Alaro Ltd

Privacy Policy

Last updated: 24 August 2026

1. Introduction

Alaro ("Alaro", "we", "us" or "our") is an AI-native legal services firm. We are committed to protecting the personal data of our clients, prospective clients, counterparties, and visitors to our platform and website (together, "you").

This Privacy Policy explains how we collect, use, share, and retain personal data in connection with our legal services, our platform, and our website. It also sets out your rights under applicable data protection law.

Alaro operates as an AI-augmented legal practice. Some of our services involve the use of artificial intelligence tools to assist with legal analysis, document review, and client communications. Where AI processing involves personal data, we explain this below.

2. Who We Are

Alaro is the data controller in respect of personal data processed under this Privacy Policy.

Contact details:

Contact details
Name Alaro Ltd (Company No. 15576861)
ICO Registration No. [To be inserted upon ICO registration]
Address Labs, 90 High Holborn, London, England, WC1V 6LJ
Email hello@alaro.ai
Website alaro.ai

Our Data Protection Officer ("DPO") can be contacted at: hello@alaro.ai.

3. Personal Data We Collect

We collect personal data in the following categories, depending on the nature of our relationship with you.

3.1 Client and Matter Data

When you engage us as a client, or when your matter involves you as an individual, we may collect:

  • Identity information: name, title, date of birth, nationality, government-issued identification documents;
  • Contact information: email address, telephone number, postal address;
  • Professional information: employer, role, professional qualifications, company registration details;
  • Financial information: billing details, bank account information, invoicing records;
  • Matter-specific information: facts, correspondence, documents, and other information you provide or that is generated in the course of us advising you;
  • Know Your Client ("KYC") and anti-money laundering ("AML") verification data, including identity documents and source-of-funds information.

3.2 Platform and Account Data

When you access our platform, we may collect:

  • Login credentials and account profile information;
  • Usage data: pages accessed, features used, timestamps, session duration;
  • Device and technical data: IP address, browser type and version, operating system, device identifiers;
  • Communications sent through the platform, including messages and document uploads.

3.3 Prospective Client and Business Development Data

When you contact us to enquire about our services, we may collect:

  • Name and contact details;
  • Information about your legal needs or organisation;
  • Records of correspondence and meetings.

3.4 Counterparty and Third-Party Data

In the course of a matter, we may receive personal data about counterparties, witnesses, or other individuals from our clients or from publicly available sources. We process this data solely to the extent necessary for the matter.

3.5 Website and Cookie Data

When you visit our website, we may collect:

  • Technical usage data (see Platform and Account Data above);
  • Information you submit through contact or enquiry forms.

For information about cookies, see Section 11 below.

4. How We Collect Personal Data

We collect personal data:

  • Directly from you, when you engage our services, create an account, contact us, or use our platform;
  • From your organisation, where your employer or another authorised party provides your details in connection with a matter;
  • From third parties, including counterparties, courts, regulators, public registers, and credit reference or identity verification agencies;
  • Automatically, through our platform and website using cookies and similar technologies.

5. How We Use Personal Data

We use personal data for the following purposes and on the following legal bases under the UK General Data Protection Regulation ("UK GDPR") and, where applicable, the EU General Data Protection Regulation ("EU GDPR").

Purposes and legal bases for processing personal data
Purpose Legal Basis
Providing legal services and advice Performance of a contract; our legitimate interests in providing professional legal services
Managing the client relationship, billing and administration Performance of a contract; our legitimate interests
Compliance with legal and regulatory obligations (including KYC/AML, professional conduct rules, and court orders) Legal obligation
Protecting our legal rights and interests, including in disputes Legitimate interests; legal obligation
Communicating with you about your matter and our services Performance of a contract; legitimate interests
Improving and maintaining our platform and services Legitimate interests
Marketing our services to existing and prospective clients (where permitted) Consent (where required); legitimate interests
Security, fraud prevention and incident management Legitimate interests; legal obligation
AI-assisted legal analysis and document processing (see Section 6) Performance of a contract; legitimate interests
Anonymised analytics and service improvement Legitimate interests

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and interests. You may request further information about this assessment.

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

6. AI-Assisted Processing

Alaro uses artificial intelligence tools as part of how we deliver legal services. This section explains how AI is used and the safeguards we apply.

6.1 How We Use AI

Our platform uses AI to assist with:

  • Legal research and analysis;
  • Document review, summarisation and drafting;
  • Identification of issues and risks in client materials;
  • Internal workflow management and communication.

AI tools are used to assist our legal professionals; they do not replace lawyer oversight or judgment. All substantive legal advice is reviewed and approved by qualified lawyers before delivery.

6.2 Automated Decision-Making

We do not use fully automated decision-making (without human review) to make decisions that produce legal or similarly significant effects about you.

Where AI tools produce outputs that inform advice or decisions affecting you, a qualified lawyer reviews those outputs before they are communicated to you.

6.3 AI Sub-processors

We use third-party AI providers as sub-processors. Details of those providers are available on request. We apply appropriate contractual, technical, and organisational safeguards to govern AI processing of personal data.

