Private beta

Privacy Policy

Last updated: August 24, 2026

Alentra is a brand operated by Komplete10 LTD, a company registered in the United Kingdom and operating from Sweden. Komplete10 LTD is the entity described as “Alentra”, “we”, “us”, and “our” in this policy. The company number, registered-office and postal address, and any required representative or data-protection contact must still be published before paid production availability. This policy describes the private-beta product and its actual data model; it is not a claim of certification or blanket compliance with any law.

1. Scope and roles

Komplete10 LTD provides a business dashboard, API, hosted wallet-session page, billing wallet, and staff-operated support and legal workflows under the Alentra brand. Credential availability is route-specific; coming-soon country/profile/provider entries are not active production support.

Komplete10 LTD generally acts as controller for business-account, security, billing, support, and site data. For end-user data submitted through a customer's session, the customer generally determines the purpose and means of processing and Komplete10 LTD acts as its processor, subject to the signed order and DPA. It may independently process limited security, fraud, billing, and legally required records.

2. Data we process

  • Account and authentication: email, display name, Firebase user ID, authentication provider, sign-in and security metadata, roles, bans, and account status.
  • Business and integration: business profile, owners and members, API-key hashes and prefixes, webhook URL and signing secret, branding, configuration, balances, and audit-access events.
  • Billing: Stripe customer, embedded Checkout, PaymentIntent, Charge, refund, dispute, tax, amount, credit, and ledger references. Stripe collects payment details, billing addresses, and any tax IDs needed for payment and tax calculation. Alentra does not store full card numbers.
  • Sessions: session ID, requested steps and parameters, customer metadata and reference IDs, state transitions, timestamps, binding and security metadata, results, errors, webhook delivery records, and technical logs.
  • Wallet and identity: the government-credential attributes requested by the customer, wallet/device evidence, signatures, issuer and verification material, and information required to verify the response. Alentra does not receive a face or fingerprint template; device authentication is controlled by the wallet platform.
  • Documents and terms: original files uploaded for sign, their names and hashes, signatures, and inline light_sign terms. For each completed sign step, the original signed documents are part of the retained evidence even if a later step stops or fails.
  • Requests and communications: inquiry, report, legal-request, privacy-request, support content, and signer-receipt delivery. A receipt address is envelope-encrypted in a short-lived verification challenge and is removed when consumed; the permanent receipt grant contains no address.
  • Analytics: consent-gated page and device data through Google Analytics on the marketing/dashboard origin. Hosted sessions use a separate analytics-free origin.

3. age_verify is business-redacted, not invisible to Alentra

For age_verify, Alentra processes the birth date supplied in the wallet presentation to compute the requested threshold. The customer receives only satisfied and min_age. The underlying signer identity and wallet evidence are sealed in the retained audit evidence and are not disclosed in the customer's age-verification audit view.

4. Why we process data

We process data to provide and secure sessions, verify wallet responses, create and preserve evidence, deliver and reconcile webhooks, authenticate customers, bill usage, handle refunds and disputes, prevent abuse, support customers, respond to lawful requests, enforce agreements, and establish, exercise, or defend legal claims. The applicable legal basis depends on Alentra's role and may include contract, customer instructions, legitimate interests, consent, and legal obligation.

5. Retention and deletion

Completed evidence is not customer-deletable.

A customer, signer, administrator, account-closure request, or self-service action cannot delete a completed step result, original signed document, signature, proof, audit record, terminal marker, wallet evidence, or integrity link. These records are retained for at least the evidence period agreed with the customer and for any longer legal hold or period required to establish, exercise, or defend legal claims. Expiry of that minimum period does not create a customer deletion right.

  • Only an uploaded object that was never used by a completed sign step and remains explicitly marked transient may be purged after expiry and the configured recovery window.
  • Expired challenges and unused private response keys are cleared from active state. Exhausted webhook delivery copies are explicitly transient and may be deleted after the production reconciliation window; completed private-session results and terminal markers remain evidence.
  • Account, inquiry, support, billing, refund, dispute, and security records are retained for the period needed for the service, accounting, fraud prevention, disputes, and applicable law.
  • Account closure restricts access and starts a staff review; it does not automatically erase records and never erases completed evidence.
  • A bound signer may request an interim receipt after any completed step or a final receipt after the whole session. Verification codes last at most ten minutes. The generic email contains no result data or attachments. Active-prefix links last at most 48 hours from issuance; terminal-session links cannot outlive the terminal +48-hour signer-access deadline. Access cannot be extended or reissued and expires without deleting retained evidence.

The exact evidence period, legal-hold process, and operational retention windows must be stated in the signed customer schedule before production use.

6. Security

Alentra uses TLS, request-bound encrypted wallet transport, server-computed document hashes, signed webhooks, tenant-scoped authorization, append-only audit rules, and Google Cloud KMS. Sensitive payloads use a fresh AES-256-GCM data key wrapped by a symmetric KMS key. A different asymmetric P-256 KMS key signs each audit hash and publishes retained public keys through JWKS. No system is risk-free; customers must protect API keys, webhook secrets, and their own copies of results.

7. Service providers and transfers

We disclose data to service providers only for the purposes described here, including Google Cloud/Firebase, Railway, Stripe, ZeptoMail, consent-gated Google Analytics, and configured timestamp authorities. See the Sub-processors page.

The current deployment uses US processing locations, including Firestore nam5, Cloud Storage US-EAST1, Functions us-central1, and a global Google Cloud KMS key. We do not claim that Standard Contractual Clauses or another transfer mechanism is automatically in place for every customer; required transfer documents must be executed before covered production processing.

8. Rights and requests

Depending on applicable law, you may request access, correction, portability, restriction, objection, or deletion. These rights are not absolute. Deletion may be refused or limited where retention is required by law, contractually instructed by the controller, or necessary for legal claims and evidence integrity.

Business users can submit an account-closure or data-review request in Dashboard Settings. End users should normally contact the business that created the session; Alentra will assist that controller. You may also use the private contact form. We verify identity and authority before disclosure.

9. Children

Alentra is a business infrastructure service, not a consumer service directed to children. Customers are responsible for selecting a lawful workflow, threshold, notice, and consent basis. If we learn that account or operational data was collected unlawfully, we will review and remove what may lawfully be removed; completed evidence remains subject to the retention rules above.

10. Changes and contact

We will post material changes with a new date and provide additional notice where required. Questions may be submitted through the private contact form. The company number, registered-office and postal address, and any required representative or data-protection contact must still be added before paid production availability.

Government-wallet proof, ready to repeat.

Start with Alentra