Skip to main content

Alliansis : Optimize Agency Partnerships

Privacy

Home

Privacy

Privacy Statement

Alliansis Inc. (“Alliansis”, “we”, “us”, or “our”) values your privacy. This policy explains how we collect, use, protect, and share your information.

Effective: July 1st, 2026

It is in two parts. Part 1 applies to everyone. Part 2 contains additional information for people in specific regions: the European Economic Area, the United Kingdom, Switzerland, California, and other U.S. states with privacy legislation. If you are in one of those regions, both parts apply to you, and where they differ, Part 2 governs.

Part 1: Information that applies to everyone

Who this policy covers, and our role

The Alliansis platform is a business tool. Everyone who uses it does so in the course of their work, as an employee or representative of a client organization or of an agency or supplier that the client works with. We do not offer the platform to consumers, and it is not intended for personal or household use.

That has an important consequence for how your data is handled. For almost everything you do on the platform, the organization that gave you access is the controller of your personal data, and we act as a processor on its documented instructions. Your organization decides what is collected, why, who inside it can see the results, and how long records are kept. Where you have a question or a request about your personal data, your organization is usually the right place to start, and we will support it in responding to you. You can also contact us directly at [email protected].

We are the controller of a smaller set of data that we determine ourselves: our marketing website, enquiries you send us, billing and subscription records for the organizations we contract with, and the security and system logs we keep to protect and operate the service.

Information We Collect

Account Information: Name, email address, company details, and password.

Usage Data: How you interact with our service, including IP addresses, browser type, device information, and access times.

Survey Data: Questions, responses, evaluations, ratings, and free-text commentary you create or submit in the Relationship Optimizer module.

Scope of Work Data: Scopes of work you create or manage in the Scope Optimizer module, including work items, work streams, assigned resources and their time allocations, deliverables, expenses, production and media costs, currencies, and the commercial values that roll up from them.

Rate Card Data: Supplier and agency rate cards you create or manage in the Ratecard Optimizer module, including roles, grades, rates, currencies, and the conversion rates applied to them.

Payment Information: Processed securely by Stripe and Chargebee. We do not store your payment card details.

Communications: Messages you send us and records of our interactions.

Scope of Work Data and Rate Card Data are primarily commercial records about organizations rather than about individuals. Where an individual is identified within them (for example, by being named as an assigned resource on a scope of work, or by having a rate attached to them personally rather than to a role), that information is personal data and is handled under this policy. Rate, cost, and time-allocation information associated with an identified individual is treated as confidential and is accessible only to authorized users within the organizations concerned.

We do not request, require, or intend to collect or process special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation), criminal offense data, or data concerning children. Please do not enter such information in free-text fields.

Your activity is recorded against you

This section describes how activity on the platform is recorded. People often assume this works differently, so please read it.

The platform is not anonymous. When you submit a survey response, write a comment, create or edit a scope of work, change a rate, or approve something, we record what was done, when it was done, and who did it. Your identity is collected and stored alongside the action. We do not offer anonymous participation, and we do not describe any part of the platform as anonymous.

Your organization may choose to configure reports and shared views so that names and email addresses are not displayed to other participants, for example so that feedback is presented without showing who gave it. That is a setting controlling what other users see. It does not change what is collected. The underlying record of who did what continues to exist, remains available to authorized administrators, and remains available where it is needed for audit purposes or to resolve a dispute.

We record this attribution because the platform is used to make decisions that carry commercial and contractual weight. Someone approving a scope of work is committing their organization to spend. Someone submitting an evaluation is contributing to a judgment about a business relationship. Both your organization and the organization on the other side of that relationship may later need to establish who took an action, and when.

What this means in practice:

– Closing or deactivating an account removes your access. It does not erase the record that you previously submitted, approved, or changed something.
– Records of significant actions (approvals, sign-offs, submissions, changes to commercial values) are kept as part of an audit trail after you stop using the platform, and after you leave your employer.
– Free-text you write may be read by authorized people at your own organization, and depending on how your organization configures the service, at the other organization in the relationship being evaluated.

