Alpha Level
Contact us

Privacy Policy

This Privacy Policy explains what personal data Alpha Level SHPK collects, how we use it, who we share it with, your rights under the EU General Data Protection Regulation ("GDPR") and Albanian Law No. 9887/2008, and how to contact us about it.

Version: V1.0  ·  Last updated: 7 May 2026  ·  Effective: 7 May 2026

This Policy is written to satisfy the information obligations of GDPR Articles 13 and 14, and equivalent provisions of Albanian law. If anything is unclear, write to us at info@alphalevel.net (subject: "Privacy").

1. Data Controller

The data controller — the entity that decides why and how your personal data is processed — is:

Alpha Level SHPK ("Alpha Level", "we", "us", "our")
NIPT (tax ID): M36606201D
Registered address: Rruga "Bardhyl Pojani", Lagjia nr. 2, 7001 Korçë, Albania
Email: info@alphalevel.net
Phone: +355 69 208 8969

We have not appointed a formal Data Protection Officer (DPO). Privacy questions, requests to exercise rights, and grievances are handled by our Privacy contact at info@alphalevel.net with subject line "Privacy".

2. Categories of personal data we collect

Depending on how you interact with us, we collect:

CategoryExamplesSource
Identificationname, email address, phone, billing/postal address, company name, role, tax ID where requiredyou, when you create an account, place an Order, sign a contract or send us a message
Account credentialsusername, hashed password, session tokens, account-recovery answersyou, when you register a dashboard account
Order / contract dataservices purchased, prices, scope, delivery dates, project milestones, signed SOWsyou and us, when you place an Order or sign a contract
Payment metadatapayment method type, last 4 digits of the card, billing country, transaction reference, tax-jurisdiction signals — NOT the full card number, CVV or full bank accountthe Payment Processor (Merchant of Record) at checkout, then passed to us as a transaction confirmation
Correspondence contentthe body of emails, support messages, chat transcripts you send us, attachmentsyou, when you contact us
Project assetsbrand assets, content drafts, login credentials for systems you ask us to work on, copy you submit for editing, and any other materials you send us to perform the Serviceyou, during a project engagement
AI / chatbot inputfree-form messages you submit to a chatbot we have built and that runs on our infrastructure (whether for testing on alphalevel.net or in production for one of our clients)you, when you interact with a chatbot
Behavioural / analytics datapages viewed, clicks, time on page, referrer, device type, browser, language, approximate location (city-level, derived from IP), pseudonymous analytics IDs from cookiesyour browser, via Google Analytics 4 (only if you consent to analytics cookies)
Cookie datathe contents and identifiers of cookies and similar storage on your deviceyour browser, see the Cookie Policy
Marketing-consent recordswhether and when you opted in to marketing communications, the wording you agreed toyou, when you tick a consent box

We do not knowingly collect "special categories" of personal data (GDPR Art. 9 — health, racial or ethnic origin, religious beliefs, etc.). Please do not include such data in correspondence with us; if you do, we will delete it.

3. Why we process your data and our lawful basis

Under GDPR Article 6 we may only process your personal data when one of the listed lawful bases applies. We pair each purpose with its basis below.

PurposeLawful basis
Performing the Services you have ordered (delivering a website, content, chatbot, SEO retainer, subscription, etc.)Art. 6(1)(b) — performance of a contract with you
Creating and operating your dashboard accountArt. 6(1)(b) — performance of a contract
Processing payments through the Merchant of RecordArt. 6(1)(b) — performance of a contract; Art. 6(1)(c) — legal obligation (anti-money-laundering, fiscal records)
Issuing and retaining invoices and accounting recordsArt. 6(1)(c) — legal obligation (Albanian fiscal law requires retention)
Customer support and dispute resolutionArt. 6(1)(b) — performance of a contract; Art. 6(1)(f) — legitimate interest (to defend or resolve claims)
Site security, fraud prevention, abuse-of-service monitoringArt. 6(1)(f) — legitimate interest in keeping our systems and customers safe
Service improvement and analytics (aggregated, where possible pseudonymised)Art. 6(1)(a) — your consent for analytics cookies; Art. 6(1)(f) — legitimate interest where consent is not legally required
Direct marketing of similar services to existing customers (newsletters, product updates)Art. 6(1)(f) — legitimate interest in soft opt-in for own similar services; you may opt out at any time
Direct marketing to non-customers / general newsletter subscribersArt. 6(1)(a) — your consent (opt-in)
Responding to data-subject rights requestsArt. 6(1)(c) — legal obligation under GDPR / Albanian law
Handling legal claims, defending or asserting rightsArt. 6(1)(f) — legitimate interest

Where we rely on legitimate interest (Art. 6(1)(f)), we have balanced our interest against your rights and freedoms; you have an unconditional right to object (see §8).

Where we rely on consent (Art. 6(1)(a)), you have an unconditional right to withdraw consent (see §8); withdrawal does not affect lawfulness of processing carried out before withdrawal.

