Privacy Policy

Last updated: July 21, 2026

Legal entity: Elykia LLC (Wyoming, USA)

1. Introduction and Applicable Legal Framework

This Privacy Policy describes how Elykia LLC ("Elykia", "we", "our") collects, uses and protects information on our Marketing Mix Modeling (MMM) SaaS platform. Our privacy practices are designed around industry standards to protect your commercial and operational information.

By using our services, you acknowledge that you act on behalf of a company or commercial entity (B2B). While Elykia operates under the jurisdiction of the State of Wyoming (USA), we recognise and apply the protection standards required by Argentina's Personal Data Protection Law No. 25,326 for our clients resident in that territory.

2. Data We Collect

Under the data minimisation principle, we only process the information strictly necessary for the platform to work:

  • Account data: Full name and email address provided at sign-up.
  • Security and session: We automatically collect the IP address and User Agent to keep sessions secure and prevent unauthorised access.
  • Credentials: Passwords are stored encrypted (hashed). Elykia neither knows nor stores plain-text passwords.
  • API tokens and metrics: When you connect advertising platforms, we securely store Access Tokens and Refresh Tokens under the OAuth protocol. We pull performance metrics (such as spend, clicks, impressions and ROAS) in read-only mode, and we configure the account's URL tracking parameters once, for attribution purposes (see Section 3).
  • Measurement data (attribution script): If the Client installs our measurement script on their store, we collect browsing data from that store's visitors in order to attribute sales correctly: pages visited, referring page, campaign parameters (UTMs and advertising click identifiers), device and browser type, and approximate location (city level) derived from the IP address. The IP address is discarded immediately after that derivation and is only retained as an irreversible hash with a daily-rotating key. The buyer's email and phone number, where available, are turned into SHA-256 hashes generated in the browser itself before transmission: the script never sends this data in plain text. These technologies use first-party cookies and identifiers on the Client's store domain.

3. What We Do NOT Do

To safeguard the integrity of our clients' operations, Elykia makes the following guarantees:

  • We do not create or alter campaigns: We never create, pause, edit or delete campaigns, ad sets or ads. The only write operation we perform is, at the time an advertising account is connected, configuring the tracking parameters on ad URLs (UTMs and account-level campaign and ad identifiers) so that each sale can be attributed to the campaign that generated it. All other access is strictly read-only on performance metrics.
  • We do not sell data: We do not trade your personal information, tokens or campaign metrics with third parties.

4. Sub-processors and International Data Transfer

To host and process data we use first-tier cloud infrastructure providers:

  • OVHcloud: Provides our servers and core infrastructure, including hosting of the production database (PostgreSQL) and the application services.
  • UploadThing: Service used exclusively to host and serve the PDF reports generated by the platform.
  • Cloudflare: Provides the content delivery network (CDN) in front of the platform and storage for the encrypted database backups.
  • Resend: Transactional email delivery service (account verification, password reset, invitations and platform notifications).
  • Stripe: Payment processor for Elykia subscription billing. Card details are entered directly into Stripe's infrastructure and never pass through Elykia's servers.
  • Anthropic: Provider of the language model that powers the platform's assistant (copilot). It receives only aggregated account performance metrics (channels, campaigns, spend, revenue) together with the user's queries; never personal data of end customers.

Compliance with Law 25,326 (Argentina): Given that Elykia LLC operates infrastructure in the United States and other international regions, the Client expressly consents to the international transfer of data for the provision of the service. Elykia undertakes to maintain technical and organisational security measures that meet the standards required by Argentina's Agency for Access to Public Information (AAIP).

4.1 Roles and Responsibilities of the Parties

This section describes the data processing agreement between Elykia and the Client (the merchant connecting their store and/or advertising accounts). Together with the rest of this Policy and the Terms and Conditions, it constitutes the contractual framework governing the processing of personal data between the parties.

  • The Client is the Data Controller. It determines the purposes and means of processing the personal data of its own end customers (the store's buyers) and retains ownership of that data.
  • Elykia is the Data Processor. It processes personal data solely on behalf of the Client and according to its documented instructions, expressed through connecting the platforms and using the product.
  • Sub-processors. The providers listed above (OVHcloud, UploadThing, Cloudflare, Resend, Stripe, Anthropic) act as Elykia's sub-processors. Elykia maintains agreements in force with each of them imposing security obligations equivalent to those described in this Policy.

4.2 Elykia's Obligations as Processor

  • Documented instructions: to process personal data only in accordance with the Client's instructions, as expressed through use of the product. Any deviation requires additional authorisation or is grounded in a legal obligation.
  • Staff confidentiality: Elykia personnel with access to personal data are bound by contractual confidentiality duties.
  • Technical and organisational security measures: those described in Section 5 (access control, encryption in transit and at rest, environment separation, encrypted backups, incident management).
  • Assistance to the Client with data subject rights: to cooperate reasonably with access, rectification, erasure and objection requests from the Client's end customers, within the legally required timeframes. For Shopify, this takes the form of processing the customers/data_request, customers/redact and shop/redact webhooks within the 30-day window required by Shopify.
  • Incident notification: to inform the Client, without undue delay and in any case within 72 hours of becoming aware, of any security breach affecting their personal data, in accordance with Section 6.
  • Return and deletion on service termination: at the Client's request, to delete all personal data associated with their account within the timeframes described in Section 7. Encrypted backups follow the rotation cycle in Section 5.3.
  • Cooperation with audits: at the Client's reasonable request, to make available the information necessary to demonstrate compliance with the obligations in this section.

