Privacy Policy

What personal data Alikely handles, in which role, and why the answer for your CRM data is “we read it and don't keep it”.

Draft — not approved and not in force. This text is under review and may change before it is published as final.

Draft 0.2 · 6 October 2026.

The short version

  • We do not store your CRM data. Records are read from your HubSpot account when the Alikely card loads, scored, and discarded once the answer is sent. Nothing from them is stored or cached.
  • What we store about your organisation: an encrypted access token for your HubSpot account, the HubSpot user ID of the person who installed Alikely, and your saved profiles. A profile holds property names, weights, match settings and filter values — filter values can include HubSpot owner IDs — and the HubSpot user ID of the person who created it.
  • Alikely reads with the permissions granted when it was installed, so its results can include records that a particular user could not open in HubSpot. Section 11.3 explains this.
  • Our application runs in the EU (Microsoft Azure, Sweden Central). This website and our email addresses run through Cloudflare, and email to us is delivered to a Microsoft mailbox.
  • This website sets no cookies, runs no analytics and loads nothing from a third party.
  • We do not sell personal data, and we do not use your data to train AI models.

1. Who is responsible

Legal entity Lucas Rehn (sole trader, enskild firma), trading as Alikely
Organisation number 199905287398
VAT number SE990528739801
Address Hagarydsvägen 41, 586 63 Linköping, Sweden
Privacy contact privacy@alikely.app

We act in two roles, and the difference matters for your rights:

  • As controller for the personal data we handle to run our own business: people who write to us, and administrators and users of customer accounts. Sections 2–10 cover this.
  • As processor for the personal data in your HubSpot account that Alikely reads on your instruction. You are the controller of that data. Section 11 covers this.

2. What we process as controller

Category Data Source
Contact and correspondence Name, email address, company, and what you write to us You, by emailing an @alikely.app address
Account administration HubSpot account ID, the HubSpot user ID of the person who installed Alikely, and the dates it was installed and uninstalled Your HubSpot account, via the API
Profiles Profile name, object type, whether it is shared or personal, property names, weights, match settings and filter values, and the HubSpot user ID of the person who created it. Filter values can include HubSpot owner IDs, which are pseudonymous personal data about your own users Your users, when they save a profile
Technical logs Request metadata, timestamps, error information, HubSpot account ID. Logs do not contain record values from your CRM Generated when the service runs

3. Why, and on what legal basis

Purpose Legal basis (GDPR Art. 6)
Providing the service, authenticating users, keeping profiles Performance of a contract (Art. 6.1 b), or our legitimate interest in serving our business customer (Art. 6.1 f)
Support and correspondence, including requests to get Alikely Legitimate interest in answering the people who contact us (Art. 6.1 f)
Security, error diagnosis, abuse prevention Legitimate interest in a secure and functioning service (Art. 6.1 f)
Service announcements to administrators Legitimate interest in informing customers of changes that affect them (Art. 6.1 f)

We do not use your data for advertising, we do not profile you, and we do not make automated decisions with legal effect about anyone.

4. What we do not store

Alikely is built to be stateless for customer data. Records are held in memory only while a request is being answered, and nothing from them is cached between requests. The application has no database table for any of the following:

  • Company, deal, ticket, project or custom object records, or their property values
  • Contacts, names or email addresses from your CRM
  • Emails, calls, meetings or other activity
  • Similarity scores and match results — they are computed for each view and discarded

If our database were fully compromised, an attacker would learn which HubSpot accounts use Alikely, which user IDs installed it and created profiles, and what those profiles contain — property names, weights and filter values, including owner IDs. They would not obtain your records.

5. Recipients and subprocessors

Provider Purpose Location
Microsoft Azure (Microsoft Ireland Operations Ltd) Hosting of the application, database and encryption keys Sweden Central, EU
Cloudflare, Inc. Hosting of this website, DNS, and forwarding of email sent to @alikely.app addresses Global network, under the safeguards in section 6
Microsoft The mailbox that receives email sent to @alikely.app addresses Under the safeguards in section 6

For the data in your HubSpot account, HubSpot is not our subprocessor: it is your provider under your own contract, and Alikely accesses your account with the authorisation you grant at installation.

Otherwise we disclose personal data only where required by law, or to professional advisers under a duty of confidentiality.

6. Transfers outside the EU/EEA

The application and its database run in the EU. Cloudflare operates a global network, and Microsoft may process mailbox data outside the EU/EEA; where personal data is transferred outside the EU/EEA, the transfer relies on the European Commission's Standard Contractual Clauses or another valid transfer mechanism under Chapter V of the GDPR. No CRM data passes through this website, our email forwarding or our mailbox.

