Aletheia

Privacy Policy

This Privacy Policy explains how ALETHEIA Consulting L.L.C. collects, uses, shares, protects and retains personal information in connection with its website, Applicant onboarding, Client Access, prospective and actual Engagements, finance administration, communications and related business operations.

1. Scope and our role

1.1 This Policy applies globally to personal information processed by ALETHEIA through or in connection with aletheiaco.com, Applicant onboarding, Client Access, Client and Engagement administration, communications, document exchange, finance, compliance and security operations, subject to the territorial scope of the law that applies to the relevant processing.

1.2 For most platform account, onboarding, Client-relationship, compliance, security and business-administration activities, ALETHEIA acts as a controller because it determines why and how the relevant personal information is used.

1.3 For some Client-directed activities, ALETHEIA may process personal information on a Client's documented instructions as a processor. Where that occurs, the applicable Engagement, data-processing terms or other written agreement will govern that processing in addition to this Policy.

1.4 This Policy does not reduce any contractual confidentiality obligation owed under ALETHEIA's General Terms of Engagement or an Engagement.

2. Who this Policy covers

2.1 This Policy may apply to Applicants, Client representatives, authorised Client users, personnel and participants connected with an Engagement, payers, provider contacts, professional advisers, website users and other individuals who communicate or interact with ALETHEIA.

2.2 If a Client provides personal information about its personnel, representatives, guests, participants or other individuals, the Client is responsible for having an appropriate lawful basis and for providing any notice required from the Client as controller.

3. Personal information we may collect

3.1 Identity and account information, such as name, business email, telephone number, job title, organisation, relationship to the organisation, verified email status, account identifier and authentication or session information.

3.2 Organisation and onboarding information, such as legal entity details, registration information, registered and billing addresses, business activity, authority declarations, supporting evidence, application status, review history and compliance screening information.

3.3 Service Request and Engagement information, such as requests, objectives, locations, timing, participants, travel or operational requirements, documents, communications, Proposals, acceptance records, Engagement status and related operational information.

3.4 Finance and payment information, such as Invoice details, billing contacts, payment method, payment date, payment references, payer identity, supporting evidence, funding information and payment verification or allocation records.

3.5 Communications, such as messages, questions, change requests, information requests, support correspondence and records of material instructions.

3.6 Security and technical information, such as IP address, browser and device information, session identifiers, authentication events, security logs, audit/activity records, timestamps, error information and evidence of protected actions.

3.7 Documents and content you provide, including files uploaded for onboarding, Engagement, compliance, operational, finance or other authorised purposes.

3.8 Compliance and risk information, such as sanctions or ownership screening results, source-of-funds information where required, identity or authority checks, fraud/security indicators and records necessary to comply with legal, banking, insurance or regulatory requirements.

4. Sensitive or special-category information

4.1 ALETHEIA seeks to minimise collection of sensitive personal information. In some Engagements, operational planning may require limited information concerning accessibility, health, medical, security or other sensitive circumstances.

4.2 Where data-protection law treats information as special-category, sensitive, biometric or criminal-offence data, ALETHEIA will process it only where necessary and where an additional lawful condition or other legal basis is available. Depending on the circumstances, this may include explicit consent, vital interests, legal claims, substantial public-interest grounds or another condition permitted by Applicable Law.

4.3 Clients and users should not provide sensitive personal information unless it is reasonably necessary for the relevant purpose and they are authorised to do so.

5. How we collect personal information

5.1 Directly from you when you register, verify an account, complete onboarding, submit or update information, communicate, upload documents, respond to a Proposal, provide payment information or use the platform.

5.2 From your organisation, authorised colleagues, professional advisers, payers, Third-Party Providers or other persons involved in an application, Engagement, payment or authorised business relationship.

5.3 From public or commercial sources used for proportionate company, identity, sanctions, ownership, compliance or risk checks.

5.4 Automatically from the platform and supporting infrastructure when you authenticate, use protected functions, upload documents or interact with the service.

6. Why we use personal information and our lawful bases

The lawful basis depends on the purpose, the person concerned and the law that applies. Different jurisdictions use different legal concepts. Where UK GDPR or EU GDPR applies, ALETHEIA expects to rely principally on legitimate interests, legal obligations, contract where the individual is personally a party, and consent where consent is genuinely appropriate. Where another privacy law applies, ALETHEIA will use a lawful basis or processing ground recognised by that law and may provide a jurisdiction-specific supplement.

7. Legitimate interests

7.1 Where ALETHEIA relies on legitimate interests, the relevant interests may include operating and securing the platform, administering business relationships, preventing fraud or misuse, protecting confidential information, managing commercial and operational risk, supporting Clients, improving service reliability and establishing or defending legal rights.

