Alphorix Privacy Policy
For alphorix.net and the Alphorix marketing & sales CRM
Effective date: 6 August 2026
This Policy explains how Alphorix handles personal data when it operates the website and CRM, and how it handles lead, contact, campaign and communication data on behalf of its customers.
Our core commitments
- We do not sell Personal Data or Customer Data.
- Customer Data is processed only to provide, secure and support the Service under the customer's instructions.
- We do not use Customer Data to train third-party or general-purpose artificial intelligence models without a separate, explicit written agreement.
- We provide individuals with practical ways to exercise their privacy rights.
1. Who we are and what this Policy covers
Alphorix is a trading name of Alphorix For Marketing Services, a business established in Abu Dhabi, United Arab Emirates. In this Policy, "Alphorix", "we", "us" and "our" refer to that entity.
This Policy applies when you visit alphorix.net, create or use an Alphorix workspace, start a trial, purchase a subscription, contact our sales or support teams, receive communications from us, or otherwise interact with the Alphorix marketing and sales CRM (together, the "Service").
This Policy does not govern the independent privacy practices of an Alphorix customer, including a broker, prop firm, financial-services advertiser or marketing team that uses the Service. Those customers decide why and how they use the personal data in their own workspaces and must provide their own notices to leads, clients and other individuals.
For this Policy, "Personal Data" means information relating to an identified or reasonably identifiable individual. "Customer Data" means data a customer or its authorised users upload, collect, generate, transmit or manage through a workspace.
2. Our role: controller and processor
2.1 When Alphorix decides how data is used
Alphorix acts as a data controller when it processes information about website visitors, prospective customers, account administrators, authorised users, suppliers and business contacts for its own purposes. These purposes include operating the website, administering accounts, billing, securing the Service, providing support, improving the Service and communicating about Alphorix.
2.2 When a customer decides how data is used
For Customer Data, the customer normally acts as the controller and Alphorix acts as its processor or service provider. We handle that data under the customer's documented instructions, the applicable agreement and any Data Processing Agreement. If your data appears in a customer's workspace, you should usually direct your request to that customer. We will assist the customer where required by law and contract.
3. Personal Data we collect
3.1 Enquiries, forms and business contacts
When you submit a form, request a demonstration, start a trial, attend an online meeting or contact us, we may collect your name, work email, telephone number, country, company, job title, website, the content of your message and your communication preferences.
3.2 Account and workspace information
When an account is created or administered, we may collect the workspace name, company details, administrator and user names, work email addresses, telephone numbers, country, role and permission settings, login credentials, plan details, invited users, workspace configuration, brand assets, custom-domain settings and other information needed to configure the Service. Passwords are stored in hashed form rather than readable text.
3.3 Billing and transaction information
When a paid subscription is purchased, we collect billing contacts, billing address, tax details, invoice information, plan and payment status. Card payments are processed by an external payment provider. Alphorix does not need to store full payment-card numbers or security codes and may receive only limited transaction references, card brand and the final digits needed for account administration. Bank-transfer records may be retained for reconciliation and legal recordkeeping.
3.4 Technical and usage information
We automatically record information needed to operate and protect the Service, such as IP address, browser and device type, operating system, referring page, pages or features used, timestamps, login events, session identifiers, error reports, audit events and approximate location inferred from IP address. We may also collect aggregated feature-usage information to understand performance and improve the user experience.
3.5 Customer Data inside the CRM
Customers may upload or capture data about leads, contacts, clients, campaigns and sales activity. Depending on the customer's configuration, Customer Data may include names, contact details, country, language, lead source, campaign identifiers, assigned agent, pipeline status, qualification or priority information, notes, tasks, meetings, email and WhatsApp content or metadata, call outcomes, deposit or conversion fields, uploaded files, consent records and other fields created by the customer. Alphorix does not independently decide which individuals a customer adds to the CRM or the purposes for which the customer contacts them. Each customer is responsible for the legality, accuracy and relevance of the Customer Data it collects and for obtaining any required notices, permissions or consents.
3.6 Support and service communications
If you contact support, we may retain your correspondence, attachments, diagnostic information, call or meeting details and the steps taken to resolve the issue. Calls are not recorded unless you are informed and any consent required by law is obtained.
3.7 Integrations and connected services
If a Workspace Admin enables an integration, the connected provider may send data to or receive data from Alphorix within the permissions approved by the customer. Examples may include lead sources, email delivery, messaging, forms, webhooks or advertising platforms. The customer controls whether to connect or revoke an integration and should review the provider's privacy terms and requested permissions.
3.8 Information from other sources
We may receive business contact or account information from an authorised colleague, referral partner, service provider, public business source or a platform you ask us to connect. We do not operate a commercial contact-enrichment dataset and do not collect publicly available personal data for resale.
