Privacy Policy
Last Updated: September 1st 2025
1. Introduction
Welcome to Alludium Ltd (Company No. 15062888), a company incorporated in England and Wales ("we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our AI platform services, including our website, applications, AI agent creation tools, APIs, and related services (collectively, the "Services").
Registered Office: International House, 36-38 Cornhill, London, United Kingdom, EC3V 3NG
Your privacy is important to us. We are committed to protecting your personal information and being transparent about our data practices. This Privacy Policy applies to all users of our Services, regardless of location, and complies with applicable privacy laws including:
EU General Data Protection Regulation (GDPR)
UK Data Protection Act 2018 and UK GDPR
Privacy and Electronic Communications Regulations 2003 (PECR) as amended
EU Artificial Intelligence Act
California Consumer Privacy Act (CCPA)
Other relevant data protection regulations
Data Controller: Alludium Ltd acts as the data controller for:
Account information and user management
Platform analytics and service improvement
Marketing and communications
Security and fraud prevention
Data Processor: Alludium Ltd acts as a data processor when:
Processing your AI training data at your direction
Executing your AI agent operations as instructed
Storing and processing your content as directed by you
Performing data processing activities on your behalf
When we act as your data processor, you remain the data controller for your content and bear responsibility for ensuring lawful processing, including obtaining necessary consents from individuals whose data you process through our platform.
By using our Services, you agree to the collection and use of information in accordance with this Privacy Policy and our Terms of Service.
2. Information We Collect
We collect information you provide directly to us, information we obtain automatically when you use our Services, and information from third-party sources.
2.1 Information You Provide to Us
Account Information:
Name, email address, and contact details
Username and password
Company or organization name (for business accounts)
Payment information (processed by third-party payment processors)
Profile information and preferences
AI Agent and Content Data:
AI agents you create, configure, and deploy
Training data you upload or provide
Prompts, inputs, and instructions you provide
Content you create or upload through our Services
Communications with our support team
Optional Information:
Profile pictures or avatars
Biographical information
Integration preferences and settings
Feedback and survey responses
2.2 Information We Collect Automatically
Usage Information:
How you access and use our Services
Features you use and frequency of use
Time, date, and duration of your sessions
AI agent performance and usage metrics
Search queries and interaction patterns
Technical Information:
IP address and geographic location
Device type, operating system, and browser information
Unique device identifiers
Network connection information
Log files and error reports
Analytics and Performance Data:
Website and application analytics
Performance metrics and system diagnostics
User interface interactions and click patterns
A/B testing data and feature usage statistics
2.3 Information from Third Parties
We may receive information about you from:
Third-party services you connect to our platform
Business partners and integrations
Public databases and data sources
Social media platforms (if you connect them)
Enterprise customers who add you as an authorized user
3. How We Use Your Information
We use your personal information for the following purposes:
3.1 Service Provision and Operation
Provide, maintain, and improve our Services
Process your AI agent creation and management requests
Enable AI model inference using third-party AI models
Facilitate account creation and authentication
Process payments and manage subscriptions
Provide customer support and respond to inquiries
3.2 Service Enhancement and Development
Analyze usage patterns to improve our platform
Develop new features and capabilities
Conduct research and development activities
Perform quality assurance and testing
Optimize platform performance and reliability
3.3 Communication and Marketing
Send transactional emails and service notifications
Provide technical updates and security alerts
Send marketing communications (with your consent)
Conduct surveys and request feedback
Communicate about new features and services
3.4 Legal and Security Purposes
Comply with legal obligations and regulations
Prevent fraud, abuse, and security threats
Enforce our Terms of Service and policies
Respond to legal requests and government inquiries
Protect our rights and the rights of our users
3.5 Business Operations
Analyze business metrics and performance
Conduct financial and accounting activities
Manage vendor and partner relationships
Support corporate transactions (mergers, acquisitions)
4. Legal Basis for Processing
For users in the European Union/European Economic Area, we process your personal information based on the following legal grounds:
Contract Performance: Processing necessary to provide our Services and fulfill our Terms of Service, including:
Account management and authentication
Service delivery and customer support
Payment processing and subscription management
Consent: Where you have provided explicit consent for:
Marketing communications
Non-essential cookies and tracking
Specific data uses beyond our core services
Integration with third-party services
Legal Compliance: Processing required to comply with legal obligations, including:
Regulatory reporting and compliance
Response to legal requests
Tax and accounting requirements
Note on Legitimate Interests: We have removed most legitimate interest claims from this policy to simplify compliance. Where legitimate interests are claimed, we maintain documented legitimate interest assessments available upon request. For most processing activities, we rely on contract performance or seek explicit consent.
