Privacy Policy
This Privacy Policy explains how AlphaClone Systems collects, uses, stores, and protects your personal information. Read it in full before using our platform.
1. Data Controller
The data controller responsible for your personal information is:
Alphaclone Systems, LLC
30 N Gould St, Sheridan, WY 82801, USA
Wyoming, USA · Filing ID 2026-002002581
Email: [email protected]
Data Protection Officer (DPO): [email protected]
Website: https://alphaclonesystems.com
2. Data We Collect
2.1 Account & Identity Data
When you register an account, we collect: full name, email address, password (stored as a salted bcrypt hash — never in plain text), company name, phone number (optional), profile photo (optional), timezone, and country.
2.2 Business Operational Data
Data you create or import while using the platform, including: CRM contact records, invoice and quote data, contract documents, financial records (journal entries, expenses, chart of accounts), project and task records, calendar events, meeting recordings (stored in your workspace only), and team member information.
2.3 Google API Data (Gmail Integration)
When you connect Gmail, AlphaClone requests the following Google OAuth scopes:
- gmail.readonly — to display your inbox within the platform
- gmail.send — to send emails on your behalf from within the platform
- gmail.compose — to draft and compose emails
- gmail.modify — to label and manage emails (e.g., mark as read)
What we do NOT do with Gmail data:
- We do not store your email content on AlphaClone servers
- We do not use Gmail data for advertising or marketing purposes
- We do not share Gmail data with third parties outside of processing your request
- We do not allow humans to read your email content unless you explicitly request support access
- We do not use Gmail data to train AI models
Gmail data is retrieved in real time via Google's API and displayed only to the authenticated user. You can revoke AlphaClone's Gmail access at any time from your Google Account Permissions page.
2.4 LinkedIn API & Lead Gen Forms Data
When you authorize LinkedIn OAuth integration, AlphaClone requests access to requested product scopes including: openid, profile, email, r_basicprofile, r_profile_basicinfo, w_member_social, w_organization_social, r_organization_social, r_organization_admin, rw_organization_admin, r_ads, rw_ads, r_ads_reporting, r_events, rw_events, r_1st_connections_size, and r_verify.
LinkedIn Lead Gen Forms & Lead Data Processing:
- When prospects submit a LinkedIn Lead Gen Form connected to your account, form responses (such as full name, email address, company name, job title, and phone number) are securely received via real-time webhooks or API sync.
- Lead data is mapped directly into your AlphaClone CRM leads table to enable automated follow-ups and lead management.
- We do not sell, share, or monetize LinkedIn lead data with any unauthorized third parties.
- You retain full control to modify, export, or delete lead records at any time within your workspace.
2.5 Calendly Integration & Scheduling Data
When you connect Calendly via OAuth, AlphaClone retrieves event types, scheduled meetings, invitee names, email addresses, and event details solely to sync booking availability and auto-ingest meeting invitees into your CRM leads and calendar. OAuth access tokens are stored using AES-256 encryption at rest.
2.6 Microsoft 365, Outlook, Calendar & Tasks Data
When you connect Microsoft 365, AlphaClone may process mailbox metadata, selected email content, calendar events, meeting details, task lists, user profile information, and OAuth tokens solely to provide inbox sync, email sending, calendar scheduling, task sync, CRM matching, and user-requested automation. Microsoft data is scoped to your connected account and workspace, and access can be revoked from your Microsoft account or AlphaClone integration settings.
2.7 Meta, Facebook, Instagram & WhatsApp Business Data
When you connect Meta products, AlphaClone may process Facebook Page details, Instagram business profile data, post content, media assets, comments, direct business messages, Lead Ads form responses, WhatsApp Business message metadata, delivery status, phone numbers, and consent/opt-out signals. This data is used only for publishing, inbox sync, lead capture, CRM updates, and user-requested customer communication workflows.
2.8 AI Assistant, Bonnie & Hermes Runtime Data
AI prompts, tool calls, execution logs, approvals, task plans, and agent run metadata may be stored in your workspace for auditability, recovery, debugging, and user-visible history. External actions such as sending messages, publishing posts, billing changes, or sensitive data access are governed by platform policy, user permissions, and approval controls where applicable. We do not use your workspace data to train third-party foundation models unless you separately agree in writing.
2.9 Usage & Technical Data
We automatically collect technical data when you use the platform: IP address, browser type and version, operating system, device type, pages visited, features used, session duration, and error logs. This data is used for platform security, debugging, and improving the user experience.
2.10 Payment Data
Payment processing is handled entirely by Stripe, Inc. AlphaClone never stores, processes, or has access to your credit card details. What we retain is limited to: Stripe Customer ID, subscription plan details, billing address, and payment history (invoice amounts and dates). See Stripe's Privacy Policy for how they handle payment data.
2.11 AI Growth Agent Data
The AI Growth Agent uses publicly available business directory data to identify prospective leads. We do not scrape private data or use data obtained through unauthorized means. Outreach conversations managed by the AI agent are stored in your workspace and are not accessible to other users or AlphaClone staff without your consent.
2.12 Model Context Protocol (MCP) AI Agent Data
AlphaClone's MCP server enforces strict technical controls: all data is scoped to your tenant workspace only, DELETE and DDL operations are blocked, and credentials/secrets are never transmitted. MCP access tokens are user-generated and can be revoked at any time from Settings → Integrations → MCP.
3. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), United Kingdom, and other GDPR-applicable jurisdictions, our legal basis for processing your data is:
Contract Performance (Art. 6(1)(b) GDPR)
Processing necessary to provide the services you've subscribed to — account management, invoicing, CRM functionality, and platform features.
