Privacy Policy
Last updated: July 28, 2026
alayer.ai ("we," "us," or "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit alayer.ai or engage our services. We are PECB-certified, ISACA member compliance auditors — we hold ourselves to the same standards we audit others for.
1. Overview & Data Controller
The data controller for personal data collected through this website is alayer.ai. For questions about this policy or your personal data, contact us at privacy@alayer.ai.
This policy applies to all personal data we process in connection with our website, service delivery, marketing, and business operations. It covers obligations under GDPR (EU/UK), CCPA, and applicable data protection laws.
2. Data We Collect
2.1 Data You Provide Directly
- Contact & inquiry data: Name, email address, company name, phone number, service interest, and message content when you complete our contact form.
- Partner program data: Business information, referral details, and payment information for Edge Alliance partners.
- Service delivery data: Documents, policies, system information, and organizational data shared with us to conduct audits and compliance assessments.
- Account data: Login credentials if you access any client portal or Aristotle AI tool.
2.2 Data Collected Automatically
- Usage data: Pages visited, time on site, referring URL, and browser/device type — collected via analytics tools.
- Cookie data: See our Cookie Policy for full details.
- Server logs: IP addresses, access timestamps, and error logs retained for security purposes.
2.3 Data from Third Parties
- Partner referral information provided by Edge Alliance partners.
- Professional profile information from LinkedIn where relevant to business relationships.
3. How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Responding to inquiries and providing quotes | Contact data, service interest | Legitimate interest / Contract |
| Delivering audit and compliance services | Service delivery data, contact data | Contract performance |
| Processing Edge Alliance partner commissions | Partner data, payment information | Contract performance |
| Improving our website and services | Usage data, analytics | Legitimate interest (with consent for cookies) |
| Marketing communications (if opted in) | Email, name | Consent |
| Legal obligations and dispute resolution | All relevant data | Legal obligation |
| Security and fraud prevention | Server logs, IP addresses | Legitimate interest |
4. Legal Basis for Processing (GDPR)
Under GDPR and UK GDPR, we process your personal data on the following legal bases:
- Contract (Art. 6(1)(b)): Processing necessary to perform services you have engaged us for.
- Legitimate Interests (Art. 6(1)(f)): Processing necessary for our legitimate business interests (responding to inquiries, improving services, security), where these don't override your rights.
- Consent (Art. 6(1)(a)): Analytics cookies and optional marketing communications, where you have given explicit consent.
- Legal Obligation (Art. 6(1)(c)): Where processing is required to comply with applicable law.
5. Data Sharing & Disclosure
We do not sell your personal data. We may share data with:
- Service providers: Hosting, analytics, email delivery, and CRM tools used to operate our business, under data processing agreements.
- PECB & ISACA: Certification and membership bodies as required for audit certifications and professional standards.
- Edge Alliance partners: Only the data necessary to facilitate referral relationships and commission payments.
- Legal authorities: Where required by law, court order, or to protect rights and safety.
- Business transfers: In connection with a merger, acquisition, or sale of assets, subject to confidentiality obligations.
6. Data Retention
- Inquiry / contact data: 3 years from last contact, unless a service relationship develops.
- Service / audit data: 7 years from completion of engagement (to meet professional and legal retention requirements).
- Partner data: Duration of partnership plus 7 years for financial records.
- Analytics data: 26 months (aggregated and anonymized).
- Server logs: 90 days.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure ("right to be forgotten"): Request deletion of your data (subject to legal retention obligations).
- Restriction: Request that we restrict processing of your data.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests or for direct marketing.
- Withdraw consent: Where processing is based on consent, withdraw it at any time.
- CCPA rights (California residents): Right to know, delete, opt-out of sale (we do not sell data), and non-discrimination.
To exercise any of these rights, contact us at privacy@alayer.ai. We will respond within 30 days (GDPR) or 45 days (CCPA).
You also have the right to lodge a complaint with your supervisory authority (e.g., ICO in the UK, your national DPA in the EU).
8. Cookies
We use cookies and similar technologies on our website. For full details of the cookies we use, their purpose, and how to manage your preferences, please see our Cookie Policy.
9. Security
As a PECB-certified, ISACA member compliance organization, we apply rigorous security controls to protect your personal data, including:
- SSL/TLS encryption for all data in transit
- Access controls and role-based permissions
- Regular security assessments aligned with ISO 27001
- Staff training on data protection and security
- Incident response procedures
No method of transmission over the internet is 100% secure. In the event of a breach affecting your rights and freedoms, we will notify you and relevant authorities as required by applicable law.
10. International Data Transfers
If we transfer personal data outside the EEA or UK, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or other approved transfer mechanisms.
11. Contact Us & Updates
For privacy-related inquiries, requests, or complaints:
Email: privacy@alayer.ai
For CCPA requests (California residents): Please email privacy@alayer.ai with the subject line "CCPA Request" and we will respond within 45 days.
We may update this Privacy Policy from time to time. The "last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated by posting a notice on our website.
