Privacy Policy
What personal data Alikely handles, in which role, and why the answer for your CRM data is “we read it and don't keep it”.
Draft 0.2 · 6 October 2026.
The short version
- We do not store your CRM data. Records are read from your HubSpot account when the Alikely card loads, scored, and discarded once the answer is sent. Nothing from them is stored or cached.
- What we store about your organisation: an encrypted access token for your HubSpot account, the HubSpot user ID of the person who installed Alikely, and your saved profiles. A profile holds property names, weights, match settings and filter values — filter values can include HubSpot owner IDs — and the HubSpot user ID of the person who created it.
- Alikely reads with the permissions granted when it was installed, so its results can include records that a particular user could not open in HubSpot. Section 11.3 explains this.
- Our application runs in the EU (Microsoft Azure, Sweden Central). This website and our email addresses run through Cloudflare, and email to us is delivered to a Microsoft mailbox.
- This website sets no cookies, runs no analytics and loads nothing from a third party.
- We do not sell personal data, and we do not use your data to train AI models.
1. Who is responsible
| Legal entity | Lucas Rehn (sole trader, enskild firma), trading as Alikely |
|---|---|
| Organisation number | 199905287398 |
| VAT number | SE990528739801 |
| Address | Hagarydsvägen 41, 586 63 Linköping, Sweden |
| Privacy contact | privacy@alikely.app |
We act in two roles, and the difference matters for your rights:
- As controller for the personal data we handle to run our own business: people who write to us, and administrators and users of customer accounts. Sections 2–10 cover this.
- As processor for the personal data in your HubSpot account that Alikely reads on your instruction. You are the controller of that data. Section 11 covers this.
2. What we process as controller
| Category | Data | Source |
|---|---|---|
| Contact and correspondence | Name, email address, company, and what you write to us | You, by emailing an @alikely.app address |
| Account administration | HubSpot account ID, the HubSpot user ID of the person who installed Alikely, and the dates it was installed and uninstalled | Your HubSpot account, via the API |
| Profiles | Profile name, object type, whether it is shared or personal, property names, weights, match settings and filter values, and the HubSpot user ID of the person who created it. Filter values can include HubSpot owner IDs, which are pseudonymous personal data about your own users | Your users, when they save a profile |
| Technical logs | Request metadata, timestamps, error information, HubSpot account ID. Logs do not contain record values from your CRM | Generated when the service runs |
3. Why, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service, authenticating users, keeping profiles | Performance of a contract (Art. 6.1 b), or our legitimate interest in serving our business customer (Art. 6.1 f) |
| Support and correspondence, including requests to get Alikely | Legitimate interest in answering the people who contact us (Art. 6.1 f) |
| Security, error diagnosis, abuse prevention | Legitimate interest in a secure and functioning service (Art. 6.1 f) |
| Service announcements to administrators | Legitimate interest in informing customers of changes that affect them (Art. 6.1 f) |
We do not use your data for advertising, we do not profile you, and we do not make automated decisions with legal effect about anyone.
4. What we do not store
Alikely is built to be stateless for customer data. Records are held in memory only while a request is being answered, and nothing from them is cached between requests. The application has no database table for any of the following:
- Company, deal, ticket, project or custom object records, or their property values
- Contacts, names or email addresses from your CRM
- Emails, calls, meetings or other activity
- Similarity scores and match results — they are computed for each view and discarded
If our database were fully compromised, an attacker would learn which HubSpot accounts use Alikely, which user IDs installed it and created profiles, and what those profiles contain — property names, weights and filter values, including owner IDs. They would not obtain your records.
5. Recipients and subprocessors
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Azure (Microsoft Ireland Operations Ltd) | Hosting of the application, database and encryption keys | Sweden Central, EU |
| Cloudflare, Inc. | Hosting of this website, DNS, and forwarding of email sent to @alikely.app addresses | Global network, under the safeguards in section 6 |
| Microsoft | The mailbox that receives email sent to @alikely.app addresses | Under the safeguards in section 6 |
For the data in your HubSpot account, HubSpot is not our subprocessor: it is your provider under your own contract, and Alikely accesses your account with the authorisation you grant at installation.
Otherwise we disclose personal data only where required by law, or to professional advisers under a duty of confidentiality.
6. Transfers outside the EU/EEA
The application and its database run in the EU. Cloudflare operates a global network, and Microsoft may process mailbox data outside the EU/EEA; where personal data is transferred outside the EU/EEA, the transfer relies on the European Commission's Standard Contractual Clauses or another valid transfer mechanism under Chapter V of the GDPR. No CRM data passes through this website, our email forwarding or our mailbox.
