LEGAL & DATA PRIVACY NOTICE

Customer Contract Portal Privacy Notice

How Alliance Connectivity Ltd collects, uses, and safeguards personal data when you review, complete, and electronically sign your service agreement through our secure online contract portal.

Version1.0 (Current)
ScopeOnline Contract Portal
Data ControllerAlliance Connectivity Ltd (12919154)
JurisdictionUK GDPR & DPA 2018
Privacy Inquiries

Questions regarding governance or portal data?

enquiries@allianceconnectivity.co.uk

What We Collect

Business and signatory contact details, your service order configuration, your secure electronic signature, and cryptographic signing audit trail timestamps.

Zero special category data

Why We Use It

To create, execute, and deliver your contractual service agreement, facilitate secure Direct Debit billing, maintain fraud protection, and meet statutory UK obligations.

Strict lawful basis adherence

Your Statutory Control

You maintain full statutory rights under UK GDPR to access, rectify, restrict, or object to the use of your personal data at any time without charge.

1-month response guarantee
Section 1.0

Who We Are

The customer contract portal is operated by Alliance Connectivity Ltd ("Alliance Connectivity", "we", "us", "our"), a private limited company registered in England and Wales under company registration number 12919154, with its registered office situated at:

Alliance Connectivity Ltd1a Station Road, Great Sankey, Warrington, WA5 1RH, United Kingdom

Alliance Connectivity acts as the Data Controller for all personal data processed through the online contract portal. We are formally registered with the UK Information Commissioner's Office (ICO) as a recognized data controller under UK data protection legislation.

This Portal Privacy Notice specifically supplements our overarching website Privacy Policy and Clause 10 of our Master Terms & Conditions. In the event of any direct operational conflict regarding digital contract execution, the terms of this portal notice take precedence.

Section 2.0

Scope of this Notice

This notice governs personal data captured and processed when you access a secure, personalized contract link issued by Alliance Connectivity, review proposed commercial terms, input authorized signatory details, apply your electronic signature, and complete Direct Debit mandate confirmations.

Our communications, connectivity, and utility services are supplied primarily to corporate and commercial entities (B2B). Most information processed within the contract portal pertains directly to corporate business entities. Where data relates to an identifiable individual—such as a designated business signatory, sole trader, or general business partner—it constitutes personal data under UK GDPR and is fully protected by this notice.

Section 3.0

Data We Collect

The table below itemizes the categories of personal and contractual data processed during your portal session:

CategoryData Elements & ExamplesSource
Identity & Role
Essential
Signatory name, job title/role, the business organisation you representYou, or your assigned sales representative
Contact Details
Direct
Business address, direct email address, business telephone numberYou, or your assigned sales representative
Order Details
Commercial
Services selected, quantities, contract term length, commencement date, pricing, assigned account executiveAlliance Connectivity
Signature & Consent
Verification
Electronic signature timestamp, statutory confirmations (signing authority, terms acceptance, Direct Debit completion verification)You (via portal submission)
Signing Audit Trail
Security Audit
IP address, browser and device user agent, cryptographic viewing/signing timestamps, unique contract reference IDCollected automatically by portal system
Technical Data
System
Secure session identifiers, security access telemetry, system error logsCollected automatically during portal session

Special Category Data: Alliance Connectivity does not request, process, or store sensitive special category data (such as health, biometric, religious, or ethnic data) within the contract portal. You must not input sensitive category details into portal text fields.

Section 4.0

How & Why We Use It

Under UK data protection law (UK GDPR Article 6), we must establish a legitimate lawful basis for each processing purpose:

Preparing, presenting, and executing your service agreement

Lawful Basis: Contract (UK GDPR Art. 6(1)(b)) where you are a sole trader or partner. Otherwise Legitimate Interests (Art. 6(1)(f)) in contracting with the business entity you represent.

Activating, delivering, and provisioning telecommunications & connectivity services

Lawful Basis: Contract / Legitimate Interests in fulfilling service agreements and provisioning network lines.

Billing, account management, and Direct Debit collections

Lawful Basis: Contract / Legitimate Interests in administering payment workflows and account billing.

Maintaining a cryptographic signing audit trail to prove valid execution

Lawful Basis: Legitimate Interests (Art. 6(1)(f)) in establishing, exercising, and defending legal claims.

Maintaining statutory business, financial, and tax accounting records

Lawful Basis: Legal Obligation (UK GDPR Art. 6(1)(c)) under UK corporate and HMRC legislation.

Protecting portal infrastructure and preventing fraudulent submissions

Lawful Basis: Legitimate Interests (Art. 6(1)(f)) in safeguarding network security and fraud prevention.

Account administration, contractual service notices, and renewals

Lawful Basis: Contract / Legitimate Interests in ongoing contract governance.

Automated Decisions & Data Selling Policy

We do not use contract portal personal data for automated decision-making or profiling that produces legal or similarly significant effects. We never sell or lease your personal data to commercial third parties.

Section 5.0

Direct Debit Details

Bank Detail Separation & Security

Your sensitive banking and payment details are never entered or stored within the contract portal database.

When you click the "Open Direct Debit Details" prompt in the signing sequence, you are securely redirected to an encrypted, certified payment bureau form. That certified provider captures your bank sort code and account number, sets up the Direct Debit instruction, and manages collections under strict BACS Scheme Rules and the Direct Debit Guarantee.

The contract portal records only your affirmative confirmation that you have completed the Direct Debit setup form.

