Security and Data
Version: v1.0 — Last updated: July 6, 2026
This page describes Elron’s operational commitments regarding security, confidentiality, and the use of artificial intelligence. It supplements our contractual and data protection documents: Privacy Policy, DPA, and Subprocessors.
1. Data processing principles
Elron is designed to help property management teams handle incoming requests while keeping their teams in operational control.
- Data is used to provide the Service requested by the Customer, including classification, ticketing, summarization, search, draft generation, and action preparation.
- Elron does not sell personal data or make it available for advertising purposes.
- Sensitive actions, including sending an email or performing a business action, remain subject to human approval.
- Access to internal systems is limited to authorized personnel in accordance with the principle of least privilege.
2. Emails and attachments
Elron is not intended to become a complete archive of the Customer’s mailbox. By default, Elron connects to email accounts through authorized APIs and does not store a full copy of connected mailboxes.
Storage is limited to what the Service requires. Certain excerpts, messages, attachments, tickets, action plans, drafts, or search representations may be retained when necessary to process a request, prepare an action, preserve operational context, or audit processing.
In practice:
- Access to mailboxes uses Google or Microsoft OAuth when those connectors are enabled.
- The Customer can revoke access from Elron or directly from its Google or Microsoft account.
- OAuth tokens are encrypted at the application level.
- Data processed on the Customer’s behalf is deleted at the end of the agreement according to the timeframes in the DPA.
3. Hosting and infrastructure
Elron’s application and primary database are hosted on Google Cloud in the European Union. Customers serving the US market benefit from the same security controls and contractual safeguards; Elron does not represent its EU infrastructure as US-based hosting.
Infrastructure measures include:
- Encryption in transit using TLS;
- Encryption at rest, managed by the cloud provider for the database, object storage, and backups;
- Encrypted backups and point-in-time recovery;
- Separate development, staging, and production environments;
- Organization-level data isolation.
4. Email connection security
Elron’s Gmail integration has completed a CASA Tier 2 validation (Cloud Application Security Assessment), as required by Google for applications requesting sensitive scopes. This validation is based on a formal security assessment reviewed by an authorized assessor and evidenced by a validation letter.
For Google and Microsoft accounts, Elron relies on the identity provider’s security mechanisms, including 2FA or MFA when enforced by the Customer’s organization. Email-and-password sign-in remains available when enabled, but Elron does not yet provide native 2FA for that method.
5. Artificial intelligence
Elron’s AI features use the OpenAI API by default, with a Data Processing Addendum in place.
At a Customer’s request, Decalab may offer processing through Gemini on Google Vertex AI, subject to contractual and technical activation. This option can align AI processing with the Customer’s Google Cloud environment when required for security or compliance.
In all cases:
- Only the context required for the requested task is sent to the relevant AI provider;
- AI providers engaged by Decalab are contractually prohibited from reusing Customer data to train their models;
- Decalab does not use Customer data to train general-purpose models made available to third parties;
- Drafts, summaries, and action plans must be reviewed and approved by a user before action is taken.
6. Traces and platform improvement
Elron retains certain technical logs and AI agent execution traces to diagnose errors, monitor Service quality, improve the platform, and investigate incidents.
These traces are subject to internal restrictions:
- Access is limited to authorized teams;
- Retention is limited as described in the Privacy Policy;
- Personal data is redacted or minimized where technically feasible;
- Traces are not used to train third-party models.
Evaluation, prompt engineering, and quality-improvement work may use synthetic, anonymized, or non-customer test datasets, as well as aggregated metrics.
7. Subprocessors and compliance evidence
Elron’s subprocessors are listed in the Subprocessors document, which describes their purposes, the categories of data involved, processing locations, and contractual safeguards.
When contractually requested or as part of a security review, Decalab can provide available relevant materials, including the DPA, subprocessor list, CASA evidence, AI provider safeguards, hosting information, and responses to the Customer’s security questionnaire.
8. Security contact
For security or compliance questions:
security@elron.aiprivacy@elron.ailegal@elron.ai
DECALAB EURL — 149 avenue du Maine, 75014 Paris, France