1. Introduction and Scope
This Privacy Policy governs the collection, processing, storage, and disclosure of personal and organizational data by Alphasol LLC ("Alphasol," "we," "our," or "us"), a limited liability company registered under the laws of the United States. This document applies to all data ingested through our digital properties, client engagement portals, cloud-integrated platforms, and associated infrastructure systems.
Alphasol operates as a Business Integrator, providing cloud infrastructure deployment, product engineering, and digital growth execution for enterprise clients across multiple jurisdictions. Due to the technical nature of our services, data processing activities extend across multiple cloud environments, API integrations, and distributed server architectures. This policy reflects the full scope and complexity of those operations.
By accessing alphasol-llc.com, submitting a partnership intake request, or entering into any engagement with Alphasol, you acknowledge and agree to the practices described in this policy.
2. Corporate Identity and Data Controller
Alphasol LLC is the data controller for all information collected through our platforms and engagement workflows.
- Registered Entity: Alphasol LLC
- Corporate Structure: United States Limited Liability Company
- US Corporate Headquarters: 3000 Custer Road, Suite 270 #134, Plano, TX 75057
- International Operational Hub: 43 Allibhai Centre, 233-A, Block 2, PECHS, Karachi, Pakistan 75400
- Primary Contact: hello@alphasol-llc.com
- Website: https://alphasol-llc.com
All data governance decisions are made at the US corporate level. Personnel operating from our Pakistan engineering hub are bound by the same data handling obligations under binding internal agreements and our company-wide security policy.
3. Categories of Data We Collect
3.1 Information You Provide Directly
- Identity Data: Full name, professional title, organizational role
- Contact Data: Business email address, phone number (when provided)
- Corporate Data: Company name, industry classification, website URL, organizational scale
- Engagement Data: Integration scope selection, project briefs, strategic objectives, and technical requirements submitted via our intake form
- Communication Data: All correspondence exchanged via email, intake forms, or project management channels during active engagements
3.2 Automatically Collected Technical Data
- Server Log Data: IP addresses, request timestamps, HTTP methods, response codes, user-agent strings, and referring URLs generated by interactions with our web server
- Session Analytics: Page interaction patterns, scroll depth, element engagement signals, and time-on-page metrics collected in aggregate, anonymized form
- Cookie Data: Session identifiers, functional preference tokens, and analytics identifiers as described in Section 8
- Device and Network Data: Browser type and version, operating system, screen resolution, and connection type
3.3 Data Ingested Through Cloud Application Integrations
When Alphasol deploys, manages, or integrates cloud infrastructure on behalf of a client, we may process:
- API authentication tokens and service account credentials (stored exclusively in encrypted vaults with access scoped to role requirements)
- Database schemas, pipeline configurations, and environment variables within managed infrastructure environments
- Webhook payloads and event stream data routed through our managed services
- Application performance metrics and error telemetry from monitored client systems
Note on Client Infrastructure Data: All data processed within client cloud environments is governed by a separate, project-specific Data Processing Agreement (DPA) executed at the commencement of each engagement. This Privacy Policy covers Alphasol's own corporate data operations.
4. Legal Basis for Processing
Where applicable international data protection legislation applies, including but not limited to the General Data Protection Regulation (GDPR), UK GDPR, and equivalent standards in other jurisdictions, Alphasol processes personal data under the following legal bases:
| Processing Purpose | Legal Basis |
|---|---|
| Responding to partnership inquiries and intake submissions | Legitimate interests / Pre-contractual measures |
| Service delivery, cloud integration, and sprint execution | Contractual necessity |
| Legal compliance and regulatory reporting obligations | Legal obligation |
| Website analytics and performance monitoring | Legitimate interests |
| Marketing communications (where opted-in) | Consent |
| Security monitoring and fraud prevention | Legitimate interests |
| Financial record-keeping and billing | Legal obligation / Contractual necessity |
5. How We Use Collected Data
Alphasol uses collected data strictly for the following operational purposes:
- Partnership Assessment: Evaluating alignment between prospective client requirements and Alphasol's integration capabilities, and responding to submitted intake briefs
- Engagement Delivery: Executing cloud deployments, engineering sprints, and growth campaigns per approved project scopes and signed Statements of Work
- Account Management: Maintaining accurate records of active and historical engagements, billing cycles, deliverable archives, and client communications
- Platform Security: Monitoring server access logs, detecting anomalous activity patterns, and protecting the integrity of client infrastructure environments under our management
- Service Improvement: Analyzing aggregate, irreversibly anonymized usage patterns to refine Alphasol's service methodologies and digital platform performance
- Legal Compliance: Fulfilling obligations under applicable US federal and state law, and equivalent international standards where applicable
We do not sell, rent, or trade personal data to third parties for commercial gain under any circumstances. Data is processed only to deliver the services described above or to comply with legal obligations.
