In plain language. We collect the information you give us when you contact us, plus basic technical data needed to run this website. We use it to respond to you, secure the site and, where you agree, keep you informed. We do not sell personal information and we do not use it for cross-site advertising. If you use Elysium as a patient, guest, customer or other end user of one of our business customers, that customer decides how your data is used and we process it on their behalf. You can access, correct or delete your information by writing to privacy@elysiumecosystem.com.
1. Policy application
This Privacy Policy explains how Elysium Innovative Labs LLC, which operates under the name Elysium Ecosystem (“Elysium”, “we”, “us” or “our”), handles personal information. It applies when you:
- visit or interact with elysiumecosystem.com and its localized versions (the “Website”);
- submit an inquiry, request a demonstration or otherwise contact us by form, email, telephone, text message or video;
- receive marketing or service communications from us;
- attend our events or webinars, or apply for a position with us; or
- act on behalf of a business that is a prospect, customer, partner or vendor of Elysium.
When we are the controller and when we are a processor. For the information described above, Elysium decides why and how personal information is processed. Under laws such as the GDPR and UK GDPR we are the “controller”; under U.S. state privacy laws we are the “business”. Elysium also provides an enterprise platform (Elysium Core, MOTAI, OBI, ECOE, Elysium Meet, Nexus and the industry solutions built on them, together the “Services”) to organizations (our “Customers”). When a Customer uses the Services to process information about its own patients, clients, guests, employees or other individuals (“Customer Data”), the Customer decides why and how that information is used and Elysium acts as a “processor”, “service provider” or, for regulated health information, a “business associate”. In that case:
- this Privacy Policy does not govern the Customer Data, which is governed by the Customer’s own privacy notice and by our agreement with the Customer (including, where applicable, a data processing agreement and a HIPAA business associate agreement);
- if you are a patient, client or other end user of a Customer, please contact that Customer to exercise your privacy rights. If you contact us instead, we will forward your request to the Customer where we can identify it and will not respond to it ourselves except as the Customer instructs.
The contact details of a Customer’s own authorized users (for example, an account administrator) are processed by Elysium as controller for account administration, billing, support and security, and are covered by this Policy.
Related documents. This Policy works together with our Cookie Policy, Messaging Terms, Email Policy, Health Information Notice and Terms of Use.
Personal information means information that identifies, relates to, describes or could reasonably be linked with an identified or identifiable individual, and includes what U.S. laws call “personal information” and what European laws call “personal data”.
2. Information we collect
2.1 Information you provide to us
| Category | Examples | When we collect it |
|---|---|---|
| Contact and inquiry details | Name, work email address, telephone number (optional), company, industry, organization size, area of interest, and the content of your message | When you complete the contact form or otherwise write to us |
| Communications | Emails, text messages, chat messages, voicemail, call or meeting notes and, where we tell you and the law allows, recordings and transcripts | When you communicate with us |
| Marketing preferences and consent records | Subscription choices, opt-in and opt-out history, the wording you agreed to, and the date, time and technical source of the consent | When you subscribe, opt in or opt out |
| Events, demonstrations and support | Registration details, questions, feedback, survey responses | When you register for an event or ask for support |
| Recruiting | Résumé, work history, contact details and other information you choose to provide | When you apply for a position |
2.2 Information collected automatically
- Device and log data. IP address, browser type and version, operating system, device type, referring page, pages requested, date and time of each request, and language settings. Our hosting and network providers generate these logs to deliver the Website and protect it from abuse.
- Approximate location. Country or region inferred from your IP address. We do not collect precise geolocation through the Website.
- Preference data. If you choose a language, we store that choice in a first-party cookie and in your browser’s local storage so the Website can show the right language on your next visit. See the Cookie Policy.
- Security and anti-abuse signals. The contact form includes a hidden field that ordinary visitors never see; automated submissions that fill it in are discarded. We do not use browser fingerprinting.
