Legal

Privacy Policy

Last updated: 26 August 2026

1. Introduction

1.1 This privacy policy applies to www.elvatix.com (the 'Site'), the web application app.elvatix.com and the Elvatix Chrome extension (together the 'Services'), operated by Elvatix B.V., registered under Dutch Chamber of Commerce (KVK) number 91816637, based at Fahrenheitweg 24, 6101 WR Echt, the Netherlands.

1.2 This policy explains which personal data we process, why, with which parties, how long we retain it and what rights you have. We act in accordance with the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (Uitvoeringswet AVG).

1.3 Questions about this policy or your data: support@elvatix.com.

2. Roles: data controller and data processor

2.1 For the data of our own users and website visitors (account data, billing, website use), Elvatix B.V. is the data controller.

2.2 For the data of candidates and prospects that a user looks up, assesses or approaches through Elvatix, the user (or their organisation) is the data controller and Elvatix acts as a data processor. We process that data solely on behalf of, and in accordance with, the instructions of the user.

2.3 For customers acting as data controller, we enter into a Data Processing Agreement (DPA) on request. Among other things, this sets out the complete list of sub-processors, the security measures and the retention periods; the public version in section 7 names the categories.

3. What data we process

3.1 User data: name, email address, company name, job title, the identification of the connected LinkedIn account, configured templates and instructions, and the messages, conversations and lists you create in Elvatix.

3.2 Candidate and prospect data: publicly available LinkedIn profile information (name, role, employer, work experience, education, location, headline, profile photo and public posts) and the data from conversations conducted through the connected LinkedIn account. This data is retrieved through the user’s LinkedIn account, within the rights and limits of that account.

3.3 Data we generate based on the above: search filters, scorecards and match scores per candidate, draft messages and draft replies, and usage statistics (messages sent, acceptances, replies).

3.4 Billing and payment data: company details, billing address, VAT number and payment status. Bank account numbers and payment mandates are processed by our payment provider, not by Elvatix itself.

3.5 Technical data: IP address, browser type, device information, cookies and log records of Service usage.

4. How and why we process data

4.1 To provide the Services: finding and assessing candidates, generating personal messages and replies, sending and following up through the connected LinkedIn account, and tracking results in your dashboard.

4.2 To manage and invoice accounts, subscriptions, credits and payments.

4.3 To secure the Services, prevent abuse and comply with legal obligations.

4.4 To improve the quality of our AI outcomes. For this we use aggregated and anonymised usage statistics and feedback given by users themselves. We do not train our own AI models on candidate or prospect data, and neither do our AI providers (see section 6).

4.5 Legal bases: performance of the contract (4.1, 4.2), legal obligation (4.3) and legitimate interest (4.3, 4.4). For candidate and prospect data, the user, as data controller, determines the legal basis; as a rule this is the legitimate interest of recruitment.

5. LinkedIn connection

5.1 Elvatix works exclusively through the user’s own LinkedIn account (LinkedIn Recruiter, Recruiter Lite, Sales Navigator or LinkedIn Search). The connection runs through a specialised connection partner, hosted in the EU and SOC 2 Type II certified; the LinkedIn login credentials themselves are not stored by Elvatix.

5.2 All search, read and send actions take place on behalf of, and with the rights of, that account, at the pace and within the limits set by LinkedIn. Elvatix does not send a message without the user instructing it to do so.

5.3 Elvatix does not build or maintain its own database of LinkedIn profiles separate from users’ accounts.

6. Use of AI models

6.1 To assess profiles and write messages we use AI language models from reputable providers. Profile and vacancy data is sent to the model per request and the result is returned to your Elvatix environment.

6.2 We use these models exclusively through paid business APIs. Under these providers' terms, data sent through these APIs is not used to train or improve their models. Input and output may be retained temporarily (up to a few weeks) for abuse detection, after which it is deleted.

6.3 Every AI outcome is a proposal. The user assesses candidates and reviews messages before anything is sent; Elvatix does not make automated decisions about individuals with legal effect within the meaning of Article 22 GDPR.

7. Sub-processors and other recipients

7.1 We do not sell personal data and only share it with parties necessary to provide the Services. Data processing agreements are in place with each of these parties.

7.2 Hosting and database: a SOC 2 Type II certified cloud infrastructure partner that encrypts data with AES-256 and protects against DDoS attacks. This partner participates in the EU-US Data Privacy Framework and also applies the European Commission's Standard Contractual Clauses (SCCs).

7.3 LinkedIn connection: a SOC 2 Type II certified connection partner that hosts exclusively within the European Union.

7.4 AI providers: language models for assessment and text generation, as described in section 6.

7.5 Payment provider (Netherlands): payments, direct debits and invoices.

7.6 Email partner: account emails, onboarding emails and product updates to users.

7.7 Supporting services: search index within your own contact list, storage of profile photos and hosting of the website elvatix.com.

7.8 Where data is processed outside the European Economic Area (in particular by the hosting partner and the AI providers), this is done on the basis of an adequacy decision (EU-US Data Privacy Framework) or the European Commission’s Standard Contractual Clauses.

8. Security

8.1 Data is stored encrypted (AES-256) and transmitted encrypted (TLS).

8.2 Administrator access to the production environment is limited to a minimal number of people and secured with two-factor authentication. Users only see their own data and that of their own organisation; this is enforced in the database’s privacy rules.

8.3 API keys and access tokens of our sub-processors are managed server-side and are not stored in the browser or the extension.

8.4 In the event of a data breach that poses a risk to data subjects, we inform affected customers without undue delay and, where required, report the breach to the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority) within 72 hours.

9. Retention periods

9.1 We retain candidate and prospect data, generated messages and conversations in the user’s Elvatix environment for as long as the account is active, so that lists, results and the inbox remain available. Users can delete contacts and lists themselves.

9.2 After an account is terminated, all user, candidate and prospect data is deleted within 30 days, except for data we are legally required to retain for longer.

9.3 We retain billing data for seven years under the Dutch fiscal retention obligation.

9.4 We do not retain technical log records longer than necessary for security and troubleshooting.

10. Your rights

10.1 You have the right to access, correct and delete your personal data, to restrict and object to processing, and to data portability.

10.2 Candidates and prospects who have been approached through Elvatix can exercise their rights with the organisation that approached them (the data controller). If you contact Elvatix, we help get your request to the right party without delay, and we carry out deletion from our systems as soon as that party asks us to.

10.3 Requests can be sent to support@elvatix.com. We respond within 30 days. You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority).

11. Cookies

11.1 On the website we use functional cookies and, only with your consent, analytics and advertising cookies. Details are set out in our Cookie Policy.

11.2 Cookies expire after a maximum of 13 months. You can adjust preferences through the cookie banner or your browser settings.

12. Changes and contact

12.1 We update this policy when our Services or sub-processors change. The date at the top shows the last change; for significant changes we inform users by email.

12.2 Questions, requests or concerns about this privacy policy: support@elvatix.com, or by post to Elvatix B.V., Fahrenheitweg 24, 6101 WR Echt, the Netherlands.