Privacy policy

Last updated: February 23, 2026

1. Identity of the company operating the service

Legalpro BV
Registration: BE1005.495.466
Address: Klein Normandie 19, 1950 Kraainem, Belgium
Contact: support@alibly.eu

2. Roles under data protection law

In the context of a hiring process, the employer and its hiring team initiating an Alibly review act as the data controller for candidate data. Legalpro BV acts as a data processor on behalf of that controller.

Legalpro BV acts as an independent data controller for hiring-team account data and for compliance, security, and audit logging purposes.

3. Data collected from hiring teams

When you use Alibly as part of a hiring team, we collect:

  • First name, last name, company name (collected during signup)
  • Email address for authentication via magic link
  • Workspace membership and role
  • Subscription plan and billing interval (stored on workspace, not on individual user)
  • Review usage statistics (monthly counts per workspace)
  • Candidate review details you provide (candidate name, email, company, role)
  • Candidate CV (optional, uploaded as PDF). The file is processed once to extract job positions and is immediately discarded. Only extracted structured position data (employer, title, dates) is stored.

Purpose: providing the Alibly service.
Legal basis: contract performance (Art. 6(1)(b) GDPR).

4. Data collected from candidates

When a candidate authorises an Alibly review, we process the following data:

  • Consent record (version and timestamp)
  • Professional network data transferred to Alibly through official data portability mechanisms, including the LinkedIn Member Data Portability (3rd Party) API:
    • Work history and positions (title, company, dates, location)
    • Connection details (first name, last name, LinkedIn profile URL, connection date, company, and job title)
    • Connection titles and company names are used for AI-assisted classification; connection names and profile URLs are retained only within the generated report for the duration of the hiring process

Alibly does not access LinkedIn accounts directly and does not collect or store LinkedIn login credentials.

Alibly requests access to two specific categories of LinkedIn data: (1) first-degree connection data (name, LinkedIn profile URL, position title, company name, and connection date) and (2) profile positions (company name, title, and employment dates). No other categories of LinkedIn data are requested or accessed.

LinkedIn data is transferred once per Alibly review via the LinkedIn Member Data Portability API and processed immediately upon receipt. Raw portability payloads are discarded after processing. Connection details (names, LinkedIn profile URLs, job titles, and companies) and derived analytical metrics are retained in the report. There is no ongoing monitoring of the candidate's LinkedIn account. Connection identities are not reused across reviews and are not aggregated into any external dataset or contact database.

Purpose: generating professional-network validation for the hiring team's Alibly review.
Legal basis: explicit consent (Art. 6(1)(a) GDPR).

Where Legalpro BV acts as a processor, the relevant hiring team or employer determines the lawful basis for the hiring process. Where applicable, Legalpro BV may also rely on Article 6(1)(f) GDPR (legitimate interests) for ensuring platform security, fraud prevention, and service integrity.

5. What is not stored

We do not store:

  • Raw connection export files or portability payloads
  • Connection email addresses
  • LinkedIn messages, posts, private communications, or content
  • Unprocessed portability payloads received from third-party platforms
  • Uploaded CV files (only extracted position data is retained)
  • Connection names, LinkedIn profile URLs, and professional details are retained within reports but are not used to build any standalone contact database

Only derived analytical metrics and report outputs necessary for the specific hiring process are retained.

6. Use of artificial intelligence

Alibly uses AI services (currently OpenAI) to assist with data classification and extraction. Specifically:

  • Title classification: Job titles from professional network connection data are sent to an AI service to classify seniority level, professional function, and industry sector. Only deduplicated titles and company names are sent. No personal identifiers (names, email addresses, profile URLs, dates of connection) are included in these requests.
  • CV position extraction (when a hiring team uploads a CV): The text content of the uploaded PDF is sent to an AI service to extract structured position data (employer name, job title, start and end dates). The uploaded PDF file is not stored. Only the extracted structured data is retained.
  • CV-vs-network comparison: Extracted CV positions are compared against positions derived from professional network data to identify matches, date discrepancies, and positions appearing on only one source. This comparison is performed server-side using deterministic logic, not AI.

AI outputs are used for classification and comparison purposes only. No automated hiring decisions or candidate scoring is performed. All AI-generated classifications are clearly labeled as estimates in reports.

OpenAI processes data under a Data Processing Addendum. API data is not used for model training.

7. Data retention

Candidate-derived analytical metrics and reports are retained only for the duration of the relevant hiring process. Authorised users may delete an Alibly review at any time. Upon deletion, associated data becomes inaccessible and may be permanently purged in accordance with our internal retention schedule.

Raw portability data and unprocessed payloads are discarded immediately after processing.

Hiring-team account data is retained while the account remains active and for a limited period thereafter where required for legal, accounting, or compliance purposes.

  • Subscription and billing records: retained for the duration of the account plus 7 years (Belgian accounting law requirement)
  • Payment transaction records: retained by Stripe under their retention policy
  • Review usage statistics: retained for the duration of the workspace

8. Automated decision-making

Alibly uses artificial intelligence to classify job titles, categorize company sectors, extract position data from uploaded CVs, and compare positions across sources. These are processing aids that generate statistical estimates, not decisions. Alibly does not make automated decisions within the meaning of Article 22 GDPR. All classifications are clearly labeled as estimates. Reports generated by the Service are decision-support tools. All hiring decisions remain solely the responsibility of the hiring team and the employer.

9. Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you
  • Request rectification of inaccurate data
  • Request erasure of your data
  • Restrict processing in certain circumstances
  • Data portability
  • Object to processing
  • Withdraw consent at any time (where processing is based on consent)

To exercise any of these rights, contact us at support@alibly.eu.

