Legal
Last updated 10 September 2026
This policy covers aidealigence.com, the Access Agent web app, the Agent API (aidealigence.com/api/v1), the MCP server (aidealigence.com/mcp/), and the Playground — collectively, “the Service.” It applies whether you use the Service as a signed-in human researcher or as a developer/agent calling the API directly with a key.
Account information. Email address, name, and a salted hash of your password (never the password itself) when you create an account. If you subscribe to a paid plan, Stripe collects and processes your payment details directly — we store a Stripe customer/subscription reference, never your card number.
Objective queries and research data. The text of the objectives you submit (“find the person responsible for …”), and everything the research pipeline produces from it: organisations, people, evidence, sources, and scores. This is the core data the Service exists to generate, and it is retained so you can view past research and so a completed run doesn’t have to be re-run (and re-billed) to be read again.
API usage. Every billable API/MCP call is logged as a usage event — operation, credits charged, duration, and outcome — against your API key, so your usage dashboard and billing are accurate. API keys themselves are stored only as a hash, the same as your password; the raw key is shown once, at creation, and is not recoverable by us.
Technical data. IP address and basic request metadata (timestamp, endpoint, status code), used for rate limiting, fraud prevention, and debugging. The homepage’s anonymous demo widget rate-limits by IP for the same reason, before any account exists.
The people an objective surfaces — a recommended decision-maker, an alternative candidate — are usually not our customers or account holders; they are third parties whose publicly available professional information (name, job title, employer, publicly stated role or remit) we process on a customer’s behalf. Our lawful basis for this is legitimate interests (UK GDPR / GDPR Article 6(1)(f)): identifying the person most likely to hold relevant authority for a specific, legitimate business objective (a partnership, a procurement decision, an investment introduction) is exactly the kind of professional-context research a company or individual has always been able to do manually, and we only ever process information that is already public.
We’ve balanced this against the individual’s own interests: we surface current professional role information, not private or sensitive personal data; we never fabricate a claim about someone (every recommendation is grounded in cited evidence, see Section 3); and anyone can object to how we process their information or request its removal by emailing privacy@aidealigence.com, the same route Section 6 describes for our own account holders.
Answering an objective requires real research, which means real calls to outside providers on your behalf. We use:
We do not currently integrate Exa, Apollo, ZoomInfo, or any contact-database vendor — the Service deliberately researches each objective from public sources rather than querying a pre-built contact database. If that changes, this section will be updated before the integration ships.
International transfers: some of the providers above may process data outside the UK/EEA. We are confirming the specific transfer mechanism (UK IDTA or EU Standard Contractual Clauses) in place with each provider and will state it here, provider by provider, once confirmed — this line will be replaced with the specifics, not left as a standing gap.
Account data (login, plan, API keys) is retained for as long as your account is active. Objective/research data — the text of an objective and the organisations, people, and evidence it surfaced — is retained for 12 months from when the research completed, then deleted, whether or not your account is still active; you can still delete it sooner yourself at any time. Usage events (billing records) are retained for at least as long as required for tax and accounting purposes after an account closes. You can request deletion of your account and any remaining associated data at any time (see Section 7) — we’ll delete what we can and retain only what we’re legally required to (e.g. billing records HMRC requires us to keep).
If you’re in the UK or EU, you have rights under UK GDPR / GDPR to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, email privacy@aidealigence.com — we’ll respond within 30 days. You can delete your own API keys and webhooks at any time from your account without contacting us.
Passwords and API keys are stored as one-way hashes, never in recoverable form. Webhook deliveries are signed (HMAC-SHA256) so a receiver can verify authenticity. Traffic to the Service is encrypted in transit (HTTPS/TLS). No system is perfectly secure; if we become aware of a breach affecting your data, we’ll notify you as required by applicable law.
We use strictly-necessary cookies/local storage for authentication (keeping you signed in) and no advertising cookies. If analytics is enabled, it runs cookieless (Plausible) by default; any tracking that does set a cookie will only run after you accept it in the cookie banner. See the banner on your first visit for current choices.
We’ll update the “last updated” date above when this policy changes, and post material changes on this page. Continued use of the Service after a change means you accept the updated policy.
Questions or data requests: privacy@aidealigence.com. General support: support@aidealigence.com.
Digital Pulse 365 Ltd. Company number 15351208.
Registered office: 128 City Road, London, United Kingdom, EC1V 2NX.
ICO registration: in progress. We’ll publish the registration number here once it’s issued.