Privacy Policy
Who we are
Elevate Platform (the “Platform”, “we”, “us”) operates the ELEVATE continuous-intelligence service. For the purposes of the EU General Data Protection Regulation (GDPR), Elevate Platform is the data controller for the personal data described below. You can reach us about privacy matters at privacy@elevate-platform.eu.
What we collect
- Trial requests. When you ask for a trial we collect your name, work email, company/organisation, your stated intended use, and any message you include.
- Account & authentication. If a trial is approved we hold your email, a hashed password, your role and organisation membership, and login timestamps.
- Usage. Operational logs needed to run and secure the service (e.g. request metadata, error events, and security events such as failed logins).
- Content you create. Sources, streams, collections, notes and reports you produce in the Platform.
- Cookies. We set a single strictly-necessary session cookie to keep you signed in. We do not use advertising or third-party analytics cookies, so no cookie consent banner is required.
Why we use it, and our legal bases
- To provide the service you have requested or signed in to — performance of a contract (or steps prior to one).
- To secure and operate the Platform, prevent abuse, and keep audit and security records — legitimate interests.
- To contact you about your trial and respond to your enquiries — legitimate interests / contract.
- To monitor and analyse published sources in order to produce intelligence analysis — legitimate interests. See People mentioned in the sources we monitor.
People mentioned in the sources we monitor
This section concerns people who are not our users. ELEVATE continuously collects and analyses material that has already been published — news reporting, vendor and research publications, and material issued by public authorities. That material sometimes names or otherwise identifies individuals, and analysing it is therefore processing of their personal data.
Why we do it. Our purpose is to produce intelligence analysis for organisations that assess and defend against security and geopolitical risk. Our legal basis is legitimate interests — ours and our customers’ interest in understanding threats, balanced against the interests and rights of the individuals concerned. We have carried out and documented an assessment of that balance, and we will provide it on request.
What we limit ourselves to. We monitor a curated set of sources rather than crawling the open internet. Our analysis is directed at organisations, threat groups, techniques, infrastructure and events, not at profiling individuals. Where material concerns alleged or established criminal conduct, we restrict ourselves to authoritative public sources such as indictments, court records, sanctions listings and authority publications, and we apply additional safeguards including restricted access and time limits on retention.
Why we have not contacted you directly. Where personal data reaches us from a published source rather than from the individual, the GDPR allows us not to notify each person individually where doing so would involve disproportionate effort. Given the volume of material we process, that is the case here. This notice is how we make that information available instead, as Article 14(5)(b) requires.
Your rights. If you are named in material we hold, you have the right to ask what we hold about you, to have it corrected if it is inaccurate or out of date, to ask us to erase it, and to object to our processing it. Where you object, we will stop unless we can demonstrate compelling legitimate grounds that override your interests. Email privacy@elevate-platform.eu and we will respond within the statutory timeframe.
AI processing
ELEVATE uses large-language-model providers to analyse and synthesise content. We pass the text being processed to those providers solely to return a result to you. Your content is not used to train AI models. Processing is performed on EU infrastructure and we do not transfer personal data outside the EU by default.
Who we share it with (processors)
We share data only with service providers acting on our instructions (“processors”): our EU hosting provider, our transactional email provider, and the language-model providers used to process content. We do not sell personal data. Our current list of sub-processors is published, including what each one does and where it operates.
How long we keep it
Trial-request data is retained for the duration of the trial programme and a reasonable period afterwards. Account and content data are retained while your account is active and deleted (or anonymised) on request or within a reasonable period after closure. Security and operational logs are kept only as long as needed for their purpose.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to certain processing. To exercise any of these, email privacy@elevate-platform.eu and we will respond within the statutory timeframe. You also have the right to lodge a complaint with your supervisory authority — in Sweden this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
Changes to this policy
We may update this notice as the service and our legal structure evolve. Material changes will be reflected by the “last updated” date above.
Contact
Privacy enquiries:
privacy@elevate-platform.eu
General & support:
support@elevate-platform.eu