Elastcode Ltd, a company registered in Cyprus, of Paphos, Cyprus ("Elastcode", "we", "us") is established in the European Union, so the GDPR applies to us directly. This page states how we meet it, what we will sign, and how to exercise your rights. It complements our Privacy Policy.
For visitors to our websites we are the controller. For business data inside a customer workspace the customer is the controller and we are the processor, acting only on their instructions.
We provide a DPA to any customer who requests one, incorporating the Article 28 obligations, our sub-processor list, Standard Contractual Clauses for transfers outside the EEA, and our security measures. Request it at hello@elastbiz.com.
Our cloud service runs on EU infrastructure. Beyond that, Elastbiz can be self-hosted under the Elastic License v2, in which case your data never leaves your own servers and we are not a processor at all. We prefer to answer residency questions with architecture rather than with a policy document.
Access, rectification, erasure, restriction, objection, and portability. Email hello@elastbiz.com from the address associated with your account, or through your workspace administrator if the data sits in a customer workspace. We respond within one month and may ask for proof of identity where a request concerns someone else's data.
If a personal data breach occurs we notify the competent supervisory authority within 72 hours of becoming aware of it where the regulation requires, and we notify affected customers without undue delay so they can meet their own obligations.
We maintain records of processing activities, keep an up-to-date sub-processor list, and use Standard Contractual Clauses where a transfer leaves the EEA. Our data protection contact point is hello@elastbiz.com. You may also complain to the Office of the Commissioner for Personal Data Protection in Cyprus, or to your local supervisory authority.