AlphaWeb
Legal

Privacy Policy

Effective Date: 15 July 2026

Introduction

This Privacy Policy explains how AlphaWeb and AlphaWeb.AI (“AlphaWeb,” “we,” “us”), collects, uses, shares, and protects personal data in connection with the AlphaWeb agentic operating system and related websites, applications, and services (the “Services”).

This Policy applies to website visitors, audit applicants, Customers and their Account owners, administrators, and Authorized Users, individuals using the Services personally, and, more narrowly, the end customers and other individuals whose personal data a Customer submits to or generates through the Services. This Policy does not cover third party websites, applications, or services we integrate with but do not operate, each with its own privacy practices.

1. Scope and Identity

1.1 Who we are and contact.

The Services are operated by Alpha Labs EE d.o.o., registered in Croatia. Questions about this Policy can be sent to support@alphaweb.ai.

1.2 Scope.

This Policy covers the AlphaWeb website and Services at alphaweb.ai and not third party integrations under Section 9.

2. Our Privacy Roles

2.1 Two different roles.

AlphaWeb processes personal data in two capacities, and the applicable rules depend on which capacity applies to the specific data. For data we collect for our own purposes, such as website visitors, audit applicants, Account administrators, billing contacts, and our own marketing lists, AlphaWeb decides how and why it is processed, and this Policy describes those purposes directly.

2.3 Where we act on a Customer's behalf.

For data a Customer submits or generates about its own end customers, contacts, or personnel (for example, order, attribution, or lifecycle marketing data), AlphaWeb generally processes it only as instructed, to provide the Services. The Customer, not AlphaWeb, is primarily responsible for deciding how that data is used and for responding to privacy rights requests; an individual may need to contact the relevant Customer directly, as described in Section 13.7. Some processing, such as fraud prevention, platform security, and de-identified analytics, is nonetheless carried out by AlphaWeb for its own legitimate operational purposes even where data originated from a Customer's use of the Services, as described with legal bases in Section 6.

3. Who This Policy Covers

CategoryDescription
Website visitorsPeople who browse our website without creating an Account.
Prospective customers and audit applicantsPeople who apply for an audit, consultation, or demo.
Customers and Account ownersThe entities we contract with and the individuals who administer their Accounts.
Authorized UsersEmployees or contractors who use the Services under a Customer’s Account.
Consumer CustomersIndividuals who use the Services in a personal, non-business capacity.
Support contactsPeople who contact our support team, regardless of Account status.
Integration usersPeople whose accounts on a connected third party service interact with the Services.
People whose data a Customer uploadsEnd customers and leads whose data a Customer submits, per Section 2.3.
Newsletter subscribersPeople who subscribe to AlphaWeb’s own marketing communications.

4. Personal Data We Collect

The table below describes categories of personal data AlphaWeb may collect, based on company materials reviewed for this Policy. We do not collect a category unless relevant to operating the Services for that category of person.

CategoryExamplesSourceTypical purpose
Identity and contact informationName, business email, phone, job titleDirectly, or via an inviting CustomerAccount creation, communication, support
Account and authentication informationLogin credentials, API keys, session dataDirectly, or via the CustomerAccount access and security
Business informationCompany name, website, industry, revenue or GMV bandThe applicant, Business Customer, or public sourcesApplication review and onboarding
Billing and transaction informationBilling contact, tokenized payment details, invoice historyThe Business Customer and our payment processorBilling and fee collection
Device, usage, and location informationBrowser type, device identifiers, feature usage, IP address, approximate locationAutomatically, via the website and ServicesProduct operation, security, fraud prevention, analytics
Cookie and tracking identifiersCookie IDs, pixel identifiersAutomatically, per Section 8Analytics, and where enabled, advertising
Support communicationsMessages, call notes, attachmentsDirectly from the individualCustomer support
Customer Data submitted by a Business CustomerOrder, pricing, attribution, and end customer data via integrationsThe Business Customer or its connected platformsProviding the Services, per Section 2.3
Prompts and AI interaction dataInstructions and content submitted to the platform and generated OutputThe Customer submitting the promptOperating AI features per Section 7
Marketing preferencesSubscription status, communication preferencesDirectly from the individualSending or suppressing marketing communications

5. Sources of Information

We may receive personal data directly from the individual (for example, applying for an audit or contacting support); from a Customer (for example, inviting an Authorized User or submitting end customer data); from devices and browsers through cookies under Section 8; from integrations the Customer connects under Section 9; from service providers who help operate the Services; from publicly available sources when reviewing an application; and from payment processors in connection with billing.