You may request deletion of your Alibly review report and all associated derived data at any time by contacting support@alibly.eu. The authorised user who created the review may also delete it directly from their dashboard. Deletion permanently removes all derived metrics and report data.

Where Legalpro BV acts as a data processor, we will forward data subject requests to the relevant hiring team or employer acting as controller, unless we are legally required to respond directly.

You also have the right to lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit).

10. Third parties and data transfers

  • Hosting: Vercel (US, with EU data processing agreement)
  • Database: Neon (managed PostgreSQL)
  • AI processing: OpenAI (US, with Data Processing Addendum). Used for job title classification and CV text extraction. No personal identifiers are included in requests.
  • Stripe, Inc. — payment processing, invoicing, and subscription management. Alibly does not receive, process, or store credit card numbers, bank account details, or other sensitive payment information. Data transferred to Stripe: email, name, company, billing address. Purpose: subscription billing, overage billing, invoice generation, tax calculation. Stripe acts as an independent data controller for payment data. Stripe is PCI-DSS Level 1 certified. Stripe may process data outside the EU/EEA under Standard Contractual Clauses. Stripe's privacy policy: https://stripe.com/privacy.

We do not sell personal data. We do not share personal data with third parties for advertising or marketing purposes. Subprocessors are engaged solely for hosting, infrastructure, and operational support under data processing agreements.

Where personal data is transferred outside the European Economic Area, appropriate safeguards are implemented in accordance with Chapter V GDPR, including standard contractual clauses where applicable.

11. LinkedIn data portability disclosures

Candidate data is accessed through LinkedIn's Member Data Portability (3rd Party) API under the EU Digital Markets Act.

  • LinkedIn does not endorse, verify, or sponsor Alibly or its outputs
  • An authorised user within a hiring team initiates an Alibly review, and no data transfer occurs unless and until the candidate authorises the transfer through the official portability authorisation flow
  • No data is accessed without the candidate's explicit consent
  • Alibly only requests the minimum categories of LinkedIn data required to generate the professional-network validation

You may revoke Alibly's access to your LinkedIn data at any time through your LinkedIn account settings. Revoking access prevents future data transfers but does not affect reports already generated from previously transferred data, as raw data is discarded immediately after processing.

12. Third-party connection data

When a candidate consents to an Alibly review, their LinkedIn connections' professional details (name, LinkedIn profile URL, job title, company, and connection date) become part of the report. These individuals have not separately consented to Alibly processing their data.

Connection data is visible only to authorised members of the hiring team's workspace involved in the hiring process.

The lawful basis for this processing is the legitimate interest of the hiring team in evaluating a candidate within a hiring process (GDPR Article 6(1)(f)). A balancing test has been conducted as part of our Data Protection Impact Assessment.

Connection data is:

  • Purpose-limited to the specific hiring process for which the review was created
  • Subject to the same retention and deletion policies as the report
  • Never used for marketing, advertising, or building a standalone contacts database
  • Deleted when the authorised user deletes the review or when the hiring process ends. Individuals appearing in a report may also request erasure of their data by contacting support@alibly.eu

Any person whose data appears in an Alibly report may contact support@alibly.eu to exercise their rights under GDPR, including access, rectification, and erasure.

13. Cookies and tracking

We use functional authentication session cookies that are strictly necessary for the Service to operate.

Analytics cookies (Microsoft Clarity) are used for session replay and heatmap analytics to improve the user experience. These cookies are only set when you explicitly consent to analytics cookies via our cookie banner. You may withdraw consent at any time. Microsoft Clarity's privacy policy: https://privacy.microsoft.com.

14. Security measures

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, role-based permissions, audit logging, and secure infrastructure hosting.

15. Changes to this policy

We may update this privacy policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email.

16. Contact

If you have any questions about this privacy policy or our data practices, contact us at: support@alibly.eu

For data protection inquiries, contact support@alibly.eu

17. EU VAT and tax data

Alibly collects VAT identification numbers from B2B customers for reverse-charge invoicing. Business address information is collected by Stripe during checkout for automatic tax calculation.

This data is processed under the legal basis of legal obligation (tax compliance).

18. Workspace and team data

Workspace name, plan, seat count, and subscription status are stored to manage team access and billing. Workspace membership records (user ID, role, join date) are stored for access control.

Workspace invitation records (email, status, expiry) are stored temporarily and deleted after acceptance or expiry.

Team members within a workspace can see shared review results; they cannot see data from other workspaces.

19. Data Protection Impact Assessment

Alibly has conducted a Data Protection Impact Assessment (DPIA) under GDPR Article 35 for the processing of LinkedIn connection data. The DPIA documents the data flows, risks to data subjects, and safeguards in place.

A copy of the DPIA is available upon request by contacting support@alibly.eu.

20. Email validation and abuse prevention

Alibly rejects signups from known disposable or temporary email providers to prevent trial abuse.

On signup, a hashed version of the signup IP address and the User-Agent string are stored for abuse detection purposes only. This data is not used for marketing, profiling, or any purpose other than detecting patterns of abuse.

Legal basis: legitimate interest (preventing fraud and abuse).

Updated February 23, 2026: tightened connection data retention language, added workspace visibility and non-aggregation statements, updated third-party connection data section with hiring-process scoping. Previously: added third-party connection data section, updated data descriptions, payment processing, workspace and team data, DPIA reference, email validation, VAT data, analytics cookies, and updated contact information.