GREHUS SAS BIC · Elia
Privacy Policy
Last updated: 19 August 2026
GREHUS SAS BIC (“GREHUS”, “we”) operates Elia. We are a Simplified Stock Company of Benefit and Collective Interest (SAS BIC) constituted in the Republic of Ecuador and legally operating under the control of the Superintendencia de Compañías, Valores y Seguros del Ecuador. This policy explains how we handle personal data of the user company (the “Customer”) and of that company’s visitors or end customers who scan a QR, answer a survey, or start a conversation. Elia is built for in-person, multi-location businesses — including restaurants, hotels, clinics, retail, salons, and similar. It is offered worldwide. The policy is based on Ecuador’s Ley Orgánica de Protección de Datos Personales and equivalent data-protection / habeas-data rules that may apply where the Customer or a visitor is located.
1. Who we are
Controller of Customer-account data: GREHUS SAS BIC, Republic of Ecuador. Contact: info@grehus.com.
Registered corporate details are those filed with the Superintendencia de Compañías, Valores y Seguros del Ecuador. GREHUS’s BIC status describes our corporate form in Ecuador. It does not create extra product warranties beyond these documents.
2. Two roles (this protects both of us)
Customer (the user company): controller of data about its visitors and end customers. This includes in-person, multi-location businesses — including restaurants, hotels, clinics, retail, salons, and similar. You decide where to place a QR or survey, what offers you show, whether a manager may contact a visitor, and how long you keep tickets.
GREHUS SAS BIC: processor of that visitor data on your instructions. We provide Elia. We are controller only of data about your organization and users (accounts, billing, support, waitlist).
Visitors should send access or deletion requests to the Customer first. We will help the Customer fulfill them when the request is valid. This split of roles protects both the user company and GREHUS.
3. Data we process
Customer users: name, email, password (hashed), organization, role, language, plan, optional WhatsApp connection, support messages.
Visitors: fork or survey choice, chat or survey answers, ticket summary, optional gift/claim code, and—only if the visitor consents on the callback form—name, email, phone, and consent time. We do not send email or text to visitors from the recovery flow.
Technical: IP, device/browser, session and security cookies, approximate time, touchpoint/QR or survey link used.
We do not ask visitors for payment cards. We do not sell personal data.
4. Why we process it
Contract: to provide Elia to the Customer (accounts, QR, chat, tickets, claims, surveys the Customer enables).
Consent: visitor callback contact; waitlist or marketing where we ask; non-essential cookies if we ever add them.
Legitimate interest / equivalent bases: security, fraud prevention, improving the product in aggregated form.
Legal obligation: tax, corporate, and authority requests that are valid in Ecuador or in the country of the request.
5. Visitor callback and chats
If a visitor asks to be contacted, Elia may show a form. Phone, email, and name are stored on the ticket and shown to the Customer’s owner/admin and that location’s director—not to assigned floor employees.
Improve chats may be summarized by automated systems (AI) to create a ticket. The Customer remains responsible for what its staff do next. Elia does not replace the Customer’s duty of care in its industry (safety, discrimination, injury, or other applicable duties).
When a visitor is sent to Google Reviews, Google’s terms and privacy policy apply to that step. We do not post a review on the visitor’s behalf.
6. Who we share data with
The Customer that owns the QR or survey and its authorized users.
Infrastructure providers acting as processors for GREHUS (hosting, email delivery, AI processing, payments such as PayPal if you subscribe, WhatsApp if the Customer connects it). We require them to use data only to provide their service.
Authorities when the law requires it.
We do not share visitor contact details with other companies or advertisers.
7. International transfers
Elia is delivered from infrastructure that may be outside the visitor’s country (including outside Ecuador) and is offered worldwide. By using Elia, the Customer instructs us to transfer visitor data as needed to operate the service, with reasonable security measures.
8. Retention
Account data: while the organization is active and for a reasonable period after (up to the time needed for billing, disputes, and legal duties).
Tickets, chats, surveys, and claims: as configured by the Customer or until the Customer asks us to delete them, unless we must keep a limited record for security or law.
Callback contact: until the Customer closes the follow-up or requests deletion, or the visitor’s valid deletion request is processed.
9. Your rights
Depending on your country, you may request access, correction, update, deletion, opposition, limitation, portability, and withdrawal of consent. You may complain to the competent data-protection or habeas-data authority in your country and, where applicable, in Ecuador.
Customer users: email info@grehus.com. Visitors: contact the user company and copy info@grehus.com if you need GREHUS to assist. We may ask for reasonable proof of identity and will not delete data we must keep by law.
10. Security and children
We use access controls, encrypted transport, and role limits (assigned employees do not see visitor phone/email). No method is perfectly secure.
Elia is not directed at children. The Customer must not use Elia to collect contact data from minors.
11. Changes
We may update this policy. The date above will change. Continued use of Elia after an update means the new policy applies to later processing. Material changes will be notified to Customer admins when practical.
These texts are GREHUS SAS BIC’s standard conditions. The user company’s local counsel should still review consumer, health, and safety duties of its industry in each country.