Alliansis : Optimize Agency Partnerships
Alliansis Inc. (“Alliansis”, “we”, “us”, or “our”) values your privacy. This policy explains how we collect, use, protect, and share your information.
It is in two parts. Part 1 applies to everyone. Part 2 contains additional information for people in specific regions: the European Economic Area, the United Kingdom, Switzerland, California, and other U.S. states with privacy legislation. If you are in one of those regions, both parts apply to you, and where they differ, Part 2 governs.
The Alliansis platform is a business tool. Everyone who uses it does so in the course of their work, as an employee or representative of a client organization or of an agency or supplier that the client works with. We do not offer the platform to consumers, and it is not intended for personal or household use.
That has an important consequence for how your data is handled. For almost everything you do on the platform, the organization that gave you access is the controller of your personal data, and we act as a processor on its documented instructions. Your organization decides what is collected, why, who inside it can see the results, and how long records are kept. Where you have a question or a request about your personal data, your organization is usually the right place to start, and we will support it in responding to you. You can also contact us directly at [email protected].
We are the controller of a smaller set of data that we determine ourselves: our marketing website, enquiries you send us, billing and subscription records for the organizations we contract with, and the security and system logs we keep to protect and operate the service.
Account Information: Name, email address, company details, and password.
Usage Data: How you interact with our service, including IP addresses, browser type, device information, and access times.
Survey Data: Questions, responses, evaluations, ratings, and free-text commentary you create or submit in the Relationship Optimizer module.
Scope of Work Data: Scopes of work you create or manage in the Scope Optimizer module, including work items, work streams, assigned resources and their time allocations, deliverables, expenses, production and media costs, currencies, and the commercial values that roll up from them.
Rate Card Data: Supplier and agency rate cards you create or manage in the Ratecard Optimizer module, including roles, grades, rates, currencies, and the conversion rates applied to them.
Payment Information: Processed securely by Stripe and Chargebee. We do not store your payment card details.
Communications: Messages you send us and records of our interactions.
Scope of Work Data and Rate Card Data are primarily commercial records about organizations rather than about individuals. Where an individual is identified within them (for example, by being named as an assigned resource on a scope of work, or by having a rate attached to them personally rather than to a role), that information is personal data and is handled under this policy. Rate, cost, and time-allocation information associated with an identified individual is treated as confidential and is accessible only to authorized users within the organizations concerned.
We do not request, require, or intend to collect or process special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation), criminal offense data, or data concerning children. Please do not enter such information in free-text fields.
This section describes how activity on the platform is recorded. People often assume this works differently, so please read it.
The platform is not anonymous. When you submit a survey response, write a comment, create or edit a scope of work, change a rate, or approve something, we record what was done, when it was done, and who did it. Your identity is collected and stored alongside the action. We do not offer anonymous participation, and we do not describe any part of the platform as anonymous.
Your organization may choose to configure reports and shared views so that names and email addresses are not displayed to other participants, for example so that feedback is presented without showing who gave it. That is a setting controlling what other users see. It does not change what is collected. The underlying record of who did what continues to exist, remains available to authorized administrators, and remains available where it is needed for audit purposes or to resolve a dispute.
We record this attribution because the platform is used to make decisions that carry commercial and contractual weight. Someone approving a scope of work is committing their organization to spend. Someone submitting an evaluation is contributing to a judgment about a business relationship. Both your organization and the organization on the other side of that relationship may later need to establish who took an action, and when.
– Closing or deactivating an account removes your access. It does not erase the record that you previously submitted, approved, or changed something.
– Records of significant actions (approvals, sign-offs, submissions, changes to commercial values) are kept as part of an audit trail after you stop using the platform, and after you leave your employer.
– Free-text you write may be read by authorized people at your own organization, and depending on how your organization configures the service, at the other organization in the relationship being evaluated.
If you are not comfortable with something being recorded against your name, the right time to raise it is with your own organization, before you submit it.
