Back to Strata

Privacy Policy

Last updated: 19 August 2026

Introduction

Welcome to Strata. Please read this Privacy Policy carefully before using the Strata platform and our Services.

This Privacy Policy is an agreement between you (“You” or “Your”) and Strata (“Company,” “We,” “Us,” or “Our”), concerning your access to and use of the Strata platform and related Services.

It describes Our policies and procedures on the collection, use, and disclosure of Your information when You use Strata, and tells You about Your privacy rights and how the law protects You. We use Personal Data to provide and improve the Services. By using Strata, You agree to the collection and use of information in accordance with this Privacy Policy and our Terms.

1. Interpretation and Definitions

1.1 Interpretation

Words with an initial capital letter have the meanings set out below. Headings are for convenience only.

1.2 Definitions

  • Account means a unique account created for You to access our Services or parts of our Services.
  • Affiliate means an entity that controls, is controlled by, or is under common control with a party, where “control” means ownership of 50% or more of the shares or other voting securities.
  • Business (CCPA/CPRA) means Strata as the legal entity that collects Consumers’ personal information and determines the purposes and means of processing that information, for Account Data.
  • CCPA means the California Consumer Privacy Act as amended by the CPRA.
  • Consumer (CCPA/CPRA) means a natural person who is a California resident.
  • Cookies means small files placed on Your Device by a website.
  • Customer Data means lead, entity, form, CRM, scrape, and related records a customer workspace stores in Strata.
  • Data Controller (GDPR) means, for Account Data, Strata. For Customer Data, the customer workspace is the controller and Strata is the processor.
  • Device means any device that can access the Services, such as a computer, phone, or tablet.
  • GDPR means the EU General Data Protection Regulation.
  • Personal Data means any information that relates to an identified or identifiable individual.
  • Service Provider means any person who processes data on behalf of the Company. For GDPR, a Service Provider is a processor / subprocessor. Named vendors are listed on the Subprocessors page.
  • Usage Data means data collected automatically, generated by use of the Services or Services infrastructure.
  • Website means the Strata application You use to access the Services.
  • You means the individual accessing or using the Services, or the organisation on whose behalf that individual acts.

2. Collecting and Using Your Personal Data

2.1 Roles

Strata is a B2B workspace. We are the controller for people who create accounts and log in (“Account Data”). When a customer uploads, scrapes, or syncs lead records, We process that Customer Data as a processor on the customer’s instructions. The customer remains the controller of Customer Data. See also the Customer DPA.

2.2 Types of Data Collected

2.2.1 Account Data You provide

While using Our Services, We may ask You to provide personally identifiable information that can be used to contact or identify You, including:

  • Email address
  • First name and last name
  • Organisation and workspace membership
  • Workspace role (for example member, admin, or owner)
  • Usage Data

2.2.2 Customer Data

Customer Data is provided by the customer or collected on the customer’s instructions. It may include names, emails, phones, job titles, company details, notes, form payloads, sent-email metadata, CRM identifiers, AI scores, coordinates, and similar business-contact fields. We process Customer Data only to provide ingest, scoring, monitoring, email, CRM, and related features the customer enables. We do not use Customer Data to advertise Strata to those leads.

People whose data is stored as Customer Data should contact the customer first. Customer admins can search, export, and erase matching lead records in Workspace Privacy. We can assist at privacy@allumni.ai. Customers must verify a requester’s identity before using the in-product tools.

2.3 Usage Data

Usage Data is collected automatically when using the Services. It may include:

  • Your Device’s Internet Protocol address (IP address)
  • Browser type and version
  • The pages of our Services that You visit
  • The time and date of Your visit and the time spent on those pages
  • Unique device identifiers and other diagnostic data

When You access the Services by or through a mobile device, We may collect the type of mobile device You use, a unique device ID, IP address, operating system, browser type, and similar diagnostic data.

2.4 Tracking Technologies and Cookies

We use Cookies and similar technologies that are necessary to operate the Services. Clerk session cookies are essential to sign-in and to keep You authenticated. Without these Cookies, the services You have asked for cannot be provided.

There is no marketing analytics pixel in Strata today. We do not use Google Analytics, Mixpanel, or Hotjar on the product. We do not use tracking and performance Cookies for advertising.

We use the following Cookie types:

  • Necessary / Essential Cookies (session; administered by Us and our authentication provider). These authenticate users and prevent fraudulent use of accounts.
  • Functionality Cookies (persistent). These remember choices such as organisation or workspace selection so You do not have to re-enter them every visit.

Inbound forms may use Google reCAPTCHA when a workspace enables bot checks. Google Places may be used when a workspace enables location lookup. Those vendors process information under their own policies.

You can instruct Your browser to refuse Cookies. If You do not accept essential Cookies, You may not be able to use sign-in or other parts of the Services.