If you are not comfortable with something being recorded against your name, the right time to raise it is with your own organization, before you submit it.

How We Use Your Information

– Provide our services and maintain your account.
– Evaluate and report on supplier relationships in the Relationship Optimizer module.
– Build, price, convert between currencies, approve, and report on scopes of work in the Scope Optimizer module.
– Maintain and apply supplier rate cards in the Ratecard Optimizer module.
– Provide AI-assisted analysis, summaries, and reporting of the data described above, for review by authorized users.
– Maintain an audit trail of who created, changed, submitted, and approved records.
– Process payments and send transaction confirmations.
Communicate with you about your account, updates, and support.
– Improve our platform through analytics and user feedback.
– Create anonymized benchmarks from aggregated survey data (no personal details included).
– Comply with legal obligations and protect our rights.
– We do not use your personal data to train machine learning models.

Information Sharing

We never sell your personal data. We only share information in these limited circumstances:

Within and between the organizations using the platform: Your data is visible to authorized users of the organization that gave you access, and, where that organization has set the service up to do so, to the counterpart organization in the business relationship being managed. Your organization controls these settings.

Service Providers: We disclose personal data to the following types of service providers, each for the purpose stated:

– Cloud hosting and infrastructure services, which host the platform and store your data
– Authentication and identity management services, which verify your identity and secure your account
– Content delivery and network security services, which deliver the service and protect it from attack
– Infrastructure monitoring and alerting services, which detect faults and security events
– Payment processing (Stripe), which takes payments
– Subscription management and billing (Chargebee), which manages your subscription and issues invoices

Each provider is bound by a data processing agreement and maintains independent security certifications. Enterprise customers may request a detailed list of service providers under a separate agreement.

Legal Requirements: We may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements, or where disclosure is required by law or court order, or is necessary to protect our rights and safety.

Business Transfers: If we’re acquired or merged, your data would transfer under the same privacy protections.

With Your Consent: When you explicitly authorize us to share specific information.

Data Security

We implement security measures including:

– All data in transit is encrypted using TLS 1.2 or higher.
– All data at rest is encrypted using AES-256 or equivalent standards.
– Role-based access controls limiting who can view your data.
– Hosted on a SOC 2-certified cloud platform with enterprise-grade security.
– Regular security assessments and updates.

Alliansis holds SOC 2 Type 1 attestation, independently assessed across the Security, Confidentiality, and Availability trust service criteria. For more details about our security practices, please visit our Security page at https://alliansis.com/security/.

While we work hard to protect your information, no system is 100% secure. We’ll notify you promptly of any security incidents that may affect your data.

Data Retention

Account data: Retained while your account is active.

Survey, scope of work, and rate card data: Retained for the duration of your organization’s active account and for a reasonable period thereafter for legitimate business purposes, or as required by law.

Audit and attribution records: Records of who created, submitted, changed, or approved something are retained as part of the audit trail for as long as they may be needed to evidence what happened, including after the individual concerned has stopped using the platform. Retention is bounded by the period in which a related legal or contractual claim could realistically be brought, and by any applicable statutory record-keeping requirement.

Anonymized data: May be retained indefinitely for benchmarking.

Deleted accounts: Personal data is removed from active systems within 30 days of account closure, except where it forms part of an audit or attribution record as described above, or where retention is required by law. Data in automated backups is overwritten in the normal backup rotation cycle. Some anonymized data may remain.

You may request deletion of your data at any time by contacting [email protected]. Where the organization that gave you access is the controller of that data, we will pass your request to it and assist it in responding. We will process requests for which we are the controller within 30 days.

Your Rights

Depending on your location, you may have these rights:

Access: Request a copy of your personal data.
Correction: Update inaccurate information.
Deletion: Request removal of your data.
Portability: Export your data in a common format.
Objection: Opt out of certain data processing.
Restriction: Limit how we use your data.

