Privacy Policy
This Privacy Policy explains how Alongtail collects, uses, shares, retains, and protects personal data when you visit our website, contact us, or work with us on process intelligence and automation projects.
Before publishing: replace the bracketed fields, confirm your actual service providers, retention periods, cookie/analytics setup, and have this reviewed against your contracts and local legal requirements.
1. Who we are
Alongtail helps companies understand how work actually happens by mapping workflows, handoffs, decisions, exceptions, and bottlenecks, then building automations, integrations, and tooling to improve those workflows.
For the purposes of this Privacy Policy, “Alongtail,” “we,” “us,” and “our” means [insert legal entity name], with registered office at [insert registered address] and company number [insert company number, if applicable].
Controller contact: [insert privacy email, e.g. privacy@alongtail.eu]. You can also contact us through the contact form on https://alongtail.eu/.
Data Protection Officer: [insert DPO details if appointed, or remove this sentence if no DPO is required/appointed].
2. Scope of this policy
This policy applies to personal data we process as a controller in connection with:
- our website and contact forms;
- sales, discovery calls, workshops, and business communications;
- client onboarding, contracting, invoicing, and relationship management;
- our own service improvement, security, and compliance activities.
During client projects, we may also process personal data contained in client materials, systems, call recordings, documents, tickets, internal communications, or workflow data. Depending on the project and contract, we may process that data as a processor on behalf of the client, as an independent controller, or as a joint controller. Where we act as a processor, the client’s privacy notice and our data processing agreement with that client govern that processing.
3. Personal data we collect
Contact and enquiry data. Email address, name, company, role, message content, communication preferences, and any information you choose to send us through the website, email, calendar tools, or other channels.
Website and technical data. IP address, device and browser information, pages viewed, time stamps, referral URLs, approximate location inferred from technical data, cookies, similar technologies, and server logs.
Project data. Information shared in workshops, calls, documents, spreadsheets, diagrams, systems, tickets, internal communications, notes, process maps, bottleneck analyses, automation specifications, and deliverables. This may include names, roles, work habits, responsibilities, decision points, approvals, and business context.
Client administration data. Contract details, billing and payment information, purchase orders, tax information, invoices, account contacts, and support history.
Marketing data. Newsletter or update preferences, event attendance, campaign engagement, and opt-out choices, where applicable.
We do not intentionally ask for special-category data, such as health, biometric, political, religious, or trade-union data, unless this is necessary for a specific engagement and covered by appropriate safeguards. Please do not send us sensitive personal data unless we have agreed how it should be handled.
4. How we use personal data and our legal bases
| Purpose | Examples of data used | Legal basis |
|---|---|---|
| Respond to enquiries and schedule calls | Contact details, company, role, message content, calendar details | Steps prior to a contract; legitimate interests in responding to business enquiries |
| Run discovery, workshops, and diagnostics | Workshop notes, workflow descriptions, role and task information | Contract performance or steps prior to contract; legitimate interests in understanding workflows; consent where required for recordings or optional processing |
| Map processes and build automations, integrations, or tooling | Client-provided materials, system data, tickets, documents, process maps, specifications, deliverables | Contract performance; legitimate interests; processor instructions where we act on behalf of a client |
| Manage client relationships, contracts, billing, and support | Business contact details, contract records, invoices, payment status, support communications | Contract performance; legal obligations; legitimate interests in business administration |
| Improve, secure, and maintain our website and services | Website logs, usage data, diagnostics, error reports, security events | Legitimate interests in service reliability and security; legal obligations where applicable |
| Send updates or marketing communications | Email address, name, company, preferences, engagement data | Consent where required; legitimate interests for relevant business-to-business communications, subject to your right to opt out |
| Comply with laws and protect rights | Records relevant to legal, tax, accounting, compliance, dispute, or security matters | Legal obligations; legitimate interests in establishing, exercising, or defending legal claims |
5. AI, automation, and client materials
Our work may involve AI-assisted analysis, automation builders, integration platforms, cloud services, and software tools to help structure process information, identify workflow gaps, draft specifications, or build automations.
When we use such tools with client materials, we aim to apply data minimisation, access controls, confidentiality obligations, and appropriate contractual safeguards. We do not intentionally use client confidential information or client personal data to train public AI models unless the client has agreed to that in writing or the processing is otherwise clearly disclosed and lawful.
Clients are responsible for ensuring that personal data they provide to us is shared lawfully and that affected individuals receive any required privacy information, unless we have agreed otherwise in writing.
6. Cookies and similar technologies
We may use strictly necessary cookies and similar technologies to operate the website and contact form. Depending on our website configuration, we may also use analytics or performance tools to understand how visitors use the site.
We will only use non-essential cookies or similar technologies where permitted by applicable law and, where required, with your consent. You can manage cookies through your browser settings and, where available, through our cookie preferences tool.
[Insert the names of analytics, cookie, form, hosting, and marketing tools actually used, or remove this sentence.]
7. Sharing personal data
We may share personal data with:
- service providers and processors, such as website hosting providers, email and calendar providers, form tools, CRM tools, analytics providers, cloud infrastructure providers, AI platform providers, project management tools, automation platforms, payment processors, and IT/security vendors;
- client-authorised systems and integration partners, where this is necessary to deliver a project or connect workflows;
- professional advisers, such as lawyers, accountants, auditors, insurers, and consultants;
- authorities or courts, where required by law or necessary to protect rights, safety, security, or legal interests;
- successors or transaction parties, if we are involved in a merger, acquisition, financing, restructuring, or sale of assets.
We do not sell personal data.
8. International transfers
Personal data may be processed in the European Economic Area and in other countries where we or our service providers operate. Where personal data is transferred outside the EEA, UK, or Switzerland, we use appropriate safeguards where required, such as adequacy decisions, Standard Contractual Clauses, or other lawful transfer mechanisms.
9. Retention
We keep personal data only for as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted by law, contract, security, dispute resolution, or legitimate business needs.
| Category | Typical retention period |
|---|---|
| Website logs and security records | [insert period, e.g. up to 12 months], unless needed longer for security or legal reasons |
| Enquiries and prospect communications | [insert period, e.g. up to 24 months after last contact], unless you ask us to delete earlier or we need the data for another lawful reason |
| Client contracts, invoices, and accounting records | [insert period required by local tax/accounting law, e.g. 7 years] |
| Project files, process maps, recordings, transcripts, and deliverables | [insert project-specific period, e.g. contract term plus 12–36 months], unless the client agreement sets a different period |
| Marketing preferences and suppression lists | Until you unsubscribe or object; suppression records may be kept to respect your opt-out |
10. Security
We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures may include access controls, least-privilege permissions, confidentiality obligations, secure configuration, encryption where appropriate, backups, monitoring, and vendor due diligence.
No internet transmission or storage system is completely secure. Please avoid sending unnecessary sensitive information through general website forms.
11. Your rights
Depending on where you live and the applicable law, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of your data;
- request restriction of processing;
- object to processing based on legitimate interests, including direct marketing;
- request data portability where applicable;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with a data protection authority.
To exercise your rights, contact us at [insert privacy email]. We may need to verify your identity before responding. If you are in Belgium, you can contact the Belgian Data Protection Authority. You may also contact your local supervisory authority.
12. Children
Our website and services are intended for business users and are not directed to children. We do not knowingly collect personal data from children.
13. Links to third-party websites
Our website or communications may link to third-party websites, services, or platforms. Their privacy practices are governed by their own policies, not this Privacy Policy.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make changes, we will update the “Last updated” date above and, where required, provide additional notice.