Elo Privacy Policy

Last Updated: 28 July 2025

Defined terms

Agreement: Privacy Policy and Terms of Service together

Customer: An individual requesting services via the Platform Data

Controller: Elo Applications Limited, Flat 3, 38 Manchester Street, Marylebone, London, UK

Elo, we, us, our: Elo Applications Limited

Elo Helper: An individual offering services via the Platform

Personal Information: Any information that identifies you directly or indirectly, as defined by UK GDPR

Platform: Elo's website, booking forms and mobile application (collectively)

You: Users of the Platform, including Elo Helpers and Customers

AES-256: Advanced Encryption Standard with 256-bit key encryption

Face ID: Biometric data (optional identity verification method)

Legitimate Interests Assessment: Internal assessment document (referenced but not published)

TLS: Transport Layer Security for data in transit

UK GDPR: UK General Data Protection Regulation

1. Introduction

This Privacy Policy explains how Elo Applications Limited ("Elo", "we", "us", "our") collects, uses, stores, shares, and deletes your Personal Information when you use our website, booking forms and mobile application (collectively, the "Platform"). We collect only the Personal Information necessary for the purposes outlined in this Policy, ensuring compliance with UK GDPR. It also outlines your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By using the Platform, you confirm that you have read and understood this Privacy Policy and our Terms of Service, which together form the Agreement. If you do not agree with these terms, please refrain from using the Platform. Elo Applications Limited, located at Flat 3, 38 Manchester Street, Marylebone, London, UK, acts as the Data Controller for your Personal Information.

Data Controller: Elo Applications Limited, Flat 3, 38 Manchester Street, Marylebone, London, UK.

1.1 Summary of Key Points

This section provides a brief overview of our privacy practices for clarity. We collect contact details, such as your name and email, account information, including your username, billing data, and usage data, such as device type or location, with your consent. We collect this information to operate the Platform, connect Elo Helpers with Customers, process payments, ensure safety, and improve our services. You have the right to access, correct, delete, or transfer your data, object to certain processing, or withdraw consent at any time. We protect your data using encryption, access controls, and regular security checks. We share your data only as necessary, such as with other users for task coordination, payment processors like Stripe, or for legal compliance. For any questions or to exercise your rights, you can contact us at hello@elotheapp.com. Please read the sections below for full details.

2. Definitions

For clarity, "Elo," "we," "our," or "us" refers to Elo Applications Limited. "You" refers to users of the Platform, including Elo Helpers, who offer services, and Service Requesters, who request services. The "Platform" encompasses Elo’s website and mobile application. "Personal Information" means any information that identifies you directly or indirectly, as defined by UK GDPR. A "Elo Helper" is an individual offering services via the Platform, and a "Customer" is an individual requesting services via the Platform.

3. Personal Information We Collect

We collect Personal Information to operate the Platform, facilitate services, and ensure safety. Below are the types of information we collect:

3.1 Information You Provide

When you use the Platform, you provide certain information. This includes your contact information, such as your name, email address, phone number, and physical address. You also provide account information, including your username, password, and profile photo. For billing purposes, you provide payment card details, billing address, and transaction history. For identity verification, you may provide government-issued ID, date of birth, and, with explicit consent, optional Face ID biometric data. Additionally, you provide profile information, such as skills, work history, availability, service descriptions, reviews, and ratings. When communicating through the Platform, you provide messages sent via the Platform and interactions with customer support. For services, you provide details of services requested or provided, including time, date, location, and specific requirements.

3.2 Information Collected Automatically

We automatically collect certain information when you use the Platform. This includes device information, such as your device type, operating system, browser, IP address, and unique device identifiers. We also collect usage information, including

pages visited, features used, time spent, click patterns, and search queries. If you consent, we collect precise location data, or we may derive city or postcode-level data from your IP address. Additionally, we collect technical information, such as log files, cookies, and similar technologies, as detailed in our Cookie Policy in Section 11.

3.3 Information from Third Parties

We may collect information from third parties. If you register via Google or Facebook, we collect basic profile data from these social media platforms. For background checks, we collect results from third-party providers with your consent. We also receive transaction details from payment processors and other relevant data from Elo Helpers, as outlined in Section 6.

4. Legal Bases for Processing

We process your Personal Information under specific legal bases as defined by UK GDPR, as described below.

4.1 Performance of a Contract

We process certain data to perform our contract with you. This includes contact information, billing information, service information, communication information, and profile information. We use this data to operate the Platform, connect Elo Helpers with Customers, process payments, provide support, and enforce our Terms of Service.

4.2 Consent

We process certain data based on your explicit consent. This includes identity verification data, such as Face ID, precise location data, marketing preferences, and cookies. We use this data to verify your identity, provide location-based services, send promotional materials, and personalise your experience. You may withdraw consent at any time via the “Privacy Settings” menu in your account or by emailing

hello@elotheapp.com. For biometric data, such as Face ID, withdrawal of consent triggers immediate deletion of the data.

4.3 Legitimate Interests

We process certain data based on our legitimate interests. This includes contact information, device information, usage information, communication information, and profile information. We use this data to improve Platform functionality, prevent fraud, ensure safety, analyse usage, and resolve disputes. Our interests, such as fraud prevention and platform integrity, are balanced against your rights to justify data processing. Details of our legitimate interests processing are available in our Legitimate Interests Assessment at elotheapp.com/privacy/lia. You may object to this processing by emailing hello@elotheapp.com, and we will review your request within 30 days, stopping processing if your rights outweigh our interests, unless required by law.

4.4 Legal Obligation

We process data to comply with legal obligations, such as tax requirements, fraud prevention, and cooperation with law enforcement.