- Fonts. The Website loads its typeface from Google Fonts. When your browser requests the font files, Google receives your IP address and standard request information under Google’s own privacy policy.
As of the effective date, the Website does not use advertising cookies, cross-site tracking technologies, session-replay tools or third-party analytics. If we add any of them, we will update this Policy and the Cookie Policy first and, where the law requires, ask for your consent before they run.
2.3 Information from other sources
- Publicly available business information (for example, professional profiles and company websites) and business contact information supplied by referral sources, event organizers, partners and lead-generation providers that are permitted to share it with us.
- Information a Customer provides about its own authorized users.
- Service providers that help us verify, enrich or protect our records.
2.4 Sensitive information and health information
We do not ask for, and you should not send us through the Website, sensitive personal information such as health or medical information, government identification numbers, financial account or payment card numbers, biometric data, precise geolocation, or information about a person’s race, religion, sexual orientation, immigration status or criminal history. Please do not put patient information in the contact form or in emails to our general mailboxes. Organizations that need to exchange protected health information with us do so under a written agreement and through the channels we designate; see the Health Information Notice.
If you send us sensitive information anyway, we will use it only to the extent needed to respond and will delete it when we are able.
3. How we use information
We use personal information only for the purposes below, and, where the GDPR or UK GDPR applies, only when we have a valid legal basis.
| Purpose | Examples | Legal basis (EEA, UK, Switzerland) |
|---|---|---|
| Respond to you and evaluate a business relationship | Answering inquiries, scheduling demonstrations, preparing proposals | Steps taken at your request before entering a contract; our legitimate interest in conducting business |
| Provide, administer and support the Services | Account set-up, onboarding, billing, support, notices about the Services | Performance of a contract; legal obligation |
| Operate, secure and maintain the Website | Delivering pages, diagnosing errors, detecting abuse and attacks | Legitimate interests in a secure, functioning Website |
| Marketing and relationship communications | Product news, event invitations, insights, by email, telephone or text message | Consent where required by law (always for text messages and for email to individuals in the EEA, UK and other opt-in jurisdictions); otherwise our legitimate interest in promoting our business, always with an easy way to opt out |
| Understand and improve the Website and our content | Aggregate usage statistics, if and when enabled | Consent where required for non-essential cookies; otherwise legitimate interests |
| Comply with law and protect rights | Responding to lawful requests, keeping records, preventing fraud, enforcing our terms, defending claims | Legal obligation; legitimate interests |
| Recruiting | Evaluating and communicating with applicants | Steps taken at your request; legitimate interests; legal obligation |
| Create de-identified or aggregated information | Statistical reporting | Legitimate interests |
We do not use the content of inquiries submitted through the Website to train artificial-intelligence models. We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing.
4. Data aggregation and de-identification
We may create aggregated or de-identified information that cannot reasonably be used to identify you, and we may use and disclose it for lawful business purposes such as analytics and reporting. We keep de-identified information in de-identified form, we do not attempt to re-identify it, and we require any recipient to make the same commitment.
5. How we share information
We do not sell personal information. We do not “share” personal information for cross-context behavioral advertising, and we have not done either in the preceding twelve months. We disclose personal information only as follows:
| Recipient | Why | Examples of information |
|---|---|---|
| Service providers and processors | They process information on our instructions to host the Website, deliver content, manage inquiries and customer relationships, send email, deliver text messages and calls, schedule meetings, provide security, analytics (if enabled) and professional services. They are bound by written agreements that restrict their use of the information. | Identifiers, contact details, inquiry content, technical data |
| Affiliates | Companies under common ownership or control that help us run our business, subject to this Policy | Contact details, inquiry content |
| Professional advisers, auditors and insurers | Legal, accounting, security and risk services | As needed for the engagement |
| Customers and partners | If you contact us in connection with a Customer or partner engagement, we may share the relevant details with them | Contact details, inquiry content |
| Authorities and other parties where required | To comply with law, legal process or lawful government requests; to protect the rights, property, safety and security of Elysium, our Customers or others; to detect and prevent fraud and abuse | As legally required |
| Successors | In connection with a merger, acquisition, financing, reorganization, bankruptcy or sale of assets, the information may transfer to the successor, which must honor this Policy or give you notice and a choice | Information relevant to the transaction |
| Any person, with your direction or consent | For example, when you ask us to share information with a colleague or partner | As you direct |
Mobile information. We do not share mobile phone numbers, text-message opt-in data or consent records with third parties or affiliates for their marketing or promotional purposes. Service providers that deliver our messages may access this information only to provide the service to us. See the Messaging Terms.
