Privacy Policy
Last updated: 3 October 2026
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal Data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
Interpretation and Definitions
Interpretation
The words of which the initial letter is capitalised have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
- Account means a unique account created for You to access the Service or parts of the Service.
- Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to NordStack Ltd, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. For the purpose of the GDPR, the Company is the Data Controller of Account and Usage Data only, and a Data Processor of Workspace Content, as set out under "Who Is Responsible for Workspace Content" below.
- Customer means the person or organisation that created a workspace on the Service, acting through its administrators.
- Workspace Content means everything put into a workspace by the Customer and the people it lets in: projects, tickets, comments, attachments, imported data and the Personal Data they contain.
- Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
- Data Controller refers to the legal person which alone or jointly with others determines the purposes and means of the processing of Personal Data.
- Device means any device that can access the Service such as a computer, a mobile phone or a digital tablet.
- Personal Data is any information that relates to an identified or identifiable individual. For the purposes of GDPR, Personal Data means any information relating to You such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity.
- Service refers to the Alba Ticket website, accessible from https://albaticket.com and the workspace addresses under it or on a customer's own domain.
- Service Provider means any natural or legal person who processes the data on behalf of the Data Controller. It refers to third-party companies or individuals employed to facilitate the Service, to provide the Service on behalf of the Data Controller, to perform services related to the Service or to assist in analysing how the Service is used. For the purpose of the GDPR, Service Providers are considered Data Processors.
- Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself.
- You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Who Is Responsible for Workspace Content
Each workspace belongs to its Customer. The Customer decides what is put into it, who may see it, how long it is kept and when it is deleted, and is the Data Controller of the Personal Data in its Workspace Content. The Company stores and processes Workspace Content only to provide the Service, on the Customer's instructions as given through the Service, and is a Data Processor of it. The Company does not read, use or disclose Workspace Content for its own purposes.
It follows that the Customer, not the Company, is responsible for having a lawful basis for the Personal Data it puts into its workspace, including data about its own customers, staff and anyone named in imported data; for telling those people how their data is used; and for answering their requests about it. If Your Personal Data is held in a workspace You do not administer, direct Your request to that workspace's administrators. The Company will pass on to the Customer any such request it receives, and will help the Customer answer it where the Service does not already let the Customer do so itself.
The Company is the Data Controller only of the little it needs to run the Service: the name and email address given at sign-up, the details of Accounts, and Usage Data.
Collecting and Using Your Personal Data
Types of Data Collected
Personal Data
While using the Service, You may be asked to provide certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:
- Email address
- Display name
- When You last logged in or used the Service, Yourself or through an AI agent You connected, kept to the hour, which is how the seats a workspace pays for or a licence allows are counted
- The AI agents and access tokens You have connected, as described under "AI Agents" below
- Details received from Your organisation's single sign-on provider, where one is used
- The address of a calendar account You connected, and the keys to it (for iCloud, Your Apple ID and an app-specific password), as described under "Calendars" below
- Where a workspace keeps You among its contacts: Your name, addresses, phone numbers and what its members recorded about their dealings with You, as described under "People in a Workspace's Contacts" below
- The time You log: what You worked on, when, for how long, with which labels and on which ticket, project or customer, and every later change to it; and, where a workspace bills its customers, the billing email address and postal address of a customer organisation and the company details an administrator enters, all of which are printed on the invoices the workspace generates and stored nowhere else
- Personal Data contained in imported data, such as the names and email addresses of people recorded in a Jira backup, a CSV file or another CRM's export, or the names of people who wrote the issues and comments of a GitHub or GitLab repository an administrator imports, which the Service reads from that host with the token they give it; and the files of a folder in a GitHub or GitLab repository an administrator connects to a knowledge base space, which the Service reads from the host they name, with the token they give it, when the repository is pushed to, when they ask, and once a night
- Usage Data
Usage Data
Usage Data is collected automatically when using the Service. Usage Data may include information such as Your Device's Internet Protocol address (IP address), browser type, browser version, the pages of the Service that You visit, the time and date of Your visit, the time spent on those pages and other diagnostic data. Your browser also names its time zone when a page connects; the Service uses it only to show times on that page in Your zone and does not keep it.