5. Information Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share your information in the following circumstances:
5.1 Service Providers and Partners
We share information with trusted third-party service providers who assist us in:
Cloud Hosting and Infrastructure:
Amazon Web Services (AWS): Cloud hosting and storage within EU/UK regions
Google Cloud Platform: Cloud hosting and services within EU/UK regions
Payment Processing:
Stripe: Payment processing and subscription management
Other payment processors as necessary for your preferred payment methods
Analytics and Monitoring Services:
Google Analytics: Website and application usage analytics (with consent)
Performance monitoring and error tracking services
Customer Support and Communication Tools:
Intercom: Live chat support and customer communication
Email service providers for transactional communications
Security and Fraud Prevention Services:
Cloudflare: Content delivery network and security services
Security monitoring and threat detection services
Marketing and Advertising Platforms (with consent):
Meta/Facebook: Social media advertising and conversion tracking
LinkedIn: Professional network advertising and B2B analytics
X/Twitter: Social media conversion tracking and advertising
All service providers are contractually bound to protect your information and use it only for specified purposes.
5.2 Business Transfers
In connection with any merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.
5.3 Legal Requirements
We may disclose your information when required by law or to:
Comply with legal process or government requests
Enforce our Terms of Service or other agreements
Protect our rights, property, or safety
Protect the rights, property, or safety of our users
Investigate potential violations or illegal activities
5.4 Consent-Based Sharing
We may share your information with your explicit consent for specific purposes not covered by this policy.
5.5 Aggregated and De-identified Data
We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you for research, analytics, or business purposes.
5.6 Data Sharing Transparency
Users can request a log of third-party data sharing for their account by contacting privacy@alludium.ai. We maintain records of all data sharing activities for compliance and audit purposes, including:
Recipient organization and contact details
Purpose of data sharing
Legal basis for sharing
Data categories shared
Retention period
Date of sharing
6. AI-Specific Data Processing
6.1 EU AI Act Compliance
We comply with the EU Artificial Intelligence Act and implement appropriate transparency, accuracy, and human oversight measures for our AI systems. Our AI agent platform facilitates the creation and deployment of AI systems and may be classified as a General Purpose AI system under the EU AI Act.
6.2 Third-Party AI Models
Important: Alludium does not train, update, or modify any AI models. We exclusively use third-party AI models (such as OpenAI, Anthropic, Google, and other providers) to power our platform.
