Privacy policy for Alite Projects.
This privacy policy explains what personal information Alite Projects collects, how we use it, who we share it with, and the rights you have. It covers our (website url address: https://aliteprojects.com/) , our partner-facing services, and the partner communications conducted as part of our business. The policy is written to be understood; legal terms are used where they are precise, plain language where it serves clarity. Effective from January 2026. The policy is reviewed periodically and updated as needed. Substantial changes are announced; the last-reviewed date on this page reflects when it was last checked. If you have questions about your information specifically, the privacy contact at the bottom of the page is the right path.Standalone Answer
What is Alite Projects’ approach to privacy?
Alite collects the minimum personal information needed to provide our services and operate our business. We do not sell personal information. We do not use personal information for advertising purposes outside our own services. We comply with applicable data protection laws including the Australian Privacy Principles (APPs), the EU and UK GDPR where applicable, the South African POPIA, and Indian data protection laws. We use sub-processors for specific services (hosting, email delivery, analytics, payment processing); the full list is maintained in our data processing addendum. Data subjects have rights including access, correction, deletion, and (where applicable) data portability; the rights apply per the law of the jurisdiction the data subject is in.
Who we are
The entities that hold your data.
Alite Projects operates through several legal entities depending on partner location. The entity that holds your data is typically the one your contract is with.
Alite Projects (India entity)
The India entity holds delivery operations data (project work, code, design files, content). Most active project data lives here. Indian data protection law applies.
Alite Projects Pty Ltd (Australia)
The Australian entity handles partner contracts and operations for Australia, New Zealand, and selectively other regions. Australian Privacy Principles (APPs) apply. Registered in Melbourne, Victoria.
Alite Projects (Switzerland)
The Swiss entity handles partner contracts and operations for Switzerland, Germany, Austria, and broader continental Europe. Swiss data protection law (FADP) and EU/UK GDPR (where applicable) apply.
Alite Projects (South Africa)
The South African entity handles partner contracts and operations for South Africa and Southern Africa. POPIA applies.
Contact details
For data protection inquiries, the privacy contact is privacy@aliteprojects.com. For inquiries involving a specific entity, you can address the relevant entity by name; routing happens internally.
Who we are
Categories of personal information.
The specific categories of personal information Alite collects in the course of doing business.
Information you give us
When you contact us, sign up for a service, become a partner, apply for a job, or otherwise interact with Alite: your name, email address, phone number, role and organisation, country of operation, and any other information you provide in the context of the inquiry or relationship.
Information from our services
When you use our services (websites we build for partners, applications we develop, AI features we operate), we may process data relevant to the service. Most of this data belongs to our partner or their client; Alite acts as a data processor for it. Specific details are in the relevant data processing addendum (DPA).
Website analytics
When you visit our website, we collect standard web analytics: pages viewed, time on page, referrer, device and browser, approximate location (country/region level). We use this for understanding how the site is used and improving it. Analytics is aggregated and not used to identify individual visitors except as needed for security purposes.
Cookies and tracking technologies
We use a limited set of cookies. Necessary cookies for site function. Analytics cookies for usage understanding. We do not use advertising or remarketing cookies on this site. The cookie policy linked below has detail.
Communications
When you communicate with us (email, phone, meeting), we retain the communication for business records. Standard correspondence retention applies; communications are deleted per retention schedules or upon request consistent with our legal obligations.
Employment-related information
For careers applications, we collect what you provide (CV, application content, references). The information is held for the duration of the recruitment process and, where appropriate, retained for future opportunities with your consent.
Sensitive personal information
We avoid collecting sensitive personal information unless necessary. For employment matters, we collect what employment law requires. For partner relationships, we generally do not collect sensitive personal information.
How we use it
Purposes we use the data for.
The specific purposes Alite uses personal information for. We do not use personal information for purposes incompatible with these.
Providing our services
To deliver the services our partners and clients have engaged us for. To run projects, communicate about the work, deliver outcomes, and handle the operational details of the engagement.
Managing partner relationships
To communicate with partners about active and prospective engagements. To send proposals, invoices, project updates, and other business correspondence. To maintain records of the relationship.
