Identity and Contact Details of the Data Controller
Alkentar Technologies ("Alkentar", "we", "us", or "our") operates as a specialized software architecture, rapid MVP engineering, and AI modernization studio. For the purposes of Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation — "GDPR") and applicable European national data protection statutes, Alkentar is the Data Controller for personal data processed through our public web platform and pre-contractual discovery channels.
We have appointed a designated Data Protection Officer (DPO) to oversee ongoing compliance with European privacy laws, data processing agreements (DPAs), and security standards.
Alkentar Technologies • Operational Headquarters: European Union • Data Protection Officer Contact: dpo@alkentar.com • General Privacy Inquiries: privacy@alkentar.com • Response Time: Maximum 30 calendar days (free of charge).
Scope and Territorial Applicability
This Privacy Policy applies to natural persons who access or interact with alkentar.com, submit inquiries via our technical discovery forms, schedule architectural consultations, or engage our engineering teams across the European Economic Area (EEA), Switzerland, the United Kingdom, and globally.
Where Alkentar processes code repositories, production databases, or proprietary data on behalf of enterprise clients under a Master Services Agreement (MSA), such processing is additionally governed by a dedicated Article 28 GDPR Data Processing Agreement (DPA).
Core Principles of Data Processing (Article 5 GDPR)
We adhere strictly to the fundamental principles established in Article 5 of the GDPR. Every personal data processing activity carried out by Alkentar satisfies the following criteria:
- Lawfulness, Fairness, and Transparency:Data is processed strictly upon documented legal bases, without hidden processing or deceptive practices.
- Purpose Limitation:Data collected for architectural discovery or technical execution is never repurposed for unrelated commercial objectives.
- Data Minimisation:We collect only the bare minimum technical and contact fields strictly necessary to evaluate, scope, and deliver software projects.
- Accuracy & Storage Limitation:We maintain mechanisms to rectify outdated records and enforce automated deletion schedules once retention periods expire.
- Integrity and Confidentiality:We deploy state-of-the-art technical and organizational measures (TOMs), including end-to-end encryption and zero-trust access controls.
Categories of Data Processed & Legal Bases (Article 6 GDPR)
In accordance with Article 6(1) of the GDPR, personal data processing is only lawful when at least one legal basis applies. The table below delineates the data categories we process, the operational purposes, and the corresponding legal grounds:
| Data Category | Operational Purpose | GDPR Legal Basis |
|---|---|---|
| Discovery & Inquiry Data (Name, business email, company, current funding stage, architectural overview) | Evaluating technical feasibility, scoping startup MVPs or enterprise AI modernization, scheduling Discovery Calls | Art. 6(1)(b) GDPR (Performance of a contract / Pre-contractual steps at request of data subject) |
| Server & Telemetry Logs (Truncated IP address, browser user-agent, request timestamp, TLS cipher suite) | Ensuring network resilience, mitigating distributed denial-of-service (DDoS) attacks, detecting unauthorized intrusions | Art. 6(1)(f) GDPR (Legitimate interests in cybersecurity and infrastructure stability) |
| Commercial & Billing Records (Entity legal address, VAT identification number, invoice history, transaction logs) | Fulfilling commercial contracting, issuing tax-compliant invoices, statutory tax accounting | Art. 6(1)(c) GDPR (Compliance with statutory legal obligations under EU commercial/tax law) |
| Client Code & Technical Artifacts (Git commits, API schemas, staging environment credentials) | Software engineering, RAG pipeline construction, performance tuning, and strangler fig architecture migration | Art. 6(1)(b) GDPR & Article 28 DPA (Contractual execution under strict confidentiality) |
Strict AI Governance & Zero Model Training Guarantee
A primary concern for European technology enterprises and venture-backed founders is preserving proprietary intellectual property when deploying modern Artificial Intelligence systems. Alkentar enforces an uncompromising AI governance policy:
1. Zero Training on Client Data: Client source code, data schemas, proprietary algorithms, and submitted business documents are NEVER submitted to public foundation model training sets (e.g., public OpenAI, Anthropic, or open-source foundation models).
2. Private Inference Tenancy: When deploying Large Language Models (LLMs), RAG pipelines, or autonomous agent workflows, we utilize enterprise zero-data-retention APIs and isolated virtual private clouds (VPCs) located within the EU.