Model Processing: When you use our Services:
Your inputs are sent to third-party AI model providers
Third-party models generate responses based on your inputs
We do not use your data to train or improve any AI models
We act solely as a conduit between you and third-party AI providers
6.3 AI Agent Data
Your AI Agents: You retain ownership of AI agents you create. We process this data to:
Host and execute your AI agents using third-party AI models
Provide platform functionality and features
Enable collaboration and sharing (as you direct)
Ensure system security and performance
Training Data: We process training data you provide to:
Format and prepare data for third-party AI model consumption
Ensure data quality and compatibility with AI model requirements
Maintain system security and integrity
We do not use your training data to train or improve any AI models
6.4 AI Outputs and Generated Content
Output Ownership: You own the outputs generated by your AI agents through third-party AI models. We may process outputs to:
Deliver results to you and your authorized users
Monitor for compliance with our Acceptable Use Policy
Ensure system reliability and performance
We do not use AI outputs to train or improve any AI models
Content Moderation: We may analyze AI-generated content to:
Detect and prevent harmful or inappropriate content
Ensure compliance with applicable laws and regulations
Protect user safety and platform integrity
Maintain service quality standards
6.5 Algorithmic Transparency and User Rights
Transparency Measures:
Clear disclosure when you are interacting with AI systems
Information about AI model capabilities and limitations provided by third-party providers
Documentation of AI system purposes and intended use cases
AI-Specific Rights:
Right to human review of AI decisions that significantly affect you
Right to challenge automated outcomes
Right to explanation of AI processing logic (subject to third-party provider capabilities)
Right to opt-out of AI processing where technically feasible
Automated Decision-Making: If we use AI for automated decision-making that significantly affects you, we will:
Provide explicit notice of such processing
Explain the logic involved in the decision-making
Offer the right to human intervention and review
Allow you to challenge the decision
7. Data Location and Storage
7.1 Data Processing Locations
Your data is processed and stored within the European Union and United Kingdom. We do not transfer personal data outside these regions except in the following circumstances:
User-Initiated Transfers: When users located outside the EU/UK input data into our system, that data is transferred to and processed within EU/UK data centers where our services operate.
Third-Party AI Model Access: When you use AI features, your inputs may be sent to third-party AI model providers. We only use providers that offer adequate data protection safeguards and EU/UK processing options where possible.
7.2 Data Hosting Infrastructure
Our primary data processing occurs within:
European Union data centers
United Kingdom data centers
Cloud infrastructure providers (AWS, Google Cloud) operating within EU/UK regions
7.3 Cross-Border Data Flows
For users accessing our services from outside the EU/UK:
Data you input is transferred to EU/UK for processing
We implement appropriate technical and organizational measures to protect data in transit
Processing occurs under the same privacy protections regardless of your location
8. Data Security
8.1 Security Measures
We implement comprehensive security measures to protect your personal information:
Technical Safeguards:
Encryption in transit and at rest using industry-standard protocols
Secure authentication and multi-factor access controls
Regular security assessments and penetration testing
Network security and monitoring systems
Automated backup and disaster recovery procedures
Organizational Safeguards:
Employee training on data protection and security
Strict access controls and need-to-know principles
Regular security audits and compliance reviews
Vendor security assessments and contractual requirements
AI-Specific Security:
Secure API connections to third-party AI model providers
Protection against prompt injection and AI-specific attacks
Monitoring for adversarial inputs and abuse
Secure handling of AI inputs and outputs
8.2 Security Limitations
While we implement strong security measures, no system is completely secure. We cannot guarantee absolute security of your information and recommend:
Using strong, unique passwords
Enabling two-factor authentication where available
Keeping your account information confidential
Reporting any suspected security issues immediately
8.3 Data Breach Response
User Notification: We will notify affected users of any personal data breach that poses a high risk to their rights and freedoms without undue delay and no later than 72 hours after becoming aware of the breach.
Notification Content: Breach notifications will include:
Nature of the breach and data types affected
Likely consequences of the breach
Measures taken to address the breach
Recommended actions for affected users
Contact information for further questions
Regulatory Notification: We will notify relevant supervisory authorities within 72 hours of becoming aware of qualifying breaches as required by GDPR and UK GDPR.
Breach Response: Our incident response procedures include immediate containment, forensic analysis, remediation measures, and continuous monitoring to prevent recurrence.
8.4 Privacy Impact Assessments
We conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities including:
AI model integration and automated decision-making
New third-party service integrations
Significant changes to data processing purposes
Cross-border data transfer implementations
DPIA summaries are available upon request where legally required. We regularly review and update DPIAs as our services evolve.
9. Data Retention
9.1 Retention Principles
We retain personal information only as long as necessary for the purposes described in this Privacy Policy, subject to legal requirements and business needs.