A current list of the sub-processors we use for the Services is available to Customers on request.
6. Cookies and similar technologies
The Website currently sets a single first-party functional cookie to remember your language choice, plus a matching entry in local storage. It does not set advertising or cross-site tracking cookies. The Cookie Policy lists every cookie and similar technology we use, explains your choices and describes how we respond to browser signals.
Global Privacy Control and Do Not Track. We treat a valid Global Privacy Control (GPC) signal as a request to opt out of the sale or sharing of personal information and of targeted advertising, as the laws of California and other states require. Because we do not sell or share personal information or track you across websites, receiving a GPC signal does not change what the Website does. The Website does not otherwise alter its behavior in response to “Do Not Track” browser settings, because there is no tracking to switch off.
7. Marketing communications and your preferences
We send marketing and relationship messages only in accordance with applicable law and your preferences:
- Email. Every marketing email contains an unsubscribe link, and we process opt-outs promptly and no later than ten business days. See the Email Policy.
- Text messages. We send marketing text messages only with your prior express consent. Reply STOP to any message to opt out. See the Messaging Terms.
- Telephone. We honor internal and national do-not-call requests. Ask us to add your number to our internal do-not-call list at any time.
- Service and legal notices. You cannot opt out of messages that are necessary to administer an existing relationship, such as security alerts, contract notices or replies to your own requests, but you can tell us which channel you prefer.
8. Artificial intelligence, automated processing and recorded communications
Elysium builds artificial-intelligence and communications technology, so we are open about how it may touch your information:
- Disclosure. If you interact with an automated assistant, chatbot or AI-generated voice operated by Elysium, we will tell you at the start of the interaction that it is not a human, consistent with laws such as the EU AI Act, California’s chatbot disclosure law and similar state laws.
- Recording and transcription. If we record or transcribe a call or meeting, we will tell you before it begins and give you the chance to object or leave. We apply the strictest consent standard of the participants’ locations, because a number of jurisdictions, including California, Florida, Illinois, Pennsylvania and Washington in the United States, require every party’s consent.
- No significant automated decisions. We do not use automated decision-making technology on the Website to make decisions that produce legal or similarly significant effects on individuals (for example, decisions about employment, credit, housing, insurance, education or access to health care). If that changes, we will update this Policy, give you the required notice and offer the access, objection and human-review rights that apply.
- Customer Data. How AI features process Customer Data is determined by the Customer’s configuration and our agreement with the Customer.
9. International data transfers
Elysium and its service providers operate in several countries. Your information may be processed in the United States and in other countries whose data-protection laws may differ from those of your country of residence.
When we transfer personal information out of the EEA, the UK or Switzerland, we rely on a lawful transfer mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum or Agreement and the Swiss addendum, and supplementary measures where necessary. Where a recipient is certified under the EU-U.S. Data Privacy Framework, the UK Extension and the Swiss-U.S. Data Privacy Framework, we may rely on that certification. Where the laws of Brazil, Mexico, Canada, Colombia or other countries require a specific mechanism or your consent for cross-border transfers, we apply it. You can request a copy of the safeguards we use by contacting us.
