Legal

Privacy Policy

How Alethia HQ collects, uses and protects personal data — for visitors to this site and users of the platform. Last updated 7 July 2026.

Who we are

Alethia HQ (“Alethia”, “we”, “us”) provides a platform for managing deals, funds flows, corporate entities and the records connected to them. For personal data collected through this website and for account data on the platform, we act as the data controller. For the content our customers store in their workspaces — entities, people, documents and related records — the customer is the controller and we process that data on their instructions.

What we collect

Account data. Name, work email address, authentication identifiers and role, when you or your organisation create an account.

Workspace content. The records your organisation keeps in Alethia — entity details, people and appointments, ownership, documents, tasks and audit history. This can include personal data about directors, officers and beneficial owners that your organisation is required to record.

Billing data. Plan, subscription status and invoicing details. Card payments are handled by Stripe; we never see or store full card numbers.

Enquiries. If you request a demo we collect the details you submit — name, email, organisation and your message — to arrange and follow up on it.

Usage data and cookies. Strictly-necessary cookies keep you signed in; analytics run only with your consent. See the Cookie Policy.

How we use it

To provide and secure the service (performance of a contract); to arrange demos and respond to enquiries you make (legitimate interests, or steps taken at your request before a contract); to bill for the service and keep required accounting records (contract and legal obligation); to protect the service against misuse (legitimate interests); and to improve the product using aggregated, non-identifying usage information.

We do not sell personal data and we do not use workspace content for advertising.

Who we share it with

We use a small number of service providers to run Alethia, each under a data-processing agreement: cloud hosting and infrastructure (Vercel; Google Cloud / Firebase for authentication, database and file storage), payments (Stripe), transactional email (Postmark) and, where your organisation enables it, public-register lookups (for example Companies House, which receives only the company number being looked up).

Beyond that, we disclose personal data only where the law requires it or as part of a corporate transaction affecting Alethia, in which case this policy continues to apply.

International transfers

Our providers may process data outside the UK and EEA. Where they do, transfers are protected by adequacy regulations or standard contractual clauses, together with each provider's technical safeguards.

Security and retention

Data is encrypted in transit and at rest. Access to workspace content is governed by roles, per-record permissions and two-factor authentication, and every change is written to an audit trail.

We keep account and workspace data for as long as the account is active and for a short period afterwards so an organisation can retrieve its records, then delete it. Billing records are retained for as long as tax law requires. Demo enquiries are kept only as long as needed to follow up.

Your rights

Under UK and EU data-protection law you can ask for access to your personal data, ask us to correct or delete it, restrict or object to processing, and receive a portable copy. Where we rely on consent you can withdraw it at any time. You can also complain to your supervisory authority — in the UK, the Information Commissioner's Office.

If your data is in a customer's workspace, that organisation controls it — direct your request to them and we will support them in meeting it.

Contact and changes

Questions and requests about this policy: privacy@alethiahq.com. We may update this policy from time to time; material changes will be flagged on this page with a new “last updated” date.