Privacy Policy
1. Who we are and what this policy covers
Effective date: September 30, 2026
Alémar Advisors, Inc. (“Alémar,” “we,” “us” or “our”) is a Delaware corporation with its principal business address at PO Box 4554, Park City, UT 84060, USA. We collect very little personal information, and this policy explains what we collect, why, who we share it with, and the choices you have.
This policy applies to https://alemaradvisors.com (the “Site”) and to information we receive from people who contact us, including prospective customers and prospective advisors. If you are in the European Economic Area (EEA), the United Kingdom or Switzerland, Alémar is the “controller” of your personal data under the GDPR and UK GDPR.
Questions or requests about your information can be sent to privacy@alemaradvisors.com.
2. Information we collect
We collect information in two ways: information you give us, and information collected automatically when you use the Site.
Information you give us. When you use our contact form, we collect your name, email address, company or organization, your role, the type of contact you are (for example, prospective customer or prospective advisor), how you heard about us, and whatever you write in your message. If you contact us as a prospective advisor, we also ask for your LinkedIn profile, areas of expertise and availability. Everything you enter in the form is stored in our CRM (see section 5). If you tick the box to receive updates from us, we record that choice. If you are a prospective customer or prospective advisor, we may also collect information you share with us by email, on calls, or in documents as we discuss working together, such as your role, background, experience, business needs and availability. Please do not send us sensitive personal information (for example, health, financial account, or government ID details) unless we ask for it.
Information collected automatically
| What is collected | Collected by | Why |
|---|---|---|
| IP address, browser and device type, pages requested, date and time, security signals | Cloudflare (hosting, content delivery and security) | To deliver the Site quickly and to detect and block attacks, bots and abuse |
| Browser and device characteristics and interaction signals when you submit a form | Cloudflare Turnstile | To confirm a form is submitted by a person rather than an automated program |
| Page visited, referring site, campaign (UTM) tags, browser, operating system, device type, country or region, time on page, how far down a page you scrolled, clicks on links to other websites, and whether a form was submitted (recorded as an event named “Client inquiry” or “Advisor application”) | Plausible Analytics | To count visits and see which pages and marketing campaigns bring people to the Site |
Plausible is a privacy-focused analytics tool. It does not use cookies, does not track you across other websites, and does not store your IP address. Its reports are aggregate counts; we cannot identify you from them.
How you found us. When you submit the contact form, we also record any marketing campaign (UTM) tags in the address of the page you submit it from, the website that referred you to that page (if it was the page you entered the Site on), and that page’s address, and we store them with your contact record in our CRM. This tells us which marketing brought you to us. Unlike Plausible’s aggregate statistics, this information is linked to you. Because the Site uses no cookies, it does not remember earlier visits.
Information from other sources. If you contact us from a work email address, we send the domain part of your address (for example, “example.com”) to HubSpot, our CRM provider. HubSpot may then add details about your company, such as its industry, size, location and website, and sometimes professional details about you, from its own data sources. We use this to understand who is contacting us and to respond appropriately. You can ask us to show you, correct or delete any details added this way, in the same way as any other request under section 8.
3. How we use your information and our legal bases
We use your information only for the purposes below. The right-hand column shows the legal basis we rely on under the GDPR and UK GDPR.
| Purpose | Information used | Legal basis |
|---|---|---|
| Respond to your contact request or question | Contact form details, your message, and any company details HubSpot may add | Taking steps at your request before entering a contract; our legitimate interest in responding to people who contact us |
| Evaluate and provide services you ask about as a prospective customer | Contact details and information you share about your needs | Performance of a contract, or steps at your request before entering one |
| Evaluate whether to work with you as a prospective advisor | Contact details and information you share about your background, expertise and availability | Steps at your request before entering a contract; our legitimate interest in selecting advisors |
| Run, maintain and secure the Site | Cloudflare and Turnstile data | Our legitimate interest in keeping the Site available and secure |
| Measure Site traffic and marketing effectiveness | Plausible aggregate data (no cookies, no personal identifiers); campaign tags, referring site and page address recorded when you submit the contact form | Our legitimate interest in understanding how the Site is used and which marketing brings people to us |
| Send you updates or marketing by email | Email address | Your consent, which you can withdraw at any time, or (for existing customers) our legitimate interest in keeping you informed about related services |
| Comply with law, resolve disputes and enforce our agreements | Any of the above | Legal obligation; our legitimate interest in protecting our rights |
We do not use your information to make automated decisions that have legal or similarly significant effects on you, and we do not build profiles of you.
