Privacy notice
About this document
| Field | Value |
|---|---|
| Version | 1.0 |
| Effective date | 1 August 2026 |
| Publication date | 1 August 2026 |
| Last reviewed | 26 July 2026 |
| Status | Approved public document |
Version history
| Version | Effective date | Change summary | How this version applies |
|---|---|---|---|
1.0 | 1 August 2026 | Initial public version | Applies to the processing described here; consent choices remain separate where required |
This notice at a glance
This summary is provided to help you navigate this notice. It does not replace, change or limit the full sections below, which are the complete description of our processing.
| Question | In short | Read more |
|---|---|---|
| Who we are | Alessia International Ltd, registered in England and Wales under company number 17259224 and registered with the UK Information Commissioner's Office under reference ZC165397 | Section 1 |
| Who controls your portfolio | For an individual professional account, you normally determine the portfolio purpose and are its controller, and Alessia processes the User Content on your behalf; for an Institution-controlled account, the applicable agreement identifies the Controller or Controllers | Section 2 |
| What we collect | Account and profile information, the portfolio content you choose to record, limited information about supervisors, assessors and colleagues a user names, content you select for optional AI features, subscription and transaction information, device, security and usage information, and communications | Section 3 |
| What we never do | We do not sell personal information or use it for cross-context behavioural advertising. No identifiable or pseudonymised User Content is available for Alessia's independent analytics, benchmarking, research or model-development use | Sections 8 and 9 |
| Patient data | Patient data is prohibited by default. A specified institutional Tenant may process expressly permitted patient data under a Patient Data Addendum; patient consent alone does not create an exception | Section 4 |
| AI features | AI features generate drafts and suggestions; a user must review and approve output. Section 7 explains our position on automated decisions | Sections 3.4 and 7 |
| Where information is held | Primary application data for individual accounts is hosted in the United Kingdom; other service providers may process information elsewhere under transfer safeguards | Section 10 |
| How long we keep it | The Retention Schedule sets out our retention periods by record type; after an individual subscription ends, read-only/export access lasts for 90 days before scheduled live account deletion | Section 11 |
| Your rights | Depending on where you live and which law applies, you may have rights including access, correction, deletion, restriction, objection, portability and withdrawal of consent, and you may complain to us and to the Information Commissioner's Office or your local authority | Section 12 |
| Who to contact | privacy@alessiahq.com for privacy enquiries and rights requests; support@alessiahq.com for general support | Sections 1 and 18 |
| Related documents | Retention Schedule · Subprocessor and Service-provider List · Cookie Notice | - |
1. Who this notice covers
This notice explains how Alessia International Ltd ("Alessia", "we", "us" or "our") handles personal information when you:
- visit alessiahq.com or another Alessia website;
- create or use an individual Alessia account through the app or app.alessiahq.com;
- buy or trial an individual subscription;
- contact support, make an enquiry or receive marketing;
- act as an Institution contact, administrator, supplier or prospective customer; or
- are named by an individual user as a supervisor, assessor, educator or colleague.
Alessia International Ltd is registered in England and Wales under company number 17259224. Our registered office is 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom. Alessia is registered with the UK Information Commissioner's Office as a fee-paying data controller under registration reference ZC165397. Alessia's processing is governed by the UK GDPR and the Data Protection Act 2018, and by the EU GDPR and other local laws where they apply.
- Privacy enquiries and rights requests: privacy@alessiahq.com
- General support: support@alessiahq.com
- Legal notices: legal@alessiahq.com
Our privacy contact is the Privacy Officer. We publish the role rather than the individual's name: privacy@alessiahq.com. Alessia has not designated a statutory Data Protection Officer; the Privacy Officer is Alessia's privacy lead and contact point.
2. Who controls portfolio information
Individual professional accounts
If you choose what personal information to record in an individual account for your professional portfolio, you normally determine that portfolio purpose and are its controller. Alessia processes the User Content on your behalf under the processing terms in Schedule 1 of the Individual Customer Terms. Those instructions cover storage, organisation, mapping, reporting, export, user-initiated optional AI functions, security safeguards, rights assistance and deletion.
Alessia remains a separate controller for information it uses for its own account administration, authentication, subscriptions, communications, analytics, security, abuse prevention, complaints, legal compliance, legal rights and corporate administration. This notice explains those activities as well as how Alessia handles User Content as processor.