Tracking Technologies and Cookies
The Service uses Cookies to manage Your login status only, and Your browser's local storage to remember Your display preferences. Neither is used to track You across websites. The types used:
- Necessary / Essential Cookies: These Cookies are essential to provide You with services available through the Service and to enable You to use some of its features. They help to authenticate users and prevent fraudulent use of user accounts. Without these Cookies, the services that You have asked for cannot be provided.
- Functionality Cookies: A Cookie keeps You logged in between visits when You ask for that at login. An administrator who switches on request logging in the system dashboard receives a Cookie that marks their own requests.
- Local storage: Your chosen colour theme and whether the project menu is expanded are kept in Your browser's local storage. When the Service is updated while a page is open, the time that page reloaded itself is kept in the tab's session storage until the tab is closed, so that it does not reload twice. While a dialog with a form is open (a new ticket, for example), what You type in it is kept in the tab's session storage too, so that it can be put back if the connection drops or the page reloads; it is removed when You send or close the dialog, is never kept for a password, and goes when the tab is closed. They stay on Your Device and are not sent to the Service.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
- To provide and maintain the Service, including to monitor the usage of the Service.
- To manage Your Account: to manage Your registration as a user of the Service, and to keep how You have arranged what You see (such as which swimlanes You collapsed on a board) with Your Account, so that pages look the same on any Device. These settings are deleted with Your Account, and a board's with the board.
- To attribute work: to show who created, changed, commented on or is assigned to tickets, and to keep that history when data is imported from another system.
- To contact You: To contact You by email regarding updates or informative communications related to the Service, including notifications about tickets You watch and security updates.
- To manage Your requests: To attend to and manage Your requests.
- For other purposes: We may use Your information for other purposes, such as data analysis, identifying usage trends, and to evaluate and improve the Service.
Retention of Your Personal Data
Workspace Content is kept for as long as the Customer keeps it. When a workspace is deleted, by its administrators or on termination, everything in it is deleted with it: tickets, comments, attachments, contacts and what was recorded about them, the email it sent and received, the keys to any calendar a member connected, Accounts, settings, imported data and the search index. The Company keeps no copy and cannot restore it; what remains in routine backups is never restored into the Service and disappears as those backups expire. The Company retains the Personal Data it controls only for as long as is necessary for the purposes set out in this Privacy Policy, or to comply with legal obligations, resolve disputes and enforce its agreements.
Public Request Forms
A workspace may open a request form to people with no account, so that a form on its own website raises a request in it. If You send such a form in, the workspace You sent it to is the Data Controller for what You typed, and the Company processes it on that workspace's behalf. What is kept is the name and email address You gave and the request itself. No account is created and no password is set: You cannot log in, and until You answer through the link, nothing has been done to check the address is Yours.
A request form, public or in the help centre, may suggest help articles as You type. When You open one, the workspace keeps which article it was, which form, when, and whether a request was then sent from that form, so it can count how often its articles answer a question. On a public form nothing that identifies You is kept with it; in the help centre it is kept with Your account.
When somebody answers Your request, the reply and a link to the request are emailed to the address You gave. The link is signed rather than stored, names that one request, and stops working after thirty days, if the request is deleted, or if the workspace is moved to another installation. Anyone holding the link can read that request and answer it, so treat it as You would a password and do not forward the email. Answering through the link is what shows the address is Yours, and at that point an account is created for You in that workspace, unless that workspace only creates accounts by invitation.
The contact form on Our own website is one of these forms, in a workspace We run. For that one the Company is the Data Controller, and what You type reaches Our support team as a request like any other.
To stop a form being sent in by machines, the Software counts how many requests an address, and the connection it came from, have raised in the last hour, on the server answering it. What is counted is a scrambled form of each, from which neither can be read back; the count is held in memory, never written down, and discarded as the hour passes. No check is made with any other company, and the page loads nothing from one.
