Last updated: July 22, 2026
Privacy Policy
How ALLM processes personal data about visitors, prospects, Customers and Users under the GDPR.
1. Scope and roles
This policy covers the public website, contact requests, ALLM accounts, Customer workspace and API. Where ALLM processes personal data in Customer Data to provide the Service, ALLM is a processor and the Customer is the controller; the Data Processing Agreement applies.
ALLM does not sell personal data or use Customer API request content for behavioural advertising.
2. Data we process
Depending on your relationship with ALLM, we may process professional identity and contact details; account and authentication data; billing and commercial data; support communications; technical data including IP address, browser, system, timestamps and security logs; cookie preferences; and pseudonymised usage data where you consented.
Please do not submit sensitive personal data in fields that do not require it. Authentication data never includes your password in plain text.
3. Purposes, lawful bases and retention
| Purpose | Lawful basis | Indicative retention |
|---|---|---|
| Manage an account and provide the API | Contract performance | Account term, then necessary statutory archive |
| Billing, fraud prevention and accounting | Legal obligation and legitimate interest | Applicable accounting and limitation periods |
| Answer contact or support requests | Legitimate interest or pre-contractual steps | Up to 3 years after last contact, unless contractual |
| Secure the Service and investigate incidents | Legitimate interest and legal obligation where applicable | Necessary period, then limited archive |
| Measure audience and improve the website | Consent where required | Choice: up to 13 months; aggregated data per settings |
| B2B marketing for similar services | Legitimate interest, with opt-out | 3 years after last contact |
Retention is adjusted where longer storage is needed to establish, exercise or defend legal claims or meet a legal obligation. Data is then deleted or irreversibly anonymised.
4. Recipients and subprocessors
Access is restricted to authorised ALLM personnel and providers needed for hosting and deployment, authentication and database services, payment, email delivery, support and consent-based analytics. Providers act only under documented instructions and confidentiality and security obligations. The Customer subprocessor list is available in the DPA.
5. International transfers
Some providers may process data outside the European Economic Area. ALLM uses an appropriate transfer mechanism, including an adequacy decision or European Commission Standard Contractual Clauses, with supplementary measures where necessary. Request information about applicable safeguards at privacy@use-allm.com.
6. Your rights
You may request access, rectification, erasure, restriction, objection, portability where applicable and withdrawal of consent at any time. Email privacy@use-allm.com. We may request proportionate proof of identity where reasonable doubt exists and respond within GDPR deadlines. You may lodge a complaint with the CNIL or your competent supervisory authority.
7. Security, breaches and updates
ALLM uses proportionate measures including access controls, encryption in transit, role segregation, logging, backups and incident-management procedures. No system is infallible. We take appropriate measures and make required notifications in the event of a personal-data breach; as processor, ALLM notifies the Customer without undue delay.
The Service is intended for professionals and is not designed for minors. We may update this policy for legal, service or practice changes and will provide appropriate notice of material changes.