10. Data retention
We keep personal information only for as long as we need it for the purposes described in this Policy, and then delete it or de-identify it. Unless a longer period is required or permitted by law, or needed to establish, exercise or defend legal claims, we apply these standard periods:
| Category | Typical retention |
|---|---|
| Website inquiries and business contact records | Up to 24 months after our last interaction with you, or for the duration of any resulting business relationship plus the period described below for contract records |
| Website server and security logs | Up to 12 months |
| Marketing subscriptions | Until you unsubscribe, after which we keep a minimal suppression record indefinitely so that we do not contact you again |
| Consent and opt-out records | Five years after the last message or the end of the relationship, to demonstrate compliance |
| Call, meeting and voicemail recordings and transcripts | Up to 12 months, unless needed for a legal claim, a complaint or a security investigation |
| Recruiting records | Up to 12 months after the position is filled, or longer with your consent |
| Contracts, invoices and tax records | As required by tax and commercial law, generally up to seven years |
11. Data security, integrity and access
We use administrative, technical and physical safeguards designed to protect personal information against loss, misuse, unauthorized access, disclosure, alteration and destruction. They include encryption of data in transit, role-based access limited to personnel who need it, logging and monitoring, confidentiality obligations for personnel, security review of service providers and an incident-response process. Our approach to security is described on our Security page.
No system is perfectly secure, and we cannot guarantee that information will never be compromised. If a breach affects your personal information, we will notify you and the relevant authorities as the law requires, including within 72 hours to supervisory authorities where the GDPR or UK GDPR applies. To report a suspected vulnerability, write to security@elysiumecosystem.com.
12. Your rights and choices
Depending on where you live, you may have some or all of the following rights. We offer them to everyone we can verify, regardless of whether the law of your location requires it.
- Access the personal information we hold about you and receive a copy, including in a portable format.
- Correct inaccurate or incomplete information.
- Delete your information, subject to legal exceptions.
- Object to or restrict certain processing, including processing based on legitimate interests and all direct marketing.
- Withdraw consent at any time, without affecting processing before withdrawal.
- Opt out of sale, sharing, targeted advertising and profiling in furtherance of significant decisions (we do none of these).
- Know the categories of sources and recipients of your information, and the specific third parties to which it has been disclosed where the law provides for that.
- Not be discriminated against for exercising your rights.
- Appeal our decision, and complain to a regulator.
How to make a request. Email privacy@elysiumecosystem.com or use the contact page and choose “privacy request”. Tell us who you are, which right you wish to exercise and the email address or phone number we hold for you. Requests are free of charge; if a request is manifestly unfounded, excessive or repetitive, we may charge a reasonable fee or decline it as the law permits, and we will tell you why.
Verification. To protect you, we must be reasonably sure you are the person the request concerns. We will ask you to confirm details we already hold, and for sensitive requests we may ask for additional information. We do not require you to create an account.
Authorized agents. You may use an authorized agent. We will ask for your written permission for the agent, or a power of attorney, and may ask you to verify your identity directly.
Timing. We respond within 30 days under the GDPR and UK GDPR (extendable by up to two further months for complex requests) and within 45 days under U.S. state laws (extendable once by a further 45 days where the law permits). Where local law sets a different deadline, such as 15 days in Brazil or 20 business days for Mexican ARCO requests, we follow it. We will tell you if we need more time.
Appeals. If we decline your request, you may appeal by replying to our decision with the word “Appeal” or by writing to privacy@elysiumecosystem.com. We will answer in writing within the period required by your state’s law (generally 45 to 60 days) and explain the outcome. If you are not satisfied, you may contact your state attorney general or other regulator.
13. Notice to residents of the EEA, the United Kingdom and Switzerland
Controller. Elysium Innovative Labs LLC, 7901 4th St N, St Petersburg, FL 33702, is the controller of the personal information described in this Policy. Data-protection contact: privacy@elysiumecosystem.com. Data Protection Officer: Not appointed. EU representative: Not applicable — the Website does not target or monitor individuals in the EU. UK representative: Not applicable — the Website does not target or monitor individuals in the UK.
Legal bases. The legal bases for each purpose are set out in the table in Section 3. Where we rely on legitimate interests, we have weighed them against your rights and interests, and you may ask for details of that assessment. Where we rely on consent, you may withdraw it at any time.
