Privacy Policy
Last updated: 29 June 2026
Elqar (Procity)("we", "us", "our") operates Elqar. This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights under UK GDPR and the Data Protection Act 2018.
1. Who we are
We are the data controller for personal data processed through Elqar. If you have questions about how we handle your data, contact us at hello@elqar.com.
2. Data we collect
We collect the following categories of personal data:
- Account data — name, email address, password (hashed), job title, organisation name
- Usage data — pages visited, features used, actions performed, timestamps
- Billing data — payment method details processed securely via Stripe; we do not store full card numbers
- Operational data — inventory records, stock movements, purchase orders, and other data you input into the platform
- Technical data — IP address, browser type, device information, error logs via Sentry
3. How we use your data
| Purpose | Legal basis |
|---|---|
| Providing and operating the service | Contract performance |
| Processing payments and managing subscriptions | Contract performance |
| Sending transactional emails (alerts, invites, receipts) | Contract performance |
| Monitoring errors and improving reliability | Legitimate interests |
| Complying with legal obligations | Legal obligation |
| Sending product updates (you can opt out) | Legitimate interests |
4. Data sharing
We do not sell your data. We share it only with trusted service providers who help us operate Elqar:
- Supabase — database hosting (EU region)
- Vercel — application hosting and deployment
- Stripe — payment processing
- Resend — transactional email delivery
- Sentry — error monitoring
All providers are bound by data processing agreements and operate under appropriate safeguards.
5. Data retention
We retain your personal data for as long as your account is active. On account deletion, we remove your data within 30 days, except where we are required to retain it for legal or accounting purposes (typically 7 years for financial records).
6. Security
We use industry-standard security measures including encrypted connections (HTTPS), hashed passwords, and strict per-organisation data isolation. Every database query is scoped to your organisation — no cross-tenant data access is possible. We conduct regular security reviews.
7. Your rights
Under UK GDPR you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate data
- Erasure — request deletion of your data
- Portability — receive your data in a machine-readable format
- Object — object to processing based on legitimate interests
- Restriction — request we limit how we use your data
To exercise any of these rights, email us at hello@elqar.com. You can also export or delete your data directly from Settings → Data inside your account. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies
We use only essential cookies required for authentication and session management. We do not currently use advertising or tracking cookies. See our Cookie Policy for full details.
9. International transfers
Your data is stored in the EU (Ireland). Some of our service providers (Vercel, Stripe, Sentry) may process data in the United States. Where this occurs, transfers are protected by Standard Contractual Clauses approved by the UK ICO.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you by email before material changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
11. Contact
For any privacy-related questions, email hello@elqar.com.