Email Sent to a Workspace
A workspace may receive email: a reply to a notification it sent, a message to an address one of its forms answers at, or a message a member logs on a contact. When You write to such an address, the message is kept whole, headers, text and attachments alike, in that workspace's object storage, with a record of who sent it, who it was for, when it arrived and what became of it. It is Workspace Content, kept and deleted with the workspace, and seen by the workspace's administrators and by whoever may see the ticket or contact it became part of. Nothing is kept outside the workspace.
A message is checked before it becomes anything: what the receiving provider reports about the sender's domain (SPF, DKIM and DMARC) and whether it called the message spam, whether it is an automatic reply, a delivery report or the workspace's own, how many messages the sender has written in the last hour, and its size. A message that fails a check is set aside and recorded rather than silently dropped; an administrator of the workspace sees it, and may let it in or leave it.
A member of a workspace may log email on a contact by sending or forwarding it to an address of their own in that workspace, and may write to a contact from the workspace. A message written there is sent through the same mail server as every other email the workspace sends, under the member's name, and a copy is kept with the contact. Both are Workspace Content: they are seen by the people in that workspace who may see its contacts, never by its customers, and are kept and deleted with the workspace. The Service reads only the mail sent to it in these ways; it has no access to anybody's mailbox.
On the hosted service, mail to a workspace's address is received by Postmark (Wildbit LLC, an ActiveCampaign company), an email provider acting for the Company, which hands the message to the Service over an authenticated connection and keeps its own copy for the shortest time its plan allows, never longer than its default of 45 days. A workspace may instead receive at an address and provider of its own, in which case that provider is the workspace's.
People in a Workspace's Contacts
A workspace may keep contacts: the people it deals with, who need not have an Account and may never have used the Service. For each of them it may hold a name, a job title and a company, email addresses, phone numbers and postal addresses, notes and fields of its own, the calls, meetings, emails and tasks its members recorded about them, the deals they are named on, and the requests they raised. All of it is Workspace Content: it is seen by the people in that workspace who may see its contacts, never by its customers, and is kept and deleted with the workspace.
Consent. A workspace may record what a contact agreed to, purpose by purpose (marketing email, a newsletter, or a purpose of its own): whether it was granted or withdrawn, how the answer reached the workspace, when, and who recorded it. An answer is never changed or removed while the contact is kept; a later answer is added beside it, so the record shows what was agreed at any time. A message a member sends from the workspace for such a purpose is sent only when the contact's latest answer for it is yes. The Service does not judge whether a message is marketing, nor whether a workspace may hold a person's data: both are the workspace's to decide.
A copy. A member who manages the workspace's contacts can make a copy of everything it holds about one person: their details, the record of their consent, what was recorded about them, the email to and from them, the requests they raised, the comments they wrote and the help articles they opened from a request form. The copy is a file in the workspace's own object storage, downloaded by a link that lasts a quarter of an hour, and is deleted 24 hours after it was made.
Erasure. The same member can erase one person. Their details, addresses, phone numbers, the record of their consent, what was recorded about them alone, the email to and from them that is part of no other person's record, any copy made of their data, the events the Service added to members' calendars for calls and meetings with them, and the record of where they were imported from are deleted: from the database at once, and from object storage and those calendars shortly afterwards. If they had an Account it is deleted with them, and they can no longer log in. The requests they raised and the comments they wrote remain, because they are the workspace's record of its own work, but under the words "Removed contact", with no name and no address, and the history of those requests names them the same way. What is kept about the erasure is that it happened, who did it and when, and nothing about the person. The help articles they opened from a request form stay counted, as a public form's are, with nothing that names them. Erasure does not read free text: where somebody else wrote the person's name into a description or a comment, it stays until the workspace edits it.
If You are a person in a workspace's contacts, that workspace's Customer is the Data Controller of Your Personal Data and the Company its Data Processor, as described under Who Is Responsible for Workspace Content. Ask the Customer what it holds about You, to correct it or to erase it; the Company will pass on any such request it receives. What an erasure removed from the Service remains in routine backups until they expire, and is never restored from them into the Service.