Your rights. In addition to the rights in Section 12, you have the right to object at any time, and free of charge, to processing for direct marketing; the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects; and the right to lodge a complaint with a supervisory authority, in particular in the country where you live, work or believe an infringement occurred. In the UK this is the Information Commissioner’s Office (ico.org.uk); in Switzerland, the Federal Data Protection and Information Commissioner; in the EEA, the authority listed by the European Data Protection Board at edpb.europa.eu.
Provision of information. Giving us your information is voluntary. If you do not provide the fields marked as required in the contact form, we will not be able to respond to your inquiry.
Cookies and electronic communications. We apply the consent rules of the ePrivacy Directive and the UK Privacy and Electronic Communications Regulations, as amended by the Data (Use and Access) Act 2025, to cookies and to electronic marketing. See the Cookie Policy and the Email Policy.
Transfers. See Section 9.
14. Notice to residents of the United States
14.1 California (CCPA/CPRA): notice at collection
This section supplements the rest of this Policy for California residents, including business contacts, whose information the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”), protects.
Categories of personal information collected in the preceding twelve months, sources and recipients
| CCPA category | Examples | Sources | Disclosed for a business purpose to | Sold or shared |
|---|---|---|---|---|
| Identifiers | Name, email address, telephone number, IP address | You; your device; referral sources | Service providers; affiliates; advisers | No |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name, company address, telephone number | You | Service providers; affiliates | No |
| Commercial information | Inquiry content, services of interest | You | Service providers; affiliates | No |
| Internet or network activity | Pages requested, browser type, referring page (server logs) | Your device | Service providers (hosting, security) | No |
| Geolocation data (approximate) | Country or region derived from IP address | Your device | Service providers (hosting, security) | No |
| Audio or electronic information | Voicemail and, with notice, call or meeting recordings | You | Service providers | No |
| Professional or employment-related information | Job title, employer, industry; application materials | You; professional sources | Service providers; recruiters | No |
| Inferences | Lead qualification and interest categories | Derived by us | Service providers | No |
| Sensitive personal information | None intentionally collected | Not applicable | Not applicable | Not applicable |
Purposes are those listed in Section 3 and retention periods are those in Section 10. We do not use or disclose sensitive personal information for purposes other than those the CCPA permits, so there is no right to limit its use.
Your CCPA rights are to know, access, correct and delete personal information, to opt out of sale and sharing, to limit the use of sensitive personal information, and to be free from retaliation. We do not sell or share personal information, including that of consumers under 16, and we do not offer financial incentives for personal information. You may submit a request by email or through the contact page as described in Section 12. We accept opt-out preference signals such as GPC.
Automated decision-making technology. We do not use automated decision-making technology to make significant decisions about consumers, so the CCPA’s ADMT rights do not currently apply to our practices.
“Shine the Light.” We do not disclose personal information to third parties for their own direct-marketing purposes (Cal. Civ. Code § 1798.83).
14.2 Other U.S. state privacy laws
Comprehensive privacy laws now apply in a large and growing number of U.S. states, including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia, with further laws being enacted and taking effect. Residents of these states may have the right to confirm whether we process their personal data and to access, correct, delete and obtain a portable copy of it; to opt out of targeted advertising, sale and profiling in furtherance of significant decisions; and to appeal a refusal. Some states add rights such as receiving a list of the specific third parties to which we have disclosed personal data (for example, Oregon), or questioning the result of profiling (for example, Minnesota). We process sensitive data only with consent where those laws require it, we honor universal opt-out signals where required, and we apply data-minimization standards. Section 12 explains how to exercise your rights and appeal.
14.3 Nevada
Nevada residents may submit a request to opt out of the sale of covered information. We do not sell covered information. You can still contact us at privacy@elysiumecosystem.com.