4. Cookies, analytics and site security
The Site does not use advertising cookies, third-party tracking cookies, or any tool that follows you across other websites. Because of this, the Site does not need to show you a cookie consent banner.
Analytics (Plausible). We use Plausible Analytics to count visits and to see which pages and marketing campaigns bring people to the Site. Plausible does not use cookies and does not collect or store personal data. Plausible’s campaign measurement relies on the referring website and any UTM tags in the link you clicked, and Plausible does not link this to your identity. Separately, if you submit the contact form, we store the campaign tags, referring site and address of the page you submit it from with your contact record (see section 2). You can read more in Plausible’s data policy.
Security cookies (Cloudflare). Cloudflare may set a small number of strictly necessary cookies to keep the Site secure and working, such as __cf_bm (helps identify automated traffic; expires after about 30 minutes) and cf_clearance (remembers that you passed a security check). These cookies are required for the Site to function and do not track you for marketing. Blocking them in your browser may prevent parts of the Site from loading.
Form security (Cloudflare Turnstile). Our contact form uses Cloudflare Turnstile to tell people apart from automated programs. Turnstile looks at signals from your browser and device and may set a security cookie. It does not require you to solve a puzzle in most cases. Cloudflare’s handling of this information is described in Cloudflare’s privacy policy.
Do Not Track and Global Privacy Control. We do not sell or share your personal information, so there is nothing to opt out of. Browser signals such as Global Privacy Control do not change how we treat your information because we already do not sell, share or track you for advertising.
5. Who we share your information with
We do not sell your personal information, and we do not share it with anyone for advertising. We have not done either in the past 12 months. We share information only with the service providers below, who work on our behalf under contracts that limit what they can do with it.
| Provider | What they do for us | What they receive | Location |
|---|---|---|---|
| Cloudflare, Inc. | Hosts the Site (Cloudflare Workers), delivers content, blocks attacks and bots, and provides Turnstile. When you submit the contact form, it is processed by a Cloudflare Worker and held in a queue for up to 24 hours before being passed to our CRM. | IP address, browser and request data, security signals, and the contents of your form submission (held for up to 24 hours) | United States (global network) |
| HubSpot, Inc. | Our customer relationship management (CRM) system, where contact form submissions and our follow-up notes are stored. When you contact us from a work email address, HubSpot may also add company details, and sometimes professional details about you, from its own data sources | Everything you enter in the contact form, the campaign tags, referring site and page address recorded when you submit it, and the domain of your email address, and notes from our interactions | United States |
| Google LLC | Runs our email, calendar and document collaboration tools (Google Workspace), which we use to communicate with you and to keep working files | Email address, the contents of emails and documents you exchange with us, and calendar invitations | United States (with data centers worldwide) |
| Plausible Insights OÜ | Website analytics | Aggregate, cookieless usage statistics (no personal identifiers) | European Union |
We may also disclose information when the law requires it, to protect our rights or safety or those of others, to our professional advisers such as lawyers and accountants, or as part of a merger, sale or reorganization of our business (in which case this policy will continue to apply to your information). We will share information for any other purpose only with your consent.
6. International data transfers
We are based in the United States, and the information you give us is stored and processed there. If you are in the EEA, the UK or Switzerland, this means your personal data is transferred to a country that those jurisdictions do not consider to provide the same level of data protection.
When we transfer your data, we rely on safeguards recognized under the GDPR and UK GDPR. Where a provider is certified under the EU-U.S. Data Privacy Framework (including its UK Extension and Swiss-U.S. Data Privacy Framework), we rely on that certification. Otherwise we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, which are built into our agreements with our providers. You can ask us for a copy of the relevant safeguards at privacy@alemaradvisors.com.
