1. Who we are and how to contact us
AdviserAlly is provided by AdviserAlly Limited, a company registered in England and Wales (company number 11343016) with a registered office at 20-22 Wenlock Road, London N1 7GU, United Kingdom. For data protection queries please email [email protected]. We may designate a Data Protection Officer or representative and will update this policy if contact details change.
2. Scope of this policy
This Privacy Policy explains how AdviserAlly Limited ("AdviserAlly Limited", "we", or "us") collects, uses, shares, and protects personal data when you: visit our websites; interact with AI chatbot widgets deployed on our customers' websites; submit information through landing page forms; engage with marketing materials (including email and SMS communications); use the AdviserAlly platform; or participate in research programmes. It reflects privacy standards adopted by leading UK SaaS providers such as Sage, Xero, and Bupa.
3. Our roles
AdviserAlly Limited acts as a data controller for personal data that we determine the purposes and means of processing for, including marketing, account administration, product analytics, and website visitor tracking.
When customers upload personal data to AdviserAlly — including client records, chatbot conversations, form submissions, landing page lead data, email campaign recipient lists, and SMS message logs — AdviserAlly Limited acts as a data processor and processes that data only on the documented instructions of the customer in accordance with our Data Processing Addendum (DPA).
4. Personal data we collect
Depending on your interactions with us, we may collect:
- Identity and contact data: Names, job titles, business email addresses, phone numbers, company details, and any public-register information you choose to share (e.g. Companies House records, or sector registers where relevant).
- Account and billing data: Authentication credentials, subscription selections, billing contacts, purchase history, and payment references (processed via Stripe, our PCI-compliant payment partner).
- Client CRM data: Contact details, status history, activity logs, notes, tags, and custom fields that customers store within AdviserAlly for their own clients and prospects.
- Chatbot conversation data: Messages exchanged between website visitors and AI chatbots, including timestamps, session identifiers, and any personal information voluntarily provided during conversations. Conversations may be analysed for sentiment and buying signals as part of ABCRank scoring.
- Landing page and form data: Information submitted through landing page forms and embeddable forms, including names, email addresses, phone numbers, and any custom fields configured by the customer.
- Email and SMS communication data: Recipient addresses and phone numbers, message content, delivery status (sent, delivered, opened, clicked, replied, bounced, failed), and engagement timestamps.
- Lead scoring data: ABCRank scores calculated from six factors — email engagement, activity recency, profile completeness, chat sentiment, workflow progress, and demographics — producing a 0–100 score and A/B/C/D tier classification.
- Usage data: Log files, device identifiers, IP addresses, session metadata, feature adoption metrics, and diagnostic information.
- Support data: Tickets, call recordings, chat transcripts, and contextual documents supplied for troubleshooting.
- Marketing and preferences data: Newsletter sign-ups, event attendance, survey responses, and communication opt-ins or opt-outs.
- Website visitor tracking: Anonymous session data from chatbot widget interactions, including timestamps, hashed IP addresses, user agent information, referrer URLs, and initial page URLs. This data is collected under the legitimate interest basis and automatically deleted after 30 days.
4a. Website visitor tracking
When you interact with the AdviserAlly chatbot widget on our customers' websites, we may create an anonymous visitor record to help improve the chatbot experience and track conversion metrics. This processing is conducted under the legitimate interest basis (Article 6(1)(f) UK GDPR).
Data collected:
- Timestamp of first widget load
- Hashed IP address (one-way hash for privacy, cannot be reversed to original IP)
- Browser user agent string (for compatibility purposes)
- Referrer URL (the page you came from)
- Initial page URL (the page where you loaded the widget)
- Unique session identifier (stored locally in your browser)
Data minimisation: Anonymous visitor records are automatically deleted after 30 days if no conversation takes place. Once you send a message and become a client, your visitor tracking data is converted to a client record and retained according to our standard retention policies.
Your rights: You have the right to object to this processing at any time by contacting [email protected]. We will stop processing your data and delete any existing visitor records within 48 hours of your request.
4b. Landing page and form data processing
When you submit information through a landing page form hosted by AdviserAlly, the data controller is the AdviserAlly customer who published the page. AdviserAlly Limited processes this data on the customer's behalf as a data processor. The customer is responsible for providing you with appropriate privacy notices and obtaining any necessary consent for their processing activities.
Analytics data: We collect anonymised page view and conversion metrics (page views, unique visitors, form submission counts) to help customers understand landing page performance. This analytics data does not include personal information and is processed under our legitimate interest in improving the Service.
4c. ABCRank lead scoring
ABCRank is an automated scoring system that analyses six factors to assign each contact a numerical score (0–100) and a tier classification (A, B, C, or D). The scoring factors are:
- Email engagement (25%): Opens, clicks, replies, and recency of email interactions
- Activity recency (23%): Days since last recorded interaction
- Profile completeness (20%): Proportion of core CRM fields populated
- Chat engagement (12%): Sentiment analysis and buying signals from chatbot conversations
- Workflow progress (10%): Active and completed automation workflows
- Demographics (10%): Company details, location, and custom fields
ABCRank scoring is performed on data held within the customer's workspace. Scores are used to help advisers prioritise their outreach and are not shared with the scored individuals. This processing is carried out under the legitimate interest basis (Article 6(1)(f) UK GDPR) by the customer as data controller. ABCRank does not make automated decisions that produce legal or similarly significant effects on individuals.
5. Special category data
We do not intentionally collect special category data (such as health or biometric data) through our marketing channels, chatbot widgets, or landing page forms. Customers may process special category data within AdviserAlly where it is necessary for their services and lawful to do so. Our DPA outlines the safeguards and encryption controls applied to such data.
