Information we process
We process tenant account details, administrator and operator identities, project configuration, mapped source and destination identities, workload selections, job progress, diagnostic events, reconciliation evidence and support enquiries. Provider authorization tokens and application credentials are processed only to deliver the configured migration.
Google user data
When a customer authorizes Google Workspace, ElephantsData accesses only the data required for the migration workloads configured by that customer. Depending on the selected route, this can include account and directory details, Gmail messages and folders, Google Drive files, contacts, calendars, Google Takeout export archives, and Google Photos media that a user explicitly selects or exports.
Google user data is used only to authenticate the connection, discover authorized accounts, transfer customer-selected content, preserve checkpoints, reconcile results, provide audit evidence, and troubleshoot the requested migration. ElephantsData does not sell Google user data or use it for advertising, credit decisions, or training general-purpose AI models.
Google user data is shared only with the customer-selected destination provider and infrastructure subprocessors required to operate and secure the migration. Access tokens and temporary migration material are retained only as operationally necessary, then removed through project deletion, token revocation, configured cleanup, or a verified customer request. ElephantsData's handling of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Migration content
ElephantsData transfers selected content between customer-authorized providers. Content may pass through worker memory or encrypted temporary staging when a workload requires resumable transfer. It is not used for advertising, profiling or training general-purpose AI models.
How we use information
- Authenticate authorized tenant users and enforce assigned roles.
- Validate provider access, licensing and migration readiness.
- Execute, checkpoint, reconcile and report requested migrations.
- Protect the service, investigate failures and maintain audit evidence.
- Respond to support and migration-planning enquiries.
Providers and subprocessors
Customer-directed operations may communicate with Microsoft, Google, Zoho, IMAP providers and infrastructure services needed to host and secure ElephantsData. Each provider processes information under its own terms and the customer's agreement with that provider.
Security and retention
Credentials and refresh tokens are encrypted at rest and are not returned to browsers after storage. Access is role controlled and security-relevant actions are audited. Project deletion is designed to purge project-linked credentials, mappings, checkpoints, reports, logs and temporary staging, subject to active-job safeguards, operational backups and legal retention requirements.
Your choices
A customer administrator can revoke provider consent, disable users and request deletion of a completed project. Requests to access, correct or delete account information can be submitted through the support page.
Contact
For privacy or security questions, submit a request through elephantsdata.com/support. Please do not include passwords, client secrets or private keys.