Privacy Policy
Version: v1.0 — Last updated: May 1, 2026
This Privacy Policy (the “Policy”) describes how DECALAB, a French single-member limited liability company (EURL) with share capital of €180,000, whose registered office is located at 149 avenue du Maine, 75014 Paris, registered with the Paris Trade and Companies Register under number 993 486 315 (“DECALAB,” “Decalab,” or “we”), collects, uses, shares, and protects personal data in connection with the Elron service (the “Service”), operated on the elron.ai domain.
This Policy is issued under Regulation (EU) 2016/679 of April 27, 2016 (the “GDPR”), amended French Act No. 78-17 of January 6, 1978 (the “French Data Protection Act”), and Directive 2002/58/EC (“ePrivacy”).
Capitalized terms not defined here have the meaning given in the Terms of Use.
1. Decalab’s role in processing data
Decalab acts in two different roles, depending on the data involved:
1.1 Decalab acts as a controller for:
- Service User account data, including name, email, OAuth identifiers, language, and profile image;
- Billing data, including Customer information, amounts, and technical payment identifiers;
- Technical and telemetry data relating to Service use, including analytics events, security logs, and error traces;
- Support communications sent to Decalab;
- Sales and marketing communications sent by Decalab.
1.2 Decalab acts as a processor within the meaning of Article 28 GDPR for:
- Data processed through Service features at the Customer’s request, including incoming and outgoing email, tenant, owner, and vendor data, tickets, action plans, attachments, and content indexed for semantic search.
For this processing, the Customer is the controller. Processing terms are set out in the DPA.
2. Controller and processor contact details
| Legal name | DECALAB EURL |
| Postal address | 149 avenue du Maine, 75014 Paris, France |
| General contact email | contact@elron.ai |
| Data protection requests | privacy@elron.ai |
| Data Protection Officer (DPO) | At this time, Decalab is not required to appoint a DPO under Article 37 GDPR. Requests may be sent to privacy@elron.ai. |
| Supervisory authority | Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy, 75007 Paris — https://www.cnil.fr |
3. Data collected and purposes
3.1 Account data
| Category of data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email, name, profile image, language | Account creation and administration; authentication | Performance of the agreement (Terms of Use) | Agreement term + 3 years |
| Password hash | Authentication | Performance of the agreement | Agreement term |
| Google / Microsoft OAuth identifiers | Authentication; connection to email accounts | Performance of the agreement; OAuth consent | Agreement term or until revoked |
Timestamped, versioned proofs of Terms acceptance (user_terms_acceptances) | Evidence of consent / contractual acceptance | Legal obligation; legitimate interest | Agreement term + 5 years |
3.2 Billing data
| Category | Purpose | Legal basis | Retention |
|---|---|---|---|
| Customer identity, billing address, SIRET number, VAT number | Billing and accounting | Performance of the agreement; legal obligation | 10 years (accounting requirement) |
| Technical identifiers associated with the payment provider | Subscription and payment management | Performance of the agreement | 10 years |
| Payment history and invoices | Commercial administration and accounting | Performance of the agreement; legal obligation | 10 years |
Decalab does not store full payment-card details. Those details are processed solely by the payment provider identified in Subprocessors.
