Privacy Policy

GDPR Compliant
CCPA Compliant
Version 2.0

Last updated: December 20, 2024

Effective date: January 1, 2025

1. Introduction and Our Commitment

At ALO Software ("we," "our," or "us"), we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or interact with us.

We believe in transparency and want you to understand exactly how your data is handled. This policy applies to all information collected through our website, software products, services, and any related communications.

Our Privacy Principles:

* We collect only what we need to provide our services

* We never sell your personal information to third parties

* We implement strong security measures to protect your data

* We give you control over your personal information

* We are transparent about our data practices

2. Information We Collect

2.1 Personal Information You Provide

We collect information you voluntarily provide to us, including:

Contact Information

* Name and email address

* Phone number

* Company name and job title

* Mailing address

Account Information

* Username and password

* Profile information

* Billing and payment details

* Service preferences

Communication Data

* Messages and inquiries

* Support tickets

* Survey responses

* Feedback and reviews

Professional Information

* Industry and company size

* Project requirements

* Technical specifications

* Business needs assessment

2.2 Information Collected Automatically

When you visit our website or use our services, we automatically collect certain information:

Technical Information

* Device Information: IP address, browser type, operating system, device identifiers

* Usage Data: Pages visited, time spent, click patterns, referral sources

* Location Data: General geographic location based on IP address

* Performance Data: Page load times, error reports, system performance metrics

2.3 Cookies and Tracking Technologies

We use various technologies to collect information automatically:

* Essential Cookies: Required for website functionality and security

* Analytics Cookies: Help us understand website usage and improve performance

* Functional Cookies: Remember your preferences and enhance user experience

* Marketing Cookies: Used for personalized advertising and campaign measurement

You can manage your cookie preferences through our Cookie Preferences Center.

3. How We Use Your Information

We use the information we collect for the following purposes:

Service Delivery

* Provide and maintain our services

* Process transactions and billing

* Deliver customer support

* Send service-related communications

Personalization

* Customize user experience

* Remember preferences and settings

* Provide relevant content recommendations

* Tailor our services to your needs

Analytics & Improvement

* Analyze website and service usage

* Improve our products and services

* Conduct research and development

* Monitor performance and security

Marketing & Communication

* Send promotional materials (with consent)

* Conduct marketing campaigns

* Measure advertising effectiveness

* Provide industry insights and updates

Legal Basis for Processing (GDPR)

For users in the European Union, we process your personal data based on:

* Consent: When you explicitly agree to data processing

* Contract: To fulfill our contractual obligations to you

* Legitimate Interest: For business operations that don't override your rights

* Legal Obligation: To comply with applicable laws and regulations

4. Data Storage, Security, and Retention

4.1 Data Storage

Your data is stored on secure servers located in the United States and may be processed in other countries where we or our service providers operate. We ensure that all data transfers comply with applicable privacy laws.

4.2 Security Measures

We implement comprehensive security measures to protect your personal information:

Technical Safeguards

* End-to-end encryption for data transmission

* AES-256 encryption for data at rest

* Secure Socket Layer (SSL) certificates

* Regular security audits and penetration testing

* Multi-factor authentication

Administrative Safeguards

* Access controls and user permissions

* Employee training on data protection

* Background checks for personnel

* Incident response procedures

* Regular security awareness training

4.3 Data Retention

We retain your personal information only as long as necessary for the purposes outlined in this policy:

* Account Data: Retained while your account is active and for 3 years after closure

* Transaction Records: Kept for 7 years for legal and tax compliance

* Marketing Data: Retained until you opt out or for 2 years of inactivity

* Website Analytics: Aggregated data retained for 26 months

* Support Communications: Kept for 3 years for quality assurance

Data Breach Notification: In the unlikely event of a data breach affecting your personal information, we will notify you and relevant authorities within 72 hours as required by law.

5. Information Sharing and Third Parties

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

5.1 When We Share Information

We may share your information in the following limited circumstances:

Service Providers

We work with trusted third-party service providers who help us operate our business:

* Cloud Hosting: Amazon Web Services (AWS), Microsoft Azure

* Payment Processing: Stripe, PayPal

* Email Services: SendGrid, Mailchimp

* Analytics: Google Analytics, Mixpanel

* Customer Support: Zendesk, Intercom

Legal Requirements

We may disclose information when required by law, such as in response to subpoenas, court orders, or government requests, or to protect our rights, property, or safety.

