This Policy is written to satisfy the information obligations of GDPR Articles 13 and 14, and equivalent provisions of Albanian law. If anything is unclear, write to us at info@alphalevel.net (subject: "Privacy").
1. Data Controller
The data controller — the entity that decides why and how your personal data is processed — is:
Alpha Level SHPK ("Alpha Level", "we", "us", "our")
NIPT (tax ID): M36606201D
Registered address: Rruga "Bardhyl Pojani", Lagjia nr. 2, 7001 Korçë, Albania
Email: info@alphalevel.net
Phone: +355 69 208 8969
We have not appointed a formal Data Protection Officer (DPO). Privacy questions, requests to exercise rights, and grievances are handled by our Privacy contact at info@alphalevel.net with subject line "Privacy".
2. Categories of personal data we collect
Depending on how you interact with us, we collect:
| Category | Examples | Source |
|---|---|---|
| Identification | name, email address, phone, billing/postal address, company name, role, tax ID where required | you, when you create an account, place an Order, sign a contract or send us a message |
| Account credentials | username, hashed password, session tokens, account-recovery answers | you, when you register a dashboard account |
| Order / contract data | services purchased, prices, scope, delivery dates, project milestones, signed SOWs | you and us, when you place an Order or sign a contract |
| Payment metadata | payment method type, last 4 digits of the card, billing country, transaction reference, tax-jurisdiction signals — NOT the full card number, CVV or full bank account | the Payment Processor (Merchant of Record) at checkout, then passed to us as a transaction confirmation |
| Correspondence content | the body of emails, support messages, chat transcripts you send us, attachments | you, when you contact us |
| Project assets | brand assets, content drafts, login credentials for systems you ask us to work on, copy you submit for editing, and any other materials you send us to perform the Service | you, during a project engagement |
| AI / chatbot input | free-form messages you submit to a chatbot we have built and that runs on our infrastructure (whether for testing on alphalevel.net or in production for one of our clients) | you, when you interact with a chatbot |
| Behavioural / analytics data | pages viewed, clicks, time on page, referrer, device type, browser, language, approximate location (city-level, derived from IP), pseudonymous analytics IDs from cookies | your browser, via Google Analytics 4 (only if you consent to analytics cookies) |
| Cookie data | the contents and identifiers of cookies and similar storage on your device | your browser, see the Cookie Policy |
| Marketing-consent records | whether and when you opted in to marketing communications, the wording you agreed to | you, when you tick a consent box |
We do not knowingly collect "special categories" of personal data (GDPR Art. 9 — health, racial or ethnic origin, religious beliefs, etc.). Please do not include such data in correspondence with us; if you do, we will delete it.
3. Why we process your data and our lawful basis
Under GDPR Article 6 we may only process your personal data when one of the listed lawful bases applies. We pair each purpose with its basis below.
| Purpose | Lawful basis |
|---|---|
| Performing the Services you have ordered (delivering a website, content, chatbot, SEO retainer, subscription, etc.) | Art. 6(1)(b) — performance of a contract with you |
| Creating and operating your dashboard account | Art. 6(1)(b) — performance of a contract |
| Processing payments through the Merchant of Record | Art. 6(1)(b) — performance of a contract; Art. 6(1)(c) — legal obligation (anti-money-laundering, fiscal records) |
| Issuing and retaining invoices and accounting records | Art. 6(1)(c) — legal obligation (Albanian fiscal law requires retention) |
| Customer support and dispute resolution | Art. 6(1)(b) — performance of a contract; Art. 6(1)(f) — legitimate interest (to defend or resolve claims) |
| Site security, fraud prevention, abuse-of-service monitoring | Art. 6(1)(f) — legitimate interest in keeping our systems and customers safe |
| Service improvement and analytics (aggregated, where possible pseudonymised) | Art. 6(1)(a) — your consent for analytics cookies; Art. 6(1)(f) — legitimate interest where consent is not legally required |
| Direct marketing of similar services to existing customers (newsletters, product updates) | Art. 6(1)(f) — legitimate interest in soft opt-in for own similar services; you may opt out at any time |
| Direct marketing to non-customers / general newsletter subscribers | Art. 6(1)(a) — your consent (opt-in) |
| Responding to data-subject rights requests | Art. 6(1)(c) — legal obligation under GDPR / Albanian law |
| Handling legal claims, defending or asserting rights | Art. 6(1)(f) — legitimate interest |
Where we rely on legitimate interest (Art. 6(1)(f)), we have balanced our interest against your rights and freedoms; you have an unconditional right to object (see §8).
Where we rely on consent (Art. 6(1)(a)), you have an unconditional right to withdraw consent (see §8); withdrawal does not affect lawfulness of processing carried out before withdrawal.
