Privacy Notice

Last updated: 21 Aug 2026

1. Who this notice is for

Aludoc holds personal data about two different groups of people, and what you can do about yours depends on which one you are.

  • Users. You have an account and you sign in to Aludoc. You gave us your details yourself, or the company you work for created your account.
  • Documented people. You appear in Aludoc because a company you work for, or a company that hired them, records the documents you need in order to work. You may have no account and may never have used Aludoc. Your data was entered by that company, not by you.

Most of the personal data in Aludoc belongs to the second group. If that is you, the company that entered your data decides what is held about you and for how long; Aludoc operates the service on their behalf. Section 9 explains what you can ask for and how.

2. Where the data comes from

Most personal data in Aludoc does not come from the person it describes. It is entered through the product by the company that employs them, or by the company that hired that employer, using their own accounts — because being able to show that a worker holds the documents their work requires is the purpose of the service.

No personal data reaches Aludoc from any source other than the companies using it. We do not buy personal data and we do not collect it from public sources.

3. What we hold

About a documented person:

  • Identity. Given and second name, first and second surname, national identity or social-security number, date of birth, gender, postal address, e-mail address and telephone number.
  • Documents. The name, issue date and expiry date of each document recorded for you, and the document file itself — in practice identity papers, medical certificates and training records.
  • Working relationships. Which company employs you, which contracts you are assigned to, which activities you perform under them, and which vehicles you are associated with.
  • Compliance state. For each document your work requires, whether it is covered, expiring, expired, missing or recorded without an expiry date — computed and stored for each day.
  • Exemptions. Where a company has excused you from a requirement: who granted it, when, until when, and the reason they gave in their own words. If it was later revoked, who revoked it and why.

About a user with an account: your user name, e-mail address, the roles you hold, the customer you belong to, and your sign-in activity.

The identity number is the most sensitive field in this product and it is required for every documented person. We name it explicitly rather than describing it as "identification data", because you should know it is here.

4. Why we hold it

So that a company hiring contracted work can verify that the people and vehicles working under its contracts hold the documents that the work requires, and so that the party responsible for a document is reminded before it expires.

We do not use your personal data for advertising, and we do not use it to build a profile of you for any purpose other than the compliance of the contracts you appear in.

5. Who can see it

  • Each customer is separate. One customer of Aludoc cannot see another customer's data at all.
  • Within a customer, data is scoped by company. A company sees its own people, vehicles and documents.
  • Both parties to a contract see that contract's compliance — including the other side's people — because verifying it is what the contract is for. A company that is not a party to a contract sees nothing of it.
  • Exemptions are visible to the parties of the contract they apply to, including the reason given for granting or revoking one.

Aludoc staff with production access can technically reach customer data in order to operate and support the service. We say so rather than leaving it unsaid, because it is true of every hosted product and a notice that omits it is misleading.

6. The e-mails we send

Aludoc sends a daily reminder to the party responsible for a document that is expiring, has expired, or was recorded without an expiry date. The reminder names the document, its type and the contract it is required for.

We keep a record of each reminder: the address it was sent to, when it was sent, whether it was delivered, how many attempts were made, and any delivery error.

7. The record of changes

When somebody creates, changes or deletes a record through the product, that is logged together with the user who did it and the time it happened. It applies to the personal data described above, and it exists so that a compliance record can be shown to be what it says it is.

Automatic overnight processing is not attributed to a user, because no user is involved. Each night Aludoc marks documents whose expiry date has passed, computes that day's compliance figures, and removes per-person compliance detail that has passed the retention described in section 8. Those changes — including that removal — are made by the system itself and are not recorded against anyone in the change log.

8. How long we keep it, and where

Aludoc runs on Microsoft Azure. Personal data, including the document files themselves, is stored in the service's database rather than in a separate file store.

These are the retention periods the product actually applies today:

  • Your record and your documents — kept until the company that entered them deletes them.
  • The daily compliance figures for a contract — kept indefinitely, because they are the evidence that the contract was covered on a given day.
  • The per-person compliance detail behind those figures — kept for a period that depends on the customer's plan, then removed.
  • The record of reminders sent — kept indefinitely.
  • The record of changes described in section 7 — kept indefinitely.

We would rather state this plainly than publish a retention period we do not enforce. Where the answer is "until the customer deletes it", that is what it says.

9. Your rights, and how to exercise them

Depending on where you are, you may have the right to ask what personal data is held about you, to obtain a copy of it, to have it corrected if it is wrong, and to ask for it to be deleted.

If you have an Aludoc account, you can see and correct much of your own data in the product. For anything else, write to support@alutelmobility.com.

If you are a documented person without an account, the company that entered your data decides what happens to it, so a request is usually fastest addressed to your employer or to the company that hired them. You can also write to support@alutelmobility.com and we will pass the request to them and help them answer it.

We would rather be clear about a limitation than let you discover it. There is no self-service page today for someone without an account to see or delete their own data; these requests are handled by hand. And because your data was entered by a company rather than by you, we generally cannot confirm who you are without that company's help.

One consequence worth stating: a compliance record exists so that a company can show, after the fact, that a worker was covered on a particular day. Deleting personal data can therefore conflict with an obligation the company itself has to keep, and a deletion request is resolved together with the company that holds that obligation.

10. Contact

For any question about this notice, or to make any of the requests described in section 9, write to support@alutelmobility.com.

An error has occurred. This application may no longer respond until reloaded.Reload 🗙