// legal
Privacy policy
How Alitycs handles personal data — both the data we hold about you as our customer, and the event data you send us about your users.
Who we are and what this policy covers
Alitycs is a product analytics service. Companies install one of our SDKs, send us events describing what happens in their product, and use Alitycs to answer questions about that behaviour.
This policy is published by [legal entity name], a company registered in [country of incorporation] under company number [company number], with its registered office at [registered address]. In this policy, “we”, “us” and “Alitycs” mean that company. “You” means whoever is reading it: a customer, someone evaluating us, a visitor to alitycs.com, or an end user of a product that runs Alitycs.
It covers alitycs.com, our documentation, our marketing and sales activity, the Alitycs application at app.alitycs.com, and our ingestion and query APIs. It does not cover any third-party website that links to us, and it does not cover how our customers run their own products.
If you are an end user of a product that uses Alitycs and you want your data corrected or deleted, the company that runs that product is the right place to start. We explain why in the next section, and we will help them act on your request.
Our two roles: controller and processor
Data protection law distinguishes between the party that decides why and how personal data is processed (the controller) and the party that processes it on that first party's instructions (the processor). Alitycs is both, for different data, and the distinction shapes the rest of this policy.
- We are a controller for the data we hold about our own business: your account, your workspace, your billing records, your support conversations, and the analytics we collect about visits to alitycs.com. We decide what to collect and why. The rest of this policy describes that processing.
- We are a processor for the event data our customers send into their workspaces. Our customers decide what events to track, which properties to attach, and which identifiers to use. We store and query that data on their behalf and under their instructions. Our customers are the controllers for it.
When we act as a processor, the terms that govern the processing are in our data processing addendum, not in this policy. If you are a customer, read the DPA alongside this document.
One person can appear in both roles. If you are an Alitycs administrator who also uses your own product, we hold your account record as a controller and your event record as a processor, and different rules apply to each.
What we collect as a controller
We keep this deliberately small. We collect the following categories of personal data about customers, prospects and site visitors.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Name, work email address, password hash, workspace name and role, authentication method, and the API keys issued to your workspace. | You, when you sign up or when a colleague invites you. |
| Usage and product telemetry | Which pages of the application you opened, which queries you ran, feature usage, device and browser type, IP address, and timestamps. | Your use of the Alitycs application. |
| Billing data | Billing contact, billing address, VAT or tax identifier, plan, invoices and payment status. We do not receive or store full card numbers — our payment processor handles those. | You, and our payment processor. |
| Support and sales data | Emails, support tickets, call notes, and anything you choose to include in them. | You, when you contact us or we contact you. |
| Website analytics | Pages viewed on alitycs.com, referrer, approximate location derived from IP address, and device type. | Your visit to our website. |
| Security and audit logs | Sign-in events, API key creation and rotation, administrative actions, and the IP addresses behind them. | Your use of the service. |
We do not ask you for special categories of personal data — health, biometrics, political opinions and the rest — and you should not send them to us in a support ticket.
What customers send us as a processor
The event data in a workspace is chosen by the customer that owns the workspace. A typical event carries an event name, a timestamp, a user or anonymous identifier, and whatever properties the customer decided to attach. Our SDKs also collect technical context such as page URL, referrer, device, browser, operating system and IP address, some of which the customer can switch off.
We do not decide what goes into an event. We do not enrich event data with data bought from third parties, and we do not use one customer's event data to serve another customer.
We do not use event data to train models that serve anyone other than the customer that owns it. Our AI features answer questions about a workspace using that workspace's own data.
Our terms ask customers not to send special-category personal data, government identifiers, payment card numbers or credentials in events. If you are an end user and you believe a product has sent us something it should not have, tell the company that runs that product, and tell us at privacy@alitycs.com so we can follow up with them.
Why we process personal data, and our lawful bases
Where the GDPR or the UK GDPR applies, we rely on the following lawful bases for the data we hold as a controller.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Providing the service, including creating your account and running your workspace | Account data, usage data | Performance of our contract with you |
| Billing, collections and tax records | Billing data, account data | Performance of our contract, and our legal obligation to keep accounting records |
| Support and service communications | Support data, account data | Performance of our contract |
| Keeping the service secure, preventing abuse, and debugging | Security logs, usage data | Our legitimate interest in a service that stays available and is not abused |
| Improving the product, measuring which features are used | Usage data, aggregated where possible | Our legitimate interest in improving a product you pay for |
| Marketing to businesses that have shown interest in us | Account data, prospect contact data | Our legitimate interest, or your consent where the law requires it |
| Non-essential cookies and website analytics | Website analytics data | Your consent |
| Meeting legal obligations and defending legal claims | Any of the above, as needed | Our legal obligation, or our legitimate interest in defending claims |
Where we rely on a legitimate interest, we have weighed it against your interests and rights, and you can object — see your rights. Where we rely on consent, you can withdraw it at any time without affecting what we did before you withdrew it.
Cookies and similar technologies
The Alitycs application sets a small number of strictly necessary cookies. They keep you signed in, remember your workspace, and protect forms against cross-site request forgery. The application does not work without them, so they are not subject to consent.
On alitycs.com we use analytics to understand which pages help people and which do not. We ask for consent before setting any non-essential cookie or similar identifier, and you can change your answer at any time at [cookie settings location].
We do not run advertising networks on our site, and we do not sell personal data or share it for cross-context behavioural advertising. Where the law treats a browser signal such as Global Privacy Control as an opt-out, we honour it.
The cookies we set, their purpose and their lifetime are listed at [cookie table — to be completed once the final analytics and consent tooling is chosen].