If an employer, university, training body or another organisation actually determines the purpose for information, using an individual account does not make the user its controller. The user must have that controller's authority and an appropriate arrangement or use an Institution-controlled account.
Institution-controlled accounts
If a university, college, employer, training body or other Institution provides or controls your Alessia account, that Institution is normally the controller of the portfolio and assessment information in that account. Alessia processes it on the Institution's instructions under a Data Processing Addendum.
Read the Institution's privacy notice for its purposes, lawful bases, access decisions, retention and your rights. Alessia remains a separate controller for limited information used for contracting, billing, security, fraud prevention, legal compliance and our direct relationship with Institution representatives.
Individual and Institution accounts are separate. Portfolio information is not automatically moved between them.
3. Information we collect
3.1 Account and profile information
This may include your name, email address, account identifier, password/authentication records, identity-provider subject and access records, age-eligibility confirmation, country, language, profession, speciality, grade, role, organisation, position, rotation, workplace or location, preferences and profile information. Our current identity provider and its verified entity, region and retention are identified in the Subprocessor List.
Alessia does not currently verify identity, professional registration, credentials, employment or authority to practise. Do not treat an Alessia profile as verified.
Providing basic account information is a contractual requirement: without a name, email address and, for a paid plan, payment confirmation, we cannot provide an account or subscription. Other information is optional unless the interface says otherwise.
3.2 Individual portfolio content
You choose what to record. Content may include encounters and case exposure, procedures, interventions, diagnoses or conditions, non-identifying demographics, dates and duration, speciality, rotation, position, location, supervisor, proficiency, notes, reflections, goals, tags, learning/CME, assessments, feedback, professional activity, certificates, credentials, references, signatures, calculations, attachments, audio, transcripts, images, video, AI-assisted drafts, competency mappings and reports.
Portfolio fields are optional unless the interface says otherwise. The presence of a field does not mean that it is appropriate to enter identifiable patient information or unnecessary information about another person.
3.3 Information about supervisors, assessors and colleagues
What a user may record about you
A user may record your name, professional email address, professional relationship, workplace, assessment, feedback or signature, or upload evidence that refers to you. We ordinarily receive this information from the user rather than directly from you.
When we send a transparency email
The email-based notice process below applies where the Service offers a field to record a supervisor's email address; where no email field or suitable address is available, the reminder route at the end of this section applies instead. If a suitable email address is first saved in an individual account, Alessia sends a transparency email promptly and within the applicable legal period. The user is told before saving that the email will identify them by name and describe the claimed supervisor, assessor or colleague relationship. To avoid repeated messages, the notice is normally sent once for each person, controller and Privacy Notice version. A new notice is sent if the email address or controller changes, or if the recorded relationship changes materially. A minor correction to a name or spelling does not by itself trigger another notice.
What the email says and who it identifies
For an Institution-controlled account, the email identifies the Institution as controller and Alessia as processor and is sent on the Institution's behalf under its configured instructions. For an individual professional account, it identifies the entering professional by name as controller of the relevant portfolio information and Alessia as processor. The email explains the categories, source and purpose of the information, links to this notice and provides a direct privacy@alessiahq.com correction or removal email link for routing and assistance. It expressly asks the recipient to email that address if they are not the person named or do not recognise the professional relationship. It includes a non-sensitive notice reference so the request can be located without exposing a portfolio-entry or account identifier. It contains no patient information, portfolio entry details, assessment content or AI content.
How long we keep the email address and notice records
The professional email address is not included in portfolio reports. Because the current feature uses it only to deliver this transparency notice, Alessia removes the raw address from its portfolio and notification records after successful delivery or after a maximum 30-day delivery and retry period. A permanent delivery failure stops retries; the user is asked to correct or remove the address, and a corrected address receives a new notice. The email delivery provider's copy expires under the current period in the Subprocessor List. Acting as processor, we retain a minimum protected record of the recipient identifier, controller, notice version, delivery date and result for three years to demonstrate that the notice was provided or attempted.