9.2 Retention Periods
Account Information:
Active accounts: Retained during account lifetime plus 6 months
Closed accounts: Deleted within 6 months unless legal retention required
Payment records: Retained for 7 years for tax and accounting purposes
Usage and Analytics Data:
Detailed usage logs: 90 days
Aggregated analytics: 2 years
Performance metrics: 1 year
AI Agent and Content Data:
Active AI agents: Retained during account lifetime
Deleted agents: Removed within 30 days
Training data: Retained as long as associated AI agents exist
Generated outputs: Retained according to your preferences
Communications:
Support tickets: 3 years
Marketing communications: Until you unsubscribe
Legal notices: As required by law
9.3 Extended Retention
We may retain information longer when:
Required by applicable law or regulation
Necessary for legal proceedings or investigations
Needed to prevent fraud or protect security
Required for legitimate business purposes with appropriate safeguards
9.4 Data Deletion
When retention periods expire, we securely delete or anonymize your information using industry-standard practices.
10. Your Privacy Rights
10.1 Access and Control
You have the right to:
Access your personal information and obtain copies
Correct inaccurate or incomplete information
Update your account and profile information
Export your data in portable formats
Control your communication preferences
10.2 Data Subject Rights (GDPR)
If you're in the EU/EEA, you have additional rights including:
Right of Access: Request information about what personal data we hold about you.
Right of Rectification: Request correction of inaccurate personal data.
Right of Erasure ("Right to be Forgotten"): Request deletion of your personal data in certain circumstances.
Right of Portability: Request transfer of your data to another service provider.
Right to Restrict Processing: Request limitation of how we process your data.
Right to Object: Object to processing based on legitimate interests or for marketing purposes.
Right to Withdraw Consent: Withdraw consent for processing where consent is the legal basis.
10.3 Exercising Your Rights
Request Methods:
Primary: Contact privacy@alludium.ai
Alternative: Written request to our registered office address
Include: Your name, email address, and specific request details
Identity Verification Requirements:
For standard requests: Email verification may be sufficient
For sensitive requests: We may request additional identification documents
Verification requirements are proportionate to the risk and sensitivity of the request
We will not request excessive documentation
Response Timeframes:
Initial acknowledgment: 48 hours
Standard response: 30 days (GDPR compliance)
Complex requests: Up to 60 days total (90 days maximum with notification)
We will inform you within 30 days if an extension is needed
Fee Structure:
Standard requests: Processed free of charge
Manifestly unfounded or excessive requests: We may charge a reasonable administrative fee
Fee amounts will be communicated before processing
10.4 Right to Lodge Complaints
You have the right to lodge complaints with supervisory authorities:
EU/EEA users: Your local data protection authority
UK users: Information Commissioner's Office (ICO)
Other jurisdictions: Relevant privacy regulatory bodies
11. Cookies and Tracking Technologies
11.1 What Are Cookies
Cookies are small text files stored on your device that help us provide and improve our Services. We also use similar technologies like pixels, beacons, and local storage.
For detailed information about our cookie practices, please see our separate Cookie Policy.
11.2 Types of Cookies We Use
Strictly Necessary Cookies:
session_id: Maintains logged-in session and user state
csrf_token: Security token to prevent CSRF attacks
cookie_consent: Stores your cookie consent preferences
__cf_bm: Bot management and security filtering (Cloudflare)
Performance and Analytics Cookies (with consent):
_ga, _gid, _gat: Google Analytics tracking for website usage analysis
Functional Cookies (with consent):
intercom-session-*: Live chat support functionality
Marketing and Advertising Cookies (with consent):
Facebook/Meta pixels: Social media advertising and conversion tracking
LinkedIn Insight Tag: Professional network advertising and B2B analytics
X/Twitter pixels: Social media conversion tracking
11.3 Cookie Management
You can control cookies through:
Our cookie consent banner and preference center
Your browser settings and preferences
Account settings for logged-in users
Contacting privacy@alludium.ai for assistance
11.4 Third-Party Cookies
Third-party services may set their own cookies. Please review their privacy policies for information about their practices.
