Elyra procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ Controller (when we decide purposes/means): We act as data controller for our own operations (e.g., your Elyra account, billing, platform security, product analytics, and our marketing). Processor (on behalf of restaurants): When a restaurant uses Elyra to manage bookings, we typically act as data processor and the restaurant is the data controller for diner data collected via our dashboard, AI phone/email agents, widget, and integrations—unless we say otherwise in a data processing agreement (DPA). Contact: info@elyrasystems.com (Subject: “Privacy”) | Postal: Elyra, Inc., 1111B S Governors Ave # 53156, Dover, DE 19904, United States.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We maintain certain data transmitted through the Services for performance, analytics, compliance, and backup. You are responsible for data you upload or actions you take. We are not liable for loss or corruption of such data, and you waive claims arising from loss or corruption. You should maintain your own backups of business-critical information (e.g., seating plans, bookings, and reports).” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We keep personal data only as long as necessary for the purposes described here: Account/contract data: for the term of your account/contract and a reasonable period thereafter for record-keeping, dispute resolution, and legal compliance. Bookings and communications: for operational needs and audit/security, then archived or anonymized where feasible. Payment records: as required by tax and financial laws. When retention ends, we delete or anonymize data. Aggregated data that no longer identifies you may be retained for analytics.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ The Services may link to or integrate third-party sites, content, telecom carriers, payment processors, reservations partners, or delivery/logistics tools (“Third-Party Services”). We do not control or endorse Third-Party Services and are not responsible for their content, accuracy, practices, or policies. Your use of Third-Party Services is at your risk and subject to their terms and privacy policies. Transactions with third parties are solely between you and those parties.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ We share data only as needed and subject to appropriate safeguards: Restaurants (controllers): Diner booking details and related communications are shared with the restaurant you are booking with, so they can seat and serve you and enforce their policies. Service providers (processors): cloud hosting, telecom/SMS, email delivery, call handling/transcription, analytics, error monitoring, customer support, and payment processing (e.g., Stripe). Providers may process data only under our instructions and must protect it appropriately. Integrations/partners (separate controllers or processors): POS, CRM, or channel partners you or the restaurant choose to connect. Their use of data follows their own privacy terms. Corporate transactions: if we undergo a merger, acquisition, or asset sale, data may transfer as part of the transaction. Legal and safety: to comply with law, respond to lawful requests, protect rights, safety, and security, and prevent fraud or abuse. We do not sell your personal data.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Our Services are hosted in the United States. If we transfer data outside the country of collection (e.g., to service providers in other regions), we use lawful transfer mechanisms such as Standard Contractual Clauses and apply additional safeguards as appropriate.” | Captured 2026-09-25Open source →Finding permalink → |
| Tier differences | All applicable tiers | unknown | “ Availability of features, plans, and add-ons (including AI agents, messaging, analytics, and integrations) may change without notice. We may discontinue or limit features at any time. Prices are subject to change.” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.