Separately, Alessia acts as controller for the minimum service-wide suppression and abuse-prevention information needed to stop repeated unwanted notices across individual-account controllers. If a no-contact objection is upheld, we retain only a protected email identifier and suppression scope while relevant individual accounts or relationships remain active, or until the objection is withdrawn. Each Institution is a separate controller and its suppression is separately scoped and managed under its instructions. The suppression record contains no raw email address, portfolio content or reason for the objection. A future assessment or verification feature that needs the address will collect it under the notice and retention terms applicable to that feature.
Your rights and how to contact us
You do not need an Alessia account to ask for access, correction, restriction or removal, or to object. Email privacy@alessiahq.com. A reply from the address that received the notice, together with its non-sensitive reference, will normally be sufficient to stop contact or report an incorrect identity or relationship. We request further verification only where we reasonably doubt identity or responding could affect another person's rights. Formal identity documents are requested only where necessary, particularly before disclosing information or deciding a contested removal request, and copies are deleted promptly after verification in accordance with the Retention Schedule. An Institution controls verification for requests concerning its account.
How a request is handled
These rights are not absolute and may require proportionate identity verification and consideration of the portfolio owner's or another person's rights. A request is applied according to its scope: an objection to further contact removes the professional email and stops further messages but does not automatically erase an accurate name or professional relationship from relevant portfolio entries. Accurate information may remain where it is reasonably necessary for the portfolio purpose and the controller has documented overriding lawful grounds. Inaccurate or unlawfully held information is corrected or removed, and disputed information is restricted while assessed.
For an individual account, Alessia assists the entering professional as controller and may tell them only that the details are under review or require correction; we do not forward the recipient's message, explanation, contact details or other complaint information. Alessia decides separately any restriction or suppression within its own controller scope. For an Institution-controlled account, the Institution controls any communication with the entering user and Alessia acts under its instructions. Full removal from entries occurs only where the relevant controller upholds the request and no overriding lawful reason supports retention. A request about an Institution-controlled account is directed to the Institution as controller. It does not permit deletion of unrelated portfolio content.
If we have no suitable contact details for you
If no suitable contact details are available, the user is prompted, where reasonably practical, to tell the person that their professional details have been recorded in Alessia and direct them to this Privacy Notice. This reminder supplements but does not transfer the relevant controller's responsibility to assess the applicable indirect-collection transparency duties, any lawful exception and appropriate public or in-product transparency.
3.4 Audio, files and AI inputs
If you choose an AI-assisted feature, we process the selected recording, file or text and the returned transcript, summary or suggestion. AI-assisted content is identified in the workflow and must be reviewed by a person.
Do not submit patient personal data or material you are not authorised to use. An institutional Patient Data Addendum does not by itself authorise patient data for AI; a separate feature-specific written authorisation is required. Approved transcription and generative-AI service providers may process only the content selected for the requested feature. Their current entities, purposes, locations, retention and transfer safeguards are published in the Subprocessor List.
AI-assisted processing is request-specific. Where a provider supports configurable expiry or deletion, Alessia uses those controls to minimise retention. This is not always zero-data-retention: a provider may temporarily retain inputs and outputs for service operation, security, abuse prevention or legal compliance. The Subprocessor and Service-provider List gives the current provider-specific periods. Content and outputs saved in your Alessia account remain subject to the Retention Schedule.
3.5 Subscription and transaction information
We receive plan, purchase channel, subscription status, price, currency, country, entitlement, trial/renewal, cancellation, refund and transaction-reference information. Subscription and entitlement providers support app-store and consumer-web purchases. App stores process purchases made through them. For a direct consumer web purchase, the checkout identifies the merchant of record, which sells the subscription as an authorised reseller under its linked terms and privacy information, while Alessia provides the Service and remains responsible for your statutory rights and remedies in relation to it. Alessia does not receive full card details. Current provider identities and roles are published in the Subprocessor List.
3.6 Device, security and usage information
This may include IP address, device/browser/app information, approximate location derived from IP, identifiers, timestamps, authentication events, audit events, feature interactions, performance, diagnostics, crash data, referring pages and security signals.
Our product analytics provider may process account identifiers, your email address and optional name, device information and configured feature-usage events where you have enabled analytics. We do not send clinical or portfolio content - including free text, audio, attachments, or AI inputs or outputs - in analytics events. The Cookie Notice and Subprocessor List describe the analytics categories and current provider.
