
02
Website and security logs
When the website is accessed, technical request data may include IP-derived security identifiers, timestamp, requested URL, user agent, response status and abuse-prevention signals. Processing supports secure delivery, fault diagnosis and protection against automated attacks.
03
Accounts and authentication
Registration and sign-in process the owner’s name, business email, organization information, password hash, verification state, session identifiers and security metadata. Passwords are not stored in plain text.
04
Contact and sales enquiries
The contact form processes name, company, business email, telephone, industry, company size, estimated WhatsApp volume, preferred language, message content, consent record and anti-abuse proof so the request can be answered and qualified.
05
Website live chat
The website guide processes the submitted question, a limited recent conversation history, page context, language and anti-abuse proof. Visitors must not submit passwords, payment-card data, health information, access tokens or other sensitive information.
06
Customer workspace data
Depending on enabled features, tenant workspaces may process company profiles, team accounts, services, opening hours, approved knowledge, conversations, contact details, booking information, operational notes, audit records and integration configuration.
07
WhatsApp and calendar integrations
If enabled, Elarvio processes message and delivery metadata received from Meta and availability or event information received from connected calendar providers. Provider access tokens are intended to be encrypted server-side and are not exposed to browser code.
08
Billing
Stripe hosts Checkout and may process customer, billing, tax, payment-method and transaction information under its own notices. Elarvio receives identifiers, subscription state, invoice state, plan, cadence and limited customer details required to operate the subscription.
09
Purposes and legal bases
Expected purposes include contract steps and service delivery, security and fraud prevention, support, compliance, billing and—only where applicable—consent-based communication. The final controller must map each purpose to the appropriate GDPR legal basis before launch.
10
Processors and recipients
Potential processors include hosting, PostgreSQL infrastructure, Meta/WhatsApp, calendar providers, Stripe, transactional email, AI services and error monitoring. The final list, processing locations, contractual safeguards and subprocessor links must match the deployed production stack.
11
International transfers
Some providers may process data outside the EEA. Before launch, the controller must document applicable adequacy decisions, Standard Contractual Clauses and supplementary safeguards for each production provider.
12
Retention and deletion
Data should be retained only for the operational, contractual, security and statutory periods that apply. Tenant-configurable retention exists for relevant records, but the final retention schedule, deletion jobs, legal holds and backup lifecycle must be approved and verified.
13
Your rights
Subject to applicable law, individuals may request access, correction, deletion, restriction, portability or objection, and may withdraw consent for future processing. Requests can be sent to support@elarvio.com; identity may need to be verified.
14
Complaints and automated decisions
Individuals may complain to the competent data-protection authority. The public guide and operational assistant can support routing and bookings, but Elarvio should not be configured to make legally significant solely automated decisions without a separately reviewed basis and safeguards.
15
Local storage and cookies
The current website can use same-origin session cookies for authentication and local browser storage for live-chat continuity and selected-plan state. Any non-essential analytics or advertising technology requires a separately implemented and reviewed consent mechanism before activation.
16
Security and changes
Controls include tenant-scoped authorization, encrypted integration secrets, signed webhook verification, bounded input, rate limits, audit records and anti-automation challenges. No system can guarantee absolute security. Material notice changes should be dated and communicated where required.
Before commercial publication, the operator identity, mandatory disclosures and actual production-provider stack must be reviewed by qualified counsel.