– Provide our services and maintain your account.
– Evaluate and report on supplier relationships in the Relationship Optimizer module.
– Build, price, convert between currencies, approve, and report on scopes of work in the Scope Optimizer module.
– Maintain and apply supplier rate cards in the Ratecard Optimizer module.
– Provide AI-assisted analysis, summaries, and reporting of the data described above, for review by authorized users.
– Maintain an audit trail of who created, changed, submitted, and approved records.
– Process payments and send transaction confirmations.
Communicate with you about your account, updates, and support.
– Improve our platform through analytics and user feedback.
– Create anonymized benchmarks from aggregated survey data (no personal details included).
– Comply with legal obligations and protect our rights.
– We do not use your personal data to train machine learning models.
We never sell your personal data. We only share information in these limited circumstances:
Within and between the organizations using the platform: Your data is visible to authorized users of the organization that gave you access, and, where that organization has set the service up to do so, to the counterpart organization in the business relationship being managed. Your organization controls these settings.
Service Providers: We disclose personal data to the following types of service providers, each for the purpose stated:
– Cloud hosting and infrastructure services, which host the platform and store your data
– Authentication and identity management services, which verify your identity and secure your account
– Content delivery and network security services, which deliver the service and protect it from attack
– Infrastructure monitoring and alerting services, which detect faults and security events
– Payment processing (Stripe), which takes payments
– Subscription management and billing (Chargebee), which manages your subscription and issues invoices
Each provider is bound by a data processing agreement and maintains independent security certifications. Enterprise customers may request a detailed list of service providers under a separate agreement.
Legal Requirements: We may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements, or where disclosure is required by law or court order, or is necessary to protect our rights and safety.
Business Transfers: If we’re acquired or merged, your data would transfer under the same privacy protections.
With Your Consent: When you explicitly authorize us to share specific information.
We implement security measures including:
– All data in transit is encrypted using TLS 1.2 or higher.
– All data at rest is encrypted using AES-256 or equivalent standards.
– Role-based access controls limiting who can view your data.
– Hosted on a SOC 2-certified cloud platform with enterprise-grade security.
– Regular security assessments and updates.
Alliansis holds SOC 2 Type 1 attestation, independently assessed across the Security, Confidentiality, and Availability trust service criteria. For more details about our security practices, please visit our Security page at https://alliansis.com/security/.
While we work hard to protect your information, no system is 100% secure. We’ll notify you promptly of any security incidents that may affect your data.
Account data: Retained while your account is active.
Survey, scope of work, and rate card data: Retained for the duration of your organization’s active account and for a reasonable period thereafter for legitimate business purposes, or as required by law.
Audit and attribution records: Records of who created, submitted, changed, or approved something are retained as part of the audit trail for as long as they may be needed to evidence what happened, including after the individual concerned has stopped using the platform. Retention is bounded by the period in which a related legal or contractual claim could realistically be brought, and by any applicable statutory record-keeping requirement.
Anonymized data: May be retained indefinitely for benchmarking.
Deleted accounts: Personal data is removed from active systems within 30 days of account closure, except where it forms part of an audit or attribution record as described above, or where retention is required by law. Data in automated backups is overwritten in the normal backup rotation cycle. Some anonymized data may remain.
You may request deletion of your data at any time by contacting [email protected]. Where the organization that gave you access is the controller of that data, we will pass your request to it and assist it in responding. We will process requests for which we are the controller within 30 days.
Depending on your location, you may have these rights:
Access: Request a copy of your personal data.
Correction: Update inaccurate information.
Deletion: Request removal of your data.
Portability: Export your data in a common format.
Objection: Opt out of certain data processing.
Restriction: Limit how we use your data.
You can also ask us to limit how your personal data is used and disclosed. Today, we do not disclose personal data to any third party acting on its own behalf: the service providers listed under Information Sharing act as our agents under contract, and visibility between the organizations using the platform is controlled by the organization that gave you access. If that ever changes, meaning we propose to disclose your personal data to a third party acting on its own behalf or to use it for a purpose materially different from the purposes described in this policy, we will notify you and offer you the opportunity to opt out first.
