Privacy Policy
Effective Date: 15 July 2026
Introduction
This Privacy Policy explains how AlphaWeb and AlphaWeb.AI (“AlphaWeb,” “we,” “us”), collects, uses, shares, and protects personal data in connection with the AlphaWeb agentic operating system and related websites, applications, and services (the “Services”).
This Policy applies to website visitors, audit applicants, Customers and their Account owners, administrators, and Authorized Users, individuals using the Services personally, and, more narrowly, the end customers and other individuals whose personal data a Customer submits to or generates through the Services. This Policy does not cover third party websites, applications, or services we integrate with but do not operate, each with its own privacy practices.
1. Scope and Identity
1.1 Who we are and contact.
The Services are operated by Alpha Labs EE d.o.o., registered in Croatia. Questions about this Policy can be sent to support@alphaweb.ai.
1.2 Scope.
This Policy covers the AlphaWeb website and Services at alphaweb.ai and not third party integrations under Section 9.
2. Our Privacy Roles
2.1 Two different roles.
AlphaWeb processes personal data in two capacities, and the applicable rules depend on which capacity applies to the specific data. For data we collect for our own purposes, such as website visitors, audit applicants, Account administrators, billing contacts, and our own marketing lists, AlphaWeb decides how and why it is processed, and this Policy describes those purposes directly.
2.3 Where we act on a Customer's behalf.
For data a Customer submits or generates about its own end customers, contacts, or personnel (for example, order, attribution, or lifecycle marketing data), AlphaWeb generally processes it only as instructed, to provide the Services. The Customer, not AlphaWeb, is primarily responsible for deciding how that data is used and for responding to privacy rights requests; an individual may need to contact the relevant Customer directly, as described in Section 13.7. Some processing, such as fraud prevention, platform security, and de-identified analytics, is nonetheless carried out by AlphaWeb for its own legitimate operational purposes even where data originated from a Customer's use of the Services, as described with legal bases in Section 6.
3. Who This Policy Covers
| Category | Description |
|---|---|
| Website visitors | People who browse our website without creating an Account. |
| Prospective customers and audit applicants | People who apply for an audit, consultation, or demo. |
| Customers and Account owners | The entities we contract with and the individuals who administer their Accounts. |
| Authorized Users | Employees or contractors who use the Services under a Customer’s Account. |
| Consumer Customers | Individuals who use the Services in a personal, non-business capacity. |
| Support contacts | People who contact our support team, regardless of Account status. |
| Integration users | People whose accounts on a connected third party service interact with the Services. |
| People whose data a Customer uploads | End customers and leads whose data a Customer submits, per Section 2.3. |
| Newsletter subscribers | People who subscribe to AlphaWeb’s own marketing communications. |
4. Personal Data We Collect
The table below describes categories of personal data AlphaWeb may collect, based on company materials reviewed for this Policy. We do not collect a category unless relevant to operating the Services for that category of person.
| Category | Examples | Source | Typical purpose |
|---|---|---|---|
| Identity and contact information | Name, business email, phone, job title | Directly, or via an inviting Customer | Account creation, communication, support |
| Account and authentication information | Login credentials, API keys, session data | Directly, or via the Customer | Account access and security |
| Business information | Company name, website, industry, revenue or GMV band | The applicant, Business Customer, or public sources | Application review and onboarding |
| Billing and transaction information | Billing contact, tokenized payment details, invoice history | The Business Customer and our payment processor | Billing and fee collection |
| Device, usage, and location information | Browser type, device identifiers, feature usage, IP address, approximate location | Automatically, via the website and Services | Product operation, security, fraud prevention, analytics |
| Cookie and tracking identifiers | Cookie IDs, pixel identifiers | Automatically, per Section 8 | Analytics, and where enabled, advertising |
| Support communications | Messages, call notes, attachments | Directly from the individual | Customer support |
| Customer Data submitted by a Business Customer | Order, pricing, attribution, and end customer data via integrations | The Business Customer or its connected platforms | Providing the Services, per Section 2.3 |
| Prompts and AI interaction data | Instructions and content submitted to the platform and generated Output | The Customer submitting the prompt | Operating AI features per Section 7 |
| Marketing preferences | Subscription status, communication preferences | Directly from the individual | Sending or suppressing marketing communications |
5. Sources of Information
We may receive personal data directly from the individual (for example, applying for an audit or contacting support); from a Customer (for example, inviting an Authorized User or submitting end customer data); from devices and browsers through cookies under Section 8; from integrations the Customer connects under Section 9; from service providers who help operate the Services; from publicly available sources when reviewing an application; and from payment processors in connection with billing.