7. How long we keep your information, and how we protect it
We keep personal information only as long as we need it for the purposes in section 3, and then delete or anonymize it.
| Information | How long we keep it |
|---|---|
| Contact form submissions in the Cloudflare queue | Up to 24 hours, until delivered to our CRM |
| Contact form submissions, CRM records and email correspondence with prospective customers and advisors | For as long as we have a business reason to keep it: while we handle your request and, if we start working together, for the length of that relationship and a reasonable period afterward. We review our records at least annually and delete or anonymize those we no longer need, unless the law requires us to keep them longer |
| Site and security logs (Cloudflare) | Up to 30 days, except where a record is needed to investigate a security incident |
| Analytics (Plausible) | Indefinitely, as aggregate statistics that contain no personal identifiers |
| Marketing email preferences | Until you unsubscribe, plus a record of your opt-out so we honor it |
We protect your information with measures appropriate to the small amount and low sensitivity of the data we hold. The Site is served over HTTPS, Cloudflare provides network and application security, access to our CRM is limited to people who need it, and each provider we use runs its own security program. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Your rights and choices
8.1 Choices available to everyone
Whoever you are and wherever you live, you can ask us to tell you what personal information we hold about you, correct it, or delete it. You can unsubscribe from marketing emails at any time using the link in the email or by contacting us. Some rights may be limited where the law allows, for example where we must keep a record to comply with a legal obligation.
8.2 If you are in the EEA, the UK or Switzerland
Under the GDPR and UK GDPR you have the right to:
- Access the personal data we hold about you and receive a copy
- Correct data that is inaccurate or incomplete
- Have your data erased
- Restrict how we use your data in certain circumstances
- Receive your data in a portable, machine-readable format
- Object to processing based on our legitimate interests, including at any time to direct marketing
- Withdraw consent at any time, without affecting processing that took place before you withdrew it
- Complain to a data protection authority. In the UK this is the Information Commissioner’s Office; in the EEA it is the authority in your country. We would appreciate the chance to address your concern first.
8.3 How to exercise your rights
Email privacy@alemaradvisors.com and tell us what you would like us to do. To protect your information, we may confirm your identity by replying to the email address we have on file or asking for information that matches our records. Someone you authorize may make a request for you if they provide written permission from you.
We will respond within one month (or, for California requests, within 45 days). If your request is complex we may extend this period, and we will tell you if so. We do not charge for handling requests unless they are clearly unfounded or excessive.
8.4 If you are a California resident
Alémar does not currently meet the thresholds that make the California Consumer Privacy Act (CCPA) apply to a business. Even so, we voluntarily follow its core requirements, and this section serves as our notice at collection.
In the past 12 months we have collected the categories of personal information below. We collect it directly from you, from your browser or device, from the service providers listed in section 5, and from HubSpot’s data enrichment, which may add company and professional details from its own sources. We use it for the purposes in section 3 and keep it for the periods in section 7.
| Category | Examples | Disclosed to |
|---|---|---|
| Identifiers | Name, email address, LinkedIn profile, IP address | Cloudflare, HubSpot, Google |
| Professional or employment-related information | Company, role, type of contact, areas of expertise, availability, background you share as a prospective customer or advisor | HubSpot, Google |
| Internet or network activity | Pages visited, referring site, landing page, campaign tags, browser and device type | Cloudflare (identifiable, for security); HubSpot (campaign, referring site and page address on your contact record); Plausible (aggregate only) |
| Geolocation data | Country or region inferred from IP address (not precise location) | Cloudflare; Plausible (aggregate only) |
We do not collect sensitive personal information, we do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not sold or shared personal information in the past 12 months, and we have no actual knowledge that we do so for anyone under 16.
As a California resident you have the right to know what personal information we collect and how we use and disclose it, to delete it, to correct it, and not to be discriminated against for exercising these rights. Because we do not sell or share personal information or use sensitive personal information, the rights to opt out of sale or sharing and to limit use of sensitive personal information do not apply. You can make a request as described in section 8.3.
9. Children and links to other sites
The Site is intended for adults and is not directed at anyone under 16. We do not knowingly collect personal information from children under 16. If you believe a child has given us personal information, contact us and we will delete it.
The Site may link to other websites. We are not responsible for their privacy practices, and this policy does not apply to them. Please read their privacy policies before providing any information.
10. Changes to this policy
We may update this policy from time to time. When we do, we will post the new version on the Site and update the effective date at the top. If a change materially affects how we use your personal information, we will give you more prominent notice on the Site or, where we have your email address, by email.
11. How to contact us
If you have a question, concern or request about this policy or your personal information, contact us at:
- Email: privacy@alemaradvisors.com
- Mail: Alémar Advisors, Inc., PO Box 4554, Park City, UT 84060, USA
We have not appointed a representative in the EU or UK under Article 27 of the GDPR or UK GDPR because our processing of EU and UK personal data is occasional and low-risk. We are also not required to appoint a Data Protection Officer. Requests from anywhere in the world can be sent to the contacts above.