Last updated: August 19, 2026
This policy explains what personal data AlertKick Ltd collects, why, on what legal basis, who we share it with, how long we keep it, and the rights you have. If you are a customer sending us monitoring data about your own systems and people, the Data Processing Agreement governs that data; this policy covers everything else.
AlertKick Ltd (company number 17201100), registered office 25 Watery Lane, Northolt, UB5 6QL, United Kingdom, operates the AlertKick service at alertkick.com and the AlertKick mobile app ("AlertKick", "we", "us"). We are the controller for the personal data described in this policy. Contact our privacy team at privacy [at] alertkick [dot] com .
We handle personal data in two different roles:
Name, email address, password (stored only as a hash), phone number if you enable SMS or WhatsApp alerts, time zone, role, on-call schedule, notification preferences, mobile device push tokens, and, if you sign in with GitHub or Google, the name, email, and provider user ID they give us. Used to create and secure your account, deliver alerts to you, and run on-call rotas.
Billing name and address, VAT number, plan, invoices, and payment status. Card details are entered directly into and held by Stripe; we see only the card brand, last four digits, and expiry. Used to charge for paid plans and keep financial records.
IP address, browser and device information, sign-in times and outcomes, pages and features used, API calls, agent versions and heartbeat status, error reports, and support requests. Used to keep the service secure (for example rate limiting and blocking abusive sources), diagnose problems, understand which features are used, and improve the service. On the marketing website, and only if you consent, Microsoft Clarity records anonymised usage (clicks, scrolling, session replays with typed text masked) so we can improve the site; Microsoft is listed on our sub-processor page.
Emails and support conversations with us, and messages you send through the contact form. Used to answer you and keep a record of what was agreed.
Described in section 2 and in Annex I of the DPA. We use it only to provide the service to the customer who sent it. We also derive aggregated statistics that do not identify anyone (for example counts of detections by rule) to operate and improve the service.
If you sign up for our newsletter or register interest, your email address and name, and whether you opened or clicked our emails. Used to send you the content you asked for. Every email has an unsubscribe link. We do not buy marketing lists and do not send marketing SMS.
Under UK GDPR and EU GDPR we rely on:
Some features use large language models to analyse events, triage alerts, and write incident summaries. Inference runs on Amazon Bedrock in the EU (Ireland). Inputs and outputs are not used by Amazon or by us to train models, and are not retained by Amazon after the request completes. AI output is advisory; the customer's team decides what to do with it, and the Terms of Service explain its limitations. We do not make decisions about individuals that produce legal or similarly significant effects by automated means.
We do not sell personal data and do not share it with third parties for their own marketing. We share it only with:
When a customer connects a messaging integration, we store the credentials and identifiers needed to deliver alerts to that service. For Slack this means the workspace ID, bot token, and channel identifiers. When a workspace member acknowledges or resolves an alert from Slack, or talks to the bot, we look up that member's email address to attribute the action to the matching AlertKick user in the audit trail; the email is used only for that matching. When the bot is mentioned in a thread it reads that thread's replies to answer with context; it does not read or store other messages. Integration data is used only to deliver and respond to alerts, is deactivated as soon as the integration is disconnected or the app is uninstalled, and is removed when the account is deleted. We never use integration data for advertising.
Customers choose a home region when they create an account: EU (Finland) or US (Virginia). Account and monitoring data is stored on dedicated servers in that region. We are a UK company and access data from the UK to operate and support the service; the UK is covered by an EU adequacy decision, and the EEA by UK adequacy regulations.
Some of our sub-processors are in the United States or operate globally. Where personal data is transferred outside the UK or EEA, we rely on an adequacy decision (including the EU-US Data Privacy Framework and its UK Extension for certified providers) or on the European Commission's standard contractual clauses together with the UK International Data Transfer Addendum, plus additional safeguards where needed. You can ask us for details of the mechanism used for a particular provider.
We encrypt all traffic in transit, store passwords only as salted bcrypt hashes, encrypt integration credentials at rest, isolate every tenant by subdomain, restrict production access to named operators over a private VPN, and monitor our own infrastructure with AlertKick. The full list of technical and organisational measures is in Annex II of the DPA and summarised on the security page. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you and any relevant regulator as the law requires.
Depending on where you are, you have the right to:
To exercise a right, email privacy [at] alertkick [dot] com from the address on your account or with enough information for us to verify you. We respond within one month, extendable by two further months for complex requests, and do not charge unless a request is manifestly unfounded or excessive. If your request concerns monitoring data sent to us by a customer, we will pass it to that customer and help them respond.
The marketing website sets no cookies of its own and stores your theme and cookie choice in your browser's local storage. With your consent, and only then, it loads Microsoft Clarity for usage analytics; you can accept or reject this in the cookie banner and change your mind at any time. The application sets strictly necessary cookies for sign-in sessions, CSRF protection, and remembering your account subdomain. Details are in the Cookie Policy.
The service is for businesses and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
We will post changes on this page and update the date at the top. For material changes we will also notify account administrators by email or with a notice in the service before they take effect.
AlertKick Ltd
25 Watery Lane, Northolt, UB5 6QL, United Kingdom
Privacy team: privacy [at] alertkick [dot] com
We will respond within 30 days. If you are unhappy with how we handle your data you can complain to the UK Information Commissioner's Office (ico.org.uk) or, if you are in the EEA, to your local data protection authority. We would appreciate the chance to address your concern first.