14.4 Health information
Federal and state laws, including HIPAA, Washington’s My Health My Data Act, Nevada’s consumer health data law and Connecticut’s consumer health data provisions, apply to health information in different ways. The Website is not intended to receive health information. See the Health Information Notice.
15. Notice to residents of other countries
- Canada. We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act and, for Québec residents, Law 25. You may request access to and correction of your information, withdraw consent, and, in Québec, request portability and information about any automated processing and about transfers outside Québec. You may complain to the Office of the Privacy Commissioner of Canada or the Commission d’accès à l’information du Québec. We send commercial electronic messages to Canadians only in accordance with Canada’s Anti-Spam Legislation (CASL).
- Brazil (LGPD). You have the rights listed in Article 18 of the LGPD, including confirmation of processing, access, correction, anonymization, blocking or deletion, portability, information about sharing and the right to revoke consent. You may contact us at privacy@elysiumecosystem.com and lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).
- Mexico. Under the Federal Law on the Protection of Personal Data Held by Private Parties, you may exercise your rights of access, rectification, cancellation and opposition (ARCO) and revoke consent by writing to privacy@elysiumecosystem.com. This Policy serves as our privacy notice; a short-form notice is available on request.
- Colombia and other Latin American countries. We respect the rights of access, update, rectification, deletion and revocation under Colombia’s Law 1581 of 2012, and the comparable rights under the laws of Argentina, Chile, Peru, the Dominican Republic (Law 172-13), Panama, Uruguay and other countries. You may write to us to exercise them and may complain to your national authority, such as the Superintendencia de Industria y Comercio in Colombia.
- Australia. We handle personal information in line with the Australian Privacy Principles. You may request access to or correction of your information and, if we cannot resolve a complaint, complain to the Office of the Australian Information Commissioner. From 10 December 2026 Australian law requires privacy policies to describe automated decisions that could significantly affect individuals’ rights; as stated in Section 8, we make none on the Website.
- India. To the extent India’s Digital Personal Data Protection Act, 2023 and Rules, 2025 apply, you may withdraw consent, request access, correction and erasure, nominate another person to exercise your rights, and use our grievance contact at privacy@elysiumecosystem.com.
- Elsewhere. We handle personal information in accordance with the data-protection laws that apply where you live. If your local law gives you rights not described here, contact us and we will honor them.
16. Children’s privacy
The Website and the Services are directed to businesses and are not intended for children. We do not knowingly collect personal information from anyone under 16, or under the higher age of digital consent where local law sets one, and we do not knowingly collect personal information from children under 13 in the sense of the U.S. Children’s Online Privacy Protection Act. If you believe a child has given us personal information, write to privacy@elysiumecosystem.com and we will delete it.
17. Third-party websites and services
The Website may link to websites, services and social networks that we do not operate. This Policy does not apply to them, and we are not responsible for their content or practices. Please read their privacy notices before providing information.
18. Notification of changes
We may update this Policy to reflect changes in our practices, technology, or legal requirements. We will post the revised Policy with a new “last updated” date. If a change is material, we will give you a more prominent notice, such as a banner on the Website or an email to subscribers, and where the law requires, we will obtain your consent again. Prior versions are available on request.
19. English language controls
We write this Policy in English and provide courtesy translations in the other languages of the Website. If a translation conflicts with the English version of this Policy, the English version controls, except where the law of your country requires otherwise.
20. Complaints and dispute resolution
If you have a concern, please contact us first at privacy@elysiumecosystem.com; we will try to resolve it promptly. Nothing in this Policy or in our Terms of Use limits your right to lodge a complaint with a supervisory authority or to bring a claim in the courts of your place of residence where the law grants that right and does not permit it to be waived.
21. Contact information
Elysium Innovative Labs LLC, operating as Elysium Ecosystem 7901 4th St N, St Petersburg, FL 33702
- Privacy requests and questions: privacy@elysiumecosystem.com
- Legal notices: legal@elysiumecosystem.com
- Security reports: security@elysiumecosystem.com
- Website: https://elysiumecosystem.com, or the contact page