01 Who we are
Altrum ("Altrum", "we", "us" or "our") is a mobile application development studio. We design, build, launch and maintain iOS, Android and cross-platform applications for clients worldwide.
For the purposes of the EU and UK General Data Protection Regulation (GDPR), Altrum acts as a data controller for personal data collected through this website and through our own business operations, and as a data processor when we handle personal data on behalf of a client under a development or maintenance agreement.
All privacy questions, requests and complaints go to ten20.ae@gmail.com. Please write "Privacy request" in the subject line so it reaches the right person quickly.
02 Scope of this policy
This policy applies to:
- This website and any subdomains operated by Altrum.
- Email, messaging and call correspondence with prospective, current and former clients.
- Proposals, contracts, invoicing and other business administration.
- Recruitment enquiries and applications sent to us.
It does not apply to applications we have built for clients that are operated by those clients. In those cases the client is the controller and their own privacy policy governs the app — see section 14.
03 Information we collect
We collect only what we need to answer your enquiry, deliver our services and run our business. We do not buy personal data from data brokers, and we do not sell personal data.
3.1 Information you give us
| Category | Examples | Why we have it |
|---|---|---|
| Contact details | Name, email address, phone number, company, job title | To reply to enquiries and manage the client relationship |
| Project information | Briefs, requirements, wireframes, brand assets, feedback | To scope, quote and deliver the work |
| Contract & billing data | Signatory details, billing address, tax identifiers, payment references | To contract lawfully and get paid |
| Correspondence | Emails, chat messages, meeting notes, call summaries | To maintain a record of decisions and commitments |
| Credentials you share | Access to repositories, store accounts, cloud consoles | Only where required to perform the agreed work |
| Recruitment data | CV, portfolio links, work history | To assess applications you send us |
3.2 Information collected automatically
When you visit this website, our hosting provider records standard server request data. This is generated by the technical operation of the internet rather than by tracking software we have installed.
- Request logs: IP address, timestamp, requested URL, HTTP status, referring page, user-agent string.
- Device and browser characteristics: browser type and version, operating system, screen size (used by the page layout at render time only).
- Local preferences: your light/dark theme choice, stored in your browser's local storage — see Cookie Policy.
This website does not run advertising trackers, does not fingerprint visitors, and does not use analytics cookies. If that changes we will update this policy and the Cookie Policy before deploying them.
3.3 Information we never ask for
Please do not send us special-category data (health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation), payment card numbers, or government identity documents by email. If a project genuinely requires such data, we will agree a secure, contracted channel first.
04 How we use information
We use personal data for the following purposes and no others:
- Responding to enquiries. Reading your brief, replying, and preparing a proposal or estimate.
- Delivering services. Designing, developing, testing, releasing and maintaining the agreed product.
- Project administration. Scheduling, progress reporting, change requests and issue tracking.
- Contracting and billing. Producing agreements, invoices, receipts and payment reminders.
- Support and warranty. Investigating defects reported during the warranty period or a care plan.
- Security and integrity. Detecting abuse of our systems, preventing fraud, and keeping audit trails.
- Legal compliance. Meeting tax, accounting, export and other statutory obligations.
- Service communications. Notifying you of changes to our terms, security incidents or the status of your project.
- Business improvement. Understanding which enquiries we can serve well, in aggregate and without profiling individuals.
We do not use your data for automated advertising, do not build behavioural profiles, and do not send marketing email to people who have not asked for it.
05 Legal bases for processing (GDPR)
Where the EU or UK GDPR applies, we rely on the following legal bases:
| Processing | Legal basis |
|---|---|
| Replying to an enquiry you sent us | Legitimate interests, and steps prior to entering a contract |
| Delivering a project under an agreement | Performance of a contract |
| Invoicing, accounting and tax records | Legal obligation |
| Securing our systems and preventing abuse | Legitimate interests |
| Storing your theme preference locally | Strictly necessary for a function you requested |
| Any optional analytics we may add later | Consent, requested before it is set |
| Retaining a portfolio reference to completed work | Legitimate interests, subject to your contractual consent |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that the processing is limited, expected in a business-to-business context, and not overriding of your rights. You may object at any time — see section 11.