4. Why we use Personal Data and our lawful grounds
We process Personal Data only for identified, lawful purposes and limit processing to what is reasonably necessary. Under the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, processing is based on consent or another condition permitted by law. Where the EU GDPR, UK GDPR or a similar regime applies, the lawful ground may be performance of a contract, compliance with law, legitimate interests that do not override individual rights, or consent.
| Purpose | Typical data | Lawful ground |
|---|---|---|
| Operate the Service | Account, workspace, user and Customer Data | Contract; customer instructions |
| Support and communications | Contact details, correspondence and support records | Contract; consent; legitimate interests where permitted |
| Billing and administration | Billing contact, transaction and invoice information | Contract; legal obligations |
| Security and abuse prevention | Login events, IP address, device and audit logs | Legal obligations; legitimate interests where permitted |
| Service improvement | Aggregated or de-identified usage statistics and limited telemetry | Legitimate interests where permitted |
| Marketing | Business contact details and communication preferences | Consent or other lawful basis; opt-out available |
| Legal compliance | Records relevant to a legal request, dispute or regulatory duty | Legal obligation; establishment or defence of legal claims |
The exact lawful ground depends on the context, the data involved and the law that applies to the individual. We may create aggregated or de-identified statistics to measure reliability, usage and service performance. We will not use such information to identify an individual and will apply measures intended to prevent re-identification.
5. How we handle Customer Data
- Instructions. We process Customer Data only to provide, maintain, secure and support the Service, or as otherwise documented in the customer's agreement or written instructions.
- Confidentiality and access. Access by Alphorix personnel is limited to authorised individuals who need it for operations, security, troubleshooting, support, legal compliance or another documented purpose.
- No sale or advertising use. We do not sell Customer Data, use it to build advertising profiles for third parties, or allow one customer to access another customer's data.
- No general-purpose AI training. Customer Data is not used to train third-party or general-purpose AI or machine-learning models without a separate, explicit written agreement and an appropriate lawful basis.
- Customer responsibility. Customers must provide lawful instructions, maintain required notices and consents, configure access appropriately, honour data-subject rights, and avoid uploading data they are not legally entitled to use.
- Assistance. Where required, we assist customers with data-subject requests, security enquiries, impact assessments, audits and breach response, subject to the applicable agreement and law.
6. When we disclose Personal Data
We disclose Personal Data only when reasonably necessary for the Service, required by law or directed by the customer. Recipients may include:
- Infrastructure and sub-processors that provide hosting, managed databases, encrypted object storage, backups, authentication, monitoring and technical support.
- Payment and billing providers. Current card payments are processed through Stripe; Alphorix receives only the transaction information needed to administer the subscription.
- Communication providers used for transactional email and customer-directed workflows, including Resend and connected email or WhatsApp services where enabled by the customer.
- Professional advisers, auditors, insurers and other specialists who are bound by confidentiality duties.
- Government authorities, courts, regulators or law-enforcement bodies where disclosure is legally required or reasonably necessary to protect rights, safety, security or the integrity of the Service.
- A buyer, investor or successor in connection with a genuine financing, merger, reorganisation or sale of all or part of the business, subject to appropriate confidentiality and notice where required.
- Third parties a customer instructs us to connect with or disclose data to through an enabled integration.
Service providers are required by contract to use Personal Data only for authorised purposes, protect it appropriately and comply with applicable data-protection requirements. An up-to-date sub-processor list is available on request from legal@alphorix.net.
Alphorix does not sell Personal Data and does not share it for third-party cross-context behavioural advertising.
7. International data transfers
Alphorix is based in the Abu Dhabi, United Arab Emirates and serves customers in multiple countries. Personal Data may therefore be stored or accessed in the UAE or another country in which Alphorix or a service provider operates. Privacy laws in those countries may differ from the law where the individual lives.
When a cross-border transfer requires safeguards, we use measures appropriate to the applicable law. These may include transferring to a jurisdiction recognised as providing adequate protection, contractual data-protection clauses, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, supplementary security measures, or another lawful transfer mechanism. Customers may request information about the safeguards relevant to their account.
8. Cookies and similar technologies
alphorix.net uses first-party cookies and similar technologies that are necessary to authenticate users, maintain sessions, remember preferences, protect against abuse and understand basic technical performance. We may collect page views, feature interactions, referral information and device or browser characteristics for these purposes.
We do not deploy third-party advertising cookies or cross-site behavioural tracking on alphorix.net.
You can use your browser settings to block or remove cookies, but disabling strictly necessary cookies may prevent account login or other Service functions. If Alphorix later introduces optional analytics or advertising technologies, we will update the relevant notice and obtain consent where required before activating them.
9. Security and incident response
We maintain technical and organisational measures designed to protect Personal Data from accidental or unlawful loss, destruction, alteration, disclosure or access. These measures include encryption in transit using TLS 1.2 or later, encryption at rest, hashed passwords, workspace-level data isolation, role-based access controls, login protection, audit logging, encrypted backups, monitoring, vulnerability management and incident-response procedures.