Section 6.0

Who We Share It With

We share personal data strictly on a need-to-know basis to fulfill contractual orders and uphold operational compliance:

Technology & Hosting Processors

Certified cloud infrastructure and portal hosting providers who maintain secure, encrypted environments as authorized data processors.

Network Operators & Carriers

Tier-1 cellular networks (O2, EE, Vodafone, Three), broadband carriers (Openreach, CityFibre), and payment acquirers required to activate your services.

Secure Transactional Messaging

Encrypted email dispatch systems that transmit your personalized contract link and finalized counter-signed copies.

Advisers & Regulatory Bodies

Professional legal counsel, auditors, HMRC, and law enforcement agencies where disclosure is mandated by UK statutory obligations.

All authorized data processors operate under binding Data Processing Agreements (DPAs) mandating stringent confidentiality and technical security safeguards.

Section 7.0

International Transfers

Primary contract portal data is hosted securely in sovereign UK and European Economic Area (EEA) data centres.

Where external service providers access data outside the UK (e.g. for specialized technical support or cloud telemetry), we ensure robust transfer safeguards are in place. These include UK Government Adequacy Regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to European Commission Standard Contractual Clauses (SCCs).

Section 8.0

How Long We Keep It

We retain personal and contractual data only for as long as necessary to satisfy contractual, legal, accounting, and reporting obligations:

Record CategoryStatutory Retention PeriodRetention Ceiling
Signed agreements and signing audit trailFor the duration of the agreement plus 6 years (statutory limitation period for UK contract claims)6 Years Post-Term
Billing, payment confirmation, and accounting records6 years from the end of the financial tax year to which they relate (HMRC compliance)6 Years
Unsigned or expired contract linksSecurely purged 90 days after link expiry, unless subsequent signature is executed90 Days
Portal security telemetry and technical server logsRetained for up to 12 months for diagnostic and security auditing before automated deletion12 Months

Upon expiration of relevant retention ceilings, all records are permanently erased, securely shredded, or irreversibly anonymized.

Section 9.0

Security & Protection

We implement comprehensive technical and organizational safeguards to ensure data integrity, confidentiality, and availability:

Encryption in Transit & At Rest

Enforced HTTPS/TLS 1.3 protocol encryption for all data transit and AES-256 database storage encryption.

Time-Limited Signing Tokens

Cryptographically generated, expiring contract links personal to designated signatories.

Role-Based Access Control

Strict least-privilege internal access with comprehensive access logging and multi-factor authentication.

Audit Trail Verification

Tamper-evident signing logs preserving immutable cryptographic timestamps and IP signatures.

Important: Contract links are strictly confidential to the named signatory. Please do not forward contract signing URLs. If you suspect an unauthorized party has accessed your link, notify our support team immediately.

Section 10.0

Cookies & Technical Telemetry

The customer contract portal employs strictly necessary session cookies and essential cryptographic tokens only.

These technical identifiers are vital to maintain your active signing session, preserve form input state across steps, and prevent Cross-Site Request Forgery (CSRF). Because they are strictly required for security and core portal functionality, they do not require consent under UK PECR regulations.

The contract portal executes zero third-party commercial advertising trackers or behavioral targeting pixels.

Section 11.0

Your Statutory Rights

Under UK data protection laws, individuals whose personal data is processed have enforceable statutory rights:

Art. 15

Right of Access

Obtain confirmation as to whether your personal data is processed and request a comprehensive copy of the records held.

Art. 16

Right to Rectification

Request prompt correction of inaccurate personal data or completion of incomplete signatory records.

Art. 17

Right to Erasure

Request deletion of your data when it is no longer necessary for the legal purposes for which it was gathered.

Art. 18

Right to Restriction

Request limitation of processing while accuracy is contested or during verification of legitimate interest objections.

Art. 21

Right to Object

Object at any time to processing based on legitimate interests, and unconditionally opt out of direct marketing.

Art. 20

Data Portability

Receive your personal data in a structured, commonly used, and machine-readable format where applicable.

Exercising Your Rights: We will acknowledge and respond to all verified statutory requests within one calendar month. In accordance with UK GDPR, requests are processed free of charge unless manifestly unfounded or excessive.

Please note that certain rights may be limited where legal obligations (such as retaining executed contracts for limitation periods) require continuous preservation.

Section 12.0

Contact & Complaints

To exercise your statutory rights, request data updates, or raise inquiries regarding this notice, please reach out via any of our designated communication channels:

Data Protection Lead
Privacy & Compliance Team
enquiries@allianceconnectivity.co.uk
Telephone Inquiries
Customer Care & Legal
01925 500818
Mon – Fri, 9:00am – 5:30pm
Registered Office (Postal)
Alliance Connectivity Ltd
Attn: Data Protection Officer
1a Station Road, Great Sankey,
Warrington, WA5 1RH, UK
Independent Regulator (ICO)
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, SK9 5AF
ico.org.uk/make-a-complaint Helpline: 0303 123 1113

We welcome the opportunity to address and resolve any privacy concern directly with you first, though you retain the right to lodge a complaint with the ICO at any time.

Section 13.0

Changes to this Notice

Alliance Connectivity may update this Customer Contract Portal Privacy Notice periodically to reflect legislative modifications, portal capability updates, or operational enhancements.

The active version and latest publication timestamp will always be clearly accessible within the contract portal footer and header. For substantial alterations materially impacting your statutory rights, we will provide conspicuous notification or direct communication where appropriate.