7. How long we keep things

CRM data Not retained — held in memory only while a request is answered, then discarded
Access token for your account Deleted as soon as we detect that Alikely has been uninstalled
Profiles While Alikely is installed, and deleted 30 days after it is uninstalled
Account record HubSpot account ID, installer's user ID and install dates: kept after an uninstall so that a reinstall is recognised — deleted on request
Correspondence Up to 24 months after the last message, unless it is part of a contractual record
Technical logs Short-lived operational retention, normally under 90 days

8. Security

  • Access tokens are encrypted at rest, with keys held in Azure Key Vault, and are never sent to the browser.
  • All traffic runs over TLS.
  • Alikely asks HubSpot for read permissions only. It does not create, change or delete anything in your HubSpot account.
  • Access to production systems is limited to the personnel who operate the service, which at present means one person.
  • We hold no ISO 27001 or SOC 2 attestation, and we say so rather than implying otherwise. The main control is architectural: your records are never stored.

Report a suspected vulnerability to privacy@alikely.app.

9. Cookies and tracking

This website sets no cookies, runs no analytics, embeds no fonts, scripts or images from third parties, and does not track you across sites. There is no consent banner because there is nothing to consent to.

The application uses only what is strictly necessary to authenticate a user's session — short-lived, signed credentials. They are not used for tracking or analytics. This section will describe them in more detail when this policy is finalised.

10. Your rights

Where we are the controller, you may request access to your personal data, rectification, erasure, restriction of processing and portability, and you may object to processing based on legitimate interest. Write to privacy@alikely.app and we will respond within one month.

If your data is in a customer's HubSpot account — for example as a contact at a company that uses Alikely — that company is the controller. Direct your request to them; we will assist them, but we hold no copy of their records.

You may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, or with the supervisory authority in your own country.

11. Data processing terms (GDPR Article 28)

These terms apply where we process personal data on behalf of a customer, and form part of the terms of service. A separate signable data processing agreement with the same content is available on request.

11.1 Subject matter and duration

Reading records from the customer's HubSpot account to compute and display similar records of the same object. Processing lasts for as long as Alikely is installed.

11.2 Nature, purpose and scope

Reading, comparing and displaying property values of companies, deals, tickets, projects and custom object records, as selected in the customer's profiles. Alikely does not write to the customer's account. No customer personal data from records is stored on the processor's systems: data is retrieved for a request, scored, returned to the authorised user and discarded. Profiles are stored and can contain HubSpot owner IDs as filter values.

11.3 Categories of data subjects and data; visibility

Data subjects: the customer's business contacts as they appear in records, and the customer's own users. Data: the property values of the records being compared, as present in the customer's CRM — for example company names, deal names and amounts, ticket subjects — and HubSpot user and owner identifiers. The customer determines what its CRM contains and must not configure Alikely to compare special categories of personal data (Art. 9).

Alikely reads with the permissions granted when it was installed, not with each user's own HubSpot permissions. The results a user sees can therefore include records, and the values of the fields a profile compares, that the same user could not open in HubSpot. The customer decides which fields its profiles compare and which users can see the card, and should take this into account.

11.4 Instructions

We process personal data only on the customer's documented instructions — these terms and the customer's use and configuration of Alikely — unless EU or member state law requires otherwise, in which case we inform the customer first unless that law forbids it. We will tell the customer if we consider an instruction to infringe data protection law.

11.5 Confidentiality

Personnel authorised to process personal data are bound by confidentiality and limited to those who need access to operate the service.

11.6 Security

Appropriate technical and organisational measures under Article 32, including encryption of stored credentials, TLS in transit, read-only API permissions, and an architecture that does not persist customer records.

11.7 Subprocessors

The customer gives general authorisation for the subprocessors listed in section 5. We will give at least 30 days' notice before adding or replacing one, during which the customer may object on reasonable data protection grounds; if the objection cannot be resolved, the customer may stop using the service without penalty. We impose equivalent data protection obligations on each subprocessor and remain liable for their performance.

11.8 Assistance

Taking into account the nature of the processing, we assist the customer with data subject requests, security, breach notification and impact assessments under Articles 32–36. Because we hold no copy of the customer's records, requests about record data are fulfilled by the customer inside HubSpot.

11.9 Personal data breach

We notify the customer without undue delay and no later than 72 hours after becoming aware of a personal data breach affecting their data, with the information available at the time and updates as the investigation proceeds.

11.10 Deletion and return

When Alikely is uninstalled we delete the stored access token as soon as we detect the uninstall, and the customer's profiles 30 days later. Records are never stored, so there is nothing further to return.

11.11 Audit

We make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits by the customer or an auditor it mandates. In the first instance an audit is satisfied by documentation: written answers to a security questionnaire and a description of the measures in place. Where that is reasonably shown not to be enough, an inspection may take place on at least 30 days' written notice, no more than once a year unless a breach or a supervisory authority requires otherwise, without disrupting the service and subject to confidentiality, at the customer's own cost.

12. Changes to this policy

We may update this policy. Material changes are notified to account administrators at least 30 days in advance. The version and date at the top of this page identify what is in force.

13. Contact

privacy@alikely.app — privacy questions, data subject requests, DPA requests and security reports.