Security is a shared responsibility. Customers must protect credentials, review user access, configure roles correctly, use secure devices and promptly report suspected unauthorised access to support@alphorix.net.
No internet service can guarantee absolute security. If a Personal Data breach occurs, Alphorix will investigate, contain and document the incident. We will notify affected customers and, where Alphorix is the controller, the competent authority and affected individuals when and as required by applicable law.
10. Retention, export and deletion
We keep Personal Data only for as long as reasonably required for the purpose for which it was collected, the customer's instructions, security, dispute resolution and applicable legal, accounting or regulatory obligations. Retention periods differ by data type and context.
- Active workspace data is retained while the subscription or trial remains active and as needed to provide the Service.
- After a paid workspace is cancelled or terminated, Customer Data is ordinarily held in a read-only state for 30 days to allow export, then deleted from the active environment unless law, a legal hold or a written agreement requires otherwise.
- Backup copies may remain for a limited period until they are overwritten through the normal encrypted backup cycle; they remain protected and are not returned to active use except for recovery or legal necessity.
- Billing, tax, contract, security and dispute records may be retained for the period required by law or reasonably necessary to establish or defend legal claims.
- Marketing opt-out records may be retained to ensure that an unsubscribe request continues to be respected.
Workspace Admins should export required Customer Data before the end of the applicable access period. Deletion from the active environment may be irreversible.
11. Your privacy rights
Depending on where you live and the law that applies, you may have rights to:
- receive information about the data we process and request access to it;
- correct incomplete or inaccurate Personal Data;
- request deletion where the legal conditions are met;
- restrict or object to certain processing, including direct marketing;
- receive data you provided in a structured, commonly used and machine-readable format, and request transfer where technically feasible;
- withdraw consent without affecting processing that was lawful before withdrawal;
- object to a decision based solely on automated processing where it produces legal or similarly significant effects; and
- submit a complaint to the competent data-protection authority.
To exercise a right relating to data Alphorix controls, email legal@alphorix.net and describe your request. We may need to verify your identity and authority before acting. We aim to respond within 30 days, or within another period required by applicable law. We may extend the period or decline part of a request only where the law allows and will explain the reason where permitted.
If your request concerns data placed in the Service by an Alphorix customer, contact that customer first. As processor, Alphorix cannot independently decide whether the customer's data should be accessed, corrected or deleted, but we will support the customer in responding where required.
12. Marketing and customer communications
Alphorix may send product information, invitations or business communications where it has consent or another lawful basis. You can unsubscribe from marketing email using the link in the message or by contacting legal@alphorix.net. We may keep a minimal suppression record so that we do not contact you again for the same marketing purpose.
Account, billing, security, legal and service-availability notices are transactional and may continue while an account remains active. Alphorix customers are independently responsible for messages they send to their own leads or contacts through the Service. To opt out of a customer's communication, use the opt-out method in that message or contact the customer directly.
13. Automated workflows, scoring and AI
The Service may route leads, flag service-level risks, create reminders, calculate lead-health indicators or prioritise records using customer-defined rules and activity data. These tools support the customer's staff; Alphorix does not use them on its own behalf to make decisions that produce legal or similarly significant effects for a customer's lead. Customers are responsible for evaluating their automated workflows, providing any required notices, keeping meaningful human review where appropriate, and ensuring that their use does not create unlawful discrimination or prohibited profiling.
If Alphorix introduces a materially different AI or automated-decision feature, this Policy and the relevant product notice will be updated before that processing begins.
14. Children and restricted data
The Service is a business-to-business product and is not intended for anyone under 18. Alphorix does not knowingly invite children to create accounts or submit Personal Data. If you believe a child has provided data directly to Alphorix, contact legal@alphorix.net so we can investigate and take appropriate action.
Customers must not use the Service to process children's data or highly sensitive data unless that processing is lawful, appropriate safeguards are in place, and the Service and applicable agreement expressly support it. Customers must not upload full payment-card credentials, passwords belonging to third parties, or data obtained unlawfully.
15. Third-party sites and services
The Service may contain links to or integrations with external websites, messaging services, advertising platforms and other providers. Their privacy practices are governed by their own notices. Alphorix is not responsible for an independent provider's processing, except to the extent the provider acts as Alphorix's contracted processor. Review the permissions and privacy terms before enabling an integration.
16. Changes to this Policy
We may update this Policy to reflect changes in law, the Service, security practices or data processing. The effective date at the top shows the latest revision. For a material change, we will provide reasonable advance notice to Workspace Admins by email, in-product notice or another appropriate method, unless an urgent legal or security reason requires faster action.
17. Contact and complaints
For questions, rights requests or privacy complaints, contact:
If you are not satisfied with our response, you may submit a complaint to the competent data-protection authority, including the UAE Data Office where it has jurisdiction, or the authority in your country where applicable.