Who Shares Their Data With Us
We collect data from various individuals and entities who interact with Elicit Technology's services. For clarity, "you" may fall into one of the following categories.
Regardless of which category you fall under, this policy covers how we handle your data.
Interpretation and Definitions
Words with capitalized initial letters have specific meanings defined below. These definitions apply whether the terms appear in singular or plural form.
Personal Data We Collect
We collect several types of information from and about users of our service.
Information You Provide Directly
When using Elicit Technology services, you may provide the following:
- Contact Information — name, email address, phone number, company name, job title, and business address.
- Account Details — registration information, profile data, company details, logistics expertise, and operational requirements.
- Shipment and Logistics Data — when using our platforms, portals, or APIs, you may submit or access shipment details, consignee information, customs documents, invoices, and supply chain data.
- Communication Data — content of emails, support tickets, feedback forms, and inquiries sent to us.
- Configuration Data — customizations, workflow preferences, API configurations, and integration settings for your logistics operations.
Data Protection Officer and Privacy Contacts
Elicit Technology has appointed a Data Protection Officer (DPO) to oversee compliance with data protection laws and handle privacy-related inquiries. All privacy-related communications can be directed to support@elicittechnology.com.
Data Protection Officer
Grievance Redressal Officer (India)
Privacy & Security Issues
We respond to privacy inquiries within 5 business days and data subject rights requests within 30 days.
Automated Decision-Making and Profiling
Elicit Technology does not use automated decision-making (including profiling) that produces legal effects or similarly significant effects on you. We do not use algorithms or AI to make decisions about:
- Creditworthiness or pricing adjustments
- Service eligibility or access restrictions
- Contract performance or modifications
- Customer categorization that affects service terms
Limited Profiling for Service Improvement
We use aggregated analytics to understand usage patterns (e.g., most-used features, platform performance) for platform optimization. This does not affect your account status, pricing, or access. You have the right to object to this processing at any time by contacting support@elicittechnology.com.
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will comply with applicable notification requirements.
EU/UK Users — GDPR
- Supervisory authority notified within 72 hours of becoming aware of a breach
- Individuals notified without undue delay for high-risk breaches
- Nature, consequences, and mitigation measures disclosed
US Users — State Privacy Laws
- California: notification within timeframes required by Civil Code § 1798.82
- Compliance with other applicable state breach laws
- Email notice plus a prominent website notice
India Users — DPDP Act
- Data Protection Board notified as required under the DPDP Act, 2023
- Prompt notification of affected users with details and remedial actions
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).
Your California Rights
- Right to Know — request disclosure of personal information we have collected about you in the past 12 months.
- Right to Delete — request deletion of your personal information (subject to legal exceptions).
- Right to Correct — request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing — exercise your right to opt out of the sale or sharing of personal information.
- Right to Limit Use of Sensitive Personal Information — restrict our use of sensitive personal information.
- Right to Non-Discrimination — we will not discriminate against you for exercising your privacy rights.
Elicit Technology does not sell personal information to third parties for monetary consideration. We do not share personal information for cross-context behavioral advertising.
If this changes in the future, we will provide a prominent "Do Not Sell or Share My Personal Information" link on our homepage, obtain explicit opt-in consent before selling or sharing your data, and honor all opt-out requests within 15 business days.
How to Exercise Your California Rights
To submit a verifiable consumer request, contact us at support@elicittechnology.com (subject line: "California Privacy Request") or via www.elicittechnology.com/privacy-request.
We will verify your identity before processing requests and respond within 45 days (extendable by 45 days with notice). You may designate an authorized agent to submit requests on your behalf.
Security and Compliance
Elicit Technology maintains industry-recognized security standards and adheres to international compliance frameworks.
Current Certifications
Privacy Framework Compliance
Security Measures
- Encryption — HTTPS/TLS for data in transit; encryption at rest for stored data.
- Access Controls — authentication, authorization, and role-based access restrictions.
- Network Security — firewalls, intrusion detection, and monitoring systems.
- Annual third-party security audits conducted by independent auditors.
- Quarterly vulnerability assessments and penetration testing.
- Continuous security monitoring and threat detection (SIEM integration).
Data Retention Schedule
We retain personal data only as long as necessary for the purposes outlined in this Privacy Policy, or as required by law.
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Account Information | Active account + 30 days after closure | Service provision |
| Shipment & Logistics Data | 1–7 years (per client contract & regulations) | Customs compliance, contractual |
| Financial Records | 7 years from the transaction date | Tax laws, accounting standards |
| Customs Documentation | 5–7 years (varies by jurisdiction) | Regulatory requirements |
| Usage Logs & Analytics | 30–90 days (active use); longer for security investigations | Platform improvement, security |
| Marketing Communications | Until unsubscribe + 30 days | Consent |
| Backup Data | 30 days (automated rotation) | Disaster recovery |
| Support Tickets & Communications | 3 years from resolution | Service quality, legal defense |
After retention periods expire, we securely delete or anonymize data in accordance with industry best practices (DOD 5220.22-M standard for data sanitization).
Privacy by Design and Default
Elicit Technology incorporates Privacy by Design principles into our platform development and operational processes.
Data Minimization
We collect only the minimum personal data necessary for each specific purpose.
Purpose Limitation
Data is used only for the purposes disclosed at the time of collection.
Privacy-Protective Defaults
Platform settings default to the most privacy-protective options, e.g. minimal data sharing and analytics opt-out.
Pseudonymization & Anonymization
Where feasible, we replace identifying data with pseudonyms or aggregate data.
Data Protection Impact Assessments
Conducted for high-risk processing activities before deployment.
Security-First Architecture
Encryption, access controls, and monitoring are built into platform design from inception.
Contact Us
If you have questions about this Privacy Policy, wish to exercise your data rights, or need to report a privacy concern, please contact us.
"Your trust is essential to us. This Privacy Policy reflects our commitment to protecting your data and respecting your privacy rights across all jurisdictions and industries we serve."
Have a privacy question?
Our Data Protection Officer typically responds within 5 business days.
© 2026 Elicit Technology. All Rights Reserved.