← Back to Strategize Labs Home Page

Privacy Policy

Effective Date: 11 April 2026 · Last Updated: 2 September 2026

1. Who We Are

Alfrada and Strategize Labs are trading names of Strategize and Insight Practice Limited, a company incorporated in England and Wales (Company No. 14032259), with its registered office at Unit 1 Camboro Business Park, Oakington Road, Girton, Cambridge, England, CB3 0QH (the "Company", "we", "us", or "our").

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the Data Controller of the personal data we collect through our platform at app.alfrada.ai and the Alfrada desktop application, and our marketing websites at alfrada.com, alfrada.ai, strategize.inc, and strategizelabs.com (collectively, the "Service").

Data Protection Contact: privacy@strategize.inc

2. What Personal Data We Collect

We collect and process the following categories of personal data:

2.1 Account Data

When you register for an account, we collect your name, email address, and (if applicable) company name. If you subscribe to a paid plan, payment information is collected and processed by our payment processor, Stripe, and is not stored on our servers.

2.2 User Content

The Service enables you to submit text prompts, upload documents, images, audio files, and other content ("User Content"). User Content may contain personal data if you choose to include it. We process User Content solely to provide the Service to you.

Special category data. Some features (for example the Medical Vision tool, which offers a second-opinion read of X-rays, scans, and clinical documents) may involve health data or other special category data under Article 9 UK GDPR. We process such data only because you have chosen to upload it, on the basis of your explicit consent (Art 9(2)(a)), and only on our own EU-based infrastructure. Medical Vision is not a medical device and its output is not medical advice. You may withdraw consent at any time by deleting the relevant files or conversations.

2.3 Conversation and Memory Data

We store your conversation history, AI-generated responses, and contextual memory data to provide a personalised and persistent experience. This data is stored on servers located in the European Union (see Section 6).

2.4 Technical and Usage Data

We automatically collect limited technical data, including IP address (for rate limiting and security), browser type and version, device information, and timestamps of access. We do not use third-party analytics or tracking services on the Alfrada application (app.alfrada.ai).

2.5 Marketing Website Analytics Data

On our marketing websites (alfrada.com, alfrada.ai, strategize.inc, strategizelabs.com), we use analytics cookies — only with your consent — to collect aggregated data about page views, traffic sources, scroll depth, and session behaviour. The sole purpose is to understand which marketing channels drive visitors to our site so that we can optimise acquisition spend and control customer-acquisition costs. This data is not linked to your Alfrada application account. See our Cookie Policy for the specific technologies used.

2.6 Credentials and Integrations

We store third-party credentials in our encrypted Vault. If you connect third-party accounts (e.g., Gmail, Google Calendar, Drive, Docs, Sheets, Slides and Analytics, Microsoft Outlook and Teams, GitHub, Slack, Zoom, LinkedIn, X, Facebook, Discord, Canva, Hunter.io), OAuth authentication is handled by Composio (Privacy Policy), which manages token exchange and renewal on our behalf. We store only an encrypted connection identifier; we do not store your passwords for these services.

2.7 WhatsApp Assistant Data

If you choose to link a WhatsApp device to the Alfrada WhatsApp assistant, messages exchanged through that linked device (including messages from your contacts) are received by your personal bridge and stored in a per-user database on our EU servers so the assistant can read history and reply on your instruction. This feature is off until you link a device, and you can unlink it at any time, which stops collection. Where those messages contain other people's personal data, you are responsible for ensuring you are entitled to process it through the Service (see our Terms of Service).

2.8 Enquiry and Lead Data

If you use the "book a deployment call" or similar contact forms on our marketing websites, we collect the details you enter (name, work email, company, role, and a description of what you need help with) together with the page you arrived on, the referrer, and any campaign parameters or advertising click identifiers (for example a Google Ads gclid) present in the URL that brought you to us. We use this to respond to your enquiry and to attribute the enquiry to the marketing channel that produced it. Forms are protected by Cloudflare Turnstile, which processes your IP address to distinguish people from bots.