6. How We Use Personal Data and Our Legal Bases
| Purpose | Description | Legal basis (where GDPR-style bases apply) |
|---|---|---|
| Providing the Services | Operating the platform | Performance of a contract |
| Creating and administering Accounts | Setup, role management, authentication | Performance of a contract |
| Reviewing applications | Evaluating audit or onboarding applications | Legitimate interest, or pre-contract steps at the individual’s request |
| Billing | Charging fees, invoicing, payment methods | Performance of a contract; legal obligation |
| Customer support | Responding to support requests | Performance of a contract; legitimate interest |
| Security and fraud prevention | Detecting and preventing unauthorized access, fraud, and abuse | Legitimate interest; legal obligation in some cases |
| Legal compliance | Responding to legal requests, meeting regulatory obligations | Legal obligation |
| Product analytics and improvement | Understanding feature usage, generally de-identified | Legitimate interest |
| AI functionality | Operating AlphaBrain and Teammate features per Section 7 | Performance of a contract; legitimate interest |
| Marketing communications | Product updates or marketing, per Section 14 | Consent, where required; legitimate interest with opt-out |
| Enforcing agreements | Enforcing the Terms, investigating violations | Legitimate interest; performance of a contract |
| Corporate transactions | Due diligence and data transfer for a merger, per Section 18 | Legitimate interest; legal obligation |
Where we rely on legitimate interests, the specific interest is identified above, and we balance it against the individual's rights rather than using it as a generic catch-all basis.
7. AI and Automated Processing
7.1 What uses AI and what data is submitted.
AlphaWeb uses AI to generate recommendations, content, and creative assets, and, where configured with sufficient autonomy, to take actions such as adjusting campaigns within the guardrails a Customer configures. Data submitted may include Customer Content, Customer Data, and prompts entered by an Authorized User, per Section 4.
7.2 Third party AI providers and training practices.
Certain AI capabilities may be powered in part by third party model providers. AlphaWeb does not use Customer Content or Customer Data to train shared or general purpose AI models offered to the public, and Customer data remains isolated from other customers' environments. AlphaWeb uses de-identified or aggregated data to monitor, maintain, improve, and train AlphaWeb's own proprietary platform and models. Because this data does not identify a specific individual, no separate opt-out is offered for this use.
7.3 Human review and automated decisions.
Company materials state each workflow can be configured from “requires approval” to “fully autonomous,” with higher stakes actions gated for the Customer's own approval and an audit trail of actions taken, so the degree of human review depends substantially on how the Customer configures each workflow. AlphaWeb does not use AI within the Services to make solely automated decisions producing legal or similarly significant effects on individual consumers (for example, denying credit, employment, or insurance), except where a Business Customer configures the Services to do so as part of its own operations, in which case that Customer is responsible for compliance with applicable law. An individual with questions about how an AI feature processed their data can contact us using the details in Section 20.
8. Cookies and Similar Technologies
8.1 Categories and consent.
The website and Services may use strictly necessary, preference, analytics, and, where enabled, advertising or marketing cookies used to measure our own campaign performance. Where required by law, we will request consent before setting non-essential cookies.
8.2 Controls and third party cookies.
Individuals can control cookies through browser settings and, where applicable, platform signals such as Global Privacy Control. Some cookies may be set by third party analytics or advertising providers, who may independently process resulting data.
9. How We Share Personal Data
We may share personal data with the following recipients, each processing data only as necessary for the purpose described:
| Recipient category | Purpose | Relationship |
|---|---|---|
| Hosting and infrastructure providers | Storing and running the Services | Processor or service provider |
| Payment processors (for example, Stripe, Adyen, PayPal) | Processing payments | Processor, service provider, or independent controller depending on the provider’s role |
| Ecommerce, advertising, and lifecycle platforms connected by the Customer (for example, Shopify, Meta, Google, TikTok, Klaviyo) | Enabling the connected integration | Typically independent controllers of their own platforms, acting at the Customer’s direction |
| AI model providers | Powering certain AI features per Section 7 | Processor or subprocessor |
| Support, communications, and analytics providers | Operating support, messaging, and analytics tools | Processor or service provider |
| Professional advisers | Legal, accounting, and other services | Independent controller, bound by confidentiality |
| Customers and their administrators | Sharing an Authorized User’s data with the inviting Customer | Controller of its own workforce data |
| Authorities and transaction parties | Legal requests per Section 18; corporate transactions per Section 18 | As required by law, or as applicable |
We have not confirmed the complete current list of subprocessors and vendors above. We have also not independently verified, against applicable law's specific definitions (including the California Consumer Privacy Act), whether any disclosure above, particularly to advertising or analytics providers, would be a “sale” or “sharing” of personal data.
