Customer Contract Portal Privacy Notice
How Alliance Connectivity Ltd collects, uses, and safeguards personal data when you review, complete, and electronically sign your service agreement through our secure online contract portal.
What We Collect
Business and signatory contact details, your service order configuration, your secure electronic signature, and cryptographic signing audit trail timestamps.
Why We Use It
To create, execute, and deliver your contractual service agreement, facilitate secure Direct Debit billing, maintain fraud protection, and meet statutory UK obligations.
Your Statutory Control
You maintain full statutory rights under UK GDPR to access, rectify, restrict, or object to the use of your personal data at any time without charge.
Who We Are
The customer contract portal is operated by Alliance Connectivity Ltd ("Alliance Connectivity", "we", "us", "our"), a private limited company registered in England and Wales under company registration number 12919154, with its registered office situated at:
Alliance Connectivity acts as the Data Controller for all personal data processed through the online contract portal. We are formally registered with the UK Information Commissioner's Office (ICO) as a recognized data controller under UK data protection legislation.
This Portal Privacy Notice specifically supplements our overarching website Privacy Policy and Clause 10 of our Master Terms & Conditions. In the event of any direct operational conflict regarding digital contract execution, the terms of this portal notice take precedence.
Scope of this Notice
This notice governs personal data captured and processed when you access a secure, personalized contract link issued by Alliance Connectivity, review proposed commercial terms, input authorized signatory details, apply your electronic signature, and complete Direct Debit mandate confirmations.
Our communications, connectivity, and utility services are supplied primarily to corporate and commercial entities (B2B). Most information processed within the contract portal pertains directly to corporate business entities. Where data relates to an identifiable individual—such as a designated business signatory, sole trader, or general business partner—it constitutes personal data under UK GDPR and is fully protected by this notice.
Data We Collect
The table below itemizes the categories of personal and contractual data processed during your portal session:
| Category | Data Elements & Examples | Source |
|---|---|---|
Identity & Role Essential | Signatory name, job title/role, the business organisation you represent | You, or your assigned sales representative |
Contact Details Direct | Business address, direct email address, business telephone number | You, or your assigned sales representative |
Order Details Commercial | Services selected, quantities, contract term length, commencement date, pricing, assigned account executive | Alliance Connectivity |
Signature & Consent Verification | Electronic signature timestamp, statutory confirmations (signing authority, terms acceptance, Direct Debit completion verification) | You (via portal submission) |
Signing Audit Trail Security Audit | IP address, browser and device user agent, cryptographic viewing/signing timestamps, unique contract reference ID | Collected automatically by portal system |
Technical Data System | Secure session identifiers, security access telemetry, system error logs | Collected automatically during portal session |
Special Category Data: Alliance Connectivity does not request, process, or store sensitive special category data (such as health, biometric, religious, or ethnic data) within the contract portal. You must not input sensitive category details into portal text fields.
How & Why We Use It
Under UK data protection law (UK GDPR Article 6), we must establish a legitimate lawful basis for each processing purpose:
Preparing, presenting, and executing your service agreement
Lawful Basis: Contract (UK GDPR Art. 6(1)(b)) where you are a sole trader or partner. Otherwise Legitimate Interests (Art. 6(1)(f)) in contracting with the business entity you represent.
Activating, delivering, and provisioning telecommunications & connectivity services
Lawful Basis: Contract / Legitimate Interests in fulfilling service agreements and provisioning network lines.
Billing, account management, and Direct Debit collections
Lawful Basis: Contract / Legitimate Interests in administering payment workflows and account billing.
Maintaining a cryptographic signing audit trail to prove valid execution
Lawful Basis: Legitimate Interests (Art. 6(1)(f)) in establishing, exercising, and defending legal claims.
Maintaining statutory business, financial, and tax accounting records
Lawful Basis: Legal Obligation (UK GDPR Art. 6(1)(c)) under UK corporate and HMRC legislation.
Protecting portal infrastructure and preventing fraudulent submissions
Lawful Basis: Legitimate Interests (Art. 6(1)(f)) in safeguarding network security and fraud prevention.
Account administration, contractual service notices, and renewals
Lawful Basis: Contract / Legitimate Interests in ongoing contract governance.