To exercise any of these rights, please email [email protected]. We will respond within 30 days. There is no charge for exercising these rights. Where the organization that gave you access is the controller of the data concerned, we will refer your request to it and assist it in responding.
These rights are not always absolute. In particular, a request to delete an audit or attribution record may be refused where the record is needed to establish, exercise, or defend a legal claim, or where a law requires it to be kept. Where that happens, you will be told why. Where the law provides for it, we or your organization can instead restrict the record so that it is stored but not otherwise used. Part 2 explains this in more detail for your region.
We use cookies and similar technologies to:
– Keep you logged in
– Remember your preferences
– Analyze site usage
– Provide security features
You can control cookies through your browser settings, though some features may not work properly if disabled.
Our service is a business tool and is not intended for children under 16. We don’t knowingly collect personal information from children. If we discover we’ve collected such information, we’ll delete it promptly.
Our service may contain links to other websites. We’re not responsible for their privacy practices, so please review their policies before sharing information.
We may update this policy to reflect changes in our practices or legal requirements. When we do, we will update the “Effective” date at the top of this page. Your continued use of our service after changes are posted constitutes acceptance of the updated policy.
Questions about this privacy policy? Contact us at [email protected].
This section applies if you are in the European Economic Area, the United Kingdom, or Switzerland. It supplements Part 1 and is provided under the EU General Data Protection Regulation, the UK GDPR and Data Protection Act 2018, and the Swiss Federal Act on Data Protection.
For personal data processed through the platform (your account, your survey responses, scopes of work, rate cards, and the audit records attached to them), the organization that gave you access is the controller, and Alliansis Inc. is a processor acting on its documented instructions under Article 28 GDPR. That organization is responsible for telling you what it collects and why, for choosing the legal basis, and for deciding on requests you make about your data. We will assist it in doing so.
Alliansis Inc. is the controller for our marketing website, enquiries sent to us, billing records for the organizations we contract with, and the security and system logs we keep to operate and protect the service.
Where Alliansis acts as controller, we rely on:
– Legitimate interests (Article 6(1)(f)): to operate, secure, and improve the service, to maintain the integrity of audit records, and to establish, exercise, or defend legal claims.
– Performance of a contract (Article 6(1)(b)): to administer subscriptions and provide contracted services.
– Legal obligation (Article 6(1)(c)): where a law requires us to retain or disclose data.
We do not rely on consent as the basis for processing platform data, because you use the platform in the course of your employment rather than as a matter of personal choice. This means there is no consent for you to withdraw, and it is also why a request about your data is normally a matter for the organization that gave you access.
You have the right to request access to your personal data, and its rectification or erasure; to restrict or object to processing; and to data portability. You may exercise these against the controller, normally your own organization, and we will support it. You can also write to us at [email protected] and we will route your request.
Two limits are especially relevant on this platform:
– Erasure is not absolute. Under Article 17(3), the right to erasure does not apply where processing is necessary for compliance with a legal obligation, or for the establishment, exercise, or defense of legal claims. Records showing who approved a scope of work, who changed a commercial value, or who submitted an evaluation may fall within that exception, because they may be required as evidence in a contractual or employment dispute. Where a controller relies on this, it must be able to justify it and must keep the record only for as long as such a claim remains realistically possible.
– Restriction as an alternative to erasure. Under Article 18, personal data can be restricted rather than erased. Restricted data is stored but not otherwise processed, except with your consent, for the establishment, exercise, or defense of legal claims, or on the other limited grounds set out in Article 18(2). In practice this means the record is taken out of everyday use and reporting while remaining retrievable if a dispute arises. Where a full erasure is not available, we support restriction as the alternative.
