Last updated: 16 July 2026

Privacy Policy

How Alteridad handles personal data when you visit or use Chieftain, request access, or answer an organizational probe.

Who is responsible

Alteridad operates Chieftain and is the controller for the public website, access requests, account administration, and service operations. An organization using Chieftain is normally the controller for workplace probe content it asks us to process on its behalf.

Privacy and data-rights requests: hola@alteridad.org. Because this pilot does not yet publish a registered-office address, you can also use that address to request our current legal and postal details before providing data.

Data we collect

  • Contact and account data, including name, work email, organization, authentication events, consent time and policy version.
  • Organization material supplied by members and public-source research about the organization and its domain.
  • Probe data: the invitation address, answers, confidence, optional context, delivery status, and technical metadata needed to operate the exchange.
  • Service, security, billing, and diagnostic data such as IP-derived rate-limit records, audit events, subscription records, and error traces.

Why we use it and our legal bases

  • To take steps you request, create and provide the service, authenticate users, and administer subscriptions (contract or pre-contractual steps).
  • To secure, troubleshoot, and improve Chieftain and to support proportionate organizational research (our and our customers’ legitimate interests, balanced against individual rights).
  • To send optional access communications where you have asked us to do so, and to record the affirmative acceptance shown at collection (consent where applicable).
  • To meet accounting, security, and other legal obligations (legal obligation).

Workplace probes and AI

A probe answer is stored as testimony for the inviting organization, may be synthesized into that organization’s memory, and is sent to the organization’s configured AI provider to generate analysis. Participation is optional and every probe email includes a global one-click unsubscribe.

Do not include health, ethnicity, political opinions, religion, trade-union membership, sexual life or orientation, biometric or genetic data, allegations, or unnecessary names. These special categories can create serious risk in workplace analysis. If they are submitted accidentally, contact us so we can restrict or delete them. We do not use employee consent as the sole basis for routine employer-requested analysis.

Providers and international transfers

We use service providers only for the stated operational purposes. Depending on configuration, data may be processed outside the EEA. We rely on an adequacy decision or appropriate safeguards such as standard contractual clauses where required.

  • Supabase — database, authentication, and storage.
  • Vercel — application hosting and delivery.
  • OpenAI or Anthropic — AI analysis selected for the organization.
  • Perplexity — public-source organizational research.
  • Amazon SES or Resend — transactional and probe email delivery.
  • Stripe — subscriptions, invoices, and payment administration.
  • Sentry — error monitoring when enabled; it is not required for local development.

Retention

These are the pilot retention targets. Some expiry enforcement is currently being automated; until then, deletions are reviewed operationally on the same schedule.

  • Active organization and account data: while the service is used, then deletion or anonymization is targeted within 90 days after closure or a valid deletion request, subject to legal holds.
  • Access and waitlist requests: 12 months after the last interaction.
  • Rate-limit hashes: 7 days; email delivery metadata: 6 months; expired probe contact and token data: 30 days after expiry.
  • Billing and audit records required by law: up to 7 years. Backup copies roll off on their normal cycle, targeted within 90 days.

Sharing, security, and automated decisions

We share data with the relevant customer organization, the providers above, professional advisers, or authorities when legally required. We do not sell personal data. Chieftain uses technical and organizational safeguards including organization-scoped access controls and encrypted transport.

AI outputs support organizational reflection; they should not be used as the sole basis for employment or other decisions with legal or similarly significant effects.

Cookies and similar storage

Chieftain currently uses only storage that is necessary for authentication, security, language continuity, and core service operation. We do not use advertising cookies. If optional analytics or marketing storage is introduced, we will request any consent required before setting it.

Your choices and rights

You may ask for access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Probe recipients can unsubscribe globally with the link in any probe email.

Email hola@alteridad.org to exercise a right. We may need to verify your identity and, for customer-controlled workplace data, coordinate the request with that organization. You may also complain to the data-protection authority where you live or work.

Changes and contact

We will update the date above and give proportionate notice if a material change affects how existing data is used. Questions, privacy requests, and legal-notice requests can be sent to hola@alteridad.org.