5. Access Control and Security

We apply the principle of least privilege to protect the confidentiality of your data:

  • Clients only have access to data from the accounts they have explicitly connected.
  • Access by the Elykia team to production databases is limited to strictly necessary maintenance, technical support or bug-fixing tasks. Such administrative access generates a secure, traceable internal audit log.

5.1 Encryption in transit

All communication between the client's browser, the Elykia platform, third-party APIs (Shopify, Meta, Google, etc.) and our sub-processors takes place exclusively over TLS 1.2 or higher. Certificates are issued and rotated automatically by the hosting infrastructure.

5.2 Encryption at rest

The application servers and the production database (PostgreSQL) run on OVHcloud infrastructure, with encryption at rest at the infrastructure provider level. User passwords are never stored in plain text: they are hashed with scrypt before being persisted. Sensitive contact identifiers (email and phone) coming from ecommerce platforms are additionally hashed with SHA-256 for cross-channel identity matching.

5.3 Backups and retention

Backups of the production database, when generated, are stored on the same OVHcloud infrastructure and inherit the encryption and access controls described in Section 5.2. Access to the production server (and therefore to any backup hosted on it) is limited to authorised Elykia personnel in accordance with Section 5.5.

5.4 Environment separation

Development, testing and production environments are isolated at both the database and credential level. Production data is never replicated into testing or development environments.

5.5 Administrative server access

Access to the production server is exclusively via SSH keys; password authentication is disabled in the SSH daemon. Platform user login is managed by Better Auth, with passwords hashed using scrypt. Administrative tokens for external services are stored outside the code repository and are rotated if compromise is suspected.

6. Security Incident Protocol

Should we detect a vulnerability or incident compromising the security of your data or access tokens, Elykia undertakes to notify affected users by email without undue delay, once the breach is confirmed and its scope assessed, providing the corresponding mitigation measures.

6.1 Requests from Public Authorities

Faced with any request for personal data from a public or governmental authority, Elykia applies the following processes:

  • Legality review: every request is reviewed to verify its legal validity, legal basis and the competence of the requesting authority before any disclosure.
  • Challenging unlawful requests: Elykia reserves the right to reject, challenge or seek clarification on any request it considers unlawful, overbroad, or not compliant with applicable due process.
  • Data minimisation: should a legally required disclosure proceed, only the minimum set of data strictly necessary to comply with the request is handed over, never more than required.
  • Documentation: every request received, its legal basis, the assessment carried out and Elykia's response are documented and kept in a secure internal record.
  • Notice to the Client: unless expressly prohibited by law, Elykia will notify the affected Client before disclosing personal data for which the Client is the Data Controller.

This section does not apply to search warrants or court orders in the context of criminal investigations, which are handled in accordance with the applicable procedural law.

7. Your Rights and Data Control (ARCO Rights and AAIP)

You have full control over your account and your information. You may request the following by writing to [email protected]:

  • Access and rectification: Request correction of any inaccurate data in your account.
  • Erasure (right to be forgotten): Request deletion of your account and the associated data.
  • Rights in Argentina: In accordance with Law No. 25,326, the data subject is entitled to exercise the right of access to their personal data free of charge at intervals of no less than six months. The Agency for Access to Public Information (AAIP), the supervisory authority for Law No. 25,326, is empowered to handle complaints and claims brought in relation to non-compliance with personal data protection rules.
  • Retention and purge: We retain your data while your account is active. After you request cancellation, we will permanently delete your access tokens and metrics from our active systems within a maximum of 30 days. For technical continuity reasons, our encrypted backups may retain this information for an additional period of up to 20 days before being automatically overwritten or deleted.

8. Specific Compliance with API Policies

Elykia's use and transfer to any other app of information received from Google APIs will adhere strictly to the Google API Services User Data Policy, including the Limited Use requirements.

Data obtained through the integrations (Meta Ads, Google Ads, TikTok Ads, etc.) will be used exclusively to provide the attribution reports within the Elykia platform and will never be used to serve ads, profile users, or be sold to data brokers.

9. Jurisdiction and Contact

For commercial matters, this policy is governed by the laws of the State of Wyoming, United States. For technical or legal enquiries, or concerns about the processing of your information (including ARCO rights), contact us at: [email protected].

10. Definitions

To avoid ambiguity, the following terms have the meaning indicated throughout this Policy:

  • Personal Data: any information relating to an identified or identifiable natural person, within the meaning of Law No. 25,326 (Argentina) and equivalent regulations (including, without limitation, the European Union's GDPR).
  • Protected Customer Data: in the Shopify context, the personal data of the buyers of the Client's store that Elykia accesses through the Shopify APIs (for example: first name, last name, email, phone, address).
  • Client: the person or company that contracts Elykia's service and connects their stores and/or advertising accounts to the platform. They are the Data Controller for their buyers' personal data.
  • End Customer: the buyer or visitor of the Client's store, whose personal data may be processed by Elykia on the Client's behalf.
  • Data Controller: the party that determines the purposes and means of processing personal data. Under this Policy, the Client.
  • Data Processor: the party that processes personal data on behalf of and for the account of the Controller. Under this Policy, Elykia.
  • Sub-processor: any provider engaged by Elykia that processes personal data on its behalf, listed in Section 4.
  • Processing: any operation or set of operations performed on personal data, including collection, storage, consultation, use, transmission, erasure and destruction.
  • Security Incident: any security breach resulting in the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data processed by Elykia.

This English version is a courtesy translation. In the event of any discrepancy, the Spanish version of this Policy prevails.