06 Cookies and local storage
This website sets no advertising or analytics cookies. It stores a single key in your browser's local storage (altrum-theme) to remember whether you chose the light or dark theme. Nothing in that key identifies you, and it never leaves your device.
Our hosting provider may set strictly necessary cookies for security and load balancing. Full details, including how to clear stored preferences, are in our dedicated Cookie Policy.
07 Sharing and disclosure
We do not sell, rent or trade personal data. We share it only in these circumstances:
- Service providers (processors). Hosting, email, source control, error monitoring, video conferencing, accounting and payment processing vendors who process data on our documented instructions under a written data processing agreement.
- Your own project accounts. Where you have asked us to deploy to, or operate within, infrastructure and store accounts that you control.
- Professional advisers. Lawyers, accountants and auditors, bound by professional confidentiality, where genuinely necessary.
- Legal requirements. Where disclosure is required by law, court order or a valid request from a competent authority. Where we are legally permitted to, we will tell you first.
- Business transfer. If Altrum is involved in a merger, acquisition or asset sale, data may transfer to the successor entity under the same protections; you will be notified before it becomes subject to a different policy.
- With your instruction. Any other disclosure you specifically ask us to make.
A current list of the categories of sub-processors we rely on is available on request from ten20.ae@gmail.com.
08 International transfers
We work with clients and service providers in multiple countries, so personal data may be transferred to, and processed in, jurisdictions outside your own — including the United States and the European Economic Area.
Where personal data protected by the EU or UK GDPR is transferred to a country without an adequacy decision, we rely on appropriate safeguards, principally the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), supported by technical measures such as encryption in transit and at rest. You may request a copy of the relevant safeguards by contacting us.
09 Data retention
We keep personal data only as long as it serves the purpose it was collected for, then delete or anonymise it.
| Data | Retention period |
|---|---|
| Enquiries that do not become projects | 12 months from last contact |
| Active client project records | Duration of the engagement |
| Completed project records & deliverables | 24 months after final delivery, unless the contract says otherwise |
| Contracts, invoices and accounting records | Up to 7 years, as required by tax law |
| Server request logs | Up to 30 days, then deleted or aggregated |
| Access credentials you shared with us | Revoked and deleted at project close-out |
| Recruitment applications | 6 months, unless you ask us to keep them on file |
Backups follow their own rotation and are overwritten on a rolling schedule; data deleted from live systems may persist in an encrypted backup for a short period before it is cycled out.
10 Security measures
We apply technical and organisational measures appropriate to the risk, including:
- Encryption: TLS for all data in transit; encryption at rest on managed cloud storage and developer devices.
- Access control: least-privilege access, individual accounts, and mandatory multi-factor authentication on every system that supports it.
- Credential hygiene: secrets held in a password manager or secret store, never in source control, and rotated when a team member's access ends.
- Environment separation: development and staging environments use synthetic or anonymised data wherever practical, never live production data by default.
- Secure development: peer code review, dependency vulnerability scanning, and secure-by-default configuration for the apps we ship.
- Vendor diligence: we assess the security posture of processors before we adopt them.
- Offboarding: access is revoked and devices are wiped when a team member or contractor leaves a project.
No system is perfectly secure. We cannot guarantee absolute security of data transmitted over the internet, but we can guarantee that we will tell you promptly and honestly if something goes wrong — see section 17.
11 Your rights
Subject to your location and applicable law, you have the right to:
- Access — obtain confirmation of whether we process your data, and a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — ask us to delete data where we no longer have a lawful reason to keep it.
- Restriction — ask us to pause processing while a dispute about accuracy or legitimacy is resolved.