Replacing your name and email address with a placeholder reduces how visible you are, and we can do that on a controller’s instruction. It is pseudonymization, not anonymization: because the underlying link has to be preserved for the audit record to serve its purpose, the data remains personal data under Recital 26 GDPR, and your rights continue to apply to it.
Automated decision-making. The service includes AI-assisted analysis, summary, and reporting features. Their output is analysis for review by people at your organization. We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects concerning you within the meaning of Article 22 GDPR.
Your data is primarily processed in the United States. For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on our certification under the EU-U.S. Data Privacy Framework and the UK Extension to the EU-U.S. Data Privacy Framework (see below), and on Standard Contractual Clauses (SCCs) approved by the European Commission, together with the UK International Data Transfer Addendum, along with supplementary measures where required. Our Transfer Impact Assessment, which documents these safeguards and supplementary measures, is available to customers on request.
Alliansis Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF as set forth by the U.S. Department of Commerce. Alliansis Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, please visit https://www.dataprivacyframework.gov/. To view our certification, please visit the Data Privacy Framework List at https://www.dataprivacyframework.gov/list.
Scope of our certification. Alliansis Inc. has no U.S. subsidiaries or affiliated entities covered by this certification, and has no establishment in the European Union. Alliansis Inc. commits to subject to the EU-U.S. DPF Principles all personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom in reliance on the UK Extension to the EU-U.S. DPF. Our certification does not cover human resources data, because we have no personnel in the European Union or the United Kingdom.
Personal data covered. The personal data we receive from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom in reliance on the UK Extension to the EU-U.S. DPF comprises account identifiers (name, business email address), business contact data (job title and organization), authentication data, technical identifiers such as IP address and session identifiers, activity and audit logs recording who took which action, responses to business relationship surveys, and any personal data our customers include in the scopes of work and supplier rate cards they manage on our platform. That may include the names, roles, and seniority of individuals identified as assigned resources, together with the rates and time allocations attributed to them. We collect and use this data to provide, maintain, secure, and support our service, as described elsewhere in this policy.
Onward transfers and our liability. We disclose personal data to the types of service providers listed under Information Sharing, each of which acts as our agent under contract. Where we transfer personal data received in reliance on the EU-U.S. DPF or the UK Extension to the EU-U.S. DPF to a third party acting as an agent on our behalf, we remain liable under the EU-U.S. DPF or the UK Extension to the EU-U.S. DPF Principles if that agent processes the data in a manner inconsistent with the Principles, unless we prove that we are not responsible for the event giving rise to the damage.
Lawful requests by public authorities. We may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Your right of access. If you are an EU or UK individual whose personal data we received in reliance on the EU-U.S. DPF or the UK Extension to the EU-U.S. DPF, you have the right to access the personal data we hold about you, and to have it corrected, amended, or deleted where it is inaccurate or has been processed in violation of the EU-U.S. DPF or the UK Extension to the EU-U.S. DPF Principles. Access may be limited where the burden or expense of providing it would be disproportionate to the risks to your privacy, or where the rights of other people would be violated. See Your Rights in Part 1, or email [email protected].
How to raise a complaint. In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, Alliansis Inc. commits to resolve DPF Principles-related complaints about our collection or use of your personal data transferred to the United States in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. European Union and United Kingdom individuals with such inquiries or complaints should first contact Alliansis Inc. at [email protected]. We will respond to you within 45 days of receiving your complaint.
Independent recourse mechanism. Alliansis Inc. has further committed to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF to an independent dispute resolution body, at no cost to you.
For personal data received from the European Union, the designated body is the panel established by the European Union data protection authorities (the DPA Panel), the first of the three types of independent recourse mechanism recognized by the EU-U.S. DPF Principles. For personal data received from the United Kingdom and Gibraltar in reliance on the UK Extension to the EU-U.S. DPF, the designated body is the UK Information Commissioner’s Office and, where applicable, the Gibraltar Regulatory Authority.