12. Third-Party Services
12.1 Integrated Services
Our platform integrates with various third-party services. We act as data processor for customer data sent to these services, while the third parties act as independent data controllers:
Analytics and Performance:
Google Analytics (Google LLC)
Purpose: Website usage analysis and reporting
Data Shared: Anonymized usage patterns, device information, user behavior
Privacy Policy: https://policies.google.com/privacy
Opt-out: https://tools.google.com/dlpage/gaoptout
Legal Basis: Consent (required for non-essential analytics)
Customer Support and Communication:
Intercom (Intercom Inc.)
Purpose: Live customer support functionality and communication
Data Shared: Support conversations, account information, usage context for support
Privacy Policy: https://www.intercom.com/legal/privacy
Legal Basis: Contract performance (essential support) and consent (enhanced features)
Infrastructure and Security:
Cloudflare (Cloudflare Inc.)
Purpose: Content delivery network and security services
Data Shared: IP addresses, request data, security logs
Privacy Policy: https://www.cloudflare.com/privacypolicy/
Legal Basis: Contract performance (essential security and performance)
Amazon Web Services (AWS)
Purpose: Cloud hosting and storage infrastructure
Data Shared: All platform data stored in EU/UK regions
Privacy Policy: https://aws.amazon.com/privacy/
Legal Basis: Contract performance (essential service infrastructure)
Google Cloud Platform
Purpose: Cloud hosting and services
Data Shared: Platform data stored in EU/UK regions
Privacy Policy: https://cloud.google.com/privacy
Legal Basis: Contract performance (essential service infrastructure)
Payment Processing:
Stripe (Stripe Inc.)
Purpose: Payment processing and subscription management
Data Shared: Payment information, transaction data, billing details
Privacy Policy: https://stripe.com/privacy
Legal Basis: Contract performance (payment processing)
Marketing and Advertising (with consent):
Meta/Facebook (Meta Platforms Inc.)
Purpose: Social media advertising and conversion tracking
Data Shared: User interactions, conversion events, advertising identifiers
Privacy Policy: https://www.facebook.com/privacy/policy/
Legal Basis: Consent (required for marketing purposes)
LinkedIn (LinkedIn Corporation)
Purpose: Professional network advertising and B2B analytics
Data Shared: Professional information, engagement data, conversion metrics
Privacy Policy: https://www.linkedin.com/legal/privacy-policy
Legal Basis: Consent (required for marketing purposes)
X/Twitter (X Corp.)
Purpose: Social media conversion tracking and advertising
Data Shared: User interactions, conversion data, advertising metrics
Privacy Policy: https://twitter.com/en/privacy
Legal Basis: Consent (required for marketing purposes)
12.2 Third-Party Responsibilities
Third-party services are independent data controllers responsible for their own privacy practices. We encourage you to review their privacy policies and terms of service.
12.3 Data Sharing Controls
You can control data sharing with third-party services through:
Account settings and preferences
Integration-specific controls
Cookie consent management
Disconnecting or removing integrations
Contacting us for assistance
13. Children's Privacy
13.1 Age Restrictions
Our Services are restricted to users 18 years of age and older as specified in our Terms of Service. We do not knowingly collect personal information from individuals under 18 years of age.
13.2 Age Verification and Enforcement
We implement age verification measures including:
Terms of Service acknowledgment of age requirements during account creation
Account creation restrictions and monitoring for underage users
Proactive detection and removal of accounts suspected of underage use
13.3 Enhanced Protections for Inadvertent Collection
If Underage Use Detected:
Immediate account suspension and service termination
Deletion of all associated data including personal information and cookies within 24 hours
Parental notification where contact information is available
Enhanced monitoring procedures for compliance verification
Parental Rights:
Parents may contact us to request information about any data inadvertently collected from their children
Parents can request immediate deletion of any child's data
We will verify parental identity before providing information or taking action
13.4 EU/UK Specific Protections
For users in jurisdictions with specific protections for minors:
Enhanced consent requirements for users 16-18 in EU (GDPR Article 8)
Additional verification procedures for user age confirmation
Stricter data minimization principles for any inadvertently collected minor data
14. California Privacy Rights (CCPA)
14.1 California Consumer Rights
If you're a California resident, you have the right to:
Right to Know: Request information about the personal information we collect, use, and share about you.