If you enable notifications, our push provider may process an Alessia member identifier, device or push token, notification template, priority and the minimum variables needed to deliver the message. Push notifications contain only generic account, product, security or service messages. They do not include portfolio evidence or sensitive assessment or health information. Device and operating-system notification settings provide additional controls.
3.7 Communications and marketing
We collect enquiries, support messages, complaint and incident records, survey responses, product feedback, newsletter choices and email engagement where permitted. Do not send patient information or confidential portfolio evidence by public website form or ordinary email.
3.8 Information from public and third-party sources
We may receive business contact details from your Institution, event or referral contacts, app stores, payment providers, authentication providers and publicly available professional sources where lawful, such as professional registers, employer or institution websites and professional networking profiles. We do not use public sources to verify whether a user is a clinician.
4. Patient personal data is prohibited by default
The default rule
Alessia is not an electronic health record. Outside an expressly authorised institutional Patient Data Tenant, you must not submit information that identifies or could reasonably identify a patient, directly or through a combination such as exact date/time, exact age, named facility or team, rare diagnosis or procedure, narrative and media. Patient consent does not create an exception.
Authorised institutional Patient Data
An Institution may contract separately for a specified Tenant to process limited patient data. The applicable Order, Patient Data Addendum and Patient Data Permission Schedule identify the Controller or Controllers, permitted patient and data categories, purposes, operations, retention, data region, integrations and safeguards.
Alessia processes that information as Processor on the relevant Controller's documented instructions. The Controller is responsible for its lawful basis, special-category condition, transparency, authority, DPIA and patient rights. The permission does not extend to another account, Tenant, Institution, feature or purpose and does not make Alessia a primary clinical record or patient-care system.
How we investigate suspected patient data
Despite this rule, prohibited or out-of-scope patient data may be submitted accidentally or unlawfully. If suspected, we normally review the minimum risk metadata and seek information from the user first. We inspect portfolio content only where reasonably necessary to confirm or contain the concern, or where urgent legal or security containment means that waiting would materially increase risk. Access is restricted, limited to the relevant entry and review period, and logged without copying the content into the access record. For an Institution-controlled account, we follow the relevant Controller's instructions and contact route unless urgent containment requires immediate access.
How we tell you about an inspection
After inspecting content in an individual account, we place the detailed notice in the authenticated Service and send a generic email alert containing no entry, portfolio or patient details. The detailed notice states the inspection date and time, the reviewer's role rather than name, the general reason, the affected entry reference, the outcome and any continuing restriction, and how to contact the Privacy Officer to question or challenge the decision. It never reproduces the suspected identifier, patient information or portfolio content.
Challenging a restriction and how it lifts
A question or challenge does not automatically lift the restriction: the affected entry remains restricted while the Privacy Officer reviews it, and unaffected portfolio content remains available. We restore the affected entry promptly if the restriction is reversed. If the user edits the entry and server re-evaluation confirms that the suspected identifier has been removed, the entry-risk restriction lifts automatically and the review closes as remediated. A separate privacy complaint or independent legal, security or Institution restriction continues on its own basis. For an individual account, we handle an affected-entry challenge as an entry-risk review unless the user disputes our privacy handling or asks us to treat it as a formal privacy complaint. We assess separately whether the facts indicate a privacy or security incident. This does not limit the user's right to make a privacy complaint.
Delayed notice, Institution accounts and further action
We may delay notice where it would compromise an investigation, a legal requirement, security or another person's rights; we review any delay and give notice when the reason ends. For an Institution-controlled account, we email the Institution's nominated privacy contact as controller and provide sensitive information only through an authenticated or otherwise secure route. The Institution decides whether and how to notify the member. We may restrict access, quarantine or delete content, preserve limited evidence, investigate and notify an Institution or legally relevant party following the applicable assessment. We will assess controller roles, lawful basis, special-category condition and notification duties for the particular incident. The Acceptable Use and Patient Data Policy explains the process.
Automated indicators and restricted review
The Service may use indicators to identify a suspected direct identifier or an elevated combination risk and may place the entry under restricted review. This preserves the user's work but prevents unresolved content from proceeding through normal portfolio, reporting, sharing, assessment or AI workflows. A suspected out-of-scope direct identifier must be removed and re-evaluated; acknowledgement alone does not clear it. These indicators assess re-identification risk; they do not decide whether an entry is personal data, anonymous, lawful or safe. Identifiability depends on the context and the means reasonably likely to be available to the relevant person, including a clinician or Institution with access to a clinical record, rota, local knowledge or memory. Controls may be configured for an authorised Patient Data Tenant so that data within its Patient Data Permission Schedule is not treated as prohibited, while out-of-scope data remains subject to review.