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity, subject to the same privacy protections.

5.2 Third-Party Services

Our website may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these external services. We encourage you to review their privacy policies.

6. Your Privacy Rights

You have important rights regarding your personal information. The specific rights available to you may depend on your location:

Right to Access

Request a copy of the personal information we hold about you, including how it's used and shared.

Right to Rectification

Correct any inaccurate or incomplete personal information we have about you.

Right to Erasure

Request deletion of your personal information, subject to certain legal limitations.

Right to Restrict Processing

Limit how we process your personal information in certain circumstances.

Right to Data Portability

Receive your personal information in a portable format or transfer it to another service.

Right to Object

Object to processing of your personal information for direct marketing or legitimate interests.

How to Exercise Your Rights

To exercise any of these rights, you can:

* Email us at privacy@alosoftware.com

* Use our online privacy request form (if you have an account)

* Contact us through our customer support channels

* Send a written request to our mailing address

Response Time: We will respond to your request within 30 days (or 1 month for GDPR requests). For complex requests, we may extend this period and will notify you of any delays.

7. Regional Privacy Compliance

7.1 European Union (GDPR)

For users in the European Union, we comply with the General Data Protection Regulation (GDPR):

* We obtain explicit consent for non-essential data processing

* We provide clear information about data processing purposes

* We implement privacy by design and by default

* We conduct Data Protection Impact Assessments when required

* We have appointed a Data Protection Officer (DPO)

7.2 California (CCPA/CPRA)

For California residents, we comply with the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

* Right to know what personal information is collected and how it's used

* Right to delete personal information (with certain exceptions)

* Right to opt-out of the sale of personal information

* Right to non-discrimination for exercising privacy rights

* Right to correct inaccurate personal information

* Right to limit the use of sensitive personal information

California Notice: We do not sell personal information as defined by the CCPA. We may share information with service providers for business purposes as described in this policy.

7.3 Other Jurisdictions

We also comply with privacy laws in other jurisdictions where we operate, including:

* Canada: Personal Information Protection and Electronic Documents Act (PIPEDA)

* Australia: Privacy Act 1988

* Brazil: Lei Geral de Proteção de Dados (LGPD)

* United Kingdom: UK GDPR and Data Protection Act 2018

8. Children's Privacy

Our services are not intended for children under the age of 16 (or the minimum age required by law in your jurisdiction). We do not knowingly collect personal information from children under this age.

If we become aware that we have collected personal information from a child under the applicable age without parental consent, we will take steps to delete that information promptly.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@alosoftware.com.

9. International Data Transfers

Your personal information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws than your country.

Safeguards for International Transfers

When we transfer personal information internationally, we ensure appropriate safeguards are in place:

* Adequacy Decisions: Transfers to countries with adequate data protection laws

* Standard Contractual Clauses: EU-approved contracts for data protection

* Binding Corporate Rules: Internal policies ensuring consistent protection

* Certification Schemes: Industry-recognized privacy certifications


EU-US Data Privacy Framework: We comply with the EU-US Data Privacy Framework for transfers of personal data from the EU to the United States.

10. Changes to This Privacy Policy

How We Update This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

Notification of Changes

When we make material changes to this policy, we will notify you by:

* Sending an email to your registered email address

* Posting a prominent notice on our website

* Providing in-app notifications for significant changes

* Updating the "Last Updated" date at the top of this policy

Your Continued Use

Your continued use of our services after we publish or send a notice about changes to this Privacy Policy means you consent to the updated policy, unless you exercise your right to opt-out or delete your account.


Stay Informed: We recommend reviewing this Privacy Policy periodically to stay informed about how we protect your information.

11. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy Officer

Email: privacy@alosoftware.com

Response Time: Within 48 hours

Data Protection Officer (EU)

Email: dpo@alosoftware.com

Mailing Address

ALO Software - Privacy Department
123 Tech Street
San Francisco, CA 94105
United States

General Contact

Phone: +1 (555) 123-4567
Email: contact@alosoftware.com

This policy is effective as of January 1, 2025. By using ALO Software's services, you acknowledge that you have read, understood, and agree to be bound by this policy.