7.2 ALETHEIA will consider whether the processing is necessary and whether those interests are overridden by the individual's rights and interests. Individuals may have a right to object where data-protection law provides one.

8. Who we may share information with

8.1 Authorised personnel and contractors who need the information to operate ALETHEIA, administer the relevant relationship or perform their responsibilities.

8.2 A Client organisation and its authorised users, to the extent necessary for the Client relationship and subject to access controls.

8.3 Third-Party Providers involved in an Engagement, such as transport, accommodation, communications, interpretation, medical, security or other specialist providers, but only to the extent reasonably required for the authorised purpose.

8.4 Hosting, communications, email, document, security, malware-scanning, backup, monitoring, payment and other technology service providers used to operate and protect the platform and business.

8.5 Professional advisers, auditors, insurers, banks, regulated payment providers and other professional or financial counterparties where reasonably necessary.

8.6 Regulators, courts, law-enforcement bodies, sanctions or customs authorities, tax authorities and other competent authorities where disclosure is required or permitted by Applicable Law.

8.7 A purchaser, investor, lender, successor or restructuring counterparty where necessary in connection with a genuine corporate transaction and subject to appropriate confidentiality and data-protection safeguards.

9. International transfers

9.1 ALETHEIA is established in the Syrian Arab Republic and may work with Clients, users, providers and service providers worldwide. Personal information may therefore be collected in one country, accessed or processed in another, and transferred across borders.

9.2 Where a law restricts international transfers, ALETHEIA will use an available lawful transfer mechanism where required. Depending on the jurisdiction and circumstances, this may include an adequacy decision, standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, contractual or organisational safeguards, transfer-risk or data-protection assessments, consent or another permitted exception.

9.3 ALETHEIA will not treat the fact of an international transfer as removing its confidentiality, security or access-control obligations.

9A. Where we store and process information

9A.1 ALETHEIA's primary secure application, PostgreSQL database and private document storage are currently hosted on managed Hosting.com infrastructure in the United States. The public aletheiaco.com website and ALETHEIA transactional email infrastructure are hosted separately with Hosting.com in Arizona, United States.

9A.2 ALETHEIA creates encrypted off-site backups of the secure platform and currently stores those encrypted backups in London, United Kingdom. The backup service is restricted to authorised recovery purposes.

9A.3 Authorised ALETHEIA personnel may access personal information from Syria and from other locations where they are working where that access is necessary for the relevant authorised purpose and subject to access controls, confidentiality and security requirements.

9A.4 ALETHEIA uses separate infrastructure and service providers for functions such as public hosting, email delivery, DNS/certificates, encrypted off-site backup and operational monitoring. Operational monitoring may use Slack for limited technical alert summaries; ALETHEIA does not intend to transmit Client documents or ordinary commercial payloads through that alert channel.

9A.5 Infrastructure providers and locations may change over time. Where a change materially affects privacy information that Applicable Law requires ALETHEIA to provide, ALETHEIA will update this Policy or an applicable data-locations/subprocessor notice.

10. Security

10.1 ALETHEIA uses proportionate technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, loss and misuse.

10.2 Measures include authenticated access, role and authority controls, password reauthentication for protected actions, secure session management, encryption in transit, cryptographic password and token protections, application-level encryption for selected sensitive fields and message payloads, access logging, audit trails, malware scanning, restricted administrative access, encrypted off-site backups, monitoring and integrity controls for governed documents.

10.3 No system can guarantee absolute security. Users must also protect their credentials, devices and authorised information and must report suspected compromise promptly.

11. Retention

11.1 ALETHEIA retains personal information only for as long as reasonably necessary for the purpose for which it was collected and for legitimate legal, accounting, compliance, security, dispute, insurance and business-continuity needs.

11.2 Unsuccessful or withdrawn Client applications are normally retained for 12 months from the date of rejection or withdrawal, unless a legal, compliance, security or dispute reason requires longer retention.

11.3 Public website enquiries that do not become part of a Client, Engagement, compliance or dispute matter are normally retained for 12 months.

11.4 Completed non-financial Engagement and operational records are normally retained for 7 years after the relevant Engagement closes, unless a longer or shorter period is required or justified by Applicable Law, a legal claim, security, compliance or another legitimate record-keeping requirement.

11.5 Invoices, payments, accounting, tax, sanctions, compliance and related governed records are retained for the periods required by Applicable Law and applicable legal, accounting, regulatory and professional obligations.