10. International Data Transfers
10.1 Cross border processing and safeguards.
Because AlphaWeb and its service providers may operate in different countries than the individuals whose data is processed, personal data may be transferred to and processed in another country, potentially including the United States. Where personal data moves from the EEA, UK, or Switzerland to a country without an adequacy finding, AlphaWeb will rely on an appropriate mechanism such as the EU Standard Contractual Clauses or the UK International Data Transfer Agreement or Addendum; where a transfer is made to a country with an applicable adequacy decision, AlphaWeb relies on that decision instead.
11. Data Retention
We retain personal data for as long as necessary for the purposes described in this Policy, and in particular:
| Data category | Retention approach |
|---|---|
| Active Account data | For as long as the Account remains active |
| Closed Account data | Retention period after account closure – 30 days |
| Customer Data submitted by a Customer | For the agreement term, then deleted or returned per Section 9.10 of the Terms |
| Backups | Limited encrypted retention after deletion, 90 days |
| Billing, support, and security records | BILLING RECORD RETENTION PERIOD \u2013 5 years SUPPORT RECORD RETENTION PERIOD \u2013 2 years SECURITY LOG RETENTION PERIOD \u2013 1 year |
| Marketing records | Until unsubscribe or deletion request, plus a limited suppression period |
| Cookie data | Per the cookie’s expiry, generally no longer than 13 months |
| Legal holds and de-identified data | Legal holds: for as long as required. De-identified or aggregated data: may be retained indefinitely as it no longer identifies an individual |
We do not promise immediate deletion in every case, because some data must be retained temporarily in backups or to meet a legal obligation.
12. Security
12.1 General approach and certifications.
General approach and certifications. AlphaWeb's public materials describe its security measures, including encryption in transit and at rest, access controls, and tenant isolation between customer environments. AlphaWeb is in the process of obtaining SOC 2 Type II and ISO 27001 certifications, and describes its infrastructure as GDPR and CCPA ready. These statements are AlphaWeb's own public representations, made at a level of detail that does not disclose exploitable information about its systems.
12.2 Access controls and incident response.
Access to personal data is intended to be limited to personnel and systems that need it, with monitoring to detect anomalous activity. No system is completely secure, and AlphaWeb cannot guarantee absolute security of personal data.
13. Your Privacy Rights
13.1 Rights, requests, and verification.
Depending on location, individuals may have some or all of the following rights: access, correction, deletion, restriction, objection, portability, withdrawal of consent, opting out of certain marketing or of sale or sharing where applicable, limiting use of sensitive data, appeal, and non-discrimination for exercising these rights. A request can be submitted to support@alphaweb.ai. We take reasonable steps to verify the requester's identity, and where permitted by law, an authorized agent may submit a request subject to appropriate verification.
13.2 Response time and limitations.
We aim to respond to a verified request within the time required by applicable law. We may decline or limit a request where permitted by law, for example where it would reveal another individual's data.
13.3 Processor held data and complaints.
Where a request concerns data we process on a Customer's behalf under Section 2.3, we will direct the individual to that Customer or, where legally required, forward the request. An individual dissatisfied with our response may complain using the contact details in Section 20, and, where applicable, to their local supervisory authority under Section 17.
14. Marketing Communications
14.1 Types, consent, and opt-out.
We may send product announcements, marketing communications, and transactional communications necessary to operate the Services (such as billing notices), the last of which cannot be opted out of while the Account is active. Where required by law, we obtain consent before sending marketing communications, and in all cases provide an unsubscribe mechanism and honor opt-out requests sent to. Opting out of marketing does not affect transactional or account related communications.
15. Children's Privacy
15.1 Intended audience and parental requests.
The Services are intended for businesses and individuals meeting the minimum age in the Terms of Service, currently 18 years old, and are not directed to children below that age. A parent or guardian who believes a child provided personal data directly to AlphaWeb inconsistent with this Policy may contact support@alphaweb.ai to request deletion.
15.2 Children's data submitted by a Customer.
Where a Customer's own end customers include minors, resulting data is handled as Customer Data under Section 2.3, and the Customer is responsible for a lawful basis, including any required parental consent.