Operating our business
To run Alite as a business: financial operations, legal compliance, security, internal reporting, business planning. The standard operating data uses any agency would have.
Marketing communications (with consent)
To send periodic updates about Alite’s work, resources, and partnership opportunities. Marketing communications are with explicit consent; you can unsubscribe at any time and we honour unsubscribe requests promptly.
Recruitment
For careers applications, to evaluate candidates, communicate with applicants, and manage the recruitment process. With your consent, retention of application materials for future opportunities.
Legal compliance
To meet legal obligations including financial reporting, tax compliance, employment law obligations, and applicable data protection law.
Security and abuse prevention
To protect our systems and services from abuse, fraud, and security incidents. Standard security operations.
Improving our services
Aggregated usage analytics and feedback to improve our services and operations. Where individual-level data is used for this, it is done consistent with the consent and purpose limits above.
Who we share with
Sub-processors and disclosures.
Categories of third parties Alite shares personal information with, and the conditions under which we do so.Sub-processors
We use sub-processors for specific services: hosting infrastructure (cloud providers), email delivery (transactional email services), analytics (web analytics providers), payment processing (financial service providers), customer relationship and project management tooling (Zoho One). The current list of sub-processors is in our data processing addendum (DPA) and updated as changes occur.Service providers under contract
Auditors, lawyers, accountants, and other professional service providers who need access to certain information to provide their services. These providers are bound by confidentiality obligations.Partners and partner clients
In the partners flow, our partner agencies and (with the partner’s permission) their clients may need to interact with project information. The CSE model in the partners flow protects most communication; some operational data necessarily flows.Legal disclosures
Where required by law, we may disclose personal information to government authorities, law enforcement, or other parties as legal obligations require. We will resist disclosures that exceed legal requirement. Business transfers In the unlikely event of a business transfer (acquisition, merger), personal information held by Alite would transfer to the relevant successor entity subject to the same privacy commitments. Alite is not currently for sale and does not have plans to be sold; the disclosure exists for completeness.No sale of personal information
Alite does not sell personal information. We do not engage in advertising arrangements that share personal information with third parties for their independent use.No sharing for ad targeting
We do not share personal information with ad platforms for ad targeting purposes. We do not run advertising on our website and we do not retarget visitors via third-party ad networks.Where data lives
Data transfers and locations.
Alite operates across multiple jurisdictions; personal information may be transferred between them. The framework that protects transfers below.
Primary delivery operations in India
Most active project data lives in systems operated from India where the delivery studios are based. Indian data protection law applies. Partners outside India who have a preference for data residency in other jurisdictions should raise this in scoping; in some cases we can structure the engagement to keep specific data outside India.
Regional partner-facing data
Partner contracts, invoicing, and relationship management data lives in systems associated with the regional entity that holds the contract. Australian partner data lives in systems associated with the Australian entity; European partner data with the Swiss entity; etc.
Cross-border transfer mechanisms
For transfers between jurisdictions, we rely on standard contractual clauses (SCCs), adequacy decisions where applicable, and the appropriate transfer mechanisms required by the relevant law. For EU-to-India transfers, SCCs apply. For Australia-to-India transfers, the cross-border transfer principles of the APPs apply with appropriate contractual safeguards.
Where partners need specific arrangements
For partners with specific data residency requirements (regulated industries, government-related work, specific compliance frameworks), we can sometimes structure delivery to keep data within specific jurisdictions. These arrangements are made in scoping; the operating complexity is real.
Your rights
Rights data subjects have.
Depending on your jurisdiction, you have specific rights regarding your personal information. The framework below covers the rights generally; specific procedures depend on the applicable law.
Right to access
You can request a copy of the personal information Alite holds about you. We respond within the timeframes required by applicable law (typically 30 days). The response includes the information held, the purposes it is used for, and the recipients it has been shared with.
Right to correction
You can request correction of personal information that is inaccurate or incomplete. We update the records and notify recipients where required.
Right to deletion
You can request deletion of personal information. We delete unless we have a legal obligation to retain (financial records, legal compliance, ongoing service delivery). We tell you which categories cannot be deleted and why.