4. Sub-processors and recipients
We share personal data only with the recipients listed below, only for the purposes stated, and under written data-processing agreements where required by GDPR Art. 28.
| Recipient | Purpose | Location | Safeguard |
|---|---|---|---|
| Our authorised payment processor (acting as Merchant of Record) | payment processing, fraud screening, tax determination, refund management | EU and/or United States, depending on processor | EU Standard Contractual Clauses ("SCCs") and/or EU-US Data Privacy Framework certification, as applicable; the Payment Processor is itself a controller for certain payment-fraud purposes |
| Google LLC — Google Analytics 4 | analytics on alphalevel.net (only if you consent to analytics cookies) | United States, with EU regional data storage where supported | EU-US Data Privacy Framework; SCCs with Google Ireland Ltd. as primary EU contracting party; IP anonymisation enabled |
| Anthropic PBC — Claude API | drafting copy, building chatbots, processing user prompts inside chatbots we run on our or our clients' behalf | United States | SCCs; Anthropic does not retain API content for training; see Anthropic's Privacy Policy |
| Cloud hosting provider | hosting alphalevel.net and the dashboard tier | EU | data-processing agreement under GDPR Art. 28; SCCs where any sub-component processes data outside the EEA |
| Transactional email service | sending account, support and order emails (and marketing emails to recipients who have opted in) | EU and/or United States, depending on service | data-processing agreement under GDPR Art. 28; SCCs and/or EU-US Data Privacy Framework as applicable |
| Customer relationship management (CRM) | sales-pipeline tracking and customer history, where used | EU and/or United States | data-processing agreement under GDPR Art. 28; SCCs and/or EU-US Data Privacy Framework as applicable |
| Other AI-tool providers (occasional, per-project basis only) | where a specific deliverable requires a model other than Claude (e.g. specialised image, audio or translation tools), processing of project content for that deliverable | typically United States | SCCs; provider must offer a "no-training" / business-use mode and we configure it accordingly |
| Albanian and EU tax authorities; courts | when required by law (tax inspection, legal proceedings) | EU and Albania | legal obligation under Art. 6(1)(c) |
| Professional advisors (lawyers, accountants, auditors) | as necessary to defend our rights, audit our books, or comply with the law | EU / Albania | confidentiality obligation; legitimate interest |
We do not sell your personal data. We do not share your data with advertising networks or data brokers.
An up-to-date list of named sub-processors and the specific safeguards in place for each is available on request — write to info@alphalevel.net (subject: "Privacy — Sub-processors").
5. International transfers
Some of our sub-processors are based outside the European Economic Area, principally in the United States. Where this is the case:
- We rely on the EU-US Data Privacy Framework for transfers to recipients certified under it (e.g. Google, and our payment processor where applicable);
- We supplement this with the European Commission's Standard Contractual Clauses (SCCs, 2021/914) where the recipient is not DPF-certified or where SCCs add an additional safeguard;
- We have performed a transfer-impact assessment (TIA) for transfers to the United States that takes account of the Schrems II judgment of the Court of Justice of the European Union and any updated guidance from the European Data Protection Board.
You may request a copy of the relevant SCCs by writing to info@alphalevel.net (subject: "Privacy — SCC request").
6. How long we keep your data
We keep your personal data only for as long as necessary for the purposes for which it was collected, plus any retention period required by law.
| Data category | Retention period | Why |
|---|---|---|
| Invoicing and accounting records | 10 years | Albanian fiscal law (Tax Procedures Law, art. 51) |
| Contract / SOW / Order data | 6 years post-completion | civil-law statute of limitations for contractual claims |
| Customer correspondence (emails, chat logs with you) | 3 years post-last contact | dispute and warranty defense |
| Marketing-consent records | 3 years from withdrawal of consent or last interaction, whichever is later | proof of consent under GDPR |
| Newsletter / marketing list (active subscribers) | until you unsubscribe | based on your consent |
| Dashboard account data | for the lifetime of the account + 12 months | account recovery, then deletion |
| Free-tier inactive accounts | up to 12 months of inactivity, then deleted with 30 days' email warning | data minimisation |
| Chatbot conversation logs (for chatbots we operate or host) | 90 days | dispute and quality monitoring; longer only if a specific dispute or contractual obligation requires it |
| Server access logs and security events | 12 months | security monitoring (legitimate interest) |
| Cookie-consent records | 6 months from grant | GDPR proof-of-consent |
| Analytics data (GA4) | 14 months (default GA4 retention) | service improvement |
After the retention period ends we either delete the data or anonymise it (such that re-identification is not reasonably possible) for statistical purposes.
7. Automated decision-making and AI
GDPR Article 22 gives you the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal or similarly significant effects on you.
We use AI tools (principally Anthropic Claude) in our work and in some of the chatbots we deploy. These tools support tasks such as:
- drafting first-draft copy and content briefs
- summarising correspondence
- triaging support tickets and inbound enquiries
- scoring and routing leads on our internal CRM
- powering chatbots that answer customer questions
We do not make any fully-automated decisions that produce legal or similarly significant effects on you. Every output that affects a contractual decision (e.g. acceptance of a brief, refund determination, pricing of a bespoke engagement, hiring) is reviewed and approved by a human team member before it is acted on. Chatbots can answer informational questions and make routine bookings, but escalate to a human for anything that could create or modify a contract, payment or service obligation.