6. How We Use Personal Data and Our Legal Bases

PurposeDescriptionLegal basis (where GDPR-style bases apply)
Providing the ServicesOperating the platformPerformance of a contract
Creating and administering AccountsSetup, role management, authenticationPerformance of a contract
Reviewing applicationsEvaluating audit or onboarding applicationsLegitimate interest, or pre-contract steps at the individual’s request
BillingCharging fees, invoicing, payment methodsPerformance of a contract; legal obligation
Customer supportResponding to support requestsPerformance of a contract; legitimate interest
Security and fraud preventionDetecting and preventing unauthorized access, fraud, and abuseLegitimate interest; legal obligation in some cases
Legal complianceResponding to legal requests, meeting regulatory obligationsLegal obligation
Product analytics and improvementUnderstanding feature usage, generally de-identifiedLegitimate interest
AI functionalityOperating AlphaBrain and Teammate features per Section 7Performance of a contract; legitimate interest
Marketing communicationsProduct updates or marketing, per Section 14Consent, where required; legitimate interest with opt-out
Enforcing agreementsEnforcing the Terms, investigating violationsLegitimate interest; performance of a contract
Corporate transactionsDue diligence and data transfer for a merger, per Section 18Legitimate interest; legal obligation

Where we rely on legitimate interests, the specific interest is identified above, and we balance it against the individual's rights rather than using it as a generic catch-all basis.

7. AI and Automated Processing

7.1 What uses AI and what data is submitted.

AlphaWeb uses AI to generate recommendations, content, and creative assets, and, where configured with sufficient autonomy, to take actions such as adjusting campaigns within the guardrails a Customer configures. Data submitted may include Customer Content, Customer Data, and prompts entered by an Authorized User, per Section 4.

7.2 Third party AI providers and training practices.

Certain AI capabilities may be powered in part by third party model providers. AlphaWeb does not use Customer Content or Customer Data to train shared or general purpose AI models offered to the public, and Customer data remains isolated from other customers' environments. AlphaWeb uses de-identified or aggregated data to monitor, maintain, improve, and train AlphaWeb's own proprietary platform and models. Because this data does not identify a specific individual, no separate opt-out is offered for this use.

7.3 Human review and automated decisions.

Company materials state each workflow can be configured from “requires approval” to “fully autonomous,” with higher stakes actions gated for the Customer's own approval and an audit trail of actions taken, so the degree of human review depends substantially on how the Customer configures each workflow. AlphaWeb does not use AI within the Services to make solely automated decisions producing legal or similarly significant effects on individual consumers (for example, denying credit, employment, or insurance), except where a Business Customer configures the Services to do so as part of its own operations, in which case that Customer is responsible for compliance with applicable law. An individual with questions about how an AI feature processed their data can contact us using the details in Section 20.

8. Cookies and Similar Technologies

8.1 Categories and consent.

The website and Services may use strictly necessary, preference, analytics, and, where enabled, advertising or marketing cookies used to measure our own campaign performance. Where required by law, we will request consent before setting non-essential cookies.

8.2 Controls and third party cookies.

Individuals can control cookies through browser settings and, where applicable, platform signals such as Global Privacy Control. Some cookies may be set by third party analytics or advertising providers, who may independently process resulting data.

9. How We Share Personal Data

We may share personal data with the following recipients, each processing data only as necessary for the purpose described:

Recipient categoryPurposeRelationship
Hosting and infrastructure providersStoring and running the ServicesProcessor or service provider
Payment processors (for example, Stripe, Adyen, PayPal)Processing paymentsProcessor, service provider, or independent controller depending on the provider’s role
Ecommerce, advertising, and lifecycle platforms connected by the Customer (for example, Shopify, Meta, Google, TikTok, Klaviyo)Enabling the connected integrationTypically independent controllers of their own platforms, acting at the Customer’s direction
AI model providersPowering certain AI features per Section 7Processor or subprocessor
Support, communications, and analytics providersOperating support, messaging, and analytics toolsProcessor or service provider
Professional advisersLegal, accounting, and other servicesIndependent controller, bound by confidentiality
Customers and their administratorsSharing an Authorized User’s data with the inviting CustomerController of its own workforce data
Authorities and transaction partiesLegal requests per Section 18; corporate transactions per Section 18As required by law, or as applicable

We have not confirmed the complete current list of subprocessors and vendors above. We have also not independently verified, against applicable law's specific definitions (including the California Consumer Privacy Act), whether any disclosure above, particularly to advertising or analytics providers, would be a “sale” or “sharing” of personal data.

