01. Who this covers
This notice concerns the Elysha Works portfolio at elyshaworks.com, its Rhea guide, and the discovery-call booking service supported by the Elysha Works CRM at crm.elyshaworks.com.
Elysha Works is operated by Elysha Corpuz Dumpit, who is responsible for the personal information used to manage enquiries and discovery calls. For privacy questions or requests, contact support@elyshaworks.com. This notice does not replace a separate agreement or privacy notice for a client project or the client portal.
02. Information & purpose
Enquiries and booking questions
If you email Elysha Works, your address, message and any information you choose to include are used to respond to your enquiry.
When online booking is enabled, the form asks for your first and last name, email address, business field and main challenge. Business name and desired outcome are optional. Please share only what is needed to discuss your project—not passwords, payment-card details, health records or confidential information about other people.
Selecting Continue to available times saves your answers in the CRM before you choose a time. Elysha can use those answers to prepare and follow up about your enquiry, even if you do not finish booking. The CRM also keeps enquiry source, submission time, the notice version shown, and contact/pipeline activity.
Appointment details
The booking service processes your chosen time and time zone, appointment status, calendar identifiers, Google Meet link, and cancellation or rescheduling activity. These support scheduling, conflict checks and managing your call.
Enquiry handling and scheduling support the steps you request before a possible service agreement. Security processing helps prevent misuse and protect the service. Booking is not a newsletter subscription; optional marketing would require a separate choice. Reading this notice alone is not consent to unrelated processing.
03. Google Calendar & Meet
Visitors do not connect their own Google calendars. The integration connects Elysha’s authorised calendar. Elysha signs in with Google and approves access; this is separate from the account used to administer Firebase or Google Cloud.
- Account identity: Google account email and verification information are used to verify the authorised calendar owner.
- Availability: busy periods are checked to avoid conflicts. Visitors see available times, not the names or details of Elysha’s other events.
- Booking events: the service creates and manages the discovery-call event, its Meet link, and a private 30-minute rest block. It reads appointment status to keep the CRM in sync.
Google receives the attendee email, appointment times, event identifiers and scheduling information. The integration does not copy your project-question answers into the event description. The attendee receives meeting details and a private management link through the calendar invitation. Google and the recipient’s email provider handle delivery; a successful booking is not proof that an email reached an inbox.
Calendar credentials are held server-side, not in the public page. Google data is used only for scheduling and related security—not advertising, sale of data or general-purpose AI training. Elysha Works’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
The calendar owner can disconnect in the CRM or revoke access in Google Account connections. Revoking access stops further authorised access; it does not automatically erase existing CRM records, invitations or calendar events.
04. Rhea & browser storage
Rhea is a curated digital guide, not a human representative or an open-ended AI service. The current engine matches questions against prepared information in your browser. It does not send those questions to OpenAI or Claude.
Messages and conversation context stay in page memory. A random session identifier is stored in your browser’s session storage. Closing the tab normally clears that identifier; browser restore behaviour can vary. Clearing site data also removes local storage for the site.
Questions that Rhea cannot answer create a local fallback event containing a shortened question, page location, session identifier and timestamp. Automatic CRM delivery and the daily fallback report are not enabled. A chat message is not a promise of human follow-up or a confirmed appointment. Use the booking page or email for a direct enquiry.
These policy pages work without JavaScript and do not load external scripts or fonts. Other portfolio pages may load an icon library from jsDelivr, which receives the technical information needed to deliver that resource.
05. Providers, sharing & security
Elysha uses the information needed to respond and manage enquiries. Google/Firebase provide website hosting, backend processing, database storage and administrative authentication. Google Calendar and Meet provide scheduling and meeting services. Email providers process messages and invitations sent through them.
When public booking is enabled, Firebase App Check and reCAPTCHA Enterprise help assess whether requests come from the expected site and detect abuse. This can involve technical signals such as IP address, browser/device information and interactions with the protected service. Google processes this information under its Privacy Policy and Terms of Service.
Hosting and security services may maintain request or diagnostic logs. The booking backend uses hashed rate-limit identifiers to limit repeated requests; this does not mean all provider logs are anonymous. Providers may process data outside your country under their service terms and safeguards.
The prepared booking integration uses encrypted transport, restricted administrative access and server-side credential storage. Keep your booking-management link private: anyone who has a valid link may be able to manage that booking. No online service can guarantee absolute security.
Information may also need to be disclosed where required by applicable law or to address security abuse. It is not made public as part of the portfolio. Any materially different use or sharing must be explained before it begins.
06. Retention & your choices
For enquiries that do not become client projects, the retention period is three calendar months from the last interaction with you. Internal synchronisation or administrative activity does not restart that period. At the end of the period, Elysha reviews and deletes the associated enquiry records and answers, unless a specific applicable legal requirement or unresolved dispute requires continued retention. Active client-project records are handled under the applicable project arrangements instead.
Retention handling is manual, not automatic cleanup. Elysha reviews each eligible enquiry in the CRM and separately checks associated owner-held email and calendar copies. Cancelling an appointment alone does not delete its answers. Any retention exception is reviewed and its reason recorded.
Provider security logs and backups follow separate provider retention and deletion cycles; they are not covered by the CRM’s three-month deletion action. Removal from the CRM does not promise immediate erasure from those systems or remove invitations and messages held in recipients’ accounts. Contact us if you need help with a deletion request.
You can ask what personal information is held about you, request access or correction, and ask for deletion or restriction where applicable. You may also object to certain processing or withdraw consent where consent is the basis. Some records may need to be retained for an applicable legal requirement or an unresolved dispute; any such exception should be explained to you.
Send requests to support@elyshaworks.com, preferably from the address used for your enquiry. Include enough detail to locate the record, but do not email passwords or identity documents unless a necessary, secure verification process is agreed. Cancelling a call is separate from requesting deletion of your enquiry.
Where Philippine data-protection law applies, you can also contact the National Privacy Commission. Other rights may apply depending on your location and the circumstances.
07. Updates & contact
The effective or updated date appears at the top of this notice. Material changes to data use, including any future cloud-based chat processing, will be reflected here and in appropriate in-product disclosures before activation.
Questions about this policy? Email support@elyshaworks.com. For website and booking conditions, read the Terms of Service.