5. Special-category and sensitive information about users
Alessia does not require information about your own health, disability, ethnicity, beliefs, sexual orientation, trade-union membership or other sensitive characteristics for a standard individual account. You must not intentionally submit it unless a specific Alessia feature asks for it and explains why it is needed and how it will be used. If we receive such information contrary to this rule, we may restrict or delete it unless we have a lawful reason and applicable legal condition to retain it.
6. Our roles, instructions and UK/EU lawful bases
| Purpose | Information | Alessia's role | Primary UK/EU basis or instruction |
|---|---|---|---|
| Create and administer an individual account | Account, profile, authentication and preferences | Controller | Performance of our contract or steps requested before it |
| Provide portfolio storage, mapping, reports and exports | User-selected portfolio content and settings | Processor for the individual professional or Institution controller | Documented instructions in the Individual Customer Terms or Institution DPA; the relevant controller determines its lawful basis and any special-category condition |
| Provide optional AI transcription, summaries and suggestions | Selected inputs and outputs | Processor for User Content; controller for minimum feature-operation and security records used for Alessia's own purposes | User/Institution documented instruction for User Content; contract and legitimate interests for Alessia-controlled operational records. Prohibited patient and user special-category information must not be submitted |
| Process subscriptions and refunds | Account, plan, transaction and tax records | Controller | Contract and legal obligations |
| Send service, security, trial and renewal messages | Contact, account and subscription status | Controller | Contract, legal obligation and legitimate interests in administering the Service |
| Provide support and investigate complaints | Contact, communications, account and relevant diagnostic information | Controller for Alessia's service and handling; processor when assisting another controller with User Content | Contract and legitimate interests, or the relevant controller's documented instruction |
| Protect accounts, apply portfolio safeguards, prevent abuse and investigate incidents | Authentication, IP/device, audit and content implicated in an incident | Controller for Alessia's own security, abuse, legal and claims purposes; processor when applying instructed User Content safeguards | Legitimate interests, legal obligations and establishment/defence of legal claims, or documented controller instructions; special-category conditions for Alessia-controlled processing require case-specific approval |
| Maintain and improve reliability | Diagnostics, security and minimised usage data | Controller | Legitimate interests for strictly necessary diagnostics and security telemetry; consent for optional product analytics involving storage of, or access to, information on your device |
| Create genuinely anonymous information | Minimum information needed for the approved anonymisation operation | Processor while acting on the documented anonymisation instruction; resulting genuinely anonymous information is not personal data | Individual Customer Terms or Institution instructions; no identifiable or pseudonymised User Content is available for Alessia's independent analytics, benchmarking, research or model-development use; Institution Anonymous AI Improvement requires express written authorisation |
| Send optional marketing | Contact and marketing choices | Controller | Consent where required; otherwise a permitted existing-customer/legitimate-interest route with opt-out |
| Manage institutions, suppliers and corporate operations | Business contacts, contracts, invoices and communications | Controller | Contract, legitimate interests and legal obligations |
| Comply with law and protect legal rights | Relevant account, transaction, communication, security and content evidence | Controller where Alessia determines that legal purpose | Legal obligation, legitimate interests and legal claims; any special-category condition is assessed for the specific processing |
| Record and notify supervisors/assessors at a user's request | Limited professional identity, relationship, feedback, evidence and notice record | Processor for the portfolio and notice; controller for minimum service-wide suppression and abuse-prevention information | Relevant controller's documented instruction and lawful basis; legitimate interests and legal obligations for Alessia-controlled suppression/security records |
Where we rely on legitimate interests, we assess necessity and effects on individuals. You may ask for information about the relevant assessment. Where we rely on consent, you may withdraw it without affecting earlier lawful processing.
Additional regional notices supplement this Privacy Notice where applicable. Local mandatory rights prevail.
7. AI and automated decisions
AI features generate drafts and suggestions. They may be inaccurate, biased or misleading. A user must review and approve output. Alessia does not currently use AI to make a solely automated decision producing legal or similarly significant effects about clinical care, admission, assessment, progression, employment, credentialing or professional status.
