Skip to main content

    Privacy Policy

    Last updated: 21 June 2026  |  Applies to: alira.uk

    1. Who We Are

    ALIRA Advisory Ltd (trading as ALIRA.) is a business consultancy registered in England & Wales, Company No: 16419663. We are the data controller responsible for personal data collected through alira.uk.

    We process personal data in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).

    Data protection contact: shuhayb@alira.uk | Phone: +44 7438 747300

    We are required to register with the Information Commissioner's Office (ICO) and pay the annual data protection fee. If you wish to verify our registration, visit ico.org.uk/esdwebpages/search and search for ALIRA Advisory Ltd.

    2. What Personal Data We Collect

    Account data

    When you register or sign in via Google or email (Firebase Authentication), we receive your name, email address, and profile image URL from your authentication provider.

    Business information

    Details you provide voluntarily when using our tools, including your business idea, goals, challenges, target audience, industry, and stage. Used to generate personalised business plans and analyses.

    Contact and enquiry data

    When you submit a contact form, quick intake, or callback request: your name, email address, company name, phone number (if provided), and the message you supply.

    Payment data

    Payments are processed entirely by Stripe. We do not receive or store your card details. We retain a record of transactions (amount, credit balance, subscription status) linked to your account for fulfilment and accounting.

    Email and marketing data

    When you subscribe to our newsletter or register: your email address, subscription status, and the source of submission. We send welcome emails and, where relevant, follow-up sequences.

    Analytics data (consent required)

    Only after you accept analytics cookies do we collect: page views, scroll depth, session duration, click and interaction events, exit behaviour, referrer URL, and UTM campaign parameters. This data is linked to an anonymous visitor ID (a random UUID) stored in your browser's local storage. No name, email, or account data is linked to this ID.

    If you select "Essential only" in our cookie banner, no analytics data is collected or transmitted from your browser at any point. Server-level access logs (IP address, HTTP method, URL path) are retained for security purposes under our legitimate interests basis. These logs are not combined with visitor analytics.

    Technical session data

    Session tokens necessary to keep you signed in. These are strictly necessary for the service and cannot be disabled.

    3. Lawful Basis for Processing

    • Contract performance (Article 6(1)(b)): Delivering services you have requested: generating business plans, running tool analyses, processing payments, and managing your account.
    • Legitimate interests (Article 6(1)(f)): Operating and securing our platform, fraud prevention, server access logging, and sending service-related communications to existing users. We have assessed that our interests do not override your rights and freedoms.
    • Consent (Article 6(1)(a) and PECR Regulation 6): Analytics tracking (visitor ID, page views, engagement events). You can withdraw consent at any time by selecting "Withdraw analytics consent" in the footer of any page or by clearing your browser's local storage, which will display the consent banner again on your next visit.
    • Consent for marketing: Newsletter and email marketing. Withdraw by clicking unsubscribe in any email or by emailing shuhayb@alira.uk.
    • Legal obligation (Article 6(1)(c)): Retaining payment records for six years under UK tax and accounting law.

    4. How We Use Your Data

    • Generating AI-powered business plans, analyses, and tool outputs tailored to your inputs.
    • Managing your account, credit balance, and subscription.
    • Processing payments and issuing receipts via Stripe.
    • Sending welcome and follow-up emails (where applicable).
    • Improving our platform through aggregated analytics (only with consent).
    • Detecting and preventing fraud and security threats.
    • Complying with our legal obligations.

    5. Data Sharing and Processors

    We share personal data only where necessary with the following data processors, each under a binding data processing agreement:

    • Firebase (Google LLC): Authentication. Manages sign-in. Data processed in the USA under Standard Contractual Clauses (SCCs) and Google's DPA.
    • Vercel Inc.: Web hosting and serverless functions. Our platform is deployed on Vercel's infrastructure (USA). Data processed under SCCs.
    • Neon Inc.: PostgreSQL database hosting. Your account data, plans, and tool sessions are stored on Neon's infrastructure (USA). Data processed under SCCs.
    • Anthropic PBC (Claude AI): Your business inputs (idea description, goals, challenges) are sent to Anthropic's Claude API to generate your personalised strategy plan. Anthropic does not use API inputs to train its models. Data processed in the USA under SCCs.
    • Stripe Inc.: Payment processing. PCI-DSS Level 1 compliant. We do not receive or store your card details. Data processed in the USA under SCCs.
    • Resend Inc.: Transactional email delivery (welcome emails, follow-up sequences, newsletters). Data processed in the USA under SCCs.

    We never sell your personal data. We may disclose data where required by law, court order, or regulatory authority.

    6. International Transfers

    All third-party processors listed in Section 5 operate in the United States. Transfers outside the UK are governed by the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs) adopted under the UK GDPR. Each processor is bound by a data processing agreement.

    For further information on these transfer mechanisms, contact us at shuhayb@alira.uk.

    7. Data Retention

    • Account data: Retained while your account is active. Deleted within 30 days of account closure or a deletion request.
    • Business plans and tool sessions: Retained until you delete them, close your account, or request deletion.
    • Payment records: Retained for six years from transaction date (UK legal obligation).
    • Contact and intake submissions: Retained for up to two years, or until you request deletion.
    • Analytics data: Raw analytics events retained for 26 months; aggregated summaries retained indefinitely.
    • Server access logs: Retained for 90 days for security purposes, then deleted.
    • Newsletter unsubscribe records: Retained indefinitely to prevent re-adding you to mailing lists.