How long we keep things
We keep personal data only as long as we need it for the purpose we collected it for, then delete it or aggregate it beyond recovery.
| Data | Retention |
|---|---|
| Account and workspace records | For the life of the account, then [account retention period after closure] |
| Event data in a workspace | For the retention window of the customer's plan — [event retention window by plan] — or until the customer deletes it, whichever is sooner |
| Billing records and invoices | [statutory accounting retention period], because tax law requires it |
| Support conversations | [support retention period] after the conversation is closed |
| Security and audit logs | [security log retention period] |
| Website analytics | [website analytics retention period] |
| Backups | [backup retention period], after which deleted data ages out of backups automatically |
When a customer deletes event data, we remove it from the live service promptly and it ages out of backups on the schedule above. Deletion of an entire workspace is covered in our terms of service and, for personal data we process on a customer's behalf, in the DPA.
Who we share data with
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We do share it with a small number of service providers who help us run the business, and only as far as they need it.
- Cloud hosting and infrastructure, to store and serve data.
- Payment processing, to take payments and issue invoices.
- Email delivery, for service notices, product email and support replies.
- Support and ticketing, to manage your conversations with us.
- Error monitoring and observability, to detect and diagnose faults.
- Analytics for our own website, subject to your cookie choice.
- Professional advisers — accountants, auditors and lawyers — where they need access and are bound by confidentiality.
The current list of subprocessors that may handle customer event data, with the entity name, role and location of each, is published at [subprocessor list URL]. Customers can subscribe to notifications of changes to it; the notice period and the right to object are set out in the DPA.
We will also disclose personal data where the law requires it — a valid court order, a warrant, a regulator's demand — or to establish or defend legal claims. We assess every request, push back on ones that are overbroad, and tell the affected customer unless we are legally prevented from doing so.
If Alitycs is involved in a merger, acquisition or sale of assets, personal data may transfer to the buyer. We will tell you before that happens and before your data becomes subject to a different privacy policy.
International transfers
Alitycs operates in more than one region and our team and suppliers are not all in the same country, so personal data may be transferred outside the country where it was collected — including outside the European Economic Area and the United Kingdom.
Where we transfer personal data out of the EEA or the UK to a country without an adequacy decision, we rely on the European Commission's standard contractual clauses, [SCC module and version], together with the UK International Data Transfer Addendum where the UK GDPR applies. We carry out a transfer risk assessment for each such transfer and apply additional safeguards where the assessment calls for them.
Customers can ask which region their workspace is stored in, and enterprise customers can choose. The regions we offer and the data that stays inside each are described on our security page.
You can ask us for a copy of the safeguards we rely on by writing to privacy@alitycs.com.
Your rights and how to exercise them
Depending on where you live, you have some or all of the following rights over the personal data we hold about you as a controller.
- Access — get a copy of your personal data and information about how we process it.
- Rectification — have inaccurate data corrected and incomplete data completed.
- Erasure — have your data deleted where we no longer have a good reason to keep it.
- Restriction — have us pause processing while a dispute about accuracy or legitimate interest is resolved.
- Portability — receive the data you gave us in a structured, machine-readable format, or have us send it to another provider where that is technically feasible.
- Objection — object to processing we base on a legitimate interest, and object to direct marketing at any time, with no reason needed.
- Withdraw consent — where we asked for consent, take it back at any time.
- Complain — lodge a complaint with your supervisory authority. We would rather you came to us first, but you do not have to.
If you are in California, you also have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA.
To exercise any of these, email privacy@alitycs.com. We will ask for enough information to be sure who you are, and we will respond within one month. If your request is complex we may extend that by a further two months and will tell you why. We do not charge a fee unless a request is manifestly unfounded or excessive.
If your request concerns event data held in a customer's workspace, we are the processor and the customer is the controller. We will pass your request on to them and help them answer it, but we cannot delete or disclose their data on our own initiative.
Our data protection contact is [DPO or privacy contact name and address]. Our representative in the European Union and the United Kingdom under Article 27 is [EU/UK Article 27 representative].
Children
Alitycs is a business tool. It is not directed at children, and we do not knowingly collect personal data from anyone under 16 as a controller.
Customers must not use Alitycs to track children in ways their own law does not allow, and must have a lawful basis for any event data about a minor that reaches their workspace. If we learn that we hold data about a child that we should not, we delete it.
Security
We encrypt data in transit and at rest, keep access to production limited to the people who need it, log administrative actions, and separate every workspace's data. Our security page describes the controls in detail and tells you how to report a vulnerability.
No service is perfectly secure. If a personal data breach affects you, we will notify you and the relevant supervisory authority as the law requires; for customer event data, the notification timeframe and process are set out in the DPA.
Changes to this policy
We update this policy when our processing changes. The date at the top always reflects the current version, and we keep the previous versions so you can see what changed.
If a change materially affects you — a new purpose, a new category of recipient, a shorter route to your data — we will tell customers by email or in the application at least [notice period for material privacy changes] before it takes effect.
How to contact us
Privacy questions, requests and complaints go to privacy@alitycs.com. We read everything sent there.
By post: [legal entity name], [registered address].
If you are unhappy with our response, you can complain to the supervisory authority in the country where you live or work. In the United Kingdom that is the Information Commissioner's Office; in the European Union it is your national authority, and our lead authority is [lead supervisory authority].
The rest of the paperwork
These four documents are written to be read together. Each one assumes the others.
Terms of service
Accounts, acceptable use, data ownership, fees, liability and how either of us ends the agreement.
Read itData processing addendum
Processor terms, subprocessors, transfers, and the two annexes your reviewers will ask for.
Read itSecurity
The controls behind the promises above, and how to report a vulnerability to us.
Read itPrivacy questions and data-subject requests: privacy@alitycs.com. A real person reads everything sent there.