7. How long we keep things
| CRM data | Not retained — held in memory only while a request is answered, then discarded |
|---|---|
| Access token for your account | Deleted as soon as we detect that Alikely has been uninstalled |
| Profiles | While Alikely is installed, and deleted 30 days after it is uninstalled |
| Account record | HubSpot account ID, installer's user ID and install dates: kept after an uninstall so that a reinstall is recognised — deleted on request |
| Correspondence | Up to 24 months after the last message, unless it is part of a contractual record |
| Technical logs | Short-lived operational retention, normally under 90 days |
8. Security
- Access tokens are encrypted at rest, with keys held in Azure Key Vault, and are never sent to the browser.
- All traffic runs over TLS.
- Alikely asks HubSpot for read permissions only. It does not create, change or delete anything in your HubSpot account.
- Access to production systems is limited to the personnel who operate the service, which at present means one person.
- We hold no ISO 27001 or SOC 2 attestation, and we say so rather than implying otherwise. The main control is architectural: your records are never stored.
Report a suspected vulnerability to privacy@alikely.app.
9. Cookies and tracking
This website sets no cookies, runs no analytics, embeds no fonts, scripts or images from third parties, and does not track you across sites. There is no consent banner because there is nothing to consent to.
The application uses only what is strictly necessary to authenticate a user's session — short-lived, signed credentials. They are not used for tracking or analytics. This section will describe them in more detail when this policy is finalised.
10. Your rights
Where we are the controller, you may request access to your personal data, rectification, erasure, restriction of processing and portability, and you may object to processing based on legitimate interest. Write to privacy@alikely.app and we will respond within one month.
If your data is in a customer's HubSpot account — for example as a contact at a company that uses Alikely — that company is the controller. Direct your request to them; we will assist them, but we hold no copy of their records.
You may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, or with the supervisory authority in your own country.
11. Data processing terms (GDPR Article 28)
These terms apply where we process personal data on behalf of a customer, and form part of the terms of service. A separate signable data processing agreement with the same content is available on request.
11.1 Subject matter and duration
Reading records from the customer's HubSpot account to compute and display similar records of the same object. Processing lasts for as long as Alikely is installed.
11.2 Nature, purpose and scope
Reading, comparing and displaying property values of companies, deals, tickets, projects and custom object records, as selected in the customer's profiles. Alikely does not write to the customer's account. No customer personal data from records is stored on the processor's systems: data is retrieved for a request, scored, returned to the authorised user and discarded. Profiles are stored and can contain HubSpot owner IDs as filter values.
11.3 Categories of data subjects and data; visibility
Data subjects: the customer's business contacts as they appear in records, and the customer's own users. Data: the property values of the records being compared, as present in the customer's CRM — for example company names, deal names and amounts, ticket subjects — and HubSpot user and owner identifiers. The customer determines what its CRM contains and must not configure Alikely to compare special categories of personal data (Art. 9).
Alikely reads with the permissions granted when it was installed, not with each user's own HubSpot permissions. The results a user sees can therefore include records, and the values of the fields a profile compares, that the same user could not open in HubSpot. The customer decides which fields its profiles compare and which users can see the card, and should take this into account.
11.4 Instructions
We process personal data only on the customer's documented instructions — these terms and the customer's use and configuration of Alikely — unless EU or member state law requires otherwise, in which case we inform the customer first unless that law forbids it. We will tell the customer if we consider an instruction to infringe data protection law.
11.5 Confidentiality
Personnel authorised to process personal data are bound by confidentiality and limited to those who need access to operate the service.
11.6 Security
Appropriate technical and organisational measures under Article 32, including encryption of stored credentials, TLS in transit, read-only API permissions, and an architecture that does not persist customer records.
11.7 Subprocessors
The customer gives general authorisation for the subprocessors listed in section 5. We will give at least 30 days' notice before adding or replacing one, during which the customer may object on reasonable data protection grounds; if the objection cannot be resolved, the customer may stop using the service without penalty. We impose equivalent data protection obligations on each subprocessor and remain liable for their performance.
11.8 Assistance
Taking into account the nature of the processing, we assist the customer with data subject requests, security, breach notification and impact assessments under Articles 32–36. Because we hold no copy of the customer's records, requests about record data are fulfilled by the customer inside HubSpot.
11.9 Personal data breach
We notify the customer without undue delay and no later than 72 hours after becoming aware of a personal data breach affecting their data, with the information available at the time and updates as the investigation proceeds.
11.10 Deletion and return
When Alikely is uninstalled we delete the stored access token as soon as we detect the uninstall, and the customer's profiles 30 days later. Records are never stored, so there is nothing further to return.
11.11 Audit
We make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits by the customer or an auditor it mandates. In the first instance an audit is satisfied by documentation: written answers to a security questionnaire and a description of the measures in place. Where that is reasonably shown not to be enough, an inspection may take place on at least 30 days' written notice, no more than once a year unless a breach or a supervisory authority requires otherwise, without disrupting the service and subject to confidentiality, at the customer's own cost.
12. Changes to this policy
We may update this policy. Material changes are notified to account administrators at least 30 days in advance. The version and date at the top of this page identify what is in force.
13. Contact
privacy@alikely.app — privacy questions, data subject requests, DPA requests and security reports.