7. Data Sharing

We share personal data only as necessary for the purposes described in this Policy.

7.1 Within Alaro

Personal data may be accessed by Alaro lawyers, legal professionals, and support staff working on your matter or on our platform.

7.2 With Service Providers and Sub-processors

We engage third-party service providers and technology vendors who process personal data on our behalf, including:

  • Cloud infrastructure and hosting providers;
  • AI and machine learning providers;
  • Identity verification and KYC providers;
  • Document management and collaboration platforms;
  • Billing and payments processors;
  • IT security and monitoring services.

We enter into data processing agreements with all sub-processors and require them to implement appropriate technical and organisational measures.

7.3 With Counterparties and Third Parties

In the course of providing legal services, we may share information with counterparties, courts, tribunals, regulatory bodies, or other advisers where necessary for your matter.

7.4 Legal and Regulatory Disclosure

We may disclose personal data where required by law, regulation, court order, or to comply with our professional regulatory obligations (including those of the Solicitors Regulation Authority or equivalent body).

7.5 Business Transfers

If Alaro undergoes a merger, acquisition, or sale of all or part of its business, personal data may be transferred to the relevant third party as part of that transaction, subject to appropriate safeguards.

We do not sell personal data to third parties.

8. International Transfers

Personal data that we collect may be transferred to, and processed in, countries outside the United Kingdom or European Economic Area ("EEA"). Where we transfer personal data to a country that does not provide an equivalent level of data protection, we ensure appropriate safeguards are in place, including:

  • UK International Data Transfer Agreements ("IDTAs") or EU Standard Contractual Clauses ("SCCs") as applicable;
  • Adequacy decisions issued by the UK Secretary of State or the European Commission; or
  • Other appropriate transfer mechanisms permitted by applicable law.

A list of the countries to which we transfer data and the applicable safeguards is available on request.

9. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, and in accordance with our legal and regulatory obligations.

Data retention periods
Category Retention Period
Client matter files and correspondence 6 years from closure of the matter (or longer where required by law or professional rules)
KYC/AML records 5 years from the end of the business relationship
Platform usage logs 12 months, unless retained longer for security or legal purposes
Marketing contact records Until withdrawal of consent or objection
Website analytics data 26 months

Where personal data is no longer required, we securely delete or anonymise it in accordance with our data retention schedule.

10. Your Rights

Under UK GDPR (and EU GDPR where applicable), you have the following rights in relation to your personal data:

Your data protection rights
Right Description
Access To request a copy of the personal data we hold about you
Rectification To request correction of inaccurate or incomplete personal data
Erasure To request deletion of your personal data in certain circumstances
Restriction To request that we restrict processing of your personal data
Portability To receive your personal data in a structured, machine-readable format
Objection To object to processing based on legitimate interests or for direct marketing
Withdraw consent To withdraw consent at any time where processing is based on consent
Automated decision-making To request human review of any significant automated decision

To exercise any of these rights, please contact us at hello@alaro.ai. We will respond within one month of receipt of your request (which may be extended by a further two months for complex requests, with notice to you).

You will not ordinarily be charged for exercising your rights. We may ask you to verify your identity before processing your request.

You have the right to lodge a complaint with the Information Commissioner's Office ("ICO") at www.ico.org.uk (for UK residents) or your local supervisory authority (for EEA residents) if you believe we have not complied with applicable data protection law. We would, however, welcome the opportunity to address your concerns directly before you contact a supervisory authority.

11. Cookies

Our website and platform use cookies and similar tracking technologies to improve your experience and to analyse usage.

11.1 Types of Cookies We Use

Types of Cookies We Use
Type Purpose
Strictly necessary Required for the platform and website to function; cannot be disabled
Functional Remember your preferences and settings
Analytics Collect anonymised usage statistics to improve our services
Marketing Used to deliver relevant content and, where permitted, targeted advertising

11.2 Managing Cookies

You can control and manage cookies through your browser settings and through our cookie consent tool, available on our website. Please note that disabling certain cookies may affect the functionality of our platform or website.

For further information about cookies, please see our full Cookie Policy at alaro.ai/cookie-policy.

12. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit and at rest;
  • Access controls and role-based permissions;
  • Regular security assessments and penetration testing;
  • Staff training on data protection and information security;
  • Incident response and breach notification procedures.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO (or relevant supervisory authority) within 72 hours and notify affected individuals without undue delay where required.

13. Children

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected personal data from a child, please contact us at hello@alaro.ai and we will take steps to delete it.

14. Third-Party Links

Our website or platform may contain links to third-party websites or services. This Privacy Policy does not apply to those third-party sites. We encourage you to read their privacy policies before providing any personal data to them.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Where we make material changes, we will notify you by email or by a prominent notice on our platform or website, and update the "Last Updated" date at the top of this Policy.

We encourage you to review this Policy periodically.

16. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, or if you wish to exercise your rights, please contact:

Data Protection Officer
Alaro Ltd
Labs, 90 High Holborn, London, England, WC1V 6LJ
Email: hello@alaro.ai

This Privacy Policy is governed by the laws of England and Wales.