Institutions remain responsible for their own decisions, verification, human review and appeal processes.
8. Analytics, research and anonymous information
For User Content, Alessia performs any approved anonymisation operation under the applicable individual-professional or Institution controller instruction. We may create anonymous information only where people, patients and Institutions are not reasonably identifiable. We do not treat pseudonymised, coded, entry-level or merely de-identified information as anonymous unless a documented, context-specific assessment establishes that the relevant people are not reasonably identifiable using means reasonably likely to be available.
Genuinely anonymous information may be used for service improvement, security, capacity planning, analytics, benchmarking and research. For individual accounts, it may also be used to develop, train, test, evaluate and improve Alessia-controlled statistical and AI models. For Institution-controlled accounts, that anonymous AI-improvement use occurs only where the Institution expressly authorises it in its Order Document or another written agreement.
Anonymous AI-improvement information does not include identifiable or pseudonymised User Content. Raw narratives, audio, images, video, attachments, transcripts and signatures are excluded unless a documented assessment establishes effective anonymisation for the intended use. Third-party frameworks, terminology, calculators and other licensed materials are excluded unless the applicable rights permit model use. We do not permit a provider to use this information for its own or general model training. Before the anonymisation operation begins, the applicable controller's instructions, legal basis and any required special-category condition must be documented, and Alessia must approve the relevant impact assessment and safeguards. We assess relevant risks of singling out, linkage, inference, memorisation and extraction and will not publish or disclose a small-cell, unusual combination or model output that creates a material re-identification risk.
9. Who receives information
Depending on the feature and purchase channel, recipient categories may include:
- cloud hosting, storage, backup and infrastructure providers;
- identity, authentication and access-management providers;
- product analytics, diagnostics and security providers;
- transactional email and push-notification providers;
- optional transcription and generative-AI processors;
- app stores, subscription and entitlement services, and consumer web-payment providers; the relevant merchant of record or payment provider is identified at checkout, while institutional invoices are paid by bank transfer;
- an Institution where you use an Institution-controlled account;
- personnel and professional advisers who need access and owe confidentiality duties;
- a buyer or successor during a genuine corporate transaction subject to safeguards; and
- courts, regulators, law enforcement and other parties where required or reasonably necessary to protect legal rights, safety or security.
The published Subprocessor and Service-provider List is the authoritative current register of provider entities, roles, purposes, locations and retention. It distinguishes processors acting on our instructions from app stores, payment providers and other independent controllers. Provider names may also appear at checkout, in an app store or in a consent interface where the provider's identity is relevant to that transaction or choice. We do not sell personal information or use it for cross-context behavioural advertising.
10. International transfers
Primary application data for individual accounts is hosted in the United Kingdom. An Institution may select another available hosting region for its tenant. The current hosting provider and regions are identified in the Subprocessor List. Other service providers - including identity, email, push, analytics, subscription, support, payment and AI providers - may process information elsewhere. Selecting a hosting region does not mean every provider or support activity remains in that region.
For restricted UK/EEA transfers, we use an applicable adequacy decision, the UK International Data Transfer Agreement/Addendum, EU Standard Contractual Clauses or another valid mechanism, with transfer-risk assessment and supplementary measures where required. You may request information about, or a copy of, the safeguard relied on for a particular transfer by emailing privacy@alessiahq.com.
Additional regional notices may apply depending on where you live or the Institution providing your account. We may restrict a feature or market where necessary to comply with applicable law.