You can also ask us to limit how your personal data is used and disclosed. Today, we do not disclose personal data to any third party acting on its own behalf: the service providers listed under Information Sharing act as our agents under contract, and visibility between the organizations using the platform is controlled by the organization that gave you access. If that ever changes, meaning we propose to disclose your personal data to a third party acting on its own behalf or to use it for a purpose materially different from the purposes described in this policy, we will notify you and offer you the opportunity to opt out first.

To exercise any of these rights, please email [email protected]. We will respond within 30 days. There is no charge for exercising these rights. Where the organization that gave you access is the controller of the data concerned, we will refer your request to it and assist it in responding.

These rights are not always absolute. In particular, a request to delete an audit or attribution record may be refused where the record is needed to establish, exercise, or defend a legal claim, or where a law requires it to be kept. Where that happens, you will be told why. Where the law provides for it, we or your organization can instead restrict the record so that it is stored but not otherwise used. Part 2 explains this in more detail for your region.

Cookies & Tracking

We use cookies and similar technologies to:

– Keep you logged in
– Remember your preferences
– Analyze site usage
– Provide security features

You can control cookies through your browser settings, though some features may not work properly if disabled.

Children’s Privacy

Our service is a business tool and is not intended for children under 16. We don’t knowingly collect personal information from children. If we discover we’ve collected such information, we’ll delete it promptly.

Third-Party Links

Our service may contain links to other websites. We’re not responsible for their privacy practices, so please review their policies before sharing information.

Changes to This Policy

We may update this policy to reflect changes in our practices or legal requirements. When we do, we will update the “Effective” date at the top of this page. Your continued use of our service after changes are posted constitutes acceptance of the updated policy.

Contact Us

Questions about this privacy policy? Contact us at [email protected].

Part 2: Regional supplements

2A. European Economic Area, United Kingdom, and Switzerland

This section applies if you are in the European Economic Area, the United Kingdom, or Switzerland. It supplements Part 1 and is provided under the EU General Data Protection Regulation, the UK GDPR and Data Protection Act 2018, and the Swiss Federal Act on Data Protection.

Controller and processor

For personal data processed through the platform (your account, your survey responses, scopes of work, rate cards, and the audit records attached to them), the organization that gave you access is the controller, and Alliansis Inc. is a processor acting on its documented instructions under Article 28 GDPR. That organization is responsible for telling you what it collects and why, for choosing the legal basis, and for deciding on requests you make about your data. We will assist it in doing so.

Alliansis Inc. is the controller for our marketing website, enquiries sent to us, billing records for the organizations we contract with, and the security and system logs we keep to operate and protect the service.

Legal bases

Where Alliansis acts as controller, we rely on:

– Legitimate interests (Article 6(1)(f)): to operate, secure, and improve the service, to maintain the integrity of audit records, and to establish, exercise, or defend legal claims.
– Performance of a contract (Article 6(1)(b)): to administer subscriptions and provide contracted services.
– Legal obligation (Article 6(1)(c)): where a law requires us to retain or disclose data.

We do not rely on consent as the basis for processing platform data, because you use the platform in the course of your employment rather than as a matter of personal choice. This means there is no consent for you to withdraw, and it is also why a request about your data is normally a matter for the organization that gave you access.

Your rights, and how they apply here

You have the right to request access to your personal data, and its rectification or erasure; to restrict or object to processing; and to data portability. You may exercise these against the controller, normally your own organization, and we will support it. You can also write to us at [email protected] and we will route your request.

Two limits are especially relevant on this platform:

Erasure is not absolute. Under Article 17(3), the right to erasure does not apply where processing is necessary for compliance with a legal obligation, or for the establishment, exercise, or defense of legal claims. Records showing who approved a scope of work, who changed a commercial value, or who submitted an evaluation may fall within that exception, because they may be required as evidence in a contractual or employment dispute. Where a controller relies on this, it must be able to justify it and must keep the record only for as long as such a claim remains realistically possible.

Restriction as an alternative to erasure. Under Article 18, personal data can be restricted rather than erased. Restricted data is stored but not otherwise processed, except with your consent, for the establishment, exercise, or defense of legal claims, or on the other limited grounds set out in Article 18(2). In practice this means the record is taken out of everyday use and reporting while remaining retrievable if a dispute arises. Where a full erasure is not available, we support restriction as the alternative.

