Privacy Policy

Effective date: June 14, 2026

1. Who we are and what this policy covers

Groupe Allianceboard, Inc. (“allianceboard”, “we”, “us”) is a company based in Trois-Rivières, Québec, Canada. allianceboard provides a platform that enables companies and their users to manage their alliances and to collaborate with other companies.

This policy explains what personal information we handle, why we handle it, where it is hosted, and the rights you have. We comply with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and Québec’s Act respecting the protection of personal information in the private sector (as modernized by Law 25) and, where they apply to our processing, the EU and UK General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP).

Where the law requires your consent for a particular use of your information, such as marketing communications or non-essential cookies, we ask for it separately. We do not treat your use of our website or services as consent.

2. Our role: controller or processor

We handle personal information in two distinct capacities.

As a data controller, for information about visitors to our website, prospective customers, account and billing contacts, event and marketing contacts, and job applicants. This policy governs that processing.

As a data processor, for the content that our customers and their authorized users submit to the allianceboard platform (“Customer Data”). Our customers determine what Customer Data is submitted and are the data controllers of it. We process Customer Data only on their documented instructions under our agreement with them, including our Data Processing Agreement (DPA). If your organization has a separate written agreement with allianceboard, that agreement governs your organization’s use of the platform and the handling of Customer Data.

If your personal information is contained in a customer’s allianceboard workspace, please direct privacy questions or requests to that customer. If we receive your request directly, we will refer it to the relevant customer in accordance with our DPA.

3. Information we collect
  • Identification and business contact information, such as your name, email address, organization, title and role, business address and phone number.
  • Account information, such as your username and login credentials.
  • Customer Data submitted to the platform by or for our customers, which may include personal information relating to their alliances (for example, names and business contact details of alliance partners).
  • Usage information about how our website and the platform are used, including log data and IP-based geolocation.
  • Communications, such as comments, questions, survey responses, feedback and support enquiries.
  • Billing information needed for invoicing.
  • Recruitment information you provide when applying to work with us.

The allianceboard platform is not designed or intended for special categories of personal data (such as health data) or other sensitive personal information, and our Acceptable Use Policy prohibits uploading it.

4. How we collect your information

Most information is provided directly by you: when you use or view our website, register for or use the platform, place an order, complete a survey, provide feedback, or contact us.

We may also receive your information from the customer that invited you to use the platform (for example, your employer or a partner organization). That customer determines its own policies for the content it manages in allianceboard, which may apply to you. Please check with that organization.

5. How we use your information and our legal bases

We use personal information to: create and manage accounts and provide the platform in accordance with our agreements; send service-related and billing communications; provide customer assistance and technical support; maintain, secure and improve our website and services, including fraud prevention; create aggregated, anonymized statistical information that does not identify you and does not include customer confidential information; consider your candidacy if you apply to work with us; and comply with applicable law.

With your consent, we may also send you marketing communications about our products, services, news and thought leadership, or share your contact details with a partner company so that it can contact you about its products and services. You may withdraw your consent at any time.

We rely on the following legal bases: performance of a contract with you or your organization (or steps taken to enter into one); compliance with a legal obligation; our legitimate interests as a business (pursued proportionately and with respect for your privacy rights, for example service improvement and security); and your consent, which you may withdraw at any time without affecting processing already carried out.

6. Where your information is hosted and international transfers

Customer Data in the allianceboard platform is hosted with leading cloud infrastructure providers in data centres located in the European Union (Ireland). Transactional email is sent through infrastructure located in the European Union. Limited, access-controlled processing is carried out from Canada (by our personnel) and from within the European Union (by our development and support contractors) in order to operate, support and secure the services. A current list of our sub-processors, identifying each provider, its role, its location and the applicable transfer safeguards, is available to customers on request to privacy@allianceboard.com, and customers receive 30 days’ notice of sub-processor changes under our DPA.

Information we hold as a controller (website, marketing, billing and recruitment records) is processed in Canada and with the service providers on our sub-processor list.

Where personal information is transferred from the European Economic Area, the United Kingdom or Switzerland to a country not covered by an adequacy decision, we use recognized safeguards: the European Commission’s Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum and the Swiss adjustments, as incorporated in our DPA; the European Commission’s adequacy decision for Canada (covering commercial organizations subject to PIPEDA, confirmed in the Commission’s January 2024 review); and, for certain US-headquartered sub-processors, their certification under the EU-U.S. Data Privacy Framework alongside Standard Contractual Clauses in our contracts with them. Our sub-processors are contractually bound to protect personal information to standards consistent with our DPA.

7. How we protect your information

We maintain an information security management system certified to ISO/IEC 27001. Our technical and organizational measures include encryption at rest (AES-256) and in transit (TLS); multi-factor authentication and least-privilege access controls; logical separation of customer data; daily encrypted backups with regularly tested restore and disaster recovery procedures; and hosting in data centres holding ISO 27001 and SOC certifications. We notify affected customers without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting their Customer Data. Full details of our measures are available under our DPA on request to privacy@allianceboard.com.

8. Artificial intelligence features

allianceboard includes optional AI features, such as an AI assistant and AI-based search across a customer’s own content. These features are disabled by default and are activated for a customer’s workspace only by that customer’s administrator.