3. Lawful Basis for Processing

Under Article 6 of the UK GDPR, we process your personal data on the following legal bases:

PurposeLawful Basis
Providing the Service (account management, conversation processing, tool execution)Contract — Art 6(1)(b): necessary for the performance of a contract to which you are party
Processing paymentsContract — Art 6(1)(b)
Security, fraud prevention, and abuse detectionLegitimate Interest — Art 6(1)(f): our legitimate interest in protecting the Service and our users
Sending transactional communications (e.g., account verification, billing)Contract — Art 6(1)(b)
Complying with legal obligations (e.g., tax, financial regulation)Legal Obligation — Art 6(1)(c)
Marketing website analytics and advertising conversion measurement for channel optimisation and cost controlConsent — Art 6(1)(a): analytics and conversion-measurement tags are only activated after you click "Accept analytics" in the cookie banner. You may withdraw consent at any time (see Cookie Policy).
Responding to enquiries and deployment-call requests, and attributing them to a marketing channelLegitimate Interest — Art 6(1)(f): our interest in responding to prospective customers who contact us; and Contract — Art 6(1)(b) where the enquiry is a step towards entering into a contract with you
Processing health or other special category data you choose to upload (e.g. Medical Vision)Explicit Consent — Art 9(2)(a), alongside Art 6(1)(b)

We do not rely on consent as a lawful basis for core Service processing. We rely on consent only for marketing website analytics and conversion-measurement cookies, and for any special category data you choose to upload; you may withdraw either at any time.

4. How We Use Your Data

We do not:

5. Third-Party Processors and Sub-Processors

To provide the Service, we share personal data with the following categories of third-party processors. Each processes data solely on our instructions and subject to contractual data protection obligations.

5.1 AI Model Providers

When you use the Service, your prompts (and any files attached to the current turn) may be sent to one or more AI model providers for inference. These providers act as data processors and contractually commit to not using your data for model training. Except where marked otherwise below, providers retain prompts only for abuse-prevention monitoring — for a short, defined period set out in the provider's terms — and then delete them ("zero data retention" for every other purpose). The exact model and route used is shown in the model picker in the product, together with a residency badge, and on our public rate card.

ProviderLocationData Handling
OpenAI, LLC (GPT models)United StatesAPI data not used for training. Retained up to 30 days for abuse monitoring, then deleted. DPA
Anthropic, PBC (Claude models — direct API or via AWS Bedrock)United States (direct API); EU — London / Stockholm (Bedrock EU inference profiles); United States (Bedrock, Claude Fable 5.1 only)API data not used for training. Retained up to 30 days for abuse monitoring, then deleted. Exception: Claude Fable 5.1 is served without a zero-data-retention commitment; it is labelled "Non-ZDR" wherever it appears and is never selected automatically — you must choose it explicitly. DPA
Google LLC (Gemini API, paid tier)United StatesPaid tier: data not used for training. Retained up to 55 days for abuse monitoring, then deleted. Terms
Alibaba Cloud (Model Studio / DashScope — Qwen models)EU (Frankfurt, eu-central-1)EU-region endpoint. Data not used for training. Privacy
Z.ai / Zhipu AI (GLM models — direct API)SingaporeAPI data not used for training. Also served via AWS Bedrock (EU) for some GLM models. Privacy
Amazon Web Services (Bedrock-hosted open-weight and third-party models — NVIDIA Nemotron, Moonshot AI Kimi, Z.ai GLM, MiniMax)EU (London / Stockholm)Bedrock does not store prompts or completions and does not share them with model vendors. DPA
OpenRouter, Inc. (marketplace routing to models from DeepSeek, MiniMax, xAI, Moonshot AI, NVIDIA, Alibaba and others; also Seedance, xAI and MiniMax video generation)United States (marketplace); underlying hosts varyEvery request is sent with zdr: true and data_collection: deny, so it is routed only to hosts that commit to zero data retention; hosts that cannot honour this are excluded by name. Prompts are not stored by OpenRouter. Privacy

We also run open-weight AI models locally on our EU-based infrastructure (see Section 6), in which case your data does not leave our servers. Users of the Alfrada desktop application may additionally run models entirely on their own hardware, in which case prompts do not leave that machine. If you add your own provider API keys to the Vault, prompts are sent directly from your deployment to that provider under your own agreement with them.