11. How long we keep information
The Retention Schedule sets out our retention periods by record type. Key individual-account rules are:
- while an account is active, portfolio information is retained to provide the Service;
- after an individual subscription ends, read-only/export access lasts for 90 days before scheduled live account deletion;
- user-requested live account deletion is targeted within three days after access is revoked and confirmation sent, subject to lawful exceptions;
- consumer backup copies expire through a rolling cycle of up to 35 days;
- routine support tickets and ordinary enquiries are retained for 24 months after closure, while support attachments are deleted as soon as no longer needed and no later than 90 days after closure unless necessary material is moved into a separately governed incident, complaint, privacy, financial or legal record;
- minimised privacy-rights request records are retained for three years after completion; identity-document copies and delivered disclosure bundles are deleted within 30 days after verification or confirmed delivery respectively, subject to a documented dispute, regulator requirement, Institution instruction or legal hold;
- minimised complaint, dispute and legal-claim files are retained for six years after final closure, with only necessary material kept longer for active proceedings, appeals, regulators, insurers, a longer applicable limitation period or a documented legal hold;
- active account holders may receive optional marketing while their single marketing choice remains valid; newsletter-only leads and former users are removed from active marketing after 24 months without a link click, reply, enquiry, purchase, preference update or renewed opt-in, while a minimal suppression record may be kept to honour an opt-out;
- minimal cookie, analytics and marketing-choice evidence is kept while we rely on the choice and for three years after it is withdrawn, superseded or the processing ends; master wording and configuration versions are kept for seven years;
- executed customer and supplier contracts are generally kept for their term plus seven years, deeds for 12 years after termination or expiry, supplier due-diligence records for the relationship plus seven years, unsuccessful proposals for two years after closure and routine non-marketing business contacts for the relationship plus two years, subject to documented legal or statutory exceptions;
- identifiable product-analytics data is retained for no more than 365 days and ordinary public security logs for 90 days;
- financial/tax records are retained for seven years from the end of the relevant financial year; minimised formal incident files are retained for six years after closure, while raw incident evidence is deleted as soon as no longer necessary and no later than 90 days after closure, subject to documented legal/regulatory/insurance exceptions; and
- Institution-controlled data follows the Institution's Order Document and instructions.
12. Your choices and rights
Depending on where you live and which law applies, you may have rights to:
- be informed and obtain access;
- correct inaccurate information;
- delete information;
- restrict or object to processing;
- receive portable information;
- not be subject to a solely automated decision producing legal or similarly significant effects, and obtain human intervention, express your point of view and contest such a decision;
- withdraw consent;
- opt out of marketing, certain analytics, sale/sharing or targeted advertising;
- appeal a refused request; and
- complain to a privacy or data-protection authority.
Your right to object. You may object at any time, on grounds relating to your particular situation, to processing based on legitimate interests, and we will stop unless compelling legitimate grounds override your interests, rights and freedoms. You may object at any time, and without giving a reason, to direct marketing, and we will stop that processing.
Use in-app controls where available or email privacy@alessiahq.com. We may need to verify identity and clarify the request. For information Alessia controls, we will respond within one month; a complex or numerous request may take up to two further months, and we will tell you within the first month if so and explain why. We will route or assist with a request concerning User Content controlled by an individual professional or Institution.
Verification is proportionate to the request and the information involved. We ordinarily use account authentication for a signed-in user, or the registered email plus a matching account detail for a former user. For a supervisor, assessor or colleague who received a transparency notice, a reply from that address with the notice reference is normally sufficient to stop contact or report an incorrect identity or relationship. For another non-account holder or person named by a user, we ask for the minimum relevant contextual evidence. We request additional or redacted identity evidence only where genuine doubt remains or disclosure could affect another person. An authorised representative must show their authority. Verification documents are deleted promptly after verification unless retaining evidence is necessary for a documented legal, complaint or security reason.
If an individual professional or Institution controls the relevant User Content, contact that controller where practical. You may still use privacy@alessiahq.com; we will route and assist with the request as processor. A request involving a supervisor, assessor, another user or confidential assessment may require the controller to balance competing rights. Alessia separately decides requests concerning information it controls for its own purposes.
Complaints to Alessia
You may make a data-protection complaint about Alessia's processing electronically by following the instructions on the privacy complaints page and emailing privacy@alessiahq.com with “Data Protection Complaint”. Alessia does not require you to submit the complaint through a web form. A complaint about a decision made by an individual professional or Institution controller may be routed to that controller, while Alessia will address its own conduct and provide processor assistance. Please describe the concern, relevant dates/account and the outcome you seek, but do not email patient data or unnecessary portfolio evidence.
We target acknowledgement within five business days and in all cases will comply with the statutory maximum. We will make appropriate enquiries, keep you informed of progress where needed and communicate the outcome without undue delay. The detailed Data Protection Complaints Procedure explains investigation, records and escalation.
