Alloy

Privacy Policy

Last updated: 9 September 2026

This Privacy Policy explains how Alloy, the customer-facing AI assistant platform operated by Foundry IX ApS (“Foundry IX”, “we”, “us”), collects, uses, and protects personal data when you or your organisation use the service. Access to Alloy is restricted to authorised organisations that have entered into an agreement with us.

Who we are

The data controller for personal data processed about your use of Alloy is Foundry IX ApS, Guldbergsgade 25, kld. t.h., 2200 København N, Denmark, CVR no. 45868192. For data you connect through Alloy from your own business systems, your organisation is the controller and Foundry IX acts as a processor on its behalf, governed by a Data Processing Agreement (available on request via jon@foundryix.com).

Data we collect

  • Account & identity. When you sign in via Microsoft Entra ID (SSO) or Google, we receive your name, email address, organisation identifier, and authentication tokens needed to establish your session.
  • Assistant content. Chat messages, voice transcripts, uploaded files, canvas content, and the prompts and responses exchanged with the assistant.
  • Connected business data. Data retrieved from sources your organisation connects (e.g. SQL Server, Business Central, Azure AI Search, e-conomic, Harvest, Dinero, Uniconta, Azure DevOps, Google Drive, Meta Ads, Google Ads), used only to answer your requests — or, where your organisation has enabled write access, to carry out actions you approve in those systems — under your organisation’s access controls. Where you ask Alloy to move a file between two connected systems — for example to publish a video from your organisation’s Google Drive as an advertisement in its Meta ad account — we read it using your own access to the source and transfer it only to the destination you named.
  • Usage, credits & telemetry. Credit consumption, feature usage, diagnostic logs, and audit records of actions taken through the assistant.

How we use your data — and why

We use each category of data only for the purposes listed below. We do not build advertising profiles, do not sell personal data, and do not use your data to train AI or machine-learning models.

  • Account & identity — used to authenticate you, establish your session, and determine your organisation membership and role. Why: without it we cannot verify who you are or enforce which data and features you are permitted to access.
  • Assistant content (chat messages, voice transcripts, uploaded files, canvas content) — used to generate the responses you ask for and to maintain your conversation history so you can resume work. Why: this content is the input the assistant needs to help you; it is not used for any unrelated purpose.
  • Connected business data — retrieved on demand, only to fulfil the specific request you make, under your organisation’s access rules. Why: answering your questions requires reading the relevant records; we do not copy connected data for our own purposes.
  • Usage, credits & telemetry — used to meter and bill credit consumption, enforce usage limits, detect abuse, debug faults, and keep an audit trail of actions taken through the assistant. Why: billing, security, and accountability for what the assistant did on whose instruction.
  • All categories — where necessary, used to comply with legal obligations and to enforce our Terms of Service.

Our legal bases include performance of a contract, our legitimate interests in operating and securing the service, and compliance with legal obligations.

Cookies

Alloy uses only strictly necessary cookies: a session cookie that keeps you signed in and a cookie that remembers which organisation you have selected. We do not use advertising or third-party analytics cookies. Because these cookies are essential to providing the service you request, they do not require consent.

Sub-processors

We rely on trusted third parties to deliver Alloy. The current list of sub-processors, including each provider’s purpose, processing location, and transfer safeguard, is maintained on our sub-processor page. Content sent to AI model and voice providers is processed through their APIs solely to produce responses and is not used to train their models.

Customer data & data connections

Data accessed through Data Connections remains your organisation’s data. Access is role-based (RBAC), audited, and gated by the credentials your organisation provides. We access it only to fulfil requests initiated within your organisation and do not use it for any other purpose.

If your organisation connects an external AI client to Alloy (for example, a third-party assistant accessing Alloy’s MCP endpoint), data requested by that client is transferred to it at your organisation’s instruction and is processed by that provider under your organisation’s agreement with it. See our sub-processor page for how such clients relate to our sub-processor list. Similarly, where your organisation ingests telemetry about its own AI usage into Alloy, we process that data as a processor on your organisation’s instructions; informing the affected users is your organisation’s responsibility.

The Alloy browser extension

Alloy offers an optional browser extension. It is installed by individual users and is off unless your organisation’s administrator has enabled it. It reads only the page you are already viewing, and only acts when you click. It never sends messages, sends connection requests, or browses on your behalf.

What it collects. When you choose to save a person to your organisation’s CRM, the extension reads information already displayed on that person’s public professional profile: their name, the link to their profile, and — where your administrator has enabled each — their job title, their employer, and an email address if the profile displays one. It also records the date on which you exchanged a message or a connection invitation with that person, and which member of your organisation did so.

What it does not collect. The extension does not read, store or transmit the text of any message. On a messaging page it detects only that a message was sent or received and when, never its content. It does not collect browsing history, does not run on any site other than the professional network it supports, and does not observe pages you have not opened yourself.

Your administrator decides its scope. Which fields the extension may collect is configured centrally in Alloy. A field that is switched off is never read from the page, so it does not leave your browser at all, and the same limit is applied again on our servers so that an out-of-date extension cannot widen it.

Roles and lawful basis. Your organisation decides to use the extension, decides what it collects, and owns the CRM the data is written into; it is therefore the controller for that data, and Foundry IX acts as a processor on its behalf under the Data Processing Agreement. Your organisation is responsible for having a lawful basis for recording business-contact information about the people it deals with, typically its legitimate interest in managing its own commercial relationships, and for meeting its information obligations towards those people.

