Privacy Notice

Effective date: August 31, 2026 This Notice supersedes all prior versions as of the effective date above.

Introduction

This Privacy Notice explains how Alluvium ("Alluvium," "we," "us," "our") collects, uses, discloses, and protects personal information when you visit or interact with https://alluvium.net (the "Website") and related services (together, the "Services").
We apply a single, consistent set of privacy protections and rights to all visitors, regardless of where you are located, at or above the standard required by applicable data protection laws.
We may update this Notice periodically. Material changes will be notified via a prominent notice on the Website prior to taking effect, and the effective date above will be updated accordingly.

Who We Are - Controller Identification & DPO

Data Controller:

Alluvium Consulting Limited
Alluvium's registered offices are listed on our Contact us page.

Data Protection Officer

Email: contact@alluvium.net
All requests regarding this Notice, or the exercise of your rights, should be directed to the DPO using the contact details above.

Information We Collect and How We Use It

Identity & contact data (name, email, phone number)
Responding to inquiries; providing support; account administration. Necessary to provide the service you requested, or our legitimate interest in operating the Website.

Your IP address, device/browser data, server logs
Website security, fraud prevention, troubleshooting. Our legitimate interest in keeping the Website secure and functioning.

Online behavioral data (pages visited, time on page, click patterns)
Website analytics, service improvement, personalization. Your consent (see Section 6, Cookies).

Communications content (call logs, email content, support tickets)
Customer support, service delivery, dispute resolution. Necessary to provide the service, or our legitimate interest in resolving your query.

Marketing preferences & engagement data
Sending promotional communications, newsletters. Your consent.

Verification / due-diligence data (business or financial identifiers)
Verifying identity, preventing fraud, meeting compliance obligations. Necessary to comply with a legal or regulatory obligation applicable to our business.

Biometric data (where collected, e.g., secure access)
Identity verification for access control. Your explicit consent.

Third-party or publicly sourced data
Verification, due diligence, fraud prevention. Our legitimate interest in verifying the accuracy of information provided to us.

Further use: We only use personal data for the purposes described above. If we intend to use it for a materially different purpose, we will notify you and, where required, seek your consent before doing so.

How Your Information Is Collected

Direct interactions

Information you provide when signing up, communicating with us, or creating an account, including where you provide information about another individual (e.g., an employee, counterparty, or supplier). If you do so, you confirm you have informed that individual how Alluvium will use their information and, where required, obtained any necessary permission to share it with us.

Automated interactions

Data collected as you use the Website, device data, browsing behavior, and location data, gathered via cookies and similar technologies, subject to your consent where required (Section 6).

Third parties or public sources

Information we receive about you from financial institutions, public records, or other lawfully operating sources.

Children's Data

Our Services are not directed to, and are not intended for use by, individuals under the age of sixteen (16). We do not knowingly collect personal data from anyone under 16.

Safeguards in place:

A mandatory age-affirmation step at account/registration sign-up;

Automated blocking of account creation where the declared age is under 16;

Periodic review of account data for indicators of underage use.

If we discover we hold data from someone under 16 without appropriate consent, we will suspend processing, seek verifiable parental/guardian consent via a documented process (contact contact@alluvium.net), and delete the data within 30 days if such consent is not obtained.

Cookies & Tracking Technologies

We use cookies and similar technologies on the Website, and we apply a prior opt-in consent model:

Strictly Necessary cookies (required for the Website to function, e.g., session management, security) load without consent, as permitted by law, and cannot be disabled.

Functional, Analytics, and Marketing cookies are off by default and will not be set until you give affirmative, granular, opt-in consent through our Cookie Consent Banner.

You can accept, reject, or customize consent by category at any time via the "Cookie Settings" control in the Website footer.

Consent is logged with a timestamp and can be withdrawn at any time as easily as it was given.

Browser-level controls:

Google Chrome: chrome://settings/cookies

Mozilla Firefox: about:preferences#privacy

Apple Safari: Preferences → Privacy

Microsoft Edge: edge://settings/privacy

Full detail on each cookie category, provider, and retention period is in our Cookie Policy.

