Privacy Policy
Last updated: September 14, 2026
1. Who we are
This website (elysx.net) is operated by ELYSX (PVT) LTD (“Elysx”, “we”, “us”), a company registered in Sri Lanka (registration no. PV 00321461) with its registered office at 10/A/27, Asiri Uyana, Gangarama Wihara Mawatha, Dampe, Piliyandala 10300, Sri Lanka.
Elysx provides managed and technical services for IFS Applications to business clients, including clients in the European Union. Although we are based outside the EU, we comply with the EU General Data Protection Regulation (GDPR) where it applies to our activities.
For any question about this notice or your personal data, contact us at info@elysx.net.
2. Our representative in the European Union
Pursuant to Article 27 GDPR, we have appointed an EU representative:
myDPO Solutions, 50 Avenue des Champs-Élysées, 75008 Paris, France
If you are in the EU/EEA, you may contact our EU representative regarding any matter related to our processing of your personal data, by email to eurepresentative@elysx.net.
3. What personal data we process, and why
We deliberately keep this website’s data collection to a minimum. It uses no cookies, no analytics, no tracking, and no contact forms.
a) Server logs. Like virtually every website, our hosting provider’s web server automatically records technical access logs, which include your IP address, the pages requested, date and time, and browser type. We process this data on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in operating and securing the website. Raw logs are discarded within hours of automated processing; archived logs are retained for a maximum of approximately one month and then deleted automatically.
b) Email enquiries. If you contact us at info@elysx.net, we process the personal data you provide (your name, email address, and the content of your message) to respond to your enquiry and manage our business relationship, on the basis of our legitimate interest in responding to business enquiries (Art. 6(1)(f)) or, where applicable, to take steps prior to entering into a contract (Art. 6(1)(b)). Enquiry correspondence is retained for the duration of our business relationship or, for enquiries that do not lead to one, no longer than 24 months.
c) Business contacts. In the course of providing our services we process limited professional contact data of representatives of our clients, partners and suppliers (name, job title, business email and phone, employer, correspondence), on the basis of our legitimate interest in managing business relationships (Art. 6(1)(f)).
We do not process special categories of personal data through this website, do not use automated decision-making or profiling, and do not sell personal data.
4. Where your data is stored and international transfers
Because Elysx operates from Sri Lanka, personal data we process is accessed from outside the EU/EEA. In addition:
- This website is hosted by GoDaddy on servers located in the United States. Transfers to GoDaddy are safeguarded by GoDaddy’s Data Processing Addendum incorporating the EU Standard Contractual Clauses; GoDaddy also participates in the EU-U.S. Data Privacy Framework.
- Our business email and files are hosted on Microsoft 365. Transfers to Microsoft are safeguarded by Microsoft’s Products and Services Data Protection Addendum incorporating the EU Standard Contractual Clauses; Microsoft is certified under the EU-U.S. Data Privacy Framework.
Where we access personal data of EU clients in the course of providing IFS support services, we do so under contractual safeguards (EU Standard Contractual Clauses and supplementary technical measures) agreed with the relevant clients. That processing is governed by our contracts with those clients, who remain responsible for it as controllers; this notice covers only the processing for which Elysx is the controller.
5. Who receives your data
We do not share personal data with third parties except: our hosting provider (GoDaddy) and IT service providers (Microsoft) as described above, acting as our processors; our EU representative (myDPO Solutions) where necessary to handle GDPR matters; and public authorities where required by law.
6. Your rights
If the GDPR applies to our processing of your personal data, you have the following rights: the right to access the personal data we hold about you and to receive a copy of it; the right to rectification of inaccurate or incomplete data; the right to erasure of your data (the “right to be forgotten”) where the law allows; the right to restrict our processing in certain circumstances; the right to data portability, that is, to receive the data you provided in a structured, commonly used, machine-readable format; and the right to object to processing based on our legitimate interests. You may exercise any of these rights by contacting info@elysx.net or our EU representative at eurepresentative@elysx.net. Requests sent to the EU representative address are received by both Elysx and myDPO Solutions, who assist us in handling them.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU/EEA country where you live or work.
7. Security
We protect personal data through technical and organisational measures including encrypted connections (TLS/HTTPS), access controls, multi-factor authentication on our systems, and staff confidentiality obligations.
8. Changes to this notice
We may update this notice from time to time. The current version, with its date, is always available on this page.