Replacing your name and email address with a placeholder reduces how visible you are, and we can do that on a controller’s instruction. It is pseudonymization, not anonymization: because the underlying link has to be preserved for the audit record to serve its purpose, the data remains personal data under Recital 26 GDPR, and your rights continue to apply to it.

Automated decision-making. The service includes AI-assisted analysis, summary, and reporting features. Their output is analysis for review by people at your organization. We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects concerning you within the meaning of Article 22 GDPR.

International data transfers

Your data is primarily processed in the United States. For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, together with the UK International Data Transfer Addendum, along with supplementary measures where required. Our Transfer Impact Assessment, which documents these safeguards and supplementary measures, is available to customers on request.

Complaints to a supervisory authority

You have the right to lodge a complaint with a supervisory authority. In the EEA this is the data protection authority of the country where you live or work, or where the alleged infringement took place. In the United Kingdom it is the Information Commissioner’s Office (https://ico.org.uk/). In Switzerland it is the Federal Data Protection and Information Commissioner (https://www.edoeb.admin.ch/).

Switzerland

If you are in Switzerland, this policy should be read with the Swiss Federal Act on Data Protection. References to the GDPR should be read as references to the equivalent provisions of Swiss law, references to the EEA include Switzerland, and the supervisory authority is the Federal Data Protection and Information Commissioner. Transfers of personal data from Switzerland to the United States are made under the Standard Contractual Clauses with the adaptations set out by the Federal Data Protection and Information Commissioner.

United Kingdom

If you are in the United Kingdom, references to the GDPR should be read as references to the UK GDPR and the Data Protection Act 2018, the supervisory authority is the Information Commissioner’s Office, and transfers to the United States are made under the SCCs as supplemented by the International Data Transfer Addendum.

2B. California

This section applies if you are a California resident. It supplements Part 1 and is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”).

California privacy law applies to personal information collected in a business-to-business context, so it applies to you even though you use the platform through your employer.

Our role. For personal information processed through the platform, Alliansis acts as a service provider to the organization that gave you access. We process that information only to perform the services set out in our written agreement with that organization, and for no other purpose. If you want to exercise your rights over that information, the organization that gave you access is the business responsible, and you should direct your request to it. We will assist it in responding.

We do not sell or share your personal information as those terms are defined by the CCPA, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA.

Categories of personal information we collect. Identifiers (name, email address, IP address, account identifiers); professional or employment-related information (job title, employer, role, and where a customer records it, rates and time allocations); commercial information (scopes of work, rate cards, and their values); internet or network activity (usage and audit logs recording your actions); and the contents of survey responses and free-text commentary you submit. We collect these for the business purposes described in How We Use Your Information, and we retain them as described in Data Retention.

Your California rights. You have the right to know what personal information is collected, used, disclosed, or sold or shared; to request correction of inaccurate personal information; to request deletion; to limit the use of sensitive personal information; and not to receive discriminatory treatment for exercising any of these rights.

Limits on deletion. The CCPA permits a business or its service provider to retain personal information despite a deletion request in a number of circumstances, including where it is necessary to complete a transaction, to detect or resist fraudulent or illegal activity, to exercise or ensure another’s right to exercise free speech, to comply with a legal obligation, or otherwise for internal uses reasonably aligned with your expectations given the relationship. Audit and attribution records described in Part 1 will generally fall within one or more of these.

How to make a request. Email [email protected]. We will verify your request and respond within the time the CCPA allows. You may use an authorized agent, and there is no charge.

2C. Other U.S. states

If you are a resident of another U.S. state with a comprehensive privacy law, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana, among others, you may have rights to access, correct, delete, and obtain a copy of your personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data, do not use it for targeted advertising, and do not carry out profiling that produces legal or similarly significant effects.

As with the regions above, for data processed through the platform the organization that gave you access is the controller and we act as its processor, so requests are normally directed there. You may also email [email protected] and we will route your request. If we deny a request, you may appeal by replying to our response; where your state provides one, you may also complain to your state attorney general.