6. Cross-Border Data Transfers
Alphasol operates under United States corporate governance (Alphasol LLC). Our primary data infrastructure is hosted on US-compliant cloud platforms with data centers in the United States. However, due to our distributed operational model, with a US corporate headquarters in Plano, TX and a Pakistan engineering hub in Karachi, certain data may be accessed by personnel and authorized systems operating under both jurisdictions.
All cross-border data processing activities are governed by the following controls:
- Binding contractual agreements holding all personnel under explicit confidentiality and data handling obligations, regardless of location
- Access permissions strictly scoped to role-specific operational requirements: personnel in Pakistan access only the client project data required to execute their sprint assignments
- Encrypted transmission protocols (minimum TLS 1.2) enforced for all inter-jurisdictional data flows and remote system access
- Prohibition on local storage of client data outside of designated, access-controlled cloud environments
- Regular access audits conducted by US-based principals against all active permission sets
For EU/UK data subjects, where Standard Contractual Clauses (SCCs) or equivalent legal transfer mechanisms are applicable to cross-border data flows, Alphasol maintains and relies on those instruments supplemented by the technical safeguards described above.
7. Data Retention Schedules
Alphasol retains data for the minimum period necessary to fulfill the purpose for which it was collected, subject to legal and contractual obligations.
| Data Category | Retention Period | Basis |
|---|---|---|
| Partnership intake submissions (non-converted) | 24 months | Legitimate interests |
| Active client engagement records | Duration + 7 years | Legal / contractual obligation |
| Server access and application logs | 90 days rolling | Security monitoring |
| Cookie and website analytics data | 13 months maximum | Analytics standards |
| Financial and billing records | 7 years | US tax and legal requirements |
| Email and project correspondence | 5 years post-engagement | Operational and legal records |
Upon expiration of applicable retention periods, data is securely and permanently deleted or irreversibly anonymized using industry-standard destruction procedures.
8. Cookies and Tracking Technologies
Alphasol's web properties utilize the following categories of cookies and equivalent client-side tracking mechanisms:
Strictly Necessary Cookies
Session management tokens and functional identifiers required for core website operation. These cookies cannot be disabled without materially impairing site functionality. No consent is required for these cookies under applicable law.
Analytics Cookies
First-party analytics instruments that measure aggregate traffic patterns, device type distribution, and navigation flow data to enable performance monitoring. Data collected through these cookies is anonymized and processed in aggregate only. No personally identifiable information is built from these signals.
Performance Cookies
Lightweight monitoring scripts that capture page load times, JavaScript error events, and server response telemetry to maintain website quality standards. These instruments do not track individual users across sessions.
You may configure cookie preferences through your browser's privacy settings. Disabling non-essential cookies will not prevent you from accessing our content or submitting a partnership intake request. We do not deploy third-party advertising or behavioral tracking cookies.
9. Server Log Data and Infrastructure Telemetry
All interactions with Alphasol's digital infrastructure automatically generate server log records. These records contain technical identifiers including IP addresses, request metadata (URI, HTTP method, response code), timestamps, and user-agent strings. This data is:
- Stored in isolated, access-controlled log management systems with restricted access to authorized security and operations personnel only
- Retained for a maximum rolling period of 90 days under standard operating conditions
- Never cross-referenced with personal identity data for commercial profiling, behavioral advertising, or sale to third parties
- Subject to automated deletion procedures upon expiration of the retention window
In the event of a confirmed or suspected security incident, log data may be preserved beyond the standard 90-day window for the duration of the investigation and any subsequent legal or regulatory proceedings. Such extended retention will be documented internally and disclosed to affected parties where legally required.