AI processing takes place within our EU-based infrastructure, and model inference is performed by a managed AI service operated in the European Union. Customer Data, including prompts and AI outputs, is not used to train or improve any AI model, and the inference service does not retain prompts or outputs after a request is completed. These commitments are contractual obligations of our provider.

AI features can only retrieve information that the requesting user is already authorized to view. Tenant-level and user-level permissions are enforced before any data is provided to a model, and AI tools are limited to read-only retrieval, so they cannot create, modify or delete data. AI conversations are stored as part of Customer Data for the duration of the customer’s agreement, can be deleted in the product by authorized users, and are subject to the retention and deletion terms in section 9. Each AI request is logged for security and traceability.

9. How long we keep your information

Customer Data (where we act as processor). We retain Customer Data for the duration of the customer’s agreement. On termination, the customer may request return or deletion of Customer Data within 60 days; in any event we delete all copies from our systems within 90 days of termination, except where law requires longer storage. Residual copies in encrypted backups expire on a rolling schedule, currently no later than 60 days after deletion from our production systems. Data uploaded during a free trial is deleted after the trial ends, as set out in our Terms of Use.

Information we hold as a controller. We keep account and billing records for as long as needed to manage the relationship and to meet legal (including tax) retention requirements; marketing contact information until you opt out or after 24 months of inactivity; and recruitment information for 12 months after a hiring decision, unless you ask us to keep your application on file. When information is no longer required, we delete it securely.

10. Marketing

We send marketing communications only with your consent or as otherwise permitted by applicable law. Every marketing email we send includes an unsubscribe link, and you may opt out at any time by using that link or by emailing privacy@allianceboard.com. Opting out does not affect service or billing communications, or the lawfulness of processing carried out before your withdrawal.

11. Cookies

Cookies are small text files placed on your device. We use strictly necessary cookies to operate the website (for example, to keep you signed in). We use functionality and analytics cookies, which remember your preferences and help us understand how the website is used, only with your consent, which you can give, refuse or withdraw at any time through our cookie banner or preferences panel. We do not use advertising cookies. You can also control cookies through your browser settings; blocking some cookies may affect how the website works. For more information about cookies generally, visit www.allaboutcookies.org.

12. Your rights

Depending on where you are located, you have the right to: request access to a copy of your personal information (the first copy is free of charge); request correction of inaccurate or incomplete information; request erasure of your personal information; request restriction of processing; object to processing based on our legitimate interests; request portability of information you provided to us; withdraw consent at any time where processing is based on consent; and lodge a complaint with a supervisory authority (see section 17).

If your personal information is contained in a customer’s allianceboard workspace, that customer is the controller of it: please address your request to that customer, and we will assist them in responding in accordance with our DPA.

To exercise your rights, contact us at privacy@allianceboard.com or through our EU representative (section 13). We respond within one month under the GDPR and within 30 days under Québec law, and we may need to verify your identity before acting on a request.

13. GDPR and our EU representative

The European Commission has recognized Canada as providing an adequate level of protection for personal data transferred to commercial organizations subject to PIPEDA (Decision 2002/2/EC, confirmed in the Commission’s January 2024 review of its adequacy decisions).

Under the GDPR, our customers are the controllers of the Customer Data they process through the platform, and allianceboard is their processor. We make a Data Processing Agreement available to all customers; it incorporates the EU Standard Contractual Clauses (2021/914, Modules Two and Three), the UK International Data Transfer Addendum and the Swiss FADP adjustments, and reflects PIPEDA, Québec’s Private Sector Act and applicable US state privacy laws. To put our DPA in place, contact privacy@allianceboard.com.

In accordance with Article 27 of the EU GDPR, we have appointed Data Protection Representative Limited (trading as “DataRep”), 77 Camden Street Lower, Dublin D02 XE80, Ireland (registered in Ireland, no. 616588; www.datarep.com), as our data protection representative in the European Union. To exercise your GDPR rights, you may contact DataRep at datarequest@datarep.com, quoting “Groupe Allianceboard Inc.” in the subject line, or contact us directly at privacy@allianceboard.com.

14. Third-party websites

Our website contains links to other websites. This policy applies only to our website and services, so if you follow a link to another website, you should read its privacy policy.

15. Changes to this policy

We review this policy regularly and post any updates on this page with a revised effective date. If we make material changes, we will provide notice on our website or by email where appropriate.

16. How to contact us

Groupe Allianceboard, Inc., 75 rue Thiffault, Trois-Rivières, QC G8W 1Y5, Canada.

Privacy Officer (person in charge of the protection of personal information / responsable de la protection des renseignements personnels): privacy@allianceboard.com, +1 857 239 0262.

17. Supervisory authorities

If you believe we have not addressed your concern, you may lodge a complaint with a supervisory authority:

  • In the EU/EEA: your local data protection authority (for example, the CNIL in France) or the Irish Data Protection Commission;
  • In the UK: the Information Commissioner’s Office (ICO);
  • In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC);
  • In Canada: the Commission d’accès à l’information du Québec (CAI) or the Office of the Privacy Commissioner of Canada.