Legal
Privacy policy
We collect the details you give us so we can answer you properly, and very little else. This page says exactly what that means.
Last updated 21 September 2026
01Who we are
Elvanti is an AI automation consultancy. We map how a business runs, then build and operate the systems that run it, using our own developers. This policy covers elvanti.ai and any form, booking page or client portal we run on it.
For the purposes of data protection law we are the controller of the personal data described here. If you want to reach us about anything on this page, email hello@elvanti.ai.
02What we collect
Almost everything we hold about you is something you typed into a form. There are three groups.
What you tell us directly
- The booking form at /book: your name, work email address, company name, website, phone number, industry, team size, revenue range, the areas of the business you want to focus on, a description of your biggest bottleneck, and your timeline.
- The contact form at /contact: your name, email address, company (optional) and your message.
- Scheduling: if you book a call, the name, email address and time slot you give our scheduling provider, plus anything you add to the booking notes.
- Correspondence: emails you send us and our replies, including anything you attach.
- Client materials: if you become a client, the documents, data, process notes and system access you share with us so we can do the work.
What your browser sends with a submission
- Campaign attribution: the UTM parameters on the link you arrived through (source, medium, campaign, term and content), the referring URL, and the path of the first page you landed on.
- Your browser user agent string, and the time of submission.
What we deliberately do not store: your IP address
We never write your IP address to our database. When a form is submitted, the request arrives with an IP address. We use it once, in memory, to ask Cloudflare Turnstile whether the submission looks automated. Then we combine it with a secret salt, run it through a one-way HMAC, and store only the resulting hash.
The hash exists so we can rate-limit a single source and block repeated spam. It cannot be reversed into an address, and without our salt it cannot be matched against a list of addresses. The address itself is discarded with the request.
03Why we collect it, and our lawful basis
- To answer your enquiry. Legitimate interest. You asked a business a question; we need your details to reply usefully and to prepare for the call.
- To deliver work for clients. Performance of a contract. Once you engage us, we process what we need to build, run and support the systems we agreed to.
- To keep the forms free of spam and abuse. Legitimate interest. This is what the IP hash, the rate limit and the bot check are for.
- To understand which marketing actually works. Legitimate interest. Campaign attribution tells us which channels bring real enquiries so we stop paying for the ones that do not.
- To send you things you asked for. Consent, where consent is what applies — for example if you opt in to an email list. You can withdraw it at any time, and withdrawing it does not affect anything we did before you did.
- To meet our own legal obligations. Legal obligation. Invoices, contracts and tax records have to be kept whatever else we would prefer.
We do not sell personal data. We do not share it with advertisers, data brokers or lead marketplaces, and we do not build advertising profiles from it.
04Cookies and similar technologies
We use no advertising cookies and no cross-site tracking cookies at present. There is no Google Analytics tag, no Meta pixel and no ad network script on this site. If that ever changes we will say so here and ask for consent first where the law requires it.
What we do use:
- sessionStorage, for attribution. The first time you land, your browser stores the campaign parameters, referrer and landing path locally so that if you fill in a form three pages later we still know how you found us. It is not a cookie, it is not sent to any third party, and it disappears when you close the tab.
- Vercel Analytics. Cookieless page-view counting. It tells us how many people read a page; it does not build a profile of you or follow you to other sites.
- Cloudflare Turnstile. The bot check on our forms may place a short-lived token in your browser purely to confirm a submission is human. It is not used for advertising or tracking.
- Strictly necessary storage. When the client portal launches, a signed-in session will need a session cookie. That is required for the portal to work at all.
05Who we share it with
We use a small number of service providers to run the site. Each one processes data on our instructions, under a contract, and only for the purpose listed:
- Vercel — hosts the site and provides cookieless analytics.
- Supabase — the database and file storage where enquiries and client materials are held.
- Resend — sends transactional email, such as the notification of your enquiry and its confirmation.
- Cal.com — handles call scheduling and the calendar invitations that go with it.
- Cloudflare — provides Turnstile, the bot protection on our forms.
Beyond that, we will disclose personal data only where we have to: to our professional advisers, to a regulator or court where the law requires it, or to a buyer if the business is ever sold — in which case this policy would follow the data.
06International transfers
The providers above store and process data in the United States and other countries. If you contact us from outside those countries, your information will be transferred across borders to reach us.
Where a transfer leaves the European Economic Area, the United Kingdom or another region with transfer rules, we rely on the safeguards our providers offer for it — normally standard contractual clauses or an approved adequacy decision — together with the encryption and access controls described below. If you want to know which mechanism applies to a specific provider, ask us and we will tell you.
07How long we keep it
- Enquiries that do not become engagements: 24 months from your last contact with us, then deleted.
- Client records: for the life of the engagement, then as long as we need them for contractual, tax and accounting purposes — usually seven years.
- Client materials and system credentials: returned or destroyed at the end of an engagement, on the timetable set out in the agreement we signed with you.
- IP hashes and anti-abuse records: short-lived. They exist to enforce a rate limit and are cleared on a rolling basis.
- Email: kept while the conversation is live and for a reasonable archival period after.
If you ask us to delete something sooner, we will, unless we are legally required to keep it.
08Your rights
Depending on where you live, you have some or all of the following rights over the personal data we hold about you:
- Access — get a copy of what we hold.
- Correction — have anything inaccurate fixed.
- Deletion — have it erased, where we have no overriding obligation to keep it.
- Portability — receive it in a common machine-readable format, or have it sent elsewhere.
- Objection and restriction — object to processing we base on legitimate interest, or ask us to pause it while a dispute is resolved.
- Withdrawal of consent — where consent is the basis, take it back at any time.
To use any of them, email hello@elvanti.ai and say what you want. No form, no process. We may ask a question or two to confirm it is really you, and we will respond within 30 days. It costs nothing.
If you think we have handled your data badly, tell us first — we would rather fix it. You also have the right to complain to your local data protection authority.
09How we protect it
- Everything is served over HTTPS, and encrypted in transit.
- Data at rest sits in a managed database with row-level security, not a spreadsheet on somebody’s laptop.
- Access is limited to the people who need it to do the work, and removed when they no longer do.
- Credentials and API keys live in managed secret storage, never in the codebase.
- Forms are rate-limited and bot-checked, and raw IP addresses are never written down.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach ever affects your data, we will notify you and the relevant regulator promptly and tell you what happened.
10Children
This is a service for businesses. It is not directed at anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has sent us information, email us and we will delete it.
11The client portal
We are building an invite-only client portal for account holders. It is not live yet. When it launches, it will hold project documentation, deliverables and the files a client shares with us, behind an authenticated login. We will update this policy before it opens to describe exactly what it stores and for how long.
12Changes to this policy
When we change this policy we update the date at the top of the page. If a change materially affects how we use your data, we will say so clearly rather than quietly editing a line. The version published here is always the current one.
13Contact us
Questions about this policy, a request about your data, or a concern about how we have handled it — all go to the same place:
Your use of this site is also governed by our terms of service.