Where it goes. Captured data is sent only to your organisation’s own Alloy workspace and from there into the CRM your organisation has connected. It is not sold, not shared with any other customer, not used for advertising, and not used to train AI or machine-learning models.

Retention. Data written into your CRM is held there under your organisation’s own retention rules; deleting a record in your CRM is the way to erase it. Alloy separately keeps a small technical record so the same activity is not written twice; it holds an identifier of the CRM record and a date, not names or profile links, and is deleted with the connection.

If you are a person whose details have been recorded in a customer’s CRM this way and you wish to exercise your rights, contact that organisation as the controller. If you do not know who they are, write to us at jon@foundryix.com and we will pass the request on.

Google user data (Google API Services)

Where your organisation connects Google Drive (or another Google service) to Alloy, Alloy accesses Google user data via Google APIs using Google OAuth. This section describes how that data is handled.

  • What we access. Only the Google Drive content your organisation selects for the connection, plus the basic profile information (name, email address) provided when signing in with Google. Alloy requests only the OAuth scopes required for the connection to function.
  • How we use it. Google user data is used solely to provide the Alloy features the user requests — for example searching, analysing, or answering questions about connected Drive content through chat or voice. Access is further limited by your organisation’s configuration and each user’s permissions.
  • Storage & retention. OAuth tokens are stored encrypted. Drive content is retrieved on demand to answer requests; where content is cached or indexed to provide the service, it is deleted when the connection is removed or per the retention terms below.
  • Sharing. We do not sell Google user data, do not use it for advertising, and do not use it to train AI or machine-learning models (whether generalised or otherwise). It is shared with sub-processors only as needed to provide the service (see our sub-processor page), and content sent to AI model providers is used solely to produce the response you requested.
  • Revoking access. Your organisation can disconnect a Google connection at any time in Alloy, and you can revoke Alloy’s access from your Google Account at myaccount.google.com/permissions. On disconnection we delete the associated tokens and stop accessing the data.

Alloy’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Microsoft user data (Microsoft identity platform & Graph)

Alloy uses Microsoft Entra ID for sign-in and, where your organisation connects Microsoft 365, accesses Microsoft user data via the Microsoft Graph API. This section describes how that data is handled.

  • Sign-in. When you sign in with Microsoft Entra ID, Alloy requests the openid, email, and profile scopes — your name, email address, and organisation (tenant) identifier — used solely to authenticate you and map you to your organisation.
  • Microsoft 365 connection. If your organisation enables the Microsoft 365 connection, Alloy requests delegated, per-user permissions to read your mail, calendar, and Teams channels (Mail.Read, Calendars.Read, Team.ReadBasic.All, Channel.ReadBasic.All, ChannelMessage.Read.All), and — only where your organisation enables write mode — to send mail, manage calendar events, and post channel messages (Mail.Send, Calendars.ReadWrite, ChannelMessage.Send). Because permissions are delegated, Alloy can never access more than the signed-in user can themselves.
  • How we use it. Microsoft user data is used solely to provide the Alloy features the user requests — for example finding an email, summarising a Teams thread, or checking a calendar — through chat or voice. Actions in write mode are taken only on the user’s explicit instruction.
  • Storage & retention. OAuth tokens are stored encrypted. Mail, calendar, and Teams content is retrieved on demand to answer requests and is not synchronised into a copy we keep beyond the retention terms below.
  • Sharing. We do not sell Microsoft user data, do not use it for advertising, and do not use it to train AI or machine-learning models. It is shared with sub-processors only as needed to provide the service (see our sub-processor page), and content sent to AI model providers is used solely to produce the response you requested.
  • Revoking access. You can disconnect the Microsoft 365 connection at any time in Alloy, and you or your administrator can revoke Alloy’s access from your Microsoft account at myapps.microsoft.com or in the Microsoft Entra admin centre. On disconnection we delete the associated tokens and stop accessing the data.

Retention

We retain personal data for as long as your organisation’s account is active and as needed to provide the service, then delete or anonymise it within up to 6 months. Audit, payment, and billing records are retained longer where required to comply with applicable accounting and audit rules.

Your rights

Subject to applicable law (including the GDPR), you may have the right to access, rectify, erase, restrict, or object to processing of your personal data, and to data portability. Because your employer is often the controller, we may direct certain requests to your organisation. Contact us at jon@foundryix.com to exercise your rights. You also have the right to lodge a complaint with a supervisory authority; in Denmark this is Datatilsynet (www.datatilsynet.dk).

Automated decision-making

We do not use your personal data for automated decision-making that produces legal or similarly significant effects concerning you. Actions the assistant proposes in external systems can be gated behind human approval by your organisation.

Security

We use industry-standard measures including SSO-based authentication, encryption in transit, secrets managed in Azure Key Vault, RBAC, and audit logging. No system is perfectly secure, but we work to protect your data proportionate to its sensitivity.

International transfers

Alloy’s core processing and hosting take place within Microsoft’s European data centres. Certain sub-processors are located in the United States. See the sub-processor list for each provider’s processing location. Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.

Changes to this policy

We may update this policy from time to time. Material changes will be communicated through the service or to your organisation, and the “Last updated” date above will change.

Contact

Questions about this policy or our data practices can be sent to jon@foundryix.com.