ELKConnect

Privacy Policy

Last updated: 2026-08-18

1. Who is responsible for your data

ELK Consulting LTD (Mauritius) is the controller of your personal data for the whole ELK Connect platform. ITCWEB SARL (Cameroon) acts as the local representative for the CEMAC region.

For any question or request about your data, the dedicated address is at the bottom of this page and on the Legal notice page. We answer every request, including to say that we cannot grant it and why.

2. What we collect, and why

We collect only what the service needs in order to work, to be billed and to stay secure. Category by category, this is what that covers:

  • Account data — first and last name, email address, phone number, country, language, currency. Needed to open the account, identify you and write to you.
  • Password — kept as an irreversible cryptographic hash. We do not know your password and cannot remind you of it; we can only let you choose a new one.
  • Service data — the numbers you hold, calls made and received (number, date, duration, cost), SMS sent and received (sender, recipient, date, content), eSIM plans bought and their usage as the provider reports it.
  • Financial data — your top-ups, purchases, balance and every associated accounting entry. We store no card numbers: payments are collected by our providers, where that data stays.
  • Regulatory address — only where a regulator requires one to allocate a number. It is asked for only for those numbers, and passed only to the carrier concerned.
  • Technical data — IP address, device and browser type, connection and error logs. Needed for security, fraud detection and fault diagnosis.
  • Support exchanges — your messages, including those sent to the assistant, and our reply.

3. On what basis we do it

Each processing operation rests on a specific basis, not on a blanket consent given once and for all:

  • Performance of the contract — providing the service you asked for, billing you, delivering a number or an eSIM profile.
  • Our legal obligations — accounting, tax, retention of certain communications data, anti-money-laundering and counter-terrorist-financing rules.
  • Our legitimate interest — securing accounts, preventing fraud and abuse, improving the service. That interest is balanced against your rights, and it never overrides the confidentiality of your communications.
  • Your consent — only where it is genuinely required, for example for marketing communications, which you can refuse at any time without affecting the service.

4. The content of your communications

The content of your SMS passes through our systems because there is no other way to deliver it to you. We keep it in order to show it to you in your account, and we use it for nothing else.

We do not read your messages, we do not analyse them for advertising, we do not sell them and we pass them to no data broker. Human access to the content of a message happens in three cases only: you ask us to in order to resolve a problem, a competent authority orders it through due process, or a security investigation into serious abuse requires it.

We do not record the audio of your calls. Only a call's billing data — number, date, duration, cost — is kept.

5. Who else sees your data

Our technical providers, strictly in order to run the service, and with no other right of use:

  • Telecom carriers (Twilio, Telnyx) — routing calls and SMS, allocating numbers. They see the metadata needed for routing and, for SMS, the content.
  • eSIM providers — allocating profiles and reporting usage. They see neither your messages nor your calls.
  • Payment providers (Fapshi for Mobile Money, NOWPayments for cryptocurrency, and the institution chosen for cards) — collecting top-ups. They handle your payment data under their own responsibility.
  • Transactional email provider (Resend) — sending confirmations, receipts and verification links.
  • Hosting provider (Railway) — running the application and the database.
  • Artificial-intelligence provider (Anthropic) — for the assistant only, and only on the text you write to it. Your SMS, your calls and your financial data are not sent to it.

6. Transfers outside your country

Our providers are established in several countries, in particular the United States and the European Union. Your data may therefore be processed outside your country of residence.

We use only providers offering contractual confidentiality and security guarantees, and we frame those transfers with the appropriate clauses. The list of providers above is kept up to date; if we add one that processes personal data, this page is amended.

7. How long we keep it

  • Account data — for as long as the account exists, then deleted or anonymised within three months of its closure.
  • Messages attached to a number — deleted with the number when it is released, subject to legal retention obligations.
  • Billing data and accounting entries — ten years, as accounting and tax obligations require. They cannot be deleted on request.
  • Technical and security logs — twelve months.
  • Identity evidence collected under anti-money-laundering rules — five years after the end of the relationship, as the regulations require.

8. Your rights, and how to exercise them

At any time you may:

  • access your data and request a readable copy;
  • correct what is inaccurate — most fields can be edited directly from “My account”;
  • request deletion of your account and of the data not subject to a legal retention obligation;
  • object to processing based on our legitimate interest, or request its restriction;
  • withdraw a consent you have given, without calling into question what was done before;
  • lodge a complaint with the data-protection authority of your country of residence.

9. How we protect your data

Passwords are hashed and never stored in clear. Traffic between your device and our servers is encrypted. Our providers' API keys are encrypted in the database and are never written into our code.

Back-office access is restricted by role, every sensitive action is written to an auditable log, and sign-in attempts are rate-limited to counter brute-force attacks.

No measure is absolute. In the event of a data breach likely to harm you, we inform the competent authorities and the people concerned within the time limits set by the applicable regulations.

10. Cookies and analytics

Our site uses the cookies strictly necessary for it to work: keeping your session, remembering your language and your theme. They are not used to track you elsewhere on the web.

Any analytics or advertising cookie is set only after your agreement, given through the choice banner, and that choice can be changed at any time from the footer.

11. Minors

The service is not intended for people below the age of majority in their country of residence. We do not knowingly collect their data; if we find that an account was opened by a minor, it is closed and the associated data deleted.

12. Changes to this policy

This policy may change, in particular when a new service or a new provider is introduced. The date of the last update is shown at the top of the page, and a material change is announced to you by email or in your account.