10. International Data Transfers

10.1 Cross border processing and safeguards.

Because AlphaWeb and its service providers may operate in different countries than the individuals whose data is processed, personal data may be transferred to and processed in another country, potentially including the United States. Where personal data moves from the EEA, UK, or Switzerland to a country without an adequacy finding, AlphaWeb will rely on an appropriate mechanism such as the EU Standard Contractual Clauses or the UK International Data Transfer Agreement or Addendum; where a transfer is made to a country with an applicable adequacy decision, AlphaWeb relies on that decision instead.

11. Data Retention

We retain personal data for as long as necessary for the purposes described in this Policy, and in particular:

Data categoryRetention approach
Active Account dataFor as long as the Account remains active
Closed Account dataRetention period after account closure – 30 days
Customer Data submitted by a CustomerFor the agreement term, then deleted or returned per Section 9.10 of the Terms
BackupsLimited encrypted retention after deletion, 90 days
Billing, support, and security recordsBILLING RECORD RETENTION PERIOD \u2013 5 years SUPPORT RECORD RETENTION PERIOD \u2013 2 years SECURITY LOG RETENTION PERIOD \u2013 1 year
Marketing recordsUntil unsubscribe or deletion request, plus a limited suppression period
Cookie dataPer the cookie’s expiry, generally no longer than 13 months
Legal holds and de-identified dataLegal holds: for as long as required. De-identified or aggregated data: may be retained indefinitely as it no longer identifies an individual

We do not promise immediate deletion in every case, because some data must be retained temporarily in backups or to meet a legal obligation.

12. Security

12.1 General approach and certifications.

General approach and certifications. AlphaWeb's public materials describe its security measures, including encryption in transit and at rest, access controls, and tenant isolation between customer environments. AlphaWeb is in the process of obtaining SOC 2 Type II and ISO 27001 certifications, and describes its infrastructure as GDPR and CCPA ready. These statements are AlphaWeb's own public representations, made at a level of detail that does not disclose exploitable information about its systems.

12.2 Access controls and incident response.

Access to personal data is intended to be limited to personnel and systems that need it, with monitoring to detect anomalous activity. No system is completely secure, and AlphaWeb cannot guarantee absolute security of personal data.

13. Your Privacy Rights

13.1 Rights, requests, and verification.

Depending on location, individuals may have some or all of the following rights: access, correction, deletion, restriction, objection, portability, withdrawal of consent, opting out of certain marketing or of sale or sharing where applicable, limiting use of sensitive data, appeal, and non-discrimination for exercising these rights. A request can be submitted to support@alphaweb.ai. We take reasonable steps to verify the requester's identity, and where permitted by law, an authorized agent may submit a request subject to appropriate verification.

13.2 Response time and limitations.

We aim to respond to a verified request within the time required by applicable law. We may decline or limit a request where permitted by law, for example where it would reveal another individual's data.

13.3 Processor held data and complaints.

Where a request concerns data we process on a Customer's behalf under Section 2.3, we will direct the individual to that Customer or, where legally required, forward the request. An individual dissatisfied with our response may complain using the contact details in Section 20, and, where applicable, to their local supervisory authority under Section 17.

14. Marketing Communications

14.1 Types, consent, and opt-out.

We may send product announcements, marketing communications, and transactional communications necessary to operate the Services (such as billing notices), the last of which cannot be opted out of while the Account is active. Where required by law, we obtain consent before sending marketing communications, and in all cases provide an unsubscribe mechanism and honor opt-out requests sent to. Opting out of marketing does not affect transactional or account related communications.

15. Children's Privacy

15.1 Intended audience and parental requests.

The Services are intended for businesses and individuals meeting the minimum age in the Terms of Service, currently 18 years old, and are not directed to children below that age. A parent or guardian who believes a child provided personal data directly to AlphaWeb inconsistent with this Policy may contact support@alphaweb.ai to request deletion.

15.2 Children's data submitted by a Customer.

Where a Customer's own end customers include minors, resulting data is handled as Customer Data under Section 2.3, and the Customer is responsible for a lawful basis, including any required parental consent.

