Data Processing Agreement
Last updated: July 15, 2026
1. Scope & Roles
This Data Processing Agreement ("DPA") forms part of, and is subject to, our Terms and Privacy Policy. It describes how Elave FX processes personal data on your behalf and applies where the EU/UK GDPR or a comparable law governs that processing. For personal data of individual users, Elave FX generally acts as the controller; where we process data strictly on the documented instructions of a business customer, we act as a processor.
Data controller:[TO FILL — legal entity name], [TO FILL — registered address]. Contact for data protection: [TO FILL — DPO / privacy contact], privacy@elavefx.com.
2. Subject Matter & Duration
We process personal data only to provide and support the platform for the duration of your use of the service and as required afterwards by law. Categories of data may include account and contact details, authentication data, trading data you enter or sync, usage and device data, and payment metadata. We do not process special-category data as a routine part of the service.
3. Our Obligations
We process personal data only on documented instructions; ensure persons authorised to process it are bound by confidentiality; implement appropriate technical and organisational security measures; assist you with data-subject requests and with your security, breach, and impact-assessment obligations; and, at your choice, delete or return personal data at the end of the service (subject to legal retention).
4. Sub-Processors
We engage vetted sub-processors to run the platform. Each is bound by data-protection terms no less protective than this DPA. Our current sub-processors include:
- Supabase — authentication and database hosting
- Vercel — application hosting and delivery
- Stripe — payment processing
- Anthropic — AI processing for coaching features
- Resend — transactional and marketing email
- Broker-data providers — account syncing for the journal, where you connect an account
We will give reasonable notice of any intended change so you can object. The current list is maintained here.
5. International Transfers
Where personal data is transferred outside the EEA/UK, we rely on an appropriate transfer mechanism such as the European Commission's Standard Contractual Clauses (and the UK Addendum) together with supplementary measures where required.
6. Security & Breach
We maintain measures including encryption in transit and at rest, row-level access controls, least-privilege access, and logging. In the event of a personal-data breach affecting your data, we will notify you without undue delay and cooperate on remediation.
7. Contact
To exercise rights or request our signed DPA for business use, email privacy@elavefx.com.
This is a plain-language summary provided for transparency. A comprehensive policy reviewed by qualified counsel will replace this document before public launch. It does not constitute legal advice. Items marked [TO FILL] require your company's verified legal details.