Public-first
We prefer publicly visible information over anything behind a login, wherever that's sufficient to prepare the meeting. Less data is better, not worse.
AllyWise processes information about real people, in Europe, in a regulated field. This page says exactly what we do and what we decided not to do. It's written to be forwarded to your DPO without softening.
An American tool that profiles European contacts casually is a problem you buy along with the software. Not because it's illegal by definition, but because the burden of showing the processing is lawful falls on you, as the controller.
We did the opposite: the product decisions were made starting from the constraints. The buyer profile is ephemeral because retaining it doesn't survive the balancing test. The emotion features don't exist because they're prohibited. Sourcing goes through you because that's the most defensible configuration. This isn't compliance marketing: these are features we didn't build.
We prefer publicly visible information over anything behind a login, wherever that's sufficient to prepare the meeting. Less data is better, not worse.
AllyWise servers never access LinkedIn. The content comes from the page you're already looking at, by copy-paste or a component that reads what's in front of you. You're a professional with a legitimate and imminent relationship with that person: a far stronger position than an automated collector's.
We don't build an archive of profiles to resell or reuse. This isn't a promise of good behaviour: such an archive would be a different kind of processing, on a legal basis we don't have and aren't seeking.
We keep only what's needed to produce the brief, for as long as it's needed.
A note on transparency: the sourcing posture is undergoing specialist legal validation, and we're treating that as binding before extending the product on this front. Publicly accessible data remains personal data, and «public» does not mean «free to use».
| Your seller profile | Consent | Explicit at signup, revocable at any time. It's yours: you see it, correct it, delete it. |
|---|---|---|
| Your counterpart's company | Not personal data | Sector, size, stated priorities, tone of communication. Business information from public sources. |
| Your counterpart as a person | Legitimate interest (art. 6.1.f) | With a written, documented balancing test. Processing is ephemeral and directed at a single imminent meeting. |
Legitimate interest isn't a label that applies itself. It requires a documented Legitimate Interest Assessment: which interest, why the processing is necessary, why the person's rights don't override it. «Everyone does it» is not a legal basis, and a DPO who has read the GDPR knows that. Our LIA is a document that exists and that we maintain.
Health, including mental health. Political, religious, philosophical beliefs. Trade union membership. Sex life and sexual orientation. Ethnic origin. Genetic and biometric data. Legitimate interest covers none of this: if the system produced it, the processing would be unlawful regardless of the balancing test. So the route chosen is not to process it at all.
Signals of special categories present in the sources are not used as analytical input.
The instructions require profiling communication style only, and prohibit the jump from style to clinical or identity inferences.
Generated text is scanned and blocked before being displayed or saved if it contains references to special categories.
If they surfaced anyway, they are not stored. In any form.
The guardrail is tested adversarially against real public profiles of people with declared political, union or religious affiliations. A control that hasn't been attacked isn't a control: it's an intention.
In the workplace this is a prohibited practice under art. 5, in force since 2 February 2025, with penalties up to €35 million or 7% of worldwide turnover. We had prototyped a real-time in-conversation assistant: it was not released, and won't be in that form. It isn't a feature we lack — it's a feature we eliminated.
The method adapts order, emphasis, proof and format. Never the facts. In the product that distinction is binding, not rhetorical.
We state when content is generated by an automated system and when you're interacting with one.
We require AI Act conformity documentation from the model providers we use. The compliance chain doesn't stop downstream.
The brief is a hypothesis for a human being who has to make a decision. It isn't a score that assigns an outcome, it doesn't feed an automated process, and it produces no effects on the person it describes.
GDPR art. 22 restricts fully automated decisions with significant effects. We don't go near that boundary, and that's not an accident: it's a design invariant, stated as such.
GDPR articles 15-22, exercisable by writing to an address that answers.
This section lists commitments in progress, not results achieved. We publish it anyway, because a supplier who only declares finished things is a supplier whose gaps you can't see.
Ally S.r.l. will appoint a data protection officer before opening commercially.
Processing that profiles people at scale requires a DPIA. It will be completed before launch, not after.
The balancing test and the AI Act conformity documentation are living documents, updated when the product changes.
The sourcing posture is with a specialist lawyer, and we're treating it as blocking before building further on this front.
Write to us. We'd rather take a hard question now than a three-month block later.
Write to privacy@allywise.io