Legal Operations
Data Processing Addendum (DPA)
Official policy and operational agreements for our custom systems and deployments.
Elvtera
AI-Powered Systems. Built Around Your Business.
1. Introduction
This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer", "Controller") and Elvtera ("Processor") for the provision of services. It sets out how Elvtera processes personal data on your behalf and reflects the requirements of applicable data protection laws, including the EU and UK General Data Protection Regulation, the California Consumer Privacy Act, and India's Digital Personal Data Protection Act, 2023.
Elvtera is operated by Collins Enterprise Solutions LLP (India) and Josh Global Brands LLC (United States). The contracting entity named in your Service Agreement acts as the Processor under this DPA.
Where this DPA conflicts with the main agreement on the subject of data protection, this DPA prevails.
2. Definitions
Terms such as "personal data", "processing", "data subject", "controller", and "processor" have the meanings given to them in applicable data protection law. "Applicable Data Protection Law" means the privacy and data protection laws that apply to the processing carried out under the agreement.
3. Roles of the Parties
For personal data processed to deliver services, you act as the Controller and Elvtera acts as the Processor, processing personal data only on your documented instructions. Where Elvtera determines the purposes and means of processing for its own business operations, it acts as a Controller and does so in line with its Privacy Policy.
4. Scope and Purpose of Processing
Elvtera processes personal data only to provide the agreed services, which may include AI automation, business process automation, CRM and ERP implementation, software and web development, integrations, workflow automation, and related support. The subject matter, duration, nature, purpose, types of personal data, and categories of data subjects are defined by the services described in your Service Agreement.
5. Processor Obligations
Elvtera agrees to:
- Process personal data only on your documented instructions, unless required otherwise by law, in which case we will inform you where legally permitted
- Ensure that personnel authorised to process personal data are bound by confidentiality
- Implement appropriate technical and organisational security measures as described in Section 8
- Assist you, taking into account the nature of processing, in responding to data subject requests
- Assist you with data protection impact assessments and consultations with regulators where reasonably required
- Notify you without undue delay after becoming aware of a personal data breach affecting your data
- Make available information reasonably necessary to demonstrate compliance with this DPA
6. Subprocessors
You give general authorisation for Elvtera to engage subprocessors to help deliver the services. These include cloud and infrastructure providers such as AWS, Oracle Cloud, Azure, GCP, and Supabase, AI providers such as OpenAI, Anthropic, and Google Gemini, and platform and communication tools used in your solution.
When we engage a subprocessor, we impose data protection obligations on it that are no less protective than those in this DPA. We remain responsible for the performance of our subprocessors. We will inform you of intended changes to subprocessors and give you a reasonable opportunity to object on legitimate data protection grounds.
7. Cross-Border Transfers
Because Elvtera operates across India and the United States and uses global cloud providers, personal data may be transferred and processed in countries other than your own. Where such transfers are subject to Applicable Data Protection Law, we implement appropriate safeguards, such as standard contractual clauses or an equivalent recognised transfer mechanism, to protect the data.
8. Security Measures
Elvtera maintains technical and organisational measures designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include:
- Access controls and the principle of least privilege
- Encryption of data in transit where supported, and at rest where appropriate
- Secured and access-restricted infrastructure
- Credential management and authentication controls
- Logging and monitoring appropriate to the service
- Internal policies governing data handling and staff responsibilities
Security measures are reviewed and updated as needed to address evolving risks.
9. Personal Data Breach
In the event of a personal data breach affecting data processed on your behalf, Elvtera will notify you without undue delay after becoming aware of it, provide available details about the breach, and cooperate with you in investigating and mitigating it, so you can meet any notification obligations you have under Applicable Data Protection Law.
10. Data Subject Rights
Taking into account the nature of the processing, Elvtera will provide reasonable assistance to help you respond to requests from data subjects exercising their rights, such as access, correction, deletion, restriction, and portability. If we receive a request directly from a data subject relating to your data, we will forward it to you rather than responding ourselves, unless legally required to respond.
11. Data Deletion and Return
On termination or expiry of the services, and at your choice, Elvtera will delete or return the personal data processed on your behalf, and delete existing copies, unless retention is required by law. Deletion and return are carried out within a reasonable period, subject to any legal holds and to the practical constraints of the underlying platforms.
12. Audit Rights
Elvtera will make available to you the information reasonably necessary to demonstrate compliance with this DPA. On reasonable prior written notice, and no more than once per year unless required by a regulator or following a breach, you may audit our compliance, either through documentation we provide or through a mutually agreed process. Audits must respect the confidentiality and security of our other clients and must not disrupt our operations. Each party bears its own costs unless agreed otherwise.
13. Confidentiality
Elvtera treats all personal data processed on your behalf as confidential and ensures that personnel and subprocessors with access are bound by appropriate confidentiality obligations. This duty continues after the services end.
14. GDPR Compliance
Where the GDPR or UK GDPR applies, this DPA is intended to satisfy the requirements for a processor agreement under those laws, including the obligations set out in the relevant articles governing processor duties, security, subprocessing, and international transfers. Nothing in this DPA reduces the protections that Applicable Data Protection Law requires.
15. General
This DPA remains in effect for as long as Elvtera processes personal data on your behalf. If any provision is found unenforceable, the remainder continues to apply. This DPA is governed by the same law as your main agreement, as set out in our Terms of Service.
16. Contact
For data protection matters, contact us at hello@elvtera.com or https://elvtera.com.
Collins Enterprise Solutions LLP
1508C Devangar Nagar, Madhurapuri PO
Turaiyur, Tiruchirappalli
Tamil Nadu 621010, India
Josh Global Brands LLC
7901 4th Street North, Ste 300
St. Petersburg, FL 33702
United States