3.3 Data processed through Service features (processing on the Customer’s behalf)
| Category | Purpose | Legal basis used by the Customer as controller | Retention |
|---|---|---|---|
| Encrypted OAuth tokens for connected accounts | Access to third-party services connected by the User | Performance of the Customer’s agreement with its users | Agreement term or until revoked |
| Communication metadata and content, attachments | Classification, ticketing, and assisted reply generation | See DPA and Customer instructions | Agreement term + deletion within 30 days after termination |
| Contact data for tenants, owners, and vendors, including name, email, phone, and context | Relationship tracking and ticket assignment | See DPA | Agreement term + 30 days |
| Tickets, action plans, AI chat, and agent execution logs | Operational tracking | See DPA | Agreement term + 30 days |
| Content-derived representations for semantic search | Assistance and search features | See DPA | Agreement term + 30 days |
3.4 Technical and telemetry data
| Category | Purpose | Legal basis | Retention |
|---|---|---|---|
| IP address, user agent, session identifier | Security, fraud prevention, audit | Legitimate interest; legal obligation | 12 months |
| Anonymized / pseudonymized analytics events | Service improvement | Consent (non-essential cookies) | 12 months |
| Application error traces | Incident diagnosis and correction | Legitimate interest | 90 days |
| AI agent traces with personal data redaction | AI observability and feature improvement | Legitimate interest | 90 days |
| Structured server logs | Security and diagnosis | Legitimate interest; legal obligation | 12 months |
3.5 Communications with Decalab
| Category | Purpose | Legal basis | Retention |
|---|---|---|---|
| Support messages sent by email or in-app chat | Responding to requests | Performance of the agreement; legitimate interest | 3 years after the last interaction |
4. Cookies and similar technologies
The Service uses the following categories of cookies and similar technologies:
4.1 Essential cookies (no consent required)
These are necessary for the Service to operate and include the authentication session, CSRF token, and strictly technical display preferences.
4.2 Product analytics and improvement cookies (with consent)
These analytics tools help Decalab identify friction and improve Service features. Provider details are available in Subprocessors.
4.3 Support cookies (with consent)
These enable in-app support chat and identification of the signed-in user. Provider details are available in Subprocessors.
4.4 Consent management
On the first visit, a banner lets the User accept, reject, or configure non-essential cookies. The consent or refusal choice is retained for 6 months and can be changed at any time through the “Cookie preferences” link in the footer.
The Service does not use advertising or ad-tracking cookies.
5. Data recipients
Data is accessible, strictly on a need-to-know basis, to:
- Authorized Decalab personnel in product, support, and engineering who are bound by confidentiality obligations;
- The subprocessors listed in Subprocessors, to the extent strictly necessary to provide the Service;
- Competent judicial or administrative authorities acting under a valid request;
- An acquirer of all or part of Decalab’s business in connection with a merger, acquisition, or asset sale, subject to protections equivalent to those in this Policy.
Decalab does not sell, rent, or otherwise make personal data commercially available.
6. Use of artificial intelligence
The Service uses artificial intelligence models to provide analysis, classification, and assisted drafting features. Decalab uses third-party AI providers selected in part for the quality of their contractual safeguards and their ability to process data within the European Union or under equivalent safeguards such as Standard Contractual Clauses. The current list is available in Subprocessors.
Decalab’s commitments:
- Only the minimum context necessary for the requested task is sent to third-party AI providers;
- Third-party AI providers are contractually required not to reuse Customer data to train their models;
- No solely automated decision producing legal or similarly significant effects within the meaning of Article 22 GDPR is made without human involvement. The User retains control over operational actions such as sending correspondence, changing leases, and collecting payments.
Internal use of anonymized aggregates: Decalab may use aggregated and/or anonymized data derived from User Content for internal purposes of improving the quality, security, performance, and features of the Service, provided that no individual can reasonably be reidentified (anonymization within the meaning of GDPR Recital 26). This use is based on Decalab’s legitimate interest in improving the Service and never includes sharing identifiable User Content with third parties or training general-purpose AI models made available to third parties.
6 bis. Customer-connected third-party services
The Service allows the Customer to connect Elron to third-party services it already uses, including customer relationship management tools, property or building management software, collaborative suites, calendars, and other integrations enabled by the User.
For these integrations:
- Enabling and revoking the integration is solely the Customer’s decision;
- The Customer represents that it has the lawful right to connect data from the third-party service to Elron;
- Decalab processes the data only to provide the functionality requested by the Customer, in accordance with the DPA;
- Connected third-party services are not operated by Decalab and remain subject to their own terms and privacy policies;
- Decalab is not responsible for failures, changes, suspension, or practices of those third-party services.
7. Transfers outside the European Union
Some subprocessors may process or host data outside the European Union. Details and applicable safeguards are available in Subprocessors.