If you would like more information about a specific automated step that affected you, write to info@alphalevel.net (subject: "Privacy — automated decision query") and we will explain the logic, significance and consequences and invite human review.
8. Your rights
Under GDPR Articles 15 to 22 (and equivalent Albanian provisions) you have the right to:
- Access (Art. 15) — request a copy of the personal data we hold about you and information about how we process it;
- Rectification (Art. 16) — ask us to correct inaccurate or incomplete personal data;
- Erasure / "right to be forgotten" (Art. 17) — ask us to delete personal data, subject to legal retention obligations (e.g. invoicing records);
- Restriction (Art. 18) — ask us to suspend processing while a dispute about accuracy or lawfulness is resolved;
- Data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format and ask us to transmit it to another controller where technically feasible;
- Object (Art. 21) — object to processing based on legitimate interest (Art. 6(1)(f)), including objection to direct marketing, which we will action immediately;
- Withdraw consent (Art. 7(3)) — at any time where processing is based on consent, without affecting prior lawful processing;
- Not be subject to automated decision-making (Art. 22) — see §7 above;
- Lodge a complaint — see §9 below.
How to exercise your rights
Send a request by email to info@alphalevel.net with subject line "Privacy — [right being exercised]" (e.g. "Privacy — Access", "Privacy — Erasure"). Include enough information to identify you (typically the email address associated with your account or Order) and describe what you are asking for. We may ask for additional information to verify your identity if the request is sensitive.
We will respond within 30 days of receiving the request. We may extend this by up to a further 60 days for complex or numerous requests, and we will tell you if we need the extension within the first 30 days.
There is no fee for these requests, except where they are manifestly unfounded or excessive (in which case we may charge a reasonable fee or refuse).
9. Lodging a complaint with a supervisory authority
If you believe our processing of your personal data violates the law, you have the right to lodge a complaint with a data-protection supervisory authority.
Albania (lead authority for Alpha Level):
Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale (IDP)
(Information and Data Protection Commissioner)
Rruga "Abdi Toptani", Nd. 5, Tiranë, Albania
Web: www.idp.al
Email: info@idp.al
EU residents may also lodge a complaint with the data-protection authority in their country of habitual residence, place of work, or place of the alleged infringement. The European Data Protection Board maintains a list of national DPAs at edpb.europa.eu/about-edpb/about-edpb/members_en.
UK residents may also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
You retain this right even if you have raised the complaint with us first; raising it with us first is encouraged but not required.
10. Security
We take appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, including:
- TLS 1.2+ encryption for data in transit (HTTPS) on alphalevel.net and on the dashboard;
- access control on internal systems (least privilege, MFA on administrative accounts);
- separation of dev / staging / production environments;
- routine backups of customer-facing systems with encrypted storage;
- staff training on data protection;
- contractual security commitments with sub-processors;
- prompt notification of personal-data breaches to the supervisory authority and (where required) to affected individuals, in accordance with GDPR Articles 33 and 34.
No system is 100% secure; we cannot guarantee absolute security but we work to industry-standard levels of care.
11. Children
Our Services are not directed at children. We do not knowingly collect personal data from children under the age of 16. If you believe a child has provided personal data to us, please write to info@alphalevel.net (subject: "Privacy — child data") and we will delete it without undue delay.
12. Cookies and similar technologies
How we use cookies and similar device-storage technologies on alphalevel.net is described separately in our Cookie Policy at alphalevel.net/cookie-policy/. The Cookie Policy lists the cookies we use, their purpose, duration and how you can grant or withdraw consent.
13. Changes to this Policy
We may update this Privacy Policy from time to time. The "Last Updated" date at the top reflects the date of the latest revision.
For non-material changes (e.g. new contact channel, formatting, typo correction), the change takes effect immediately on posting.
For material changes (e.g. new sub-processors, new processing purposes, change in retention period, change in international-transfer mechanism), we will give at least 30 days advance notice, by:
- a banner on alphalevel.net;
- email to active customers and dashboard account holders;
- and (where the change affects subscription customers materially) a separate "what is changing" summary.
If you do not agree with the change, you may stop using the Service before the new version takes effect; continued use after the effective date constitutes acceptance.
(The previous version of this Policy specified a 180-day notice period; we have shortened it to 30 days, which is more typical of GDPR-mature operators and gives users a faster, clearer signal of change.)
14. Contact
For any privacy-related question, request, complaint or opt-out:
Alpha Level SHPK
NIPT: M36606201D
Rruga "Bardhyl Pojani", Lagjia nr. 2
7001 Korçë, Albania
Email: info@alphalevel.net (subject: "Privacy" — followed by the topic, e.g. "Privacy — Access")
Phone: +355 69 208 8969
We reply within 5 business days for general questions and within 30 days for formal data-subject rights requests (extendable to 90 days for complex requests, with notice).
End of Privacy Policy — Version V1.0, dated 7 May 2026.