4. Sub-processors and recipients

We share personal data only with the recipients listed below, only for the purposes stated, and under written data-processing agreements where required by GDPR Art. 28.

RecipientPurposeLocationSafeguard
Our authorised payment processor (acting as Merchant of Record)payment processing, fraud screening, tax determination, refund managementEU and/or United States, depending on processorEU Standard Contractual Clauses ("SCCs") and/or EU-US Data Privacy Framework certification, as applicable; the Payment Processor is itself a controller for certain payment-fraud purposes
Google LLC — Google Analytics 4analytics on alphalevel.net (only if you consent to analytics cookies)United States, with EU regional data storage where supportedEU-US Data Privacy Framework; SCCs with Google Ireland Ltd. as primary EU contracting party; IP anonymisation enabled
Anthropic PBC — Claude APIdrafting copy, building chatbots, processing user prompts inside chatbots we run on our or our clients' behalfUnited StatesSCCs; Anthropic does not retain API content for training; see Anthropic's Privacy Policy
Cloud hosting providerhosting alphalevel.net and the dashboard tierEUdata-processing agreement under GDPR Art. 28; SCCs where any sub-component processes data outside the EEA
Transactional email servicesending account, support and order emails (and marketing emails to recipients who have opted in)EU and/or United States, depending on servicedata-processing agreement under GDPR Art. 28; SCCs and/or EU-US Data Privacy Framework as applicable
Customer relationship management (CRM)sales-pipeline tracking and customer history, where usedEU and/or United Statesdata-processing agreement under GDPR Art. 28; SCCs and/or EU-US Data Privacy Framework as applicable
Other AI-tool providers (occasional, per-project basis only)where a specific deliverable requires a model other than Claude (e.g. specialised image, audio or translation tools), processing of project content for that deliverabletypically United StatesSCCs; provider must offer a "no-training" / business-use mode and we configure it accordingly
Albanian and EU tax authorities; courtswhen required by law (tax inspection, legal proceedings)EU and Albanialegal obligation under Art. 6(1)(c)
Professional advisors (lawyers, accountants, auditors)as necessary to defend our rights, audit our books, or comply with the lawEU / Albaniaconfidentiality obligation; legitimate interest

We do not sell your personal data. We do not share your data with advertising networks or data brokers.

An up-to-date list of named sub-processors and the specific safeguards in place for each is available on request — write to info@alphalevel.net (subject: "Privacy — Sub-processors").

5. International transfers

Some of our sub-processors are based outside the European Economic Area, principally in the United States. Where this is the case:

  • We rely on the EU-US Data Privacy Framework for transfers to recipients certified under it (e.g. Google, and our payment processor where applicable);
  • We supplement this with the European Commission's Standard Contractual Clauses (SCCs, 2021/914) where the recipient is not DPF-certified or where SCCs add an additional safeguard;
  • We have performed a transfer-impact assessment (TIA) for transfers to the United States that takes account of the Schrems II judgment of the Court of Justice of the European Union and any updated guidance from the European Data Protection Board.

You may request a copy of the relevant SCCs by writing to info@alphalevel.net (subject: "Privacy — SCC request").

6. How long we keep your data

We keep your personal data only for as long as necessary for the purposes for which it was collected, plus any retention period required by law.

Data categoryRetention periodWhy
Invoicing and accounting records10 yearsAlbanian fiscal law (Tax Procedures Law, art. 51)
Contract / SOW / Order data6 years post-completioncivil-law statute of limitations for contractual claims
Customer correspondence (emails, chat logs with you)3 years post-last contactdispute and warranty defense
Marketing-consent records3 years from withdrawal of consent or last interaction, whichever is laterproof of consent under GDPR
Newsletter / marketing list (active subscribers)until you unsubscribebased on your consent
Dashboard account datafor the lifetime of the account + 12 monthsaccount recovery, then deletion
Free-tier inactive accountsup to 12 months of inactivity, then deleted with 30 days' email warningdata minimisation
Chatbot conversation logs (for chatbots we operate or host)90 daysdispute and quality monitoring; longer only if a specific dispute or contractual obligation requires it
Server access logs and security events12 monthssecurity monitoring (legitimate interest)
Cookie-consent records6 months from grantGDPR proof-of-consent
Analytics data (GA4)14 months (default GA4 retention)service improvement

After the retention period ends we either delete the data or anonymise it (such that re-identification is not reasonably possible) for statistical purposes.

7. Automated decision-making and AI

GDPR Article 22 gives you the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal or similarly significant effects on you.

We use AI tools (principally Anthropic Claude) in our work and in some of the chatbots we deploy. These tools support tasks such as:

  • drafting first-draft copy and content briefs
  • summarising correspondence
  • triaging support tickets and inbound enquiries
  • scoring and routing leads on our internal CRM
  • powering chatbots that answer customer questions

We do not make any fully-automated decisions that produce legal or similarly significant effects on you. Every output that affects a contractual decision (e.g. acceptance of a brief, refund determination, pricing of a bespoke engagement, hiring) is reviewed and approved by a human team member before it is acted on. Chatbots can answer informational questions and make routine bookings, but escalate to a human for anything that could create or modify a contract, payment or service obligation.

