Legal
Privacy Policy
Last updated
This policy explains what personal data ALPHA DIGI SOLUTIONS Ltd. Liability Company ("Alpha Digi Solutions", "we", "us") collects through alphadigisol.com, why we collect it, who we share it with, how long we keep it, and the rights you have over it. We have written it in plain language rather than boilerplate, and it describes what this website actually does.
1.Who we are and how to reach us
ALPHA DIGI SOLUTIONS Ltd. Liability Company is the data controller for personal data collected through this website.
- Postal address: 312 W 2nd St, Unit #A7060, Casper, WY 82601, US
- Email: info@alphadigisol.com
- Telephone: +1 857 758 7197
We are a US company and we work with clients in the United States, the United Kingdom, and Canada. If you are in the UK or the European Economic Area, sections 8 and 9 describe how your data is transferred and what additional rights you have.
If you would prefer a named contact for a privacy question, email the address above with "Privacy request" in the subject line and it will be routed to the person responsible.
2.What this policy covers
This policy covers the alphadigisol.com website: the pages you browse, the forms you submit, the free tools on the site, and the calls you book with us.
It does not cover data we process on behalf of a client during a paid engagement. When we build automation systems, we generally work inside infrastructure and accounts that the client controls, and we act as a processor rather than a controller. That relationship is governed by the written agreement and, where applicable, the data processing agreement for that engagement, not by this policy. See section 6.
It also does not cover third-party websites you reach from links on this site. Those have their own policies.
3.Personal data we collect
Information you give us directly
When you submit a contact form, request a walkthrough, or use a form-gated tool on this site, we collect what you type into it:
- Name and email address. These are required to reply to you.
- Optionally, your company name, your role, a fund name, and the service or workflow you are interested in.
- The message describing what you are trying to automate, plus which audience option you selected (growing business, mid-market, or private equity).
Form submissions are sent to a form handler on our own server, which validates them and delivers them to our business inbox by email. We do not push them into a third-party CRM, and this website does not store submissions in a database.
If you book a call, the scheduling is handled by Calendly and you provide your name, email, and the time slot directly to them. See section 7.
If you email or telephone us, we keep that correspondence so we have a record of the conversation.
Information collected automatically
Like almost every website, ours records technical information when you visit:
- Your IP address, which also gives an approximate location at city or region level, never a precise one.
- Your browser and operating system, device type, and screen size.
- The pages you view, the page that referred you, and timestamps.
- Server log data generated by our hosting provider, kept for security and troubleshooting.
Session recording and heatmaps
We use Microsoft Clarity to understand how people actually use the site. Clarity records interaction events, mouse movement, clicks, scrolling, and page navigation, and reconstructs them as a session replay and as aggregated heatmaps. It is enabled with Clarity's default masking, which is designed to exclude the text you type into form fields from recordings.
We use this to find usability problems, for example a form step people abandon or a section nobody scrolls to. We do not use it to identify individuals, and we do not attempt to link a recording to a named person.
What we do not collect
We do not ask for and do not want payment card details through this website, government identifiers, health data, or any other special category data. Please do not send those to us through a web form.
4.Why we use it, and our legal basis
If you are in the UK or EEA, the UK GDPR and EU GDPR require us to identify a legal basis for each purpose. These are ours:
| Purpose | Data used | Legal basis |
|---|---|---|
| Replying to your enquiry and scoping possible work | Form fields, email and call correspondence | Legitimate interests, and steps taken at your request prior to entering a contract |
| Delivering an engagement you have signed up for | Contact and company details | Performance of a contract |
| Measuring how the site is used, so we can improve it | Analytics and session recording data | Consent where required, otherwise legitimate interests |
| Keeping the site secure and diagnosing faults | Server logs, IP address | Legitimate interests |
| Sending you information you asked for, such as an audit result | Name, email | Consent |
| Meeting accounting, tax, and other legal duties | Transaction and contract records | Legal obligation |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we have limited what we collect accordingly. You can object to that processing at any time. See section 9.
We do not carry out automated decision-making or profiling that produces legal effects for you.
We do not use your enquiry to add you to a marketing list without your consent, and we do not sell personal data. See section 10.
6.Client data during an engagement
This section matters most to clients rather than website visitors, and it is the commitment we consider most important.
- We build inside infrastructure and accounts that you control wherever the work allows it, using credentials and permissions you grant and can revoke.