    8. Your Rights Under UK GDPR

    • Right of access (Article 15): Request a copy of all personal data we hold. Registered users can export their data in JSON format directly from their dashboard.
    • Right to erasure (Article 17): Request permanent deletion of your account and associated data. Available directly from your dashboard, or by email.
    • Right to rectification (Article 16): Request correction of inaccurate data.
    • Right to restrict processing (Article 18): Request that we limit how we use your data in certain circumstances.
    • Right to data portability (Article 20): Receive your data in a structured, machine-readable format (JSON export).
    • Right to object (Article 21): Object to processing based on legitimate interests, including direct marketing.
    • Right to withdraw consent: Withdraw consent for analytics or marketing at any time without affecting any prior processing.

    To exercise any right, use your dashboard or email shuhayb@alira.uk. We will respond within one calendar month.

    You have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk | 0303 123 1113 | Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

    9. Cookies and Local Storage

    We use two categories of technologies (cookies and browser local storage):

    • Strictly necessary: Session authentication tokens (httpOnly cookies). Required for the service to function. Cannot be disabled. No consent required under PECR Regulation 6(4).
    • Analytics (consent required): An anonymous visitor ID (random UUID), session ID, and your cookie preference stored in browser local storage. Used to count page views, measure engagement, and improve the site. These are only created and sent to our servers after you click "Accept analytics" in our cookie banner. Under PECR Regulation 6, we are required to obtain your prior informed consent before placing these.

    We do not use advertising cookies, third-party tracking pixels, social media cookies, or any other cookies beyond those described above.

    To change your cookie preferences: Click "Withdraw analytics consent" or "Accept analytics cookies" in the footer of any page. Alternatively, clear your browser's local storage to reset the banner.

    10. NHS QI Tools: Data Commitment

    Our NHS Quality Improvement tools at alira.uk/nhs-qi are designed specifically to never require patient-identifiable information.

    • No patient data: You must not enter any patient-identifiable information (names, NHS numbers, dates of birth, diagnoses, clinical records, or any data from which a patient could be identified) into our platform. All improvement briefs must be anonymised before submission.
    • Local information-governance review: Not requiring patient data does not remove the need to assess your organisation’s use of the service. Your organisation should review the information entered, data handling and applicable approval requirements before use.
    • Not a clinical decision support tool: Outputs are QI planning frameworks only. They are not clinical advice, diagnoses, treatment recommendations, or validated healthcare guidance. Do not use outputs to make clinical decisions.
    • Not an MHRA-regulated medical device: Our tools are QI planning aids and are not registered as, nor intended to function as, medical devices under the Medical Devices Regulations 2002.
    • Caldicott Principles: Whilst ALIRA. is not a Caldicott Guardian-designated organisation, we are aligned with the principle that patient data should only be used where absolutely necessary. Our NHS QI tools are designed so that patient data is never necessary.
    • DSP Toolkit awareness: NHS organisations using our tools to support QI activity should satisfy themselves that their own use of the platform complies with their DSP Toolkit obligations, particularly regarding what improvement brief information staff enter.

    Questions about data handling for NHS use: shuhayb@alira.uk

    11. Data Security

    • Encrypted data transmission via TLS/HTTPS on all connections.
    • Secure server-side session management with httpOnly cookies.
    • HTTP security headers (Helmet) including Content Security Policy.
    • Rate limiting (100 requests per minute per IP) to prevent abuse.
    • Input validation on all API endpoints using Zod schema validation.
    • Payment data handled exclusively by Stripe (PCI-DSS Level 1).
    • Database access restricted to authenticated server processes only.
    • No analytics data collected or transmitted without prior user consent.

    In the event of a personal data breach that is likely to result in a risk to individuals, we will notify the ICO within 72 hours and affected individuals without undue delay, in accordance with UK GDPR Articles 33–34.

    12. AI-Generated Content and Transparency

    ALIRA. uses AI systems, including Anthropic Claude and OpenRouter-powered advisor workflows where configured, to generate personalised business strategy plans and analyses. We make the following disclosures in the spirit of the UK government's AI governance framework and ICO guidance on AI and data protection:

    What the AI does

    Your business inputs (goals, challenges, context) are processed by configured AI services to generate a structured plan or advisor response based on your inputs. Anthropic does not use API inputs to train or improve its models.

    What the AI does not do

    • AI outputs are not professional advice (legal, financial, clinical, or otherwise).
    • AI outputs are not validated recommendations for high-stakes or regulated decisions.
    • AI does not make automated decisions with legal or similarly significant effects on you (Article 22 UK GDPR does not apply to our use case).

    Your rights regarding AI outputs

    • Right to request human review: You may request a qualified consultant to review or challenge any AI-generated plan.
    • Right to explanation: You may request a plain-English explanation of the key recommendations and the reasoning behind them.
    • Right to contest: If you believe an output is inaccurate, biased, or unsuitable, email shuhayb@alira.uk. We will provide a human evaluation within 10 business days.

    Bias monitoring

    We monitor AI outputs for patterns that may indicate discrimination based on gender, age, ethnicity, industry, or business stage. Report suspected bias to shuhayb@alira.uk.

    13. Newsletter and Marketing Emails

    Every marketing email includes a one-click unsubscribe link. You may also unsubscribe at any time by emailing shuhayb@alira.uk. Once unsubscribed, we retain a suppression record to ensure we do not add you back to any mailing list.

    14. Changes to This Policy

    We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated by email or via a prominent notice on our website at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

    15. Contact