Legal

Privacy Policy

How Alethia HQ collects, uses and protects personal data — for visitors to this site and users of the platform. Last updated 23 September 2026.

Who we are

Alethia HQ (“Alethia”, “we”, “us”) provides a platform for managing deals, funds flows, corporate entities and the records connected to them. For personal data collected through this website and for account data on the platform, we act as the data controller. For the content our customers store in their workspaces — entities, people, documents and related records — the customer is the controller and we process that data on their instructions.

What we collect

Account data. Name, work email address, authentication identifiers and role, when you or your organisation create an account.

Workspace content. The records your organisation keeps in Alethia — entity details, people and appointments, ownership, documents, tasks and audit history. This can include personal data about directors, officers and beneficial owners that your organisation is required to record.

Billing data. Plan, subscription status and invoicing details. Card payments are handled by Stripe; we never see or store full card numbers.

Enquiries. If you request a demo we collect the details you submit — name, email, organisation and your message — to arrange and follow up on it.

Usage data and cookies. Strictly-necessary cookies keep you signed in; analytics run only with your consent. See the Cookie Policy.

How we use it

To provide and secure the service (performance of a contract); to arrange demos and respond to enquiries you make (legitimate interests, or steps taken at your request before a contract); to bill for the service and keep required accounting records (contract and legal obligation); to protect the service against misuse (legitimate interests); and to improve the product using aggregated, non-identifying usage information.

We do not sell personal data and we do not use workspace content for advertising.

Who we share it with

We use a small number of service providers to run Alethia, each under a data-processing agreement: cloud hosting and infrastructure (Vercel; Google Cloud / Firebase for authentication, database and file storage), payments (Stripe), transactional email (Postmark or Resend) and, where your organisation enables it, public-register lookups (for example Companies House, which receives only the company number being looked up). The full list, with what each provider receives and when, is kept on our security page.

AI features are optional and off until a workspace administrator switches them on. When they are on, documents a user asks Alethia to read are sent to Anthropic, and other prompts a user submits go to Anthropic, or to OpenAI or Google where Alethia has chosen that provider, for processing under API terms that exclude training on your content; nothing is sent unless a person triggers it, and the results are proposals for a person to review.

On the public website only, and only with your consent through the cookie banner, we use Microsoft Clarity and Google Analytics and Ads to understand how the site is used, tawk.to for live chat and Calendly for scheduling demos. Declining the banner keeps these off; they are never loaded inside the application. The Calendly booking calendar also loads if you press “Load the calendar” on the book-a-call page, for that visit only; doing so turns none of the others on.

Beyond that, we disclose personal data only where the law requires it or as part of a corporate transaction affecting Alethia, in which case this policy continues to apply.

International transfers

Our providers may process data outside the UK and EEA. Where they do, transfers are protected by adequacy regulations or standard contractual clauses, together with each provider's technical safeguards.

Security and retention

Data is encrypted in transit and at rest. Access to workspace content is governed by roles, per-record permissions and mandatory two-factor authentication, and material changes to it are recorded to an append-only audit trail.

We keep account and workspace data for as long as the account is active and for a short period afterwards so an organisation can retrieve its records, then delete it. Billing records are retained for as long as tax law requires. Demo enquiries are kept only as long as needed to follow up.

Your rights

Under UK and EU data-protection law you can ask for access to your personal data, ask us to correct or delete it, restrict or object to processing, and receive a portable copy. Where we rely on consent you can withdraw it at any time. You can also complain to your supervisory authority — in the UK, the Information Commissioner's Office.

If your data is in a customer's workspace, that organisation controls it — direct your request to them and we will support them in meeting it.

Contact and changes

Questions and requests about this policy: privacy@alethiahq.com. We may update this policy from time to time; material changes will be flagged on this page with a new “last updated” date.