6. How we collect personal data
- Directly from you when you sign up for an account, request a demo, contact support, or attend an event.
- Through chatbot widget interactions when you send messages or provide contact details in conversation.
- Through landing page forms when you submit your information on a customer's hosted page.
- Via email and SMS engagement tracking (opens, clicks, replies, delivery receipts).
- Automatically through cookies, pixels, and similar technologies when you interact with our websites or platform.
- From third-party sources such as referral partners, public registers (e.g., Companies House), or marketing platforms where you have provided consent.
7. How we use personal data
- To provide, maintain, and improve AdviserAlly and related services, including the CRM, chatbot, landing page builder, email, SMS, and workflow automation features.
- To authenticate users, manage access, and secure our infrastructure.
- To deliver customer success, training, and technical support.
- To calculate ABCRank lead scores and provide prioritisation insights to customers.
- To deliver email and SMS communications on behalf of customers.
- To host and serve landing pages and process form submissions.
- To send operational updates, product announcements, and marketing communications in line with your preferences.
- To conduct research and product development, including aggregated analytics to improve functionality.
- To comply with legal and regulatory obligations, including financial record keeping and responding to lawful requests.
8. Lawful bases for processing
AdviserAlly Limited relies on one or more of the following lawful bases under the UK GDPR: (a) performance of a contract or to take steps at your request prior to entering into a contract; (b) compliance with legal obligations; (c) legitimate interests in operating, growing, and securing our business (balanced against your rights and interests) — this includes website visitor tracking, anonymised analytics, ABCRank scoring, and email/SMS delivery tracking; and (d) consent, for example when you opt in to marketing communications, submit a landing page form, or accept analytics cookies.
10. International transfers
If personal data is transferred outside the UK or European Economic Area (for example, to cloud infrastructure or sub-processors located in the United States), we ensure appropriate safeguards are in place, including the UK Addendum to the EU Standard Contractual Clauses, International Data Transfer Agreements, or adequacy decisions. We monitor regulatory developments to maintain compliance with UK and EU requirements.
11. Data retention
Personal data is retained only for as long as necessary to fulfil the purposes described in this policy or to meet legal, accounting, or reporting obligations. Specific retention periods include:
- Anonymous visitor records: Automatically deleted after 30 days if no conversation takes place
- Chatbot conversation data: Retained during the customer's subscription and for 90 days after termination
- Landing page analytics: Anonymised data retained for the duration of the customer's subscription
- Email and SMS delivery logs: Retained for 12 months for deliverability reporting, then anonymised
- Client CRM data: Retained according to customer settings, deleted or anonymised within 90 days of contract termination
- Account and billing data: Retained for 7 years in accordance with UK accounting and tax law
12. Security measures
AdviserAlly Limited implements layered security controls comparable to other regulated UK technology providers, including encryption in transit (TLS 1.2+) and at rest, secure development practices, vulnerability management, access logging, role-based access controls with 35 granular permissions, penetration testing by accredited third parties, multi-factor authentication, and incident response procedures.
13. Marketing choices
We send marketing communications to business contacts where permitted by law, including under the "soft opt-in" provision of the Privacy and Electronic Communications Regulations (PECR). You can opt out at any time by clicking the unsubscribe link in our emails, replying STOP to our SMS messages, or contacting us directly. We will continue to send essential service notifications related to your account.
14. Automated decision-making
AdviserAlly Limited does not carry out automated decision-making that produces legal or similarly significant effects on individuals. We use automated systems for the following purposes, all of which include human oversight:
- ABCRank lead scoring: Algorithmic scoring to help teams prioritise outreach (guidance only, not a decision with legal effect)
- Chatbot AI responses: Automated conversation handling, with the option for human takeover at any time
- Chat sentiment analysis: Identification of emotional tone and buying signals in conversations
- Workflow automation: Rule-based triggers for emails, SMS, and task assignments configured by the customer
A human review is available upon request for any automated processing that affects you.
15. Children's data
AdviserAlly is intended for professional users and is not directed at children. We do not knowingly collect personal data relating to individuals under 16 years of age. If you become aware that a child has provided us with personal data through a chatbot widget, landing page form, or any other channel, please contact us so we can delete the information.
16. Your privacy rights
Individuals located in the UK or EEA have rights under the UK GDPR, including:
- Right of access: Request a copy of your personal data
- Right to rectification: Correct inaccurate personal data
- Right to erasure: Request deletion of your personal data
- Right to restrict processing: Limit how we use your data
- Right to data portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests (including ABCRank scoring and visitor tracking)
- Right to withdraw consent: Where processing relies on consent, withdraw it at any time
You can exercise these rights by emailing [email protected]. We may request verification of your identity before responding. If your data is held in a customer's AdviserAlly workspace (e.g., as a client record, chatbot conversation, or form submission), we will direct your request to the relevant customer as data controller, unless we are able to action it directly.
17. Complaints
If you have concerns about how we process personal data, please contact us in the first instance so we can help. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or your local supervisory authority.
18. Changes to this policy
We review this Privacy Policy periodically to reflect new products, regulatory updates, or guidance from the ICO. Material changes will be communicated via email, in-app notices, or our website banner with reasonable notice where practicable. The "Last updated" date shows when changes took effect.
19. Contacting us
To exercise your rights or ask questions about this policy, email [email protected] or write to AdviserAlly Limited, 20-22 Wenlock Road, London N1 7GU, United Kingdom.