Legitimate Interests (Art. 6(1)(f) GDPR)
Platform security monitoring, fraud prevention, technical debugging, and product improvement analytics.
Legal Obligation (Art. 6(1)(c) GDPR)
Responding to lawful government or court orders, tax compliance, and financial record-keeping obligations.
Consent (Art. 6(1)(a) GDPR)
Non-essential cookies (analytics, marketing), Gmail API access, and marketing communications. You may withdraw consent at any time.
4. How We Use Your Data
- Providing and operating the AlphaClone Business OS platform and its features
- Sending transactional emails (account verification, password reset, invoice confirmations)
- Processing subscription payments and managing billing through Stripe
- Providing customer support and responding to your enquiries
- Detecting, investigating, and preventing security threats and fraudulent activity
- Improving platform performance, debugging errors, and developing new features
- Sending product update notifications and feature announcements (you may opt out at any time)
- Complying with legal obligations including tax, financial record-keeping, and court orders
- Anonymizing and aggregating usage data for internal analytics (no individual identification)
5. Data Sharing & Third Parties
We do not sell, rent, or trade your personal data. We share data only with the following service providers, strictly for the purpose of delivering our service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase (US) | Database & authentication | All platform data (encrypted at rest) |
| Stripe, Inc. (US) | Payment processing | Email, billing address, Stripe customer ID |
| Google LLC (US) | Gmail API, OAuth sign-in, calendar where enabled | OAuth tokens, account profile, email/calendar actions you authorize |
| Microsoft Corporation (US) | Microsoft 365, Outlook, Calendar, Teams, To Do sync | OAuth tokens, profile data, selected mailbox/calendar/task records |
| LinkedIn Corporation (US) | OAuth, social publishing, organization analytics, Lead Gen Forms | OAuth tokens, profile/page data, post data, lead form submissions |
| Meta Platforms, Inc. (US) | Facebook/Instagram publishing, Page inbox, Lead Ads, analytics | OAuth tokens, page/profile data, posts, media, comments, lead forms |
| WhatsApp Business / Meta (US) | Customer messaging and delivery status | Phone numbers, messages, templates, delivery/read status |
| Calendly LLC (US) | Scheduling and invitee sync | OAuth tokens, event types, invitee names/emails, booking metadata |
| Cloudflare, Inc. (US) | Bot protection & security (Turnstile) | IP address, browser metadata, telemetry |
| Railway Corp. (US) | Application hosting & CDN | IP address, request metadata |
| Resend / SendGrid | Transactional email delivery | Email address, email content (transactional only) |
| AI model providers configured for the workspace | Bonnie AI assistance, drafting, summarization, classification, and task execution | Task prompts and tenant-scoped records needed to complete user-requested actions |
| Anthropic / Manus AI (optional) | MCP AI agent integration (user-initiated) | CRM data transmitted only when user activates MCP integration |
All third-party providers are contractually bound to process data only as instructed and to implement appropriate security measures. Transfers to the United States are covered by Standard Contractual Clauses (SCCs) where required by GDPR.
6. Data Retention
We retain your data for as long as your account is active and for a period afterward as required by law or legitimate business interest:
- Active account data: Retained for the duration of your subscription
- Financial records (invoices, journal entries): 7 years from creation (tax and accounting legal requirements)
- Signed contracts: 7 years from signing date
- Audit logs: 2 years from creation
- Account deletion: Personal data deleted within 72 hours of deletion request. Anonymized analytics data may be retained.
- Backup snapshots: Purged within 30 days of account deletion
- Gmail API tokens: Revoked and deleted immediately upon Gmail disconnection
7. Your Rights (GDPR, POPIA, CCPA)
Depending on your jurisdiction, you have the following rights regarding your personal data. To exercise any of these rights, email [email protected]. We will respond within 30 days.
Right of Access / Right to Know
Request a copy of all personal data we hold about you (GDPR, CCPA).
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure / Right to Delete
Request deletion of your data ("right to be forgotten").
Right to Portability
Receive your data in a structured, machine-readable format.
Right to Restrict Processing
Request that we limit processing of your data in certain circumstances.
Right to Object
Object to processing based on legitimate interests or for direct marketing.
Right to Opt-Out of Sale or Sharing
California residents can opt out of the sale or sharing of their personal information (CCPA). AlphaClone does not sell personal data.
Right to Non-Discrimination
You will not receive discriminatory treatment for exercising your privacy rights (CCPA).
8. Security Measures & Data Breach Notification
We implement enterprise-grade security to protect your data:
- AES-256 encryption at rest for all database records
- TLS 1.3 encryption in transit for all data transfers
- Bcrypt password hashing with adaptive cost factors
- Row-Level Security (RLS) on all database tables — multi-tenant data isolation
- Role-Based Access Control (RBAC) for team member permissions
- Continuous SIEM audit logging for all admin actions
- Real-time DDoS mitigation and IP threat intelligence
- Regular automated security audits and penetration testing
- Zero-knowledge architecture for financial data (your accountant sees only what you grant)
Data Breach Notification Policy
In the event of a security breach that poses a high risk to the rights and freedoms of individuals (e.g., unauthorized access to unencrypted personal data), AlphaClone Systems will notify all affected users and relevant supervisory authorities without undue delay, and in any event within 72 hours of becoming aware of the breach. Notifications will include the nature of the breach, potential consequences, and the mitigation measures taken.
10. Children's Privacy
The AlphaClone Business OS is intended for use by businesses and professionals aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact us at [email protected] and we will delete the data immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email and display a notice in the platform dashboard at least 14 days before the changes take effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact Us
For privacy-related enquiries, data subject rights requests, or complaints:
Privacy & Data Protection: [email protected]
Legal Department: [email protected]
General Support: [email protected]