5.2 Infrastructure Providers

ProviderLocationPurpose
Exoscale (Akenes SA)Switzerland / EU (Frankfurt, DE)Cloud compute, GPU servers, storage. Privacy · DPA
Amazon Web Services (Bedrock)EU (London eu-west-2, Stockholm eu-north-1); US regions only for the models identified in Section 5.1AI inference for Anthropic and other Bedrock-hosted models. DPA
Daytona Platforms, Inc.EU (Frankfurt)Sandboxed code execution. Sandboxes receive only the code and the files attached to the task, stop after 15 idle minutes, and are deleted within 24 hours. Privacy
Cloudflare, Inc. (Turnstile)United States / global edgeBot protection on signup and contact forms; processes IP address and a browser challenge token. Privacy · DPA

Metered model and tool calls made using your included plan budget (rather than your own API keys) transit gateway.alfrada.ai, a relay we operate on the same EU infrastructure, for usage metering only.

5.3 Functional Service Providers

ProviderLocationPurpose
Stripe, Inc.EU (Ireland) / USPayment processing. Privacy · DPA
ElevenLabs, Inc.US / Netherlands (auto-routed)Text-to-speech generation. Privacy
Composio (SWE Labs, Inc.)United StatesThird-party app integrations (OAuth). Privacy
Tavily (AlphaAI Technologies)United StatesWeb search for AI agents. Privacy
SearchAPI.ioUnited StatesSearch engine results. Privacy
Apify, s.r.o.United StatesWeb content extraction. Privacy
Zyte Group LimitedUnited StatesWeb extraction fallback. Privacy
Browserbase, Inc.United StatesCloud browser sessions. Privacy
SunoAPI (sunoapi.org)Not disclosedAI music generation. Privacy
Runway AI, Inc.United StatesAI video generation (text-to-video, image-to-video). Privacy
Higgsfield AI, Inc.United StatesAI image and video generation fallback. Privacy
Video generation via OpenRouter (Seedance / ByteDance, xAI, MiniMax)United States (marketplace); underlying hosts varyText-to-video and image-to-video. Finished videos are held by the provider so they can be downloaded; each result in the product carries a tag naming what its provider retains. Privacy
Pexels (Pexels GmbH)United States / GermanyStock photo and video search. Privacy
memegen.linkUnited StatesMeme image rendering (template name and caption text only). Site
Hunter.io (Hunter Web Services SAS, via Composio)France / United StatesProfessional email discovery and verification (a domain, name, or email address to look up). Privacy
The Cat API (thatapicompany)United StatesCat image and breed lookups (no personal data). Privacy
Pakistan Stock Exchange data (psx.com.pk / psxterminal.com)PakistanPublic market data lookups (ticker symbols only; no personal data).
Slack Technologies, LLC (Slack app, where installed by you)United StatesDelivering assistant messages to a Slack workspace you connect. Privacy
WhatsApp LLC / Meta Platforms (linked device, where enabled by you)United States / IrelandTransport of end-to-end encrypted messages between your WhatsApp account and your linked Alfrada bridge (see Section 2.7). Privacy
Context7 (Upstash)US / EUDeveloper documentation retrieval. Privacy
WeatherAPI.com (Zoomash Ltd)United KingdomWeather data lookups. Privacy

5.4 Marketing Website Analytics Providers

The following providers process data only on our marketing websites (not the Alfrada application) and only after you consent via the cookie banner. Data is used exclusively for marketing channel attribution, advertising conversion measurement, and cost control — never for retargeting, audience building, or behavioural profiling.

ProviderLocationPurpose
Google LLC (Google Analytics 4)United States / EUAggregate page-view and traffic-source analytics. Privacy
Google LLC (Google Ads conversion measurement)United States / EURecords whether a visit that started from a Google advertisement led to a signup or a deployment-call request, using the click identifier (gclid/gbraid/wbraid) from the ad. When you submit a deployment-call request, the email you entered is hashed in your browser and sent to Google as an "enhanced conversion" so that Google can match the lead to the ad click; Google does not receive the plain-text email. We use Google Consent Mode; no advertising storage is used until you accept. Privacy
Microsoft Corporation (Clarity)United States / EUHeatmaps, scroll maps, and anonymous session recordings for UX analysis. Privacy
LinkedIn Corporation (Insight Tag)United StatesLinkedIn campaign conversion measurement. Privacy

6. Where We Store and Process Your Data

Our primary infrastructure is hosted by Exoscale. In short: the Service is served from Zurich, Switzerland and your data is processed and stored in Frankfurt, Germany:

When you use cloud-based AI models, your prompts are transmitted to the provider's servers in the location shown in Section 5.1 — the United States (OpenAI, Google, OpenRouter, direct Anthropic), the EU (Bedrock EU regions, Alibaba Model Studio Frankfurt) or Singapore (Z.ai). Turning on EU Data Residency in the product hides every non-EU route and makes the router refuse them. Transfers outside the UK and EEA are governed by:

For smaller functional service providers where a formal DPA or transfer mechanism is not yet in place, we rely on Article 49(1)(b) of the UK GDPR (transfer necessary for the performance of the contract between you and us) and conduct ongoing assessment of the adequacy of protections offered by those providers.

