Skip to main content

Legal Operations

Data Processing Addendum (DPA)

Official policy and operational agreements for our custom systems and deployments.

Elvtera

AI-Powered Systems. Built Around Your Business.

1. Introduction

This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer", "Controller") and Elvtera ("Processor") for the provision of services. It sets out how Elvtera processes personal data on your behalf and reflects the requirements of applicable data protection laws, including the EU and UK General Data Protection Regulation, the California Consumer Privacy Act, and India's Digital Personal Data Protection Act, 2023.

Elvtera is operated by Collins Enterprise Solutions LLP (India) and Josh Global Brands LLC (United States). The contracting entity named in your Service Agreement acts as the Processor under this DPA.

Where this DPA conflicts with the main agreement on the subject of data protection, this DPA prevails.

2. Definitions

Terms such as "personal data", "processing", "data subject", "controller", and "processor" have the meanings given to them in applicable data protection law. "Applicable Data Protection Law" means the privacy and data protection laws that apply to the processing carried out under the agreement.

3. Roles of the Parties

For personal data processed to deliver services, you act as the Controller and Elvtera acts as the Processor, processing personal data only on your documented instructions. Where Elvtera determines the purposes and means of processing for its own business operations, it acts as a Controller and does so in line with its Privacy Policy.

4. Scope and Purpose of Processing

Elvtera processes personal data only to provide the agreed services, which may include AI automation, business process automation, CRM and ERP implementation, software and web development, integrations, workflow automation, and related support. The subject matter, duration, nature, purpose, types of personal data, and categories of data subjects are defined by the services described in your Service Agreement.

5. Processor Obligations

Elvtera agrees to:

  • Process personal data only on your documented instructions, unless required otherwise by law, in which case we will inform you where legally permitted
  • Ensure that personnel authorised to process personal data are bound by confidentiality
  • Implement appropriate technical and organisational security measures as described in Section 8
  • Assist you, taking into account the nature of processing, in responding to data subject requests
  • Assist you with data protection impact assessments and consultations with regulators where reasonably required
  • Notify you without undue delay after becoming aware of a personal data breach affecting your data
  • Make available information reasonably necessary to demonstrate compliance with this DPA

6. Subprocessors

You give general authorisation for Elvtera to engage subprocessors to help deliver the services. These include cloud and infrastructure providers such as AWS, Oracle Cloud, Azure, GCP, and Supabase, AI providers such as OpenAI, Anthropic, and Google Gemini, and platform and communication tools used in your solution.

When we engage a subprocessor, we impose data protection obligations on it that are no less protective than those in this DPA. We remain responsible for the performance of our subprocessors. We will inform you of intended changes to subprocessors and give you a reasonable opportunity to object on legitimate data protection grounds.

7. Cross-Border Transfers

Because Elvtera operates across India and the United States and uses global cloud providers, personal data may be transferred and processed in countries other than your own. Where such transfers are subject to Applicable Data Protection Law, we implement appropriate safeguards, such as standard contractual clauses or an equivalent recognised transfer mechanism, to protect the data.

8. Security Measures

Elvtera maintains technical and organisational measures designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include:

  • Access controls and the principle of least privilege
  • Encryption of data in transit where supported, and at rest where appropriate
  • Secured and access-restricted infrastructure
  • Credential management and authentication controls
  • Logging and monitoring appropriate to the service
  • Internal policies governing data handling and staff responsibilities

Security measures are reviewed and updated as needed to address evolving risks.

9. Personal Data Breach

In the event of a personal data breach affecting data processed on your behalf, Elvtera will notify you without undue delay after becoming aware of it, provide available details about the breach, and cooperate with you in investigating and mitigating it, so you can meet any notification obligations you have under Applicable Data Protection Law.

10. Data Subject Rights

Taking into account the nature of the processing, Elvtera will provide reasonable assistance to help you respond to requests from data subjects exercising their rights, such as access, correction, deletion, restriction, and portability. If we receive a request directly from a data subject relating to your data, we will forward it to you rather than responding ourselves, unless legally required to respond.

11. Data Deletion and Return

On termination or expiry of the services, and at your choice, Elvtera will delete or return the personal data processed on your behalf, and delete existing copies, unless retention is required by law. Deletion and return are carried out within a reasonable period, subject to any legal holds and to the practical constraints of the underlying platforms.

12. Audit Rights

Elvtera will make available to you the information reasonably necessary to demonstrate compliance with this DPA. On reasonable prior written notice, and no more than once per year unless required by a regulator or following a breach, you may audit our compliance, either through documentation we provide or through a mutually agreed process. Audits must respect the confidentiality and security of our other clients and must not disrupt our operations. Each party bears its own costs unless agreed otherwise.

13. Confidentiality

Elvtera treats all personal data processed on your behalf as confidential and ensures that personnel and subprocessors with access are bound by appropriate confidentiality obligations. This duty continues after the services end.

14. GDPR Compliance

Where the GDPR or UK GDPR applies, this DPA is intended to satisfy the requirements for a processor agreement under those laws, including the obligations set out in the relevant articles governing processor duties, security, subprocessing, and international transfers. Nothing in this DPA reduces the protections that Applicable Data Protection Law requires.

15. General

This DPA remains in effect for as long as Elvtera processes personal data on your behalf. If any provision is found unenforceable, the remainder continues to apply. This DPA is governed by the same law as your main agreement, as set out in our Terms of Service.

16. Contact

For data protection matters, contact us at hello@elvtera.com or https://elvtera.com.

Collins Enterprise Solutions LLP

1508C Devangar Nagar, Madhurapuri PO

Turaiyur, Tiruchirappalli

Tamil Nadu 621010, India

Josh Global Brands LLC

7901 4th Street North, Ste 300

St. Petersburg, FL 33702

United States