When a transfer outside the EU is necessary, Decalab relies on:
- A European Commission adequacy decision, where applicable;
- Otherwise, the European Commission’s Standard Contractual Clauses (SCCs);
- Where appropriate, supplementary technical and organizational measures such as encryption, pseudonymization, and personal-data redaction.
A copy of the applicable safeguards may be requested with a reasoned request to privacy@elron.ai.
8. Security
Decalab implements appropriate technical and organizational measures to protect data against unauthorized access, use, alteration, or disclosure, including:
- Encryption in transit: TLS for all network communications;
- Encryption at rest: cloud-provider-managed encryption for the database and object storage, and application-level encryption of connected-account OAuth tokens;
- Access control: organization-level data isolation, role separation, least-privilege access, and periodic entitlement reviews;
- Environment isolation: strict separation of development, staging, and production environments;
- Logging and monitoring: access logs, security traces, anomaly alerts, and personal-data redaction in traces;
- Backups: encrypted backups with point-in-time recovery and limited retention;
- Google application security compliance: Elron’s Gmail OAuth integration has completed a CASA Tier 2 assessment (Cloud Application Security Assessment) in accordance with Google’s requirements;
- A confidentiality agreement signed by every employee and contractor with access to data.
Because no security measure can guarantee absolute protection, Decalab will notify personal data breaches in accordance with Articles 33 and 34 GDPR and the DPA.
Two-factor authentication (2FA) will be offered to Users in the future. Until then, authentication relies on the security of identity providers such as Google and Microsoft or on a password that meets security best practices.
9. Retention periods
Retention periods by category are set out in the tables in Section 3. At the end of those periods, data is deleted or anonymized. Backups containing expired data are deleted through their normal rotation cycle.
When an account or subscription is terminated, data processed on the Customer’s behalf is deleted within no more than 30 days, unless a legal retention obligation applies or the Customer first requests its return, in accordance with the DPA.
10. Data subject rights
Under Articles 15 through 22 GDPR and the French Data Protection Act, each data subject has the following rights:
- The right of access to their data;
- The right to rectification of inaccurate or incomplete data;
- The right to erasure (“right to be forgotten”) under the conditions set out in the GDPR;
- The right to restriction of processing;
- The right to data portability for data provided in a structured, commonly used, machine-readable format;
- The right to object to processing based on legitimate interests;
- The right to withdraw consent at any time where processing is based on consent;
- The right to provide instructions regarding retention, deletion, and disclosure of data after death;
- The right to lodge a complaint with the CNIL.
Exercising these rights
Requests may be sent to privacy@elron.ai or by postal mail to the registered office. Decalab may request proof of identity where it has reasonable doubt about the requester’s identity. Decalab will respond within one month after receiving the request, which may be extended by two months for particularly complex requests following prior notice.
Data processed on behalf of a Customer
If a request concerns data processed by Decalab as a processor for a Customer, for example where a tenant asks about email exchanged with their landlord, Decalab will forward the request to the relevant Customer. The Customer handles the request as controller in accordance with the DPA.
11. Business transfers
In a merger, acquisition, asset sale, or similar transaction, Decalab may transfer the relevant data to the acquirer, provided the acquirer agrees to protections at least equivalent to those described in this Policy. Users will be informed in accordance with Section 14 and may exercise their rights where applicable.
12. Minors
The Service is intended exclusively for professional use by adults. Decalab does not knowingly collect data about minors. A report sent to privacy@elron.ai will result in prompt deletion of the relevant data.
13. Changes to this Policy
Decalab may update this Policy at any time.
Any material change affecting purposes, recipients, retention, international transfers, or data subject rights will be communicated to affected Users by email and/or an in-app banner at least 30 days before it takes effect. The last-updated date appears at the beginning of this document.
14. Contact
| Request type | Address |
|---|---|
| Data protection requests (access, rectification, objection, deletion, portability) | privacy@elron.ai |
| Legal notices | legal@elron.ai |
| Technical support | support@elron.ai |
| General questions | contact@elron.ai |
DECALAB EURL — 149 avenue du Maine, 75014 Paris, France