5. How We Use Your Personal Information

We use your Personal Information for specific purposes, being to (i) operate the Platform by enabling account creation, service matching, and functionality; (ii) facilitate services by connecting Elo Helpers with Customers and coordinating tasks; (iii) verify identities using ID and biometric checks with your consent to enhance security; (iv) process payments to handle transactions and billing (v) communicate with you by sending service updates, notifications, and promotional materials with your consent; (vi) provide support to resolve issues and disputes; (vii) ensure safety by preventing fraud, investigating suspicious activity, and maintaining trust; (viii) improve services by analysing usage, conducting research, and enhancing user

experience. We also process your Personal Information in order to comply with legal and regulatory requirements.

6. Sharing Your Personal Information

We share your Personal Information as necessary, as outlined below.

6.1 With Other Users

Elo Helpers and Customers can view relevant profile details, such as name, photo, and ratings, to coordinate tasks. Reviews and ratings you provide may be publicly visible on the Platform.

6.2 With Service Providers

We share data with third-party service providers to support Platform operations. Payment processors, such as Stripe, process transactions. Identity verification providers may conduct background checks with your consent. Cloud providers, such as Amazon Web Services, store data securely with encryption. Analytics providers, such as Google Analytics, help improve Platform performance. Marketing platforms, such as Mailchimp, may send promotional materials with your consent. A full list of third-party providers is available at elotheapp.com/privacy/partners.

6.3 For Legal Reasons

We share data to comply with laws, court orders, or regulatory requests. We may also share data to protect our rights, property, or safety, or that of our users, and to investigate fraud or violations of our Terms of Service.

6.4 Business Transfers

In the event of mergers, acquisitions, or asset sales, we may transfer your data, ensuring equivalent privacy protections are maintained.

7. Data Retention

We retain Personal Information only for as long as necessary. Account information is retained until you delete your account, plus an additional 12 months for legal compliance. Transaction records are kept for 7 years to meet tax requirements. Communication records are retained for 3 years to support dispute resolution. Identity verification data is retained until account deletion, plus 12 months, but biometric data, such as Face ID, is deleted immediately upon consent withdrawal. Location data is deleted after task completion unless needed for disputes, with a maximum retention of 3 years. Marketing data is retained until you withdraw consent. When data is no longer needed, we securely delete or anonymise it using industry-standard methods, such as locking data in a digital safe with AES-256 encryption and securely erasing it when retention ends.

8. Your Rights Under UK GDPR

You have several rights under UK GDPR. You may request a copy of your Personal Information. You can correct inaccurate or incomplete data. You may request deletion of your data when it is no longer needed or when you withdraw consent. You can limit processing in certain cases, such as during dispute resolution. You may receive your data in a structured, machine-readable format for portability. You can object to processing based on legitimate interests or marketing. You may withdraw consent for processing at any time. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk. To exercise these rights, use the “Privacy Settings” menu in your account or email hello@elotheapp.com. We will verify your identity, such as through account login or ID check, and respond within one month. You can view your data in real-time and manage consents at elotheapp.com/privacy/dashboard.

9. Data Security

We protect your Personal Information with robust measures. Data is encrypted using AES-256 for data at rest and TLS for data in transit, ensuring it is locked in a digital safe. Access is restricted through role-based controls and multi-factor authentication

for staff. We conduct regular penetration testing and vulnerability scans through security audits. Our employees receive annual data protection training. We maintain 24/7 monitoring for incidents, and in the event of a data breach, we notify affected users within 72 hours, as required by UK GDPR, via email or Platform notice, and take steps to mitigate harm.

10. International Data Transfers

Your data may be transferred outside the UK, such as to cloud providers in the European Economic Area or the United States. We ensure compliance through UK government adequacy decisions, such as for the EEA, standard contractual clauses for providers like AWS or Google in the US, and binding corporate rules where applicable. We monitor changes to adequacy decisions and update our practices as needed. A list of countries where data is transferred is available at elotheapp.com/privacy/transfers.

11. Cookies and Tracking

We use cookies and similar technologies to improve functionality and personalise experiences. Cookies are small files stored on your device to help the Platform operate smoothly or track usage for improvements. Essential cookies are necessary for functions like login and session management. Non-essential cookies support analytics, personalisation, and marketing, such as tracking usage patterns or serving targeted ads, and can be rejected without impacting Platform functionality. You can manage cookies through the “Cookie Preferences” pop-up on our website or app, or via your browser settings. Rejecting non-essential cookies will not affect core Platform features, such as account access or service requests. For more details, see our Cookie Policy at elotheapp.com/privacy/cookies.

12. Marketing Communications

With your consent, we send promotional emails or SMS. You can opt out by using unsubscribe links in emails, replying “STOP” to SMS, adjusting the “Privacy Settings”

menu in your account, or emailing hello@elotheapp.com. Service-related communications, such as task updates, will continue as they are essential for Platform use.

13. Children’s Privacy

The Platform is designed for users aged 18 and older. We verify age through ID checks and promptly delete any data from users under 18 if detected.

14. Changes to This Policy

We may update this Privacy Policy to reflect legal or operational changes. We will notify you at least 30 days before changes take effect through email for registered users or a Platform notice, such as a pop-up or banner on the website or app. The “Last Updated” date will be revised accordingly. Your continued use of the Platform after changes indicates acceptance. You can review changes at elotheapp.com/privacy.

15. Contact Us

For questions or to exercise your rights, contact us by email at hello@elotheapp.com or by post at Elo Applications Limited, Flat 3, 38 Manchester Street, Marylebone, London, UK. For complaints, you may contact the UK Information Commissioner’s Office at ico.org.uk.

This Privacy Policy is effective as of 28 July 2025.