Who We Are

ElevateIQ is an endpoint privilege-elevation service for Windows and macOS operated by Tiny Electrons LLC ("we", "us", "our"). The service consists of:

Together these are referred to as the "Service".

Roles

ElevateIQ is a B2B service. Our customer (typically an IT department or a managed service provider deploying ElevateIQ on behalf of an organization) is the data controller for personal data processed through the Service. Tiny Electrons LLC acts as the data processor on the customer's instructions, governed by a Data Processing Addendum where required.

This policy describes what we, Tiny Electrons LLC, collect, why, and how. It does not replace your employer's or organization's own privacy notice; if you are an end-user on a managed endpoint, your organization is the controller of your personal data.

Data We Collect

From managed endpoints (via the Agent)

From the Admin Console

Automatically

What we do NOT collect: keystroke data, screen captures, browsing history, document contents, file contents from outside elevation requests, microphone or camera input, or biometric templates.

How We Use Your Data

Legal Bases (GDPR / UK GDPR)

AI & Automated Decision-Making

ElevateIQ uses an AI model (currently Google Gemini) to score the risk of each elevation request and recommend an action. We also train our own model in-house on the approve and deny decisions administrators make, and it runs alongside the Gemini score. The AI's recommendation is advisory only: a request is not approved or denied automatically based on the score unless your organization has explicitly configured a rule to do so. A human administrator reviews every novel request.

Where the customer has enabled auto-approve for matching rules, the decision is governed by the rule (a deterministic policy your administrators configured), not by the AI. You can request a manual review of any automated decision by contacting your administrator or, if needed, support@elevateiq.me.

Sub-Processors

We use a small number of vetted sub-processors to operate the Service:

A current sub-processor list is available on request to support@elevateiq.me.

International Transfers

Our primary infrastructure is hosted in the United States. Where personal data is transferred from the EEA, the UK, or Switzerland to the United States, we rely on Standard Contractual Clauses or adequate-decision frameworks where applicable.

Retention

What account closure actually does. We want to be precise here rather than reassuring, because "deleted" means different things in different products.

Closing an account starts a 30-day grace period, during which the request can be cancelled. When it completes, we irreversibly scrub the directly identifying fields on the user record: the email address is overwritten, and the name, password hash, MFA secret and recovery codes are erased. The account is deactivated and can no longer be signed in to or used to authenticate. Closing an organization deactivates every user in it and marks the organization closed.

Operational records created during the subscription are not erased by this process. That includes device inventory, elevation and access-request history (with the free-text reasons and risk scores attached to them), rules, audit entries, and registered passkey credentials (public keys and their metadata, which cannot be used to sign in once the account is deactivated). Those records remain in the database, associated with the closed account, after the scrub has run. We retain them because the audit trail is the evidentiary record of who was granted administrative privilege on which machine, and a privilege-management product that silently discarded that history would be less trustworthy, not more.

Backups follow their own cycle: our database retains automated backups for 30 days, so a copy of the pre-scrub state exists within that window and ages out of it.

If you need the operational records erased as well, contact support@elevateiq.me and we will carry that out manually. If you are exercising a statutory erasure right, say so and we will treat it as such.

Security

Your Rights

Subject to applicable law, you may have the right to:

Because we process most personal data on behalf of our customer (your employer or IT provider), the most direct route is usually to make the request to them. You can also contact us at support@elevateiq.me and we will route the request appropriately.

Children

The Service is not directed to children under 16 and is intended for use in a workplace or managed-IT context. We do not knowingly collect personal data from children.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced in the Admin Console and via email to account owners. The "Last updated" date at the top of this page reflects the latest revision.

Contact

Tiny Electrons LLC
Support: support@elevateiq.me

Effective Date: 2026-09-14