- We do not use your business data, your customer data, or your documents to train any AI model of ours, and we do not permit it to be used to train a third-party provider's general models. Where a system we build calls a third-party AI provider, we configure it to use the provider's no-training path where the provider offers one.
- We do not move your data outside the environment you have approved except where you explicitly direct it.
- We access only what a given piece of work requires, and we ask you to remove our access when an engagement ends.
- Private equity engagements are covered by an NDA. References are provided under NDA only.
Where we act as a processor for you, the governing terms are the written agreement and data processing agreement for that engagement. Those terms take precedence over this policy for that data. If you need a DPA, a sub-processor list, or a security questionnaire completed, email us.
8.International transfers and how long we keep data
International transfers
We are based in the United States and our hosting is in the United States, so if you contact us from the UK, the EEA, or elsewhere, your data is transferred to the US.
Where we transfer personal data out of the UK or EEA, we rely on an appropriate safeguard under Article 46 of the GDPR, which in practice means the UK International Data Transfer Agreement or Addendum, or the European Commission's Standard Contractual Clauses, in our contract with the relevant provider. Google and Microsoft additionally self-certify under the EU-US and UK extension of the Data Privacy Framework. You can ask us which mechanism applies to a specific provider.
Retention
| Data | How long we keep it |
|---|---|
| Enquiries that do not become an engagement | Up to 24 months from your last contact with us, then deleted |
| Client contract and correspondence records | For the engagement, then as long as tax, accounting, and limitation periods require |
| Server and security logs | A short rolling window set by our hosting provider |
| Analytics and session recording data | For the retention period set by Google and Microsoft for those products, as described in their policies above |
If you ask us to delete your data sooner, we will, unless we are required to keep it. See section 9.
9.Your rights
To exercise any right below, email info@alphadigisol.com. We will not charge you, and we will respond within one month, or within 45 days for a request under California law. We may extend that once for complex requests and will tell you if we do. We may need to verify your identity before acting, which usually means confirming you control the email address in our records.
If you are in the UK or the EEA
- Access a copy of the personal data we hold about you.
- Have inaccurate data corrected.
- Have your data erased where there is no overriding reason for us to keep it.
- Restrict how we use your data while a dispute is resolved.
- Receive your data in a portable, machine-readable format.
- Object to processing we base on legitimate interests, including any direct marketing, which we will stop on request without exception.
- Withdraw a consent you previously gave, at any time, without affecting processing that already took place.
You also have the right to complain to a supervisory authority. In the UK that is the Information Commissioner's Office. In the EEA it is the authority for your country. We would appreciate the chance to resolve the issue first, but you are not required to come to us before complaining.
If you are in California
Under the CCPA as amended by the CPRA, you have the right to know what personal information we collect and how we use and disclose it, to request that we delete it, to request that we correct it, to opt out of any sale or sharing of it, and to limit the use of sensitive personal information. You may not be discriminated against for exercising these rights, and you can use an authorized agent.
In the twelve months before the date of this policy we have not sold personal information, and we have not shared it for cross-context behavioral advertising. We do not knowingly collect or sell the personal information of anyone under 16.
The categories we collect are identifiers, commercial information, and internet or network activity, as described in section 3. We disclose those categories to the service providers in section 7 for the business purposes in section 4.
Do Not Track and Global Privacy Control
There is no consistent industry standard for Do Not Track, so this site does not respond to a DNT header. We do honor a Global Privacy Control signal as an opt out of sale or sharing where it applies, which for us is a formality because we do not sell or share personal information.
10.Security, children, and changes to this policy
Security
This site is served only over HTTPS with HSTS, so traffic between you and us is encrypted in transit. We set hardening headers at the server level, including HSTS, MIME-type sniffing protection, clickjacking protection, and a referrer policy. Access to our business inbox and to client systems is restricted to the people who need it and protected by multi-factor authentication.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach that is likely to result in a risk to your rights, we will notify the relevant regulator and, where required, you.
Children
Our services are sold to businesses, and this site is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email us and we will delete it.
Changes
We will update this policy when what we do changes. The date at the top always reflects the current version. If a change materially affects how we use data you have already given us, we will take reasonable steps to tell you rather than relying on this page alone.
Questions about this document? Email info@alphadigisol.com or write to ALPHA DIGI SOLUTIONS Ltd. Liability Company, 312 W 2nd St, Unit #A7060, Casper, WY 82601, US.