Calendars
A member of a workspace may connect their own calendar at Google, Microsoft or Apple (iCloud) to it, where its administrators have set the provider up or, for iCloud, switched it on. Nothing is connected unless the member does so: for Google and Microsoft on the provider's own page, where they agree to what the Service may do, which is to see the events on that calendar and add events of its own; for iCloud, which has no such page, by giving the Service their Apple ID and a password they made at Apple for this one purpose (an app-specific password, never the Apple ID's own). They may disconnect it at any time. While a calendar is connected, the Service asks the provider, about every quarter of an hour, for the events from two days back to sixty days ahead, and of each it asks only when it is and who is invited. Where an invited address belongs to a contact of the workspace, the Service reads that event's title and description and keeps them, with its time and the people invited, as a meeting in that contact's record, which is Workspace Content like the rest of the record. An event with no contact among the people invited is not read further, and nothing about it is kept. iCloud is asked the same way, but may send the whole of an event where only its time and the people invited were asked for; the Service then takes those two from what it was sent, discards the rest unread, and keeps nothing of an event with no contact. In the other direction, a call or meeting the member schedules in the workspace is added to their calendar, with its subject, its time, the member's notes and the name of the contact and company it is with, so that much is sent to the provider the member chose. Nobody is invited or written to by the Service.
For each connection the Service keeps the address of the calendar account and the keys the provider issued or, for iCloud, the Apple ID and the app-specific password, encrypted; they are never shown, never included in an export of the workspace, and deleted when the member disconnects or the workspace is deleted. Disconnecting withdraws the Service's access at Google; Microsoft lets only the account's owner withdraw an application's access, which the member does in their Microsoft account, and an app-specific password is removed only by its owner, in their Apple Account. The Apple ID and the password are sent to Apple's iCloud servers and nowhere else. Google, Microsoft and Apple handle the member's calendar under their own terms with the member, and receive from the Service only the requests described here. On the hosted service the application a member agrees to at Google or Microsoft is the Company's, unless the workspace has entered one of its own.
AI Agents
A member may let an AI agent, such as Claude, ChatGPT or Cursor, or a script of their own, read and work on tickets for them, through the Service's API and its MCP endpoint. The agent acts as that member and can see only what they can see. What it reads, which may include Personal Data in tickets and comments and, where the member may see the workspace's contacts, the details of the people in them, is sent to the agent, and so to whoever runs it: where the agent is an application on its maker's servers, that maker receives it under its own terms and privacy policy. The Service sends nothing to any agent by itself; it answers the requests an agent makes with the member's permission, and makes no request to the agent or its maker. Choosing to connect an agent is the member's decision, within the rules of the workspace, whose administrators switch the API and the MCP endpoint on, each by itself; both are off until they do.
For each agent or token a member connects, the Service keeps its name, the name and return addresses an application gave when it registered, whether it may only read or also make changes, when it was added, when it expires and when it was last used, kept to the hour. Tokens themselves are kept only in a scrambled form from which they cannot be read back, so the Service cannot show one again once it has been made. Changes an agent makes are recorded in the ticket's history under the member's name with the agent's name beside it. To limit the load an agent can cause, and the rate at which applications can register, the server answering counts requests in memory, per token and per scrambled address; the counts are never written down and are discarded after an hour at most. Revoking an agent, or the member's account ceasing to be one that can log in, stops it at once; its record is deleted when it is revoked or with the workspace, and is never included in an export.
The Licence Portal
People who run the Software on their own servers manage their licences in the licence portal on Our website. A portal account is separate from any workspace. For it the Company is the Data Controller, and keeps: the email address You log in with, which also receives login links and messages about Your licences; when You last logged in; the licences issued to You, with the name of the organisation each is for, its dates and its limits; and the requests You make to change them, with any note You add. A licence key states the same organisation name and email address, signed, and nothing else about You. The portal sets only the session cookie that keeps You logged in, and is not measured by analytics. An installation of the Software never reports to the portal: what You run, and how many people use it, stays on Your servers. To have a portal account and its licences removed, contact Us.
Transfer of Your Personal Data
Your information, including Personal Data, may be transferred to, and maintained on, computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ. The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy.