You may also complain to the Information Commissioner's Office (ico.org.uk/make-a-complaint, telephone 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF) and retain that right whether or not you complain to Alessia first. EU/EEA users may complain to the authority in their country and may contact our representative identified in Section 18. Swiss users may contact that representative or the Federal Data Protection and Information Commissioner. Regional contact and appeal details are provided in the applicable supplements.
Washington residents should also read the Washington Consumer Health Data Privacy Policy if it applies. Nevada residents should read the Nevada Consumer Health Data Privacy Policy if it applies.
Australian, New Zealand, California, Canadian and Québec users should also read the applicable supplement linked from the public policy register.
13. Marketing
Marketing is optional. Alessia uses one separate, unticked email-marketing choice rather than campaign-by-campaign choices. Where we instead rely on the existing-customer ("soft opt-in") route, we do so only where your details were obtained during a sale or negotiation for a similar Alessia service and you were offered a simple way to refuse at collection and are offered one in every message. The record includes the choice, timestamp, source and notice version. We do not impose automatic periodic re-consent; we request a new choice if the purpose or channel materially changes or we can no longer demonstrate what you agreed to.
You may unsubscribe using the link in an email or contact us. We synchronise the choice with our delivery/marketing systems and retain a minimal suppression record to avoid contacting you again by mistake. We measure marketing-link clicks for engagement and funnel analytics; email-open tracking is disabled.
Necessary account setup, authentication, security, billing, cancellation, deletion and strictly functional onboarding messages are service communications and may continue while relevant. They do not use marketing-link tracking or contain promotional content. Feature promotions, educational newsletters, upgrade prompts, offers and promotional onboarding use your marketing choice.
14. Cookies and similar technology
The Cookie Notice describes website cookies, local storage and SDKs used for authentication, analytics, notifications and subscription administration. A consent-management platform manages consent on the marketing website only; it is not the privacy-control mechanism for the web application or mobile apps. Non-essential marketing-site tracking remains off worldwide until affirmative consent, with a way to reject or change preferences. App permissions and in-app processing use separate controls and just-in-time disclosures where required. The consent interface specifically identifies any third parties whose technologies require consent.
15. Security
We use technical and organisational measures designed to protect information, including access controls, encryption, logging, secure development and incident processes appropriate to the risk. No online service can guarantee absolute security.
Protect your credentials and report suspected unauthorised access promptly. Do not use Alessia as the only copy of career-critical evidence.
16. Age
Alessia is restricted to people aged 18 and over. We do not knowingly offer individual accounts to children. Contact us if you believe a person under 18 has created an account. The 18+ rule is a deliberate product eligibility rule even where a younger person may be enrolled in medical education.
17. Changes to this notice
We may update this notice and will publish the new effective date. We will give appropriate notice of a material change and obtain consent where law requires it. A change of provider within an already-described recipient category is normally recorded in the Subprocessor and Service-provider List rather than requiring a new version of this notice. We will update this notice where a provider change materially alters the purposes, information categories, controller roles, international-transfer description, user choices or rights described here. Archived versions will be retained.
18. Contact and regional representatives
- Controller for Alessia's own processing: Alessia International Ltd
- Controller for User Content in an individual professional account: normally the professional who determines why the information is recorded; Alessia acts as processor
- Controller for User Content in an Institution-controlled account: the relevant Institution; Alessia acts as processor
- Registered office: 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom
- Privacy: privacy@alessiahq.com
- Support: support@alessiahq.com
- Telephone:
+44 20 4514 5863
You may always contact Alessia directly at privacy@alessiahq.com. People in the EU/EEA or Switzerland may alternatively contact our appointed representative:
- Representative: Data Protection Representative Limited (trading as DataRep), registered in Ireland under number 616588
- Scope: representative under the EU GDPR in the EU/EEA and under the Swiss Federal Act on Data Protection in Switzerland; DataRep is not our UK representative
- Email: datarequest@datarep.com
- Online request form: www.datarep.com/data-request
- EU/EEA postal contact: DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland
- Switzerland postal contact: DataRep, Leutschenbachstrasse 95, ZURICH, 8050, Switzerland
When contacting DataRep, quote Alessia International Ltd in the email subject line or correspondence. Postal correspondence must be addressed to DataRep, not Alessia International Ltd, so that it reaches the representative. Describe the type of request, but do not send patient information or unnecessary portfolio content.
- Québec person responsible for protection of personal information: Privacy Officer, privacy@alessiahq.com