Right to Delete: Request deletion of your personal information (subject to certain exceptions).
Right to Opt-Out: Opt out of the sale of your personal information (we do not sell personal information).
Right to Non-Discrimination: Receive equal service and pricing regardless of exercising your privacy rights.
14.2 Categories of Information
In the last 12 months, we have collected the following categories of personal information:
Identifiers (name, email, IP address)
Commercial information (purchase history, preferences)
Internet activity (usage data, browsing behavior)
Professional information (company, job title)
Inferences (preferences, characteristics)
14.3 Sources and Purposes
We collect this information from:
Directly from you
Your use of our Services
Third-party integrations and partners
We use this information for the business purposes described in Section 3.
14.4 Information Sharing
We share personal information with service providers, business partners, and as required by law, as described in Section 5.
14.5 Exercising California Rights
To exercise your California privacy rights:
Email: privacy@alludium.ai
Subject line: "California Privacy Rights Request"
Include: Your name, email, and specific request
Response time: 45 days (extendable to 90 days)
We may verify your identity before responding using reasonable methods proportionate to the risk.
15. EU/EEA Privacy Rights (GDPR)
15.1 Our Role
We act as both a data controller and data processor under GDPR:
Data Controller for:
Account information and user management
Platform analytics and service improvement
Marketing and communications
Security and fraud prevention
Data Processor for:
Customer data you upload and process through our Services
AI training data you provide
Content you create or generate using our platform
Data processing activities performed at your direction
When acting as data processor, you remain the data controller and are responsible for:
Ensuring lawful basis for processing
Obtaining necessary consents from data subjects
Providing privacy notices to individuals whose data you process
Ensuring data subject rights can be exercised
Complying with data protection principles
15.2 Lawful Basis Summary
We process your data based on:
Contract performance: Providing Services, account management, payment processing
Consent: Marketing communications, non-essential cookies, optional features
Legal compliance: Regulatory requirements, legal requests, tax obligations
15.3 Data Protection Officer
We have not appointed a Data Protection Officer as we do not meet the mandatory appointment criteria under GDPR. For privacy matters, contact privacy@alludium.ai.
15.4 EU Representative
As we do not have an establishment in the EU and our processing activities are limited, we have not appointed an EU representative. EU residents may contact us directly at privacy@alludium.ai.
15.5 Supervisory Authority
You can contact your local supervisory authority for privacy complaints and concerns. In the UK, this is the Information Commissioner's Office (ICO).
16. Changes to This Privacy Policy
16.1 Policy Updates
We may update this Privacy Policy from time to time to reflect:
Changes in our Services or business practices
New legal requirements or regulations
Feedback from users and stakeholders
Industry best practices and standards
16.2 Notification of Changes
When we make changes, we will:
Update the "Last Updated" date at the top of this policy
Post the revised policy on our website
Notify you via email for material changes
Provide notice through our Services
Give you 30 days' notice for significant changes affecting your rights
16.3 Your Acceptance
Your continued use of our Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
17. Contact Information
17.1 Privacy Questions
For questions about this Privacy Policy or our privacy practices:
Email: privacy@alludium.ai
Subject Line: "Privacy Policy Inquiry"
17.2 Data Subject Requests
To exercise your privacy rights:
Email: privacy@alludium.ai
Subject Line: "Data Subject Rights Request"
17.3 General Contact
Alludium Ltd
Company Number: 15062888
Email: legal@alludium.ai
Website: https://www.alludium.ai/
Registered Office: International House, 36-38 Cornhill, London, United Kingdom, EC3V 3NG
17.4 Other Contacts
Technical Support: support@alludium.ai
Legal Matters: legal@alludium.ai
DMCA Notices: DMCA@alludium.ai
This Privacy Policy is effective as of August 1, 2025. We are committed to protecting your privacy and will continue to update our practices to meet the highest standards of data protection.