2.5 Use of Your Personal Data

The Company may use Account Data for the following purposes:

  • To provide and maintain our Services, including to monitor usage and keep the product secure.
  • To manage Your Account, including registration and organisation membership.
  • For the performance of a contract for the Services You or Your organisation have purchased.
  • To contact You by email or other electronic communication about updates, security, and the functionalities You use.
  • To provide You with news and product information about Strata similar to Services You already use, unless You have opted not to receive such information.
  • To manage Your requests and provide support.
  • For business transfers, such as a merger, financing, or sale of assets, in which Personal Data may be among the assets transferred.
  • For other internal purposes, such as diagnosing issues and improving the Services.

2.6 Sharing Your Personal Information

We may share information in the following situations:

  • With Service Providers listed on the Subprocessors page, to host the product, authenticate users, store data, send email, run background jobs, and (when a workspace enables them) scrape, enrich, score, or sync CRM.
  • For business transfers, in connection with any merger, sale of Company assets, financing, or acquisition.
  • With Affiliates, who must honour this Privacy Policy.
  • With Your direction or consent, for example when You connect HubSpot or Salesforce.
  • For legal reasons, if required by law or to protect rights, safety, or the Services.

We do not sell personal information and we do not share it for cross-context advertising. We do not share Account Data with other users in public areas of the product.

2.7 AI processing

Entity notes and fields may be sent to model providers through the Vercel AI Gateway to score, map, or draft content when a workspace uses those features. Model providers vary with gateway configuration. We do not use Customer Data to train public foundation models.

2.8 Email Marketing

We may use Account Data to contact You with product news or promotional materials about Strata. You may opt out by following the unsubscribe link in any such email or by contacting Us.

Marketing email to Customer Data is sent on the customer’s behalf. It requires an explicit marketing-consent flag on the record. New entities default to not consented. Marketing sends also require the workspace to set a physical mailing address (CAN-SPAM). Messages include List-Unsubscribe headers. A spam complaint unsubscribes that address.

2.9 Payments

If We provide paid products or services, payment card details are provided directly to third-party payment processors. We do not store full payment card numbers. Those processors’ use of personal information is governed by their privacy policies and PCI-DSS standards.

2.10 Retention of Your Personal Data

We retain Account Data only as long as necessary for the purposes in this Privacy Policy, including to comply with legal obligations, resolve disputes, and enforce agreements. You can download or delete Your Account from Profile. Deleting an Account anonymizes the workspace user record and removes the login. It does not wipe the customer’s lead database.

Customer Data is retained until the customer deletes it or instructs Us to erase it, except where law requires a longer period. Application erasure does not instantly remove copies in encrypted backups; those expire on the host’s backup schedule.

We also apply product retention limits, including:

  • Rendered email HTML/text copies after 90 days
  • Agent-run payloads after 30 days
  • CSV import files after 7 days

Usage Data is generally retained for a shorter period, except when needed to strengthen security, improve the Services, or comply with law.

2.11 Transfer of Your Personal Data

Your information is processed where We and our Service Providers operate, including the United States and other locations listed on the Subprocessors page. Data protection laws there may differ from those in Your jurisdiction.

We will take steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy. International transfers rely on vendor data-processing terms and standard contractual clauses where required, not on “consent by submit.”

2.12 Delete Your Personal Data

You have the right to delete or request that We assist in deleting Personal Data We have collected about You. Workspace users can download or delete Account Data from Profile. You may also contact Us to request access, correction, or deletion. We may need to retain certain information when We have a legal obligation or lawful basis to do so.

2.13 Disclosure of Your Personal Data

If the Company is involved in a merger, acquisition, or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.

The Company may be required to disclose Personal Data if required by law or in response to valid requests by public authorities. We may also disclose Personal Data in the good-faith belief that such action is necessary to comply with a legal obligation, protect and defend the rights or property of the Company, prevent or investigate possible wrongdoing, protect the personal safety of users or the public, or protect against legal liability.

2.14 Security of Your Personal Data

The security of Your Personal Data is important to Us, but no method of transmission over the Internet or electronic storage is 100% secure. We use commercially reasonable means to protect Personal Data, including access controls and encryption in transit. We cannot guarantee absolute security.

3. Your Rights

Rights relating to Personal Data may differ depending on your country.

3.1 Right to Withdraw Consent

You can withdraw consent at any time by contacting Us. Withdrawal does not affect prior processing.

3.2 Right to Request Correction

You can request correction of any inaccurate or incomplete Personal Data by contacting Us or by updating Your Account.

4. GDPR Privacy

4.1 Legal Basis for Processing

Where GDPR applies, We may process Personal Data under these conditions:

  • Consent. You have given consent for one or more specific purposes.
  • Performance of a contract. Processing is necessary for an agreement with You or Your organisation, or for pre-contractual steps.
  • Legal obligations. Processing is necessary to comply with a legal obligation.
  • Vital interests. Processing is necessary to protect vital interests of You or another person.
  • Legitimate interests. Processing is necessary for legitimate interests pursued by the Company, such as operating and securing a B2B workspace, except where overridden by Your interests or fundamental rights.