If you would like more information about a specific automated step that affected you, write to info@alphalevel.net (subject: "Privacy — automated decision query") and we will explain the logic, significance and consequences and invite human review.

8. Your rights

Under GDPR Articles 15 to 22 (and equivalent Albanian provisions) you have the right to:

  • Access (Art. 15) — request a copy of the personal data we hold about you and information about how we process it;
  • Rectification (Art. 16) — ask us to correct inaccurate or incomplete personal data;
  • Erasure / "right to be forgotten" (Art. 17) — ask us to delete personal data, subject to legal retention obligations (e.g. invoicing records);
  • Restriction (Art. 18) — ask us to suspend processing while a dispute about accuracy or lawfulness is resolved;
  • Data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format and ask us to transmit it to another controller where technically feasible;
  • Object (Art. 21) — object to processing based on legitimate interest (Art. 6(1)(f)), including objection to direct marketing, which we will action immediately;
  • Withdraw consent (Art. 7(3)) — at any time where processing is based on consent, without affecting prior lawful processing;
  • Not be subject to automated decision-making (Art. 22) — see §7 above;
  • Lodge a complaint — see §9 below.

How to exercise your rights

Send a request by email to info@alphalevel.net with subject line "Privacy — [right being exercised]" (e.g. "Privacy — Access", "Privacy — Erasure"). Include enough information to identify you (typically the email address associated with your account or Order) and describe what you are asking for. We may ask for additional information to verify your identity if the request is sensitive.

We will respond within 30 days of receiving the request. We may extend this by up to a further 60 days for complex or numerous requests, and we will tell you if we need the extension within the first 30 days.

There is no fee for these requests, except where they are manifestly unfounded or excessive (in which case we may charge a reasonable fee or refuse).

9. Lodging a complaint with a supervisory authority

If you believe our processing of your personal data violates the law, you have the right to lodge a complaint with a data-protection supervisory authority.

Albania (lead authority for Alpha Level):

Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale (IDP)
(Information and Data Protection Commissioner)
Rruga "Abdi Toptani", Nd. 5, Tiranë, Albania
Web: www.idp.al
Email: info@idp.al

EU residents may also lodge a complaint with the data-protection authority in their country of habitual residence, place of work, or place of the alleged infringement. The European Data Protection Board maintains a list of national DPAs at edpb.europa.eu/about-edpb/about-edpb/members_en.

UK residents may also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

You retain this right even if you have raised the complaint with us first; raising it with us first is encouraged but not required.

10. Security

We take appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, including:

  • TLS 1.2+ encryption for data in transit (HTTPS) on alphalevel.net and on the dashboard;
  • access control on internal systems (least privilege, MFA on administrative accounts);
  • separation of dev / staging / production environments;
  • routine backups of customer-facing systems with encrypted storage;
  • staff training on data protection;
  • contractual security commitments with sub-processors;
  • prompt notification of personal-data breaches to the supervisory authority and (where required) to affected individuals, in accordance with GDPR Articles 33 and 34.

No system is 100% secure; we cannot guarantee absolute security but we work to industry-standard levels of care.

11. Children

Our Services are not directed at children. We do not knowingly collect personal data from children under the age of 16. If you believe a child has provided personal data to us, please write to info@alphalevel.net (subject: "Privacy — child data") and we will delete it without undue delay.

12. Cookies and similar technologies

How we use cookies and similar device-storage technologies on alphalevel.net is described separately in our Cookie Policy at alphalevel.net/cookie-policy/. The Cookie Policy lists the cookies we use, their purpose, duration and how you can grant or withdraw consent.

13. Changes to this Policy

We may update this Privacy Policy from time to time. The "Last Updated" date at the top reflects the date of the latest revision.

For non-material changes (e.g. new contact channel, formatting, typo correction), the change takes effect immediately on posting.

For material changes (e.g. new sub-processors, new processing purposes, change in retention period, change in international-transfer mechanism), we will give at least 30 days advance notice, by:

  • a banner on alphalevel.net;
  • email to active customers and dashboard account holders;
  • and (where the change affects subscription customers materially) a separate "what is changing" summary.

If you do not agree with the change, you may stop using the Service before the new version takes effect; continued use after the effective date constitutes acceptance.

(The previous version of this Policy specified a 180-day notice period; we have shortened it to 30 days, which is more typical of GDPR-mature operators and gives users a faster, clearer signal of change.)

14. Contact

For any privacy-related question, request, complaint or opt-out:

Alpha Level SHPK
NIPT: M36606201D
Rruga "Bardhyl Pojani", Lagjia nr. 2
7001 Korçë, Albania

Email: info@alphalevel.net (subject: "Privacy" — followed by the topic, e.g. "Privacy — Access")
Phone: +355 69 208 8969

We reply within 5 business days for general questions and within 30 days for formal data-subject rights requests (extendable to 90 days for complex requests, with notice).


End of Privacy Policy — Version V1.0, dated 7 May 2026.