16. Sensitive Personal Data

16.1 General approach.

AlphaWeb does not intentionally collect sensitive personal data, such as health information, racial or ethnic origin, religious beliefs, or precise geolocation revealing such categories, about Account owners, Authorized Users, or Consumer Customers for its own purposes.

16.2 Sensitive data submitted by a Customer.

A Customer's own end customer data may incidentally include data treated as sensitive under some laws (for example, health related purchase data). Customers should not submit sensitive personal data beyond what is reasonably necessary for core commerce, marketing, and analytics functionality, and remain responsible for lawful handling.

17. Regional Privacy Disclosures

Because the Services are offered worldwide, the following region-specific provisions apply where relevant.

Region: EEA, UK, and Switzerland

Key disclosures: Controller identity (Section 1), legal bases (Section 6), international transfers (Section 10), rights including access, rectification, erasure, restriction, objection, portability, and consent withdrawal (Section 13), automated decision-making (Section 7), and the right to complain to a local supervisory authority.

Region: United States

Key disclosures: Categories collected, sources, and purposes (Sections 4 to 6). Based on AlphaWeb's current annual revenue and the volume of California residents' data processed, AlphaWeb does not currently meet any of the California Consumer Privacy Act's applicability thresholds (over $26,625,000 in annual revenue, processing 100,000 or more consumers' or households' personal information per year, or deriving 50 percent or more of revenue from selling or sharing personal information). A dedicated “Do Not Sell or Share My Personal Information” mechanism, Global Privacy Control honoring, and a 12-month look-back disclosure are therefore not currently required, and AlphaWeb will revisit this section if any threshold is met. Rights of access, deletion, correction, portability, and non-discrimination under Section 13 remain available regardless.

Region: Canada

Key disclosures: Rights to access and correct personal information, and to complain to the Office of the Privacy Commissioner of Canada or applicable provincial authority; processing on consent or another permitted basis. If AlphaWeb's Canadian user base includes residents of Quebec, Law 25 additionally requires a designated privacy officer whose name and contact information will be provided on request, a breach notification process to Quebec's Commission d'accès à l'information within 30 days, and privacy impact assessments for certain cross-border transfers.

Region: Brazil

Key disclosures: Processing under Brazil's Lei Geral de Proteção de Dados, rights of access, correction, deletion, portability, and information about sharing, and the right to complain to the Autoridade Nacional de Proteção de Dados. AlphaWeb does not currently have a confirmed user base in Brazil.

Region: Australia and New Zealand

Key disclosures: Rights to access and correct personal information, and to complain to the Office of the Australian Information Commissioner or New Zealand Office of the Privacy Commissioner, and overseas disclosure consistent with the Australian Privacy Principles and New Zealand's Privacy Act. New Zealand's Privacy Act applies regardless of company size. Australia currently exempts businesses with annual turnover of 3,000,000 Australian dollars or less, unless a statutory exception applies.

Region: Other jurisdictions

Key disclosures: AlphaWeb has a confirmed customer or end-user base in the United Arab Emirates and wider Middle East. The UAE's Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, together with its Executive Regulation under Cabinet Decision No. 33 of 2024, governs processing of personal data of individuals there, alongside separate free-zone regimes such as the DIFC Data Protection Law that may apply instead. Additional disclosures will be added where AlphaWeb's establishment, marketing, or processing activity makes further jurisdictions relevant.

AlphaWeb has not identified a financial incentive or price or service difference program tied to the collection or sale of personal information.

18. Corporate Transactions and Legal Requests

18.1 Corporate transactions and legal requests.

If AlphaWeb is involved in a merger, acquisition, financing, reorganization, bankruptcy, or asset sale, personal data may transfer to a successor or affiliate as part of that transaction, subject to standard confidentiality arrangements and, where required, notice to affected individuals. We may also disclose personal data where required by valid legal process, or where we believe disclosure is necessary to protect the rights, property, or safety of AlphaWeb, our Customers, or others, or to enforce our agreements.

19. Changes to This Policy

19.1 Updates and notice.

We may update this Policy to reflect changes in our practices or legal requirements, posting an updated effective date and, for a material change, additional notice through the Account or by email at least 15 days before it takes effect. Continued use after a change indicates acceptance for future processing, but does not by itself constitute consent to a materially different purpose that requires consent under applicable law, where we will seek consent separately. We will retain and make available a prior version of this Policy on request.