Privacy Policy

Privacy Policy

Last updated: 29 June 2026

This Privacy Policy explains how Alongtail collects, uses, shares, retains, and protects personal data when you visit our website, contact us, or work with us on process intelligence and automation projects.

Before publishing: replace the bracketed fields, confirm your actual service providers, retention periods, cookie/analytics setup, and have this reviewed against your contracts and local legal requirements.

1. Who we are

Alongtail helps companies understand how work actually happens by mapping workflows, handoffs, decisions, exceptions, and bottlenecks, then building automations, integrations, and tooling to improve those workflows.

For the purposes of this Privacy Policy, “Alongtail,” “we,” “us,” and “our” means [insert legal entity name], with registered office at [insert registered address] and company number [insert company number, if applicable].

Controller contact: [insert privacy email, e.g. privacy@alongtail.eu]. You can also contact us through the contact form on https://alongtail.eu/.

Data Protection Officer: [insert DPO details if appointed, or remove this sentence if no DPO is required/appointed].

2. Scope of this policy

This policy applies to personal data we process as a controller in connection with:

During client projects, we may also process personal data contained in client materials, systems, call recordings, documents, tickets, internal communications, or workflow data. Depending on the project and contract, we may process that data as a processor on behalf of the client, as an independent controller, or as a joint controller. Where we act as a processor, the client’s privacy notice and our data processing agreement with that client govern that processing.

3. Personal data we collect

Contact and enquiry data. Email address, name, company, role, message content, communication preferences, and any information you choose to send us through the website, email, calendar tools, or other channels.

Website and technical data. IP address, device and browser information, pages viewed, time stamps, referral URLs, approximate location inferred from technical data, cookies, similar technologies, and server logs.

Project data. Information shared in workshops, calls, documents, spreadsheets, diagrams, systems, tickets, internal communications, notes, process maps, bottleneck analyses, automation specifications, and deliverables. This may include names, roles, work habits, responsibilities, decision points, approvals, and business context.

Client administration data. Contract details, billing and payment information, purchase orders, tax information, invoices, account contacts, and support history.

Marketing data. Newsletter or update preferences, event attendance, campaign engagement, and opt-out choices, where applicable.

We do not intentionally ask for special-category data, such as health, biometric, political, religious, or trade-union data, unless this is necessary for a specific engagement and covered by appropriate safeguards. Please do not send us sensitive personal data unless we have agreed how it should be handled.

4. How we use personal data and our legal bases

Purpose Examples of data used Legal basis
Respond to enquiries and schedule calls Contact details, company, role, message content, calendar details Steps prior to a contract; legitimate interests in responding to business enquiries
Run discovery, workshops, and diagnostics Workshop notes, workflow descriptions, role and task information Contract performance or steps prior to contract; legitimate interests in understanding workflows; consent where required for recordings or optional processing
Map processes and build automations, integrations, or tooling Client-provided materials, system data, tickets, documents, process maps, specifications, deliverables Contract performance; legitimate interests; processor instructions where we act on behalf of a client
Manage client relationships, contracts, billing, and support Business contact details, contract records, invoices, payment status, support communications Contract performance; legal obligations; legitimate interests in business administration
Improve, secure, and maintain our website and services Website logs, usage data, diagnostics, error reports, security events Legitimate interests in service reliability and security; legal obligations where applicable
Send updates or marketing communications Email address, name, company, preferences, engagement data Consent where required; legitimate interests for relevant business-to-business communications, subject to your right to opt out
Comply with laws and protect rights Records relevant to legal, tax, accounting, compliance, dispute, or security matters Legal obligations; legitimate interests in establishing, exercising, or defending legal claims

5. AI, automation, and client materials

Our work may involve AI-assisted analysis, automation builders, integration platforms, cloud services, and software tools to help structure process information, identify workflow gaps, draft specifications, or build automations.

When we use such tools with client materials, we aim to apply data minimisation, access controls, confidentiality obligations, and appropriate contractual safeguards. We do not intentionally use client confidential information or client personal data to train public AI models unless the client has agreed to that in writing or the processing is otherwise clearly disclosed and lawful.

Clients are responsible for ensuring that personal data they provide to us is shared lawfully and that affected individuals receive any required privacy information, unless we have agreed otherwise in writing.

6. Cookies and similar technologies

We may use strictly necessary cookies and similar technologies to operate the website and contact form. Depending on our website configuration, we may also use analytics or performance tools to understand how visitors use the site.

We will only use non-essential cookies or similar technologies where permitted by applicable law and, where required, with your consent. You can manage cookies through your browser settings and, where available, through our cookie preferences tool.

[Insert the names of analytics, cookie, form, hosting, and marketing tools actually used, or remove this sentence.]

7. Sharing personal data

We may share personal data with:

We do not sell personal data.

8. International transfers

Personal data may be processed in the European Economic Area and in other countries where we or our service providers operate. Where personal data is transferred outside the EEA, UK, or Switzerland, we use appropriate safeguards where required, such as adequacy decisions, Standard Contractual Clauses, or other lawful transfer mechanisms.

9. Retention

We keep personal data only for as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted by law, contract, security, dispute resolution, or legitimate business needs.

Category Typical retention period
Website logs and security records [insert period, e.g. up to 12 months], unless needed longer for security or legal reasons
Enquiries and prospect communications [insert period, e.g. up to 24 months after last contact], unless you ask us to delete earlier or we need the data for another lawful reason
Client contracts, invoices, and accounting records [insert period required by local tax/accounting law, e.g. 7 years]
Project files, process maps, recordings, transcripts, and deliverables [insert project-specific period, e.g. contract term plus 12–36 months], unless the client agreement sets a different period
Marketing preferences and suppression lists Until you unsubscribe or object; suppression records may be kept to respect your opt-out

10. Security

We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures may include access controls, least-privilege permissions, confidentiality obligations, secure configuration, encryption where appropriate, backups, monitoring, and vendor due diligence.

No internet transmission or storage system is completely secure. Please avoid sending unnecessary sensitive information through general website forms.

11. Your rights

Depending on where you live and the applicable law, you may have the right to:

To exercise your rights, contact us at [insert privacy email]. We may need to verify your identity before responding. If you are in Belgium, you can contact the Belgian Data Protection Authority. You may also contact your local supervisory authority.

12. Children

Our website and services are intended for business users and are not directed to children. We do not knowingly collect personal data from children.

13. Links to third-party websites

Our website or communications may link to third-party websites, services, or platforms. Their privacy practices are governed by their own policies, not this Privacy Policy.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we make changes, we will update the “Last updated” date above and, where required, provide additional notice.