11.6 Governed contractual, acceptance, Proposal, Invoice, payment and audit evidence may be retained where necessary to establish or defend legal rights, meet compliance obligations and preserve the integrity of historical transactions.

11.7 Personal information may remain in encrypted backups until the relevant backup is overwritten or expires under ALETHEIA's operational backup lifecycle. Access to backup data is restricted and backups are used for authorised recovery purposes.

11.8 Where Applicable Law requires a longer or shorter retention period, the applicable legal requirement will prevail.

12. Automated rules and decision support

12.1 ALETHEIA may use automated rules to support security, session management, duplicate or organisation-match detection, malware scanning, workflow validation, permissions, notifications and other administrative functions.

12.2 ALETHEIA does not currently intend to make decisions producing legal or similarly significant effects about Applicants or Client users solely by automated processing without meaningful human involvement. Where Applicable Law requires information about automated decision-making, ALETHEIA will provide it.

13. Cookies and similar technologies

13.1 The authenticated platform may use cookies or similar technologies that are strictly necessary to provide requested functionality, authenticate users, maintain secure sessions, prevent or detect misuse, remember user-requested selections and operate the service.

13.2 Where such technologies are strictly necessary, consent may not be required under applicable e-privacy rules, although ALETHEIA will provide clear information about their use.

13.3 If ALETHEIA introduces non-essential analytics, advertising, behavioural tracking or similar technologies, it will provide appropriate information and obtain consent where required before using them.

14. Your data-protection rights

14.1 Depending on your location, the law that applies to the relevant processing and any applicable thresholds or exemptions, you may have rights to request access to personal information, correction, deletion or erasure, restriction, portability, objection, information about processing, and in some jurisdictions rights relating to sale, sharing, targeted advertising, profiling or the use of sensitive information.

14.2 You may have a right to object to processing based on legitimate interests and an absolute right to object to certain direct marketing.

14.3 Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing already carried out lawfully before withdrawal.

14.4 Some rights are subject to exemptions and may not apply to records that ALETHEIA must retain for legal, contractual, security, compliance, accounting or dispute purposes.

14.5 To exercise a privacy or data-protection right, contact privacy@aletheiaco.com. ALETHEIA may need to verify your identity before acting on a request.

15. Complaints

15.1 Please contact ALETHEIA first if you have a privacy concern so that it can be investigated and addressed.

15.2 You may also have the right to complain to a competent privacy or data-protection regulator in your jurisdiction. Where UK data-protection law applies, this may include the UK Information Commissioner's Office; where EU GDPR applies, the competent EEA supervisory authority. ALETHEIA may provide additional regulator information in a jurisdiction-specific supplement.

15.3 These complaint rights do not limit any other remedy available under Applicable Law.

15A. Local privacy laws, representatives and supplements

15A.1 ALETHEIA may be subject to privacy laws outside Syria where their territorial-scope rules apply, including because ALETHEIA offers services to, or processes personal information concerning, individuals in a particular jurisdiction.

15A.2 If applicable law requires ALETHEIA to appoint a local privacy representative, agent, data-protection contact or similar representative, ALETHEIA will publish the relevant contact details in this Policy or an applicable jurisdiction-specific supplement.

15A.3 ALETHEIA may publish jurisdiction-specific privacy supplements for particular countries or regions. A supplement may explain additional rights, disclosures, lawful bases, opt-out mechanisms, regulator information, retention or transfer arrangements required by local law. The supplement applies only within its stated scope.

15A.4 The availability of a particular right or remedy depends on the law that applies, any applicable thresholds, exemptions and the context in which ALETHEIA processes the information. Nothing in this Policy is intended to reduce a non-waivable right granted by applicable law.

16. Children

16.1 ALETHEIA's platform and Services are intended for business and professional users aged 18 or over. ALETHEIA does not knowingly offer platform accounts to children.

16.2 Information about minors may occasionally be provided in connection with an Engagement where genuinely necessary, for example for authorised travel or participant arrangements. Such information should be limited to what is necessary and handled with heightened care.

17. Changes to this Policy

17.1 ALETHEIA may update this Policy to reflect changes in law, the platform, data flows, providers or business operations.

17.2 The published Policy will identify its version and effective date. Where a change materially affects individuals, ALETHEIA will provide additional notice where Applicable Law requires it.

17.3 Historical versions may be retained for governance and evidential purposes.

18. Contact

18.1 Privacy enquiries and data-rights requests may be sent to privacy@aletheiaco.com.

18.2 Postal correspondence may be sent to ALETHEIA Consulting L.L.C., Alfarabi Street, East Mezzeh, Damascus, Syrian Arab Republic.