7. Data Retention

Data CategoryRetention Period
Account data (name, email)Duration of your account. Permanently deleted immediately upon account deletion.
Conversation historyDuration of your account. Deletable by you at any time via the Service. Permanently deleted immediately upon account deletion.
AI memory and contextDuration of your account. Deletable by you at any time via the Service. Permanently deleted immediately upon account deletion.
Uploaded documents and mediaDuration of your account. Deletable by you at any time. Permanently deleted immediately upon account deletion.
Payment records6 years after the relevant transaction, as required by HMRC record-keeping obligations. This is the only data retained after account deletion.
Technical logs (IP, access)90 days, then automatically purged. Permanently deleted immediately upon account deletion.
OAuth integration tokensUntil you disconnect the integration or delete your account. Permanently deleted immediately upon account deletion.
WhatsApp assistant message historyUntil you unlink the device, delete the history, or delete your account. Permanently deleted immediately upon account deletion.
Enquiry and deployment-call data24 months after our last contact with you about the enquiry, unless you become a customer (in which case it forms part of your account records) or ask us to delete it sooner.
Advertising click identifiers stored in your browser (marketing websites)90 days in your browser's local storage, and only if you have accepted analytics cookies. Removed automatically after 90 days.
Marketing website analytics dataGoverned by each provider's retention policy (Google Analytics: 14 months; Microsoft Clarity: 30 days; LinkedIn: up to 180 days). We do not store analytics data on our own servers. You can prevent collection by rejecting analytics cookies or withdrawing consent.

Data transmitted to AI model providers is retained by them only for abuse-prevention monitoring under their respective policies (typically up to 30–55 days, then deleted), except Claude Fable 5.1 as noted in Section 5.1. Generated media (video, music, images) may be held by the generating provider so that it can be downloaded. Sandboxes at Daytona are deleted within 24 hours. We do not control retention by third-party processors beyond the terms of their DPAs.

8. Your Rights

Under the UK GDPR, you have the following rights in relation to your personal data:

RightDescription
Access (Art 15)Request a copy of the personal data we hold about you.
Rectification (Art 16)Request correction of inaccurate or incomplete personal data.
Erasure (Art 17)Request deletion of your personal data ("right to be forgotten").
Restriction (Art 18)Request that we restrict the processing of your personal data.
Portability (Art 20)Request your data in a structured, commonly used, machine-readable format.
Objection (Art 21)Object to processing based on legitimate interests.
Withdrawal of Consent (Art 7(3))Where processing is based on consent, withdraw it at any time.

To exercise any of these rights, please contact us at privacy@strategize.inc. We will respond within one calendar month of receiving your request, as required by law. We may request proof of identity before processing your request.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):

9. Data Security

We implement appropriate technical and organisational measures to protect personal data, including:

10. Cookies

The Alfrada application (app.alfrada.ai) uses only strictly necessary cookies for authentication and session management.

Our marketing websites (alfrada.com, alfrada.ai, strategize.inc, strategizelabs.com) additionally use analytics cookies — with your consent — for the sole purpose of marketing channel optimisation, advertising conversion measurement, and customer-acquisition cost control. We do not use retargeting or behavioural profiling cookies. For full details, including a table of every cookie we set and how to withdraw consent, see our Cookie Policy.

11. Children

The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that data promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. Material changes will be communicated via the email address associated with your account or via a prominent notice on the Service. The "Last Updated" date at the top of this page indicates when this policy was last revised.

13. Governing Law and Jurisdiction

This Privacy Policy and any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with it, its subject matter, or its formation shall be governed by and construed in accordance with the laws of England and Wales.

Each party irrevocably agrees that the courts of England shall have exclusive jurisdiction to settle any such dispute or claim. By using the Service, you submit to the exclusive jurisdiction of the courts of England and waive any objection to proceedings in such courts on the grounds of venue or on the grounds that proceedings have been brought in an inconvenient forum.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:


© 2026 Strategize and Insight Practice Limited. All rights reserved.