16. Sensitive Personal Data
16.1 General approach.
AlphaWeb does not intentionally collect sensitive personal data, such as health information, racial or ethnic origin, religious beliefs, or precise geolocation revealing such categories, about Account owners, Authorized Users, or Consumer Customers for its own purposes.
16.2 Sensitive data submitted by a Customer.
A Customer's own end customer data may incidentally include data treated as sensitive under some laws (for example, health related purchase data). Customers should not submit sensitive personal data beyond what is reasonably necessary for core commerce, marketing, and analytics functionality, and remain responsible for lawful handling.
17. Regional Privacy Disclosures
Because the Services are offered worldwide, the following region-specific provisions apply where relevant.
Region: EEA, UK, and Switzerland
Key disclosures: Controller identity (Section 1), legal bases (Section 6), international transfers (Section 10), rights including access, rectification, erasure, restriction, objection, portability, and consent withdrawal (Section 13), automated decision-making (Section 7), and the right to complain to a local supervisory authority.
Region: United States
Key disclosures: Categories collected, sources, and purposes (Sections 4 to 6). Based on AlphaWeb's current annual revenue and the volume of California residents' data processed, AlphaWeb does not currently meet any of the California Consumer Privacy Act's applicability thresholds (over $26,625,000 in annual revenue, processing 100,000 or more consumers' or households' personal information per year, or deriving 50 percent or more of revenue from selling or sharing personal information). A dedicated “Do Not Sell or Share My Personal Information” mechanism, Global Privacy Control honoring, and a 12-month look-back disclosure are therefore not currently required, and AlphaWeb will revisit this section if any threshold is met. Rights of access, deletion, correction, portability, and non-discrimination under Section 13 remain available regardless.
Region: Canada
Key disclosures: Rights to access and correct personal information, and to complain to the Office of the Privacy Commissioner of Canada or applicable provincial authority; processing on consent or another permitted basis. If AlphaWeb's Canadian user base includes residents of Quebec, Law 25 additionally requires a designated privacy officer whose name and contact information will be provided on request, a breach notification process to Quebec's Commission d'accès à l'information within 30 days, and privacy impact assessments for certain cross-border transfers.
Region: Brazil
Key disclosures: Processing under Brazil's Lei Geral de Proteção de Dados, rights of access, correction, deletion, portability, and information about sharing, and the right to complain to the Autoridade Nacional de Proteção de Dados. AlphaWeb does not currently have a confirmed user base in Brazil.
Region: Australia and New Zealand
Key disclosures: Rights to access and correct personal information, and to complain to the Office of the Australian Information Commissioner or New Zealand Office of the Privacy Commissioner, and overseas disclosure consistent with the Australian Privacy Principles and New Zealand's Privacy Act. New Zealand's Privacy Act applies regardless of company size. Australia currently exempts businesses with annual turnover of 3,000,000 Australian dollars or less, unless a statutory exception applies.
Region: Other jurisdictions
Key disclosures: AlphaWeb has a confirmed customer or end-user base in the United Arab Emirates and wider Middle East. The UAE's Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, together with its Executive Regulation under Cabinet Decision No. 33 of 2024, governs processing of personal data of individuals there, alongside separate free-zone regimes such as the DIFC Data Protection Law that may apply instead. Additional disclosures will be added where AlphaWeb's establishment, marketing, or processing activity makes further jurisdictions relevant.
AlphaWeb has not identified a financial incentive or price or service difference program tied to the collection or sale of personal information.
18. Corporate Transactions and Legal Requests
18.1 Corporate transactions and legal requests.
If AlphaWeb is involved in a merger, acquisition, financing, reorganization, bankruptcy, or asset sale, personal data may transfer to a successor or affiliate as part of that transaction, subject to standard confidentiality arrangements and, where required, notice to affected individuals. We may also disclose personal data where required by valid legal process, or where we believe disclosure is necessary to protect the rights, property, or safety of AlphaWeb, our Customers, or others, or to enforce our agreements.
19. Changes to This Policy
19.1 Updates and notice.
We may update this Policy to reflect changes in our practices or legal requirements, posting an updated effective date and, for a material change, additional notice through the Account or by email at least 15 days before it takes effect. Continued use after a change indicates acceptance for future processing, but does not by itself constitute consent to a materially different purpose that requires consent under applicable law, where we will seek consent separately. We will retain and make available a prior version of this Policy on request.