Legal
Privacy Policy
Last updated: 1 October 2026
This policy explains how Aluleth Corp LLC (“we”, “us”) collects and uses personal data when you visit alulethcorp.com or contact us using the website form. This is a corporate website for Aluleth Corp LLC and its divisions. No services are sold directly on this website and no payments are processed here. We serve clients all over the world, so this policy is written to respect the main privacy laws that may apply to you, including the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA) and other US state privacy laws. If the law of your country gives you more protection, that protection applies.
Our EU representative under Article 27 GDPR is Anthony Loison EI, an individual business established in France. For clients and visitors in the EEA, Anthony Loison EI represents Aluleth Corp LLC for data protection matters under the GDPR.
This policy is written in English. If we provide a translation, the English version prevails in case of any inconsistency.
1. Who we are
The data controller is Aluleth Corp LLC, a Delaware limited liability company, Office 293, 254 Chapman Rd, Suite 101-B, Newark, DE 19702, USA.
Privacy contact: contact@alulethcorp.com (subject “Privacy”). If you are in the EEA or UK and have questions about our processing of your personal data, you can also contact us using this address. Our EU representative under Article 27 GDPR can be contacted at the same address, or at the contact details provided in our Legal Notice.
2. What we collect
- Contact form: your name, email address, company (if you provide it), subject and message, and the date of your privacy consent.
- Emails: what you send us when you write to us using the email address shown on the website.
- Technical data: your IP address, browser and device information, processed by our hosting provider in server logs and by Cloudflare Turnstile to protect our form against spam and abuse.
We do not ask for sensitive data (such as health, religion or biometric data). Please do not send it to us.
3. Why we use it
- To answer your message and follow up on your request.
- To keep accounting and tax records required by law, where applicable.
- To keep the website and forms secure and prevent spam, fraud and abuse.
We do not send you marketing emails unless you asked for them or the law allows it, and you can always opt out. We do not use your data for automated decisions that have legal or similarly significant effects on you.
Legal bases (EEA, UK and similar laws): steps taken at your request before a contract and performance of a contract (Art. 6(1)(b) GDPR) where your message relates to a potential service; legal obligation (Art. 6(1)(c)) for accounting, where applicable; our legitimate interests (Art. 6(1)(f)) for security and spam protection; and your consent (Art. 6(1)(a)) where we ask for it. You can withdraw consent at any time.
4. Cookies
We only use what is strictly necessary for the website to work and for security, such as remembering your language choice and Cloudflare Turnstile on our form. Under EU and UK cookie rules, these do not require your consent. We do not use advertising or tracking cookies. If we add analytics or other non-essential cookies in the future, we will update this policy and ask for your consent through a cookie banner where the law requires it.
5. Who receives your data
Tools on our own server. Our form (Fluent Forms) and our customer database (FluentCRM) run on our own website: your messages are stored there and are not shared with the companies that make these tools.
Service providers. We share personal data only with the providers below, and only so they can provide their service to us, under contracts that protect your data:
- Hosting and mailboxes: 20i Ltd (United Kingdom). 20i hosts our website and its database, and our email inboxes. Its servers keep technical logs (such as IP address, date and time, and pages requested) to keep the service secure and prevent attacks.
- Email delivery: Twilio SendGrid (Twilio Inc., United States). SendGrid sends the emails from our website, such as the confirmation of your message, and keeps delivery records (recipient, date, delivery status).
- Spam protection: Cloudflare, Inc. (United States). Cloudflare Turnstile checks form submissions to block bots, using technical signals from your browser and your IP address.
We may also share data with professional advisers (such as accountants or lawyers) or with authorities when the law requires it. We never sell your personal data, and we do not “share” it for cross-context behavioural advertising or use it for targeted advertising. We do not use analytics or advertising tools on this website; if this changes, we will update this policy first.
6. International transfers
We are based in the United States and our providers may process data in other countries. When we transfer personal data from a country that restricts such transfers (for example from the EEA, the UK or Switzerland), we use appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or our providers’ certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. We put these safeguards in place through our contracts with service providers. We also check that our providers maintain appropriate certifications (such as the EU-U.S. Data Privacy Framework) where relevant.
7. How long we keep it
- Contact requests that do not lead to a project: up to 3 years after our last contact, then deleted.
- Emails and project data: for the duration of our work together and for as long as needed for support and legal claims.
- Invoices and accounting records: as long as tax and accounting laws require (generally up to 10 years).
- Security logs: a short period, usually a few weeks.
- Backups: up to 2 weeks, then overwritten.
8. Security
We use reasonable technical and organisational measures to protect your data, such as encrypted connections (HTTPS), access control and trusted providers. No online service is completely secure, but we work to protect your data and will notify you and the authorities of a breach when the law requires it.
9. Your rights
Depending on where you live, you may have the right to:
- know what personal data we hold about you and get a copy of it;
- correct it or have it deleted;
- restrict or object to its use, including for follow-up or marketing messages;
- receive it in a portable format;
- withdraw your consent at any time;
- not be treated differently for exercising your rights.
To exercise your rights, write to contact@alulethcorp.com. We may ask you to confirm your identity, and we answer within the time the law gives us (generally within one month under EU and UK law, with a possible extension to three months for complex requests; other laws may provide different deadlines such as 30 days).
Region-specific information:
- EEA, UK and Switzerland: you can lodge a complaint with your local data protection authority.
- United States (California and other states with privacy laws): you have the rights to know, access, correct and delete, and to opt out of the sale or sharing of personal information and of targeted advertising. We do not sell or share personal information, or use it for targeted advertising. If we refuse your request, you can appeal by replying to our answer.
- Canada: you can contact the Office of the Privacy Commissioner of Canada.
- Brazil: you can contact the Autoridade Nacional de Proteção de Dados (ANPD).
- Australia: you can contact the Office of the Australian Information Commissioner (OAIC).
- Philippines: you can contact the National Privacy Commission.
Please contact us first: we will do our best to help.
10. Children
Our website and services are for businesses and adults. They are not directed to children under 16 (or under 13 in the United States), and we do not knowingly collect their personal data. If we become aware that we have collected personal data from a child in breach of applicable laws, we will delete it.
11. Changes
We may update this policy. Changes take effect on the “Last updated” date shown at the top of this policy, unless we state otherwise. The latest version is always on this page. If a change is important (for example if we start using new types of cookies or change the legal basis for processing), we will tell you in a clear way before it takes effect, where the law requires it.