We will help clarify the specific legal basis that applies, and whether providing Personal Data is a statutory or contractual requirement.

4.2 Your Rights under the GDPR

The Company undertakes to respect the confidentiality of Your Personal Data. Where GDPR applies, You may, subject to conditions:

  • Request access to Your Personal Data, including a copy We hold about You
  • Request correction of incomplete or inaccurate information
  • Object to processing based on legitimate interests, and object to processing for direct marketing
  • Request erasure when there is no good reason for Us to continue processing
  • Request transfer of Your Personal Data in a structured, commonly used, machine-readable format
  • Withdraw consent. If You withdraw consent, We may not be able to provide certain functionalities

Whenever possible, You can access, update, or request deletion of Account Data in Profile. If You cannot perform these actions yourself, contact Us.

4.3 Exercising GDPR Rights

Email privacy@allumni.ai. We may ask You to verify Your identity before responding. We will try to respond as soon as possible. You also have the right to complain to a Data Protection Authority in the EEA about Our collection and use of Your Personal Data.

5. CCPA/CPRA Privacy Notice (California)

This section supplements this Privacy Policy and applies solely to visitors, users, and others who reside in California.

5.1 Categories of Personal Information Collected

  • Identifiers (name, email, IP address, account name, unique identifiers): Yes
  • California Customer Records information (name, and contact details such as email or phone when You or a customer provide them): Yes
  • Protected classification characteristics: No, not as a product feature
  • Commercial information (records of Services used or considered): Yes
  • Biometric information: No
  • Internet or other network activity: Yes
  • Geolocation data: Not for Account Data. Customer Data may include coordinates when a customer stores them
  • Sensory data: No
  • Professional or employment-related information: Not required for Account Data. Customer Data may include job title and company
  • Non-public education information: No
  • Inferences used as a consumer profile: No
  • Sensitive personal information (account login information through our authentication provider): Yes

5.2 Sources of Personal Information

  • Directly from You (forms, Account, preferences)
  • Indirectly from You (observing activity on the Services)
  • Automatically from You (essential Cookies as You navigate the Services)
  • From Service Providers who help Us provide the Services
  • From the customer organisation, for Customer Data

5.3 Use of Personal Information

We may use or disclose personal information for business purposes, including to operate the Services, provide support, fulfil the reason You provided the information, respond to law-enforcement requests, detect security incidents, and for internal administration. The examples above are illustrative. If We collect additional categories or use information for materially different purposes, We will update this Privacy Policy.

5.4 Disclosure of Personal Information

In the last twelve (12) months We may have disclosed identifiers, California Customer Records information, commercial information, and internet activity to Service Providers to operate the Services. This does not mean every example in those categories was disclosed. When We disclose personal information for a business purpose, We require the recipient to keep it confidential and not use it except to perform the contract.

5.5 Sale and Sharing of Personal Information

As defined in the CCPA/CPRA, “sell” and “sale” mean transferring personal information to a third party for valuable consideration. We do not sell personal information. We do not share personal information for cross-context behavioural advertising. We do not knowingly sell or share personal information of consumers under 16.

You have the right to opt out of sale or sharing. Because We do not sell or share in those senses, there is no additional opt-out required for Strata. You may still email Us to confirm.

5.6 Your Rights under the CCPA/CPRA

  • The right to notice of categories collected and purposes of use
  • The right to know / access
  • The right to correct inaccurate personal information
  • The right to delete, subject to exceptions
  • The right to limit use and disclosure of sensitive personal information
  • The right not to be discriminated against for exercising these rights

Only You or an authorized agent may make a verifiable request. We cannot respond if We cannot verify identity. We will disclose information free of charge within 45 days, and may extend once by 45 days when reasonably necessary. Disclosures cover the 12-month period preceding the request. We provide a readily usable format for portability requests.

We collect, use, and disclose sensitive personal information (account login) as necessary to provide the Services. Our Services do not respond to browser Do Not Track signals; essential sign-in cookies are required to use the product.

California residents may also request, once a year, information about sharing Personal Data with third parties for those parties’ direct marketing. We do not share Account Data for that purpose.

6. Children’s Privacy

Our Services do not address anyone under 13. We do not knowingly collect personal data from anyone under 13. The Services are intended for business users. If You believe a child has provided Us Account Data, contact Us with enough detail to delete that information.

7. Links to Other Websites

Our Services may contain links to other websites, including CRM consoles and vendor policies. We have no control over and assume no responsibility for third-party content or privacy policies.

8. Changes to this Privacy Policy

We may update Our Privacy Policy from time to time. Changes are effective when posted on this page. We will update the “Last updated” date and, for material changes, provide additional notice (for example email or an in-product notice) before changes become effective.

9. Contact Us

If You have questions about this Privacy Policy, or to exercise Your rights, contact Us by email: privacy@allumni.ai. Controller for Account Data: Strata.

Customer DPA · Subprocessors · Terms

Data-subject requests: privacy@allumni.ai