Who We Share Your Information With

We disclose personal data only where necessary, to:

Vendors, agents, and service providers who assist us in delivering the Services, under written confidentiality and data protection obligations;

Financial institutions, to enable payment processing;

Law enforcement, regulators, or courts, where legally required or necessary to establish, exercise, or defend a legal claim;

Our external legal counsel, where necessary.

We do not sell or share your personal data for cross-context advertising purposes. Should this change in the future, we will update this Notice and provide a clear mechanism to opt out before any such activity takes effect.

International Data Transfers

Because Alluvium operates across multiple locations, personal data may be transferred to, stored, and processed in a country other than the one in which you are located.
Where this occurs, we rely on recognised safeguards designed to ensure your data receives a consistent level of protection wherever it is processed. These may include standard contractual clauses, intra-group data transfer agreements, or other legally recognised transfer mechanisms. Where required, we conduct a transfer impact assessment before a transfer takes place. You may request a copy of the applicable safeguards from our DPO.

Data Security

We take the security of your personal data seriously. Our security program includes:

Operating on infrastructure and platforms that are independently certified to recognised information security standards, including ISO/IEC 27001;

An internal Information Security Management System maintained in alignment with ISO/IEC 27001:2022 practices;

Encryption of personal data in transit and at rest;

Firewalls and network segmentation;

Multi-factor authentication for access to systems processing personal data;

Role-based access controls limiting access to personnel and processors who need it;

Confidentiality and data protection obligations imposed on all processors and sub-processors;

Regular security testing, vulnerability management, and incident response procedures.

Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected. Indicative retention periods are set out below; actual periods may vary based on the nature of our relationship with you and applicable legal requirements.

Account and identity dataDuration of the relationship, plus 6 to 7 years thereafter for legal and contractual compliance
Marketing preference dataUntil consent is withdrawn or you opt out
Communications / support recordsDuration of the relationship, plus up to 2 years
Verification / compliance records3 to 6 years, as required by applicable tax, legal, or regulatory obligations
Website analytics data (where consented)Up to 12 months, then aggregated or deleted

We may retain and process data beyond these periods for archiving, research, or statistical purposes in the public interest, subject to appropriate safeguards. Where data is anonymized such that it can no longer be linked to you, we may retain it indefinitely for research purposes. Data no longer required is securely deleted or destroyed in line with our internal Data Retention Policy.

Your Rights

We apply the same set of rights to every visitor, wherever you are located:

AccessRequest confirmation of, and a copy of, the personal data we hold about you.
CorrectionRequest correction of inaccurate or incomplete data.
ErasureRequest deletion of your data where there is no continuing basis for retaining it.
RestrictionRequest that we suspend processing of your data in specified circumstances.
ObjectionObject to processing based on our legitimate interests, or to direct marketing at any time.
Data PortabilityRequest your data in a structured, commonly used, machine-readable format, and its transfer to another provider where technically feasible.
Automated Decision-Making & ProfilingRequest not to be subject to a decision based solely on automated processing that produces a legal or similarly significant effect on you, obtain human review, and contest the decision.
Withdraw ConsentWithdraw consent at any time where processing is based on consent.
ComplainLodge a complaint with the data protection authority or regulator responsible for your country or state of residence, or seek redress through a competent court.

How to Exercise Your Rights

Submit requests to the DPO at contact@alluvium.net. We may request additional information to verify your identity before processing your request; this is a security measure and does not extend the response deadline beyond what is needed to complete verification.

Response SLA

Acknowledgment of requestWithin 5 business days of receipt
Identity verification (if required)Within 5 business days of acknowledgment
Substantive response / fulfilmentWithin 30 calendar days of receipt of a verified request
Extension for complex/numerous requestsOne further extension of up to 60 additional days, with written notice explaining the reason, provided within the initial 30-day period

Right to Complain

We encourage you to contact our DPO first so we can try to resolve your concern directly. You also have the right, at any time, to lodge a complaint with the data protection authority or regulator responsible for your country or state of residence, or to seek redress through a competent court.

Changes to This Notice

We may update this Notice periodically to reflect changes in our processing activities, legal requirements, or Services. Material changes will be communicated via a notice on the Website prior to taking effect, and the effective date at the top of this Notice will be updated accordingly.

Contact Details

For questions, comments, or requests regarding this Notice, or to exercise your rights, contact our Data Protection Officer:
Email: contact@alluvium.net