3. Compliance with EU AI Act: We architect AI systems aligned with Regulation (EU) 2024/1689 (EU Artificial Intelligence Act), ensuring algorithmic transparency, human-in-the-loop validation, and detailed technical logging.
4. No Automated Decision-Making (Art. 22 GDPR): Alkentar does not utilize automated profiling or algorithmic decision-making that produces legal or similarly significant effects on individuals.
Your code remains solely yours. Under no circumstances does Alkentar monetize, aggregate, or train external machine learning systems on client intellectual property or sensitive business logic.
Sub-processors & International Data Transfers
Alkentar prioritizes European Union data residency. All primary production servers, container registries, vector stores, and automated build pipelines are hosted in ISO/IEC 27001, ISO 27017, and SOC 2 Type II certified European data centers located within Germany, France, Ireland, or Italy.
Where our technical architecture requires vetted third-party cloud sub-processors with global operations (e.g., edge CDN delivery or transactional email dispatch), we enforce strict compliance with Chapter V of the GDPR:
• Execution of European Commission Standard Contractual Clauses (SCCs) pursuant to Commission Implementing Decision (EU) 2021/914.
• Supplementary Technical and Organizational Measures (TOMs) under the CJEU Schrems II ruling, including military-grade AES-256 encryption at rest, TLS 1.3 in transit, and customer-managed encryption key rings.
• Mandatory Transfer Impact Assessments (TIAs) confirming that local foreign laws do not undermine European privacy standards.
Data Retention & Secure Deletion Schedules
Personal data is retained only for as long as strictly necessary to fulfill the specific purposes for which it was gathered, or to comply with statutory European commercial and tax obligations:
• Technical Discovery Inquiries: Inquiries that do not progress to an active Statement of Work are permanently expunged or anonymized from our systems within 12 months.
• Commercial Contract & Financial Records: Retained for statutory periods (typically 6 to 10 years) in compliance with applicable EU Member State commercial and fiscal codes (such as § 257 HGB / § 147 AO in Germany, or the French Commercial Code).
• Project Staging Credentials & API Keys: Automatically revoked and deleted within 30 calendar days following official project sign-off and repository handover.
Your Data Subject Rights Under Chapter III GDPR
Under Articles 12 through 23 of the GDPR, European citizens and residents possess robust rights concerning their personal data. Alkentar is committed to facilitating the friction-free exercise of these rights:
To exercise any statutory GDPR rights, send an email to privacy@alkentar.com or dpo@alkentar.com with the subject line "GDPR Rights Request". We verify identity to protect your information and respond within 30 calendar days free of charge.
- Right of Access (Article 15 GDPR):You may request written confirmation as to whether your personal data is being processed, together with a copy of all stored records.
- Right to Rectification (Article 16 GDPR):You may require us to correct inaccurate personal data or complete incomplete records without undue delay.
- Right to Erasure / "Right to be Forgotten" (Article 17 GDPR):You may request the deletion of your personal data when it is no longer needed for the purposes collected, or where processing was based on withdrawn consent.
- Right to Restriction of Processing (Article 18 GDPR):You may restrict processing while the accuracy of your data is contested, or if you have objected to processing pending verification.
- Right to Data Portability (Article 20 GDPR):You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON or CSV).
- Right to Object (Article 21 GDPR):You may object at any time to processing based on legitimate interests (Art. 6(1)(f)), including any direct commercial communications.
- Right to Withdraw Consent (Article 7(3) GDPR):Where processing relies on your consent, you may revoke that consent at any time with immediate effect for future processing.
Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)
Without prejudice to any other administrative or judicial remedy, every data subject has the right to lodge a complaint with a competent European Supervisory Authority pursuant to Article 77 of the GDPR, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement.
Key European Data Protection Authorities include:
• Germany: Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) — www.bfdi.bund.de
• France: Commission Nationale de l’Informatique et des Libertés (CNIL) — www.cnil.fr
• Italy: Garante per la protezione dei dati personali (GPDP) — www.garanteprivacy.it
• European Union: European Data Protection Board (EDPB) — edpb.europa.eu
Questions Regarding Legal Terms?
Our European legal, compliance, and data protection officers are at your disposal.