10. Security Architecture
Alphasol applies enterprise-grade security controls across all data processing environments. These measures are reviewed and updated continuously as part of our operational security program:
- Encryption at Rest: AES-256 encryption applied to all stored client data and sensitive configuration artifacts
- Encryption in Transit: TLS 1.2 minimum enforced for all data transmission, including inter-system communication, remote access sessions, and API calls
- Access Control: Role-based access control (RBAC) with the principle of least privilege enforced across all internal systems and client project environments
- Authentication: Multi-factor authentication (MFA) mandatory for all administrative access to production infrastructure and client account environments
- Audit Trails: Immutable activity logs maintained for all access events within managed client infrastructure, reviewed regularly by US-based principals
- Vulnerability Management: Regular dependency auditing, security patch cycles, and penetration testing against production-facing systems
- Incident Response: A documented incident response protocol with defined breach notification procedures aligned to applicable legal timescales (72 hours for GDPR-regulated incidents; without undue delay for US-jurisdiction events)
11. Your Rights as a Data Subject
Where applicable data protection law grants you rights over personal data that Alphasol holds about you, you may exercise the following:
- Right of Access: Request a copy of the personal data Alphasol holds about you, along with information about how it is processed
- Right to Rectification: Request correction of inaccurate or materially incomplete data
- Right to Erasure: Request permanent deletion of your personal data, subject to legal retention obligations that may require us to retain certain records
- Right to Restriction: Request that Alphasol limit its processing of your data in specified circumstances, including while a rectification or objection request is under review
- Right to Data Portability: Receive data you have provided to us in a structured, commonly used, machine-readable format
- Right to Object: Object to processing conducted on the basis of legitimate interests, including direct marketing activities
- Right to Withdraw Consent: Where processing is based on your consent, withdraw that consent at any time without affecting the lawfulness of prior processing
To exercise any of these rights, submit a written request to hello@alphasol-llc.com with the subject line "Data Rights Request." We will acknowledge receipt within 5 business days and respond substantively within 30 calendar days, or within the timeframe required by applicable law.
12. Third-Party Services and Processors
Alphasol engages select third-party service providers to support operational delivery. All processors are contractually bound to:
- Process personal data only on Alphasol's documented instructions
- Maintain technical and organizational security measures equivalent to or exceeding Alphasol's own standards
- Not engage sub-processors without Alphasol's prior written consent
- Delete or return all personal data upon termination of the processing relationship
Current categories of third-party processors engaged by Alphasol include: cloud infrastructure providers (compute, storage, and networking services), transactional email delivery platforms, and project coordination and documentation systems. A current Data Processing Register is maintained internally and is available to active clients upon request under a signed confidentiality agreement.
13. Children's Data
Alphasol's services are designed exclusively for corporate entities and business professionals. We do not knowingly collect, solicit, or process personal data relating to individuals under 18 years of age. If we become aware that such data has been inadvertently collected through our intake systems, it will be permanently deleted within 48 hours of discovery, and the submitting party will be notified.
14. Policy Amendments
Alphasol LLC reserves the right to update this Privacy Policy periodically to reflect changes in our operational practices, the legal landscape, or the technology we deploy. The effective date at the top of this document will always reflect the most recent revision.
Material changes to this policy, specifically, changes that alter the categories of data collected, the purposes for which it is used, or the rights available to data subjects, will be communicated to active clients via direct email notification prior to taking effect. For prospective clients and website visitors, the updated policy will be published on this page with the revised effective date.
Continued engagement with Alphasol following publication of a revised policy constitutes acceptance of the updated terms.
15. Contact and Supervisory Authority
For all privacy-related inquiries, data rights requests, or concerns regarding this policy, contact us at:
- Email: hello@alphasol-llc.com
- Subject Line: Data Privacy Inquiry
- Entity: Alphasol LLC
If you believe your data rights have been infringed and our response has been inadequate, you have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction. EU residents may contact their national supervisory authority; UK residents may contact the Information Commissioner's Office (ICO) at ico.org.uk.