Disclosure of Your Personal Data
Law enforcement
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities.
Other legal requirements
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
- Comply with a legal obligation
- Protect and defend its rights or property
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of Users of the Service or the public
- Protect against legal liability
Security of Your Personal Data
The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.
Third-Party Service Providers
We use infrastructure, object storage and email delivery providers to run the Service. They process data only on Our behalf, under contract, and only as needed to provide the Service. We do not use advertising services.
Payment
Payments are taken by Stripe, which is the payment processor for the hosted Service and for self-hosted licences. When You buy a plan or a licence We send You to a page hosted by Stripe: card details are entered there and never reach Our servers, and no page of Ours loads anything belonging to Stripe. Managing a card, an invoice or a cancellation happens on Stripe's own pages too.
For a purchase, Stripe receives the email address of whoever buys, the name of the workspace or of the licensee, the name and address You give it, Your VAT or tax number if You enter one, and the payment itself. It also receives what is being charged for, as numbers: how many members a workspace has, or how many a licence allows, together with Our own identifier for the workspace or the licence account, which is how a payment finds its way back to You. Stripe acts as a data controller for that under its own privacy policy. What We keep is what We need to bill You and to answer questions about it: the identifiers Stripe gives Us for Your customer record and Your subscription or invoice, which plan You are on, how often You are charged, when the period ends, and the number of members, counted each night. We keep no card number, no part of one, and no bank details.
The member and agent counts are numbers, not lists: We store how many there were, not who they were. Your invoices are held by Stripe and shown to You from there, not copied into the Service.
If You delete Your workspace, the subscription that pays for it is cancelled before the workspace is removed. Stripe keeps Your customer record and Your invoices for as long as the law requires it to, which is not something We can shorten.
The Demo Workspace
The demo workspace at demo.albaticket.com is open to everyone: its logins are published, so whatever is typed or uploaded there can be read by any other visitor until it is erased, which happens every hour. Do not put Personal Data or anything confidential into it. The demo sends no email, and no calendar, mailbox, code repository, storage or single sign-on provider can be connected to it.
Analytics
We count visits to the public pages of the Service (the home page, the documentation, the sign-up form and the page shown before You log in) with Plausible Analytics, a privacy-focused analytics service. It sets no Cookies, keeps no persistent identifier and does not store Your IP address, and the address of the page is recorded without anything after a question mark. Nothing is measured once You are logged in: no page inside a workspace, and nothing about tickets, projects or the people who work on them, is sent.
GDPR Privacy
Legal Basis for Processing Personal Data
Personal Data may be processed under the following conditions:
- Consent: You have given Your consent for processing Personal Data for one or more specific purposes.
- Performance of a contract: Provision of Personal Data is necessary for the performance of an agreement with You.
- Legal obligations: Processing Personal Data is necessary for compliance with a legal obligation.
- Vital interests: Processing Personal Data is necessary to protect Your vital interests or those of another natural person.
- Legitimate interests: Processing Personal Data is necessary for the purposes of the legitimate interests pursued by the Data Controller.
Your Rights under the GDPR
You have the right to:
- Request access to Your Personal Data
- Request correction of any incomplete or inaccurate Personal Data
- Request erasure of Your Personal Data
- Object to processing of Your Personal Data
- Request restriction of processing of Your Personal Data
- Request transfer of Your Personal Data
- Withdraw Your consent
You may exercise these rights by contacting Us. You may be asked to verify Your identity before a response is given. You have the right to complain to a Data Protection Authority about the collection and use of Your Personal Data.
Links to Other Websites
The Service may contain links to other websites that are not operated by Us. We strongly advise You to review the Privacy Policy of every site You visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party sites or services.
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time. Changes are published on this page with a new "Last updated" date and take effect when published. Where a change materially reduces Your rights We will make reasonable efforts to tell workspace administrators by email beforehand; We do not send notices of minor changes. You are advised to review this Privacy Policy periodically.
Contact Us
If You have any questions about this Privacy Policy, You can contact Us by email: support@albaticket.com