Alliansis Inc. commits to cooperate with the DPA Panel and with the UK Information Commissioner’s Office, and to comply with the advice given by them. If you do not receive timely acknowledgment of your complaint from us, or if we have not resolved your complaint to your satisfaction, please contact your local data protection authority, which will refer the matter to the DPA Panel. Contact details for European Union data protection authorities are available at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en. The UK Information Commissioner’s Office can be contacted at https://ico.org.uk/make-a-complaint/. These services are provided to you at no cost.
Regulatory oversight. Alliansis Inc. is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC).
Binding arbitration. Under certain conditions, more fully described on the Data Privacy Framework website at https://www.dataprivacyframework.gov/, you may be able to invoke binding arbitration when other dispute resolution procedures have been exhausted.
You have the right to lodge a complaint with a supervisory authority. In the EEA this is the data protection authority of the country where you live or work, or where the alleged infringement took place. In the United Kingdom it is the Information Commissioner’s Office (https://ico.org.uk/). In Switzerland it is the Federal Data Protection and Information Commissioner (https://www.edoeb.admin.ch/).
If you are in Switzerland, this policy should be read with the Swiss Federal Act on Data Protection. References to the GDPR should be read as references to the equivalent provisions of Swiss law, references to the EEA include Switzerland, and the supervisory authority is the Federal Data Protection and Information Commissioner. Transfers of personal data from Switzerland to the United States are made under the Standard Contractual Clauses with the adaptations set out by the Federal Data Protection and Information Commissioner.
If you are in the United Kingdom, references to the GDPR should be read as references to the UK GDPR and the Data Protection Act 2018, the supervisory authority is the Information Commissioner’s Office, and transfers to the United States are made under our certification to the UK Extension to the EU-U.S. DPF and under the SCCs as supplemented by the International Data Transfer Addendum.
This section applies if you are a California resident. It supplements Part 1 and is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”).
California privacy law applies to personal information collected in a business-to-business context, so it applies to you even though you use the platform through your employer.
Our role. For personal information processed through the platform, Alliansis acts as a service provider to the organization that gave you access. We process that information only to perform the services set out in our written agreement with that organization, and for no other purpose. If you want to exercise your rights over that information, the organization that gave you access is the business responsible, and you should direct your request to it. We will assist it in responding.
We do not sell or share your personal information as those terms are defined by the CCPA, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA.
Categories of personal information we collect. Identifiers (name, email address, IP address, account identifiers); professional or employment-related information (job title, employer, role, and where a customer records it, rates and time allocations); commercial information (scopes of work, rate cards, and their values); internet or network activity (usage and audit logs recording your actions); and the contents of survey responses and free-text commentary you submit. We collect these for the business purposes described in How We Use Your Information, and we retain them as described in Data Retention.
Your California rights. You have the right to know what personal information is collected, used, disclosed, or sold or shared; to request correction of inaccurate personal information; to request deletion; to limit the use of sensitive personal information; and not to receive discriminatory treatment for exercising any of these rights.
Limits on deletion. The CCPA permits a business or its service provider to retain personal information despite a deletion request in a number of circumstances, including where it is necessary to complete a transaction, to detect or resist fraudulent or illegal activity, to exercise or ensure another’s right to exercise free speech, to comply with a legal obligation, or otherwise for internal uses reasonably aligned with your expectations given the relationship. Audit and attribution records described in Part 1 will generally fall within one or more of these.
How to make a request. Email [email protected]. We will verify your request and respond within the time the CCPA allows. You may use an authorized agent, and there is no charge.
If you are a resident of another U.S. state with a comprehensive privacy law, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana, among others, you may have rights to access, correct, delete, and obtain a copy of your personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data, do not use it for targeted advertising, and do not carry out profiling that produces legal or similarly significant effects.
As with the regions above, for data processed through the platform the organization that gave you access is the controller and we act as its processor, so requests are normally directed there. You may also email [email protected] and we will route your request. If we deny a request, you may appeal by replying to our response; where your state provides one, you may also complain to your state attorney general.