Right to data portability (where applicable)
Under GDPR and POPIA, you can request your personal information in a machine-readable format and have it transferred to another controller where technically feasible. The right applies to specific categories of data.
Right to object
You can object to specific processing (marketing communications, certain legitimate-interest processing). We honour valid objections.
Right to withdraw consent
Where processing is based on your consent, you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal but stops the relevant processing going forward.
Right to lodge a complaint
You can complain to the data protection authority in your jurisdiction: the Office of the Australian Information Commissioner (OAIC), the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, the Information Regulator in South Africa, the Data Protection Board of India, the relevant EU member state authority, or the UK Information Commissioner’s Office. We would prefer to address concerns directly first; the right to complain to a regulator exists regardless.
How we protect data
Security practices.
Security practices.Encryption
Personal information is encrypted in transit (TLS) and at rest where appropriate. Sensitive information receives additional protectionAccess control
Access to personal information is limited to team members who need it for their role. Access is logged. Departing team members lose access promptly.Sub-processor security
Sub-processors are evaluated for security practices before engagement. Contracts require appropriate security obligations. We monitor sub-processor security postures.Incident response
We have incident response procedures for personal information security events. Where required, we notify affected individuals and regulators within the timeframes required by law.Security testing
Our systems undergo periodic security testing. Critical applications receive deeper testing including code review, dependency audits, and penetration testing where appropriate.Honest framing on security
No security framework is perfect. We invest in security as a serious operating discipline and we communicate honestly about incidents. The framework is reasonable for our scale and sector; it is not equivalent to a major regulated industry framework.Retention
How long we keep information.
Retention periods for the different categories of personal information.Project and service data
Held for the duration of the engagement plus reasonable post-engagement retention for legal and operational purposes. Most project data is retained for 7 years after engagement end consistent with financial record-keeping requirements.Partner contact information
Held for the duration of the relationship plus reasonable post-relationship retention. Specifically for re-engagement opportunities, prior partners are retained in CRM systems unless they request deletion.Marketing communications data
Held for the duration of consent. Withdrawn consent leads to suppression list inclusion (so we do not contact you again) which is permanent.Recruitment data
For unsuccessful applications, held for 6-12 months from application unless you consent to longer retention for future opportunities. For successful applications, the data becomes part of employment records subject to employment-related retention.Web analytics
Aggregated analytics are held indefinitely as aggregated data. Individual-level analytics data is typically held for 14-26 months per analytics provider defaults.Communications
Email and other business communications held for standard correspondence retention periods, typically 7 years.
Other matters
Specific additional matters.
Specific provisions that warrant treatment.
Children’s privacy
Alite’s services are not directed at children. We do not knowingly collect personal information from children under 16. If we become aware that we have collected such information, we delete it.
Automated decision-making
Alite does not currently engage in automated decision-making with legal or similarly significant effects on individuals. Our AI Engineering practice builds systems that may include automated decision-making for our clients; the privacy implications of those systems are addressed in the relevant DPA between Alite and the client.
Direct marketing under SPAM Act
For Australian recipients, our direct marketing communications comply with the SPAM Act 2003. For European recipients, communications comply with the ePrivacy framework.
CCPA-equivalent rights
California residents have specific rights under CCPA. We do not engage in “sale” of personal information under the CCPA definition. California residents can exercise CCPA rights using the contact paths below.
Changes to this policy
We update this policy as our practices change or as legal requirements evolve. The published date and last-reviewed date track changes. Substantial changes (new purposes, new data categories, new sub-processor types) are announced; minor clarifications are made without separate announcement.
Contact for privacy matters
For privacy inquiries: privacy@aliteprojects.com (or current equivalent). For data subject rights requests: same address with “data subject request” in the subject. We respond within the timeframes required by applicable law.
Related Links
Terms of service · Cookie policy · Data processing addendum (DPA) · About Alite · Contact
Next step
Questions about privacy?
For specific privacy inquiries or data subject rights requests, email the privacy contact. We respond within the timeframes required by applicable law. Substantive responses to substantive inquiries.