We do not use contract portal personal data for automated decision-making or profiling that produces legal or similarly significant effects. We never sell or lease your personal data to commercial third parties.
Direct Debit Details
Bank Detail Separation & Security
Your sensitive banking and payment details are never entered or stored within the contract portal database.
When you click the "Open Direct Debit Details" prompt in the signing sequence, you are securely redirected to an encrypted, certified payment bureau form. That certified provider captures your bank sort code and account number, sets up the Direct Debit instruction, and manages collections under strict BACS Scheme Rules and the Direct Debit Guarantee.
The contract portal records only your affirmative confirmation that you have completed the Direct Debit setup form.
International Transfers
Primary contract portal data is hosted securely in sovereign UK and European Economic Area (EEA) data centres.
Where external service providers access data outside the UK (e.g. for specialized technical support or cloud telemetry), we ensure robust transfer safeguards are in place. These include UK Government Adequacy Regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to European Commission Standard Contractual Clauses (SCCs).
How Long We Keep It
We retain personal and contractual data only for as long as necessary to satisfy contractual, legal, accounting, and reporting obligations:
| Record Category | Statutory Retention Period | Retention Ceiling |
|---|---|---|
| Signed agreements and signing audit trail | For the duration of the agreement plus 6 years (statutory limitation period for UK contract claims) | 6 Years Post-Term |
| Billing, payment confirmation, and accounting records | 6 years from the end of the financial tax year to which they relate (HMRC compliance) | 6 Years |
| Unsigned or expired contract links | Securely purged 90 days after link expiry, unless subsequent signature is executed | 90 Days |
| Portal security telemetry and technical server logs | Retained for up to 12 months for diagnostic and security auditing before automated deletion | 12 Months |
Upon expiration of relevant retention ceilings, all records are permanently erased, securely shredded, or irreversibly anonymized.
Security & Protection
We implement comprehensive technical and organizational safeguards to ensure data integrity, confidentiality, and availability:
Enforced HTTPS/TLS 1.3 protocol encryption for all data transit and AES-256 database storage encryption.
Cryptographically generated, expiring contract links personal to designated signatories.
Strict least-privilege internal access with comprehensive access logging and multi-factor authentication.
Tamper-evident signing logs preserving immutable cryptographic timestamps and IP signatures.
Important: Contract links are strictly confidential to the named signatory. Please do not forward contract signing URLs. If you suspect an unauthorized party has accessed your link, notify our support team immediately.
Your Statutory Rights
Under UK data protection laws, individuals whose personal data is processed have enforceable statutory rights:
Right of Access
Obtain confirmation as to whether your personal data is processed and request a comprehensive copy of the records held.
Right to Rectification
Request prompt correction of inaccurate personal data or completion of incomplete signatory records.
Right to Erasure
Request deletion of your data when it is no longer necessary for the legal purposes for which it was gathered.
Right to Restriction
Request limitation of processing while accuracy is contested or during verification of legitimate interest objections.
Right to Object
Object at any time to processing based on legitimate interests, and unconditionally opt out of direct marketing.
Data Portability
Receive your personal data in a structured, commonly used, and machine-readable format where applicable.
Exercising Your Rights: We will acknowledge and respond to all verified statutory requests within one calendar month. In accordance with UK GDPR, requests are processed free of charge unless manifestly unfounded or excessive.
Please note that certain rights may be limited where legal obligations (such as retaining executed contracts for limitation periods) require continuous preservation.
Contact & Complaints
To exercise your statutory rights, request data updates, or raise inquiries regarding this notice, please reach out via any of our designated communication channels:
Attn: Data Protection Officer
1a Station Road, Great Sankey,
Warrington, WA5 1RH, UK
Wycliffe House, Water Lane, Wilmslow, SK9 5AF
We welcome the opportunity to address and resolve any privacy concern directly with you first, though you retain the right to lodge a complaint with the ICO at any time.
Changes to this Notice
Alliance Connectivity may update this Customer Contract Portal Privacy Notice periodically to reflect legislative modifications, portal capability updates, or operational enhancements.
The active version and latest publication timestamp will always be clearly accessible within the contract portal footer and header. For substantial alterations materially impacting your statutory rights, we will provide conspicuous notification or direct communication where appropriate.