- Portability — receive data you gave us in a structured, machine-readable format, or have it sent to another provider.
- Objection — object to processing based on legitimate interests, including any direct marketing.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
- Complain — lodge a complaint with your supervisory authority (in the UK, the Information Commissioner's Office; in the EU, your national data protection authority).
Making a request
Email ten20.ae@gmail.com with "Privacy request" in the subject. We will acknowledge within 5 business days and respond substantively within 30 days, extendable by a further 60 days for complex requests (we will tell you if that happens). We may ask for proof of identity where we cannot otherwise verify who you are. Exercising these rights is free; we may charge a reasonable fee only for manifestly unfounded or repetitive requests.
12 United States state privacy rights
If you are a resident of California, Colorado, Connecticut, Virginia, Utah or another state with comprehensive privacy legislation, you have rights to know, access, correct, delete, and to opt out of the sale or sharing of personal information and of targeted advertising and profiling.
To be explicit: Altrum does not sell personal information, does not share it for cross-context behavioural advertising, and does not use it for targeted advertising or profiling. There is therefore nothing to opt out of, but you may still exercise your access, correction and deletion rights using the process in section 11. We will not discriminate against you for exercising any privacy right. You may use an authorised agent to submit a request on your behalf, with written proof of authorisation.
13 Children's privacy
Our website and services are directed at businesses and are not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
Where a client engages us to build an app aimed at children, we implement the applicable requirements — including COPPA in the United States, the UK Age Appropriate Design Code, and the Apple and Google kids-category policies — as part of the project scope.
14 Applications we build for clients
When we develop or maintain an application for a client, that client is the data controller for the app's end-user data and Altrum acts as a processor. In that role we:
- Process end-user personal data only on the client's documented instructions.
- Enter into a data processing agreement setting out subject matter, duration, nature and purpose of processing.
- Impose confidentiality obligations on every person we authorise to access the data.
- Assist the client with data subject requests, impact assessments and breach notification.
- Engage sub-processors only with the client's authorisation, and remain liable for their performance.
- Delete or return the data at the end of the engagement, at the client's election.
If you are an end user of an app we built and have a privacy request, please contact the company that publishes the app. If you are unsure who that is, write to us and we will point you in the right direction.
15 Automated decision-making and AI
We do not make decisions producing legal or similarly significant effects about you by automated means alone. Every proposal, estimate and hiring decision involves human judgement.
Our engineers may use AI-assisted development tools. Where we do, we use business or enterprise tiers configured so that client content is not used to train third-party models, and we do not paste client credentials, end-user personal data or confidential materials into consumer AI services. If a client prohibits AI tooling in their agreement, we honour that across the engagement.
16 Third-party links and services
Our website loads a web font from Google Fonts, which may involve a request to Google's servers containing your IP address and user-agent. No cookie is set by that request. Pages may also link to external sites such as app store listings. We are not responsible for the privacy practices of third-party sites, and we encourage you to read their policies.
17 Data breach notification
We maintain an incident response process covering detection, containment, assessment and notification. If a personal data breach is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it.
- Notify affected individuals without undue delay where the risk to them is high.
- Tell you what happened, what data was involved, what we have done, and what you should do.
- Where we act as a processor for a client, notify that client without undue delay so they can meet their own obligations.
18 Changes to this policy
We review this policy at least annually and whenever our processing changes materially. The effective date at the top of the page always reflects the current version. For material changes we will give prominent notice on this website and, where we hold your contact details and the change affects you, by email — at least 14 days before the change takes effect where practical. Continuing to use our website or services after a change takes effect means you accept the revised policy.
19 How to contact us
For any question about this policy, to exercise a right, or to raise a concern about how we have handled your data:
Email: ten20.ae@gmail.com
Subject line: "Privacy request"
Acknowledgement within 5 business days · substantive response within 30 days
If you are not satisfied with our response, you have the right to complain to your local data protection authority. We would appreciate the chance to resolve it with you first.