Privacy Policy

Last Updated: June 11, 2026

Almita Limited, trading as Decisions Lab ("we," "us," or "our"), operates a Software-as-a-Service (SaaS) platform for behavioral simulation, market research, audience modeling, and cold email outreach. This Privacy Policy explains how we collect, use, store, and protect your information when you visit our website, decisionslab.io (the "Site"), or use our platform (collectively, the "Services"). By using our Services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Services.

1. Information We Collect

We collect the following types of information to provide and improve our Services:

a. Personal Information

  • Contact Information: When you create an account or contact us, we collect information such as your name, email address, and company details.
  • Account Information: Username, password, and other details provided during account registration.
  • Payment Information: For users on paid plans, we collect billing details (e.g., credit card information) through our third-party payment processor, Stripe. We do not store payment information directly on our servers.
  • User-Provided Content: You may upload outreach materials (e.g., email templates) and lead lists, which may contain personal or business-related information.

b. Non-Personal Information

  • Usage Data: We collect information about how you interact with our Services, including IP addresses, browser type, device information, pages visited, and time spent on the Site. We use PostHog to analyze this data and improve our Services.
  • Website Crawling Data: With your permission, our platform may crawl your website to gather information relevant to your cold email outreach campaigns, such as business descriptions or contact details.

c. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience, analyze usage, and deliver personalized content. You can manage cookie preferences through your browser settings.

d. Data About Individuals We Profile

To provide our behavioral simulation and market-research Services, we collect publicly available professional information about individuals, such as information from LinkedIn, X, and other public sources, obtained through official platform APIs and licensed third-party data providers. This may include names, job titles, employers, public posts, and other publicly expressed professional information.

We use this information solely to build behavioral profiles and personas for market research, and to model how audiences are likely to respond to messages, content, and campaigns. We do not sell this information, and we do not disclose individual-level simulation outputs to anyone other than the customer who requested the analysis.

The source of this data is publicly accessible sources and licensed data providers. The lawful basis for this processing is our legitimate interests (and those of our customers) in conducting market research and improving business communications, balanced against the rights of the individuals concerned. Because this data is professional and public in nature, and is not used to make decisions about individuals, we consider this balance appropriate.

Any individual whose public data we have processed may contact us at hello@decisionslab.io to access, correct, or request deletion of that data, or to object to the processing.

2. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain our platform's functionality, including creating and managing your account.
  • Process payments through Stripe for paid plans.
  • Analyze usage patterns via PostHog to improve our Services.
  • Crawl your website (with permission) to gather data for your outreach campaigns.
  • Build behavioral profiles and personas from publicly available professional data to simulate how audiences are likely to respond to messages, content, and campaigns.
  • Conduct market research and behavioral modeling on behalf of our customers.
  • Send you updates, newsletters, or promotional materials (you may opt out at any time).
  • Ensure compliance with our Terms of Service and prevent prohibited activities, such as spamming.
  • Comply with legal obligations, such as responding to lawful requests.

Our AI features use OpenAI and AWS. These services process user-provided content and publicly available professional data to power behavioral simulation, market research, and outreach features. We do not use your data to train external AI models.

3. How We Share Your Information

We do not share your personal information with third parties, except:

  • Service Providers: We use Vercel for application hosting, Supabase for database and storage, StackAuth for authentication, Stripe for payment processing, PostHog for analytics, Resend for transactional email, OpenAI for AI processing, and AWS for AI and infrastructure. These providers are contractually obligated to protect your data.
  • Legal Compliance: We may disclose information if required by law, such as in response to a court order or subpoena.
  • Business Transfers: In the event of a merger, acquisition, or sale, your information may be transferred as part of the transaction, with notice to you.

4. Data Storage and Security

We store your data securely using industry-standard measures, including encryption and access controls. User-uploaded content (e.g., outreach materials, lead lists) is stored for as long as necessary to provide the Services or as required by law. However, no system is completely secure, and we cannot guarantee absolute security.

5. Your Rights and Choices

Depending on your location (e.g., EU under GDPR, California under CCPA, Hong Kong under PDPO), you may have rights to:

  • Access, correct, or delete your personal information.
  • Opt out of marketing communications.
  • Request data portability or restrict processing.

Hong Kong residents may exercise rights under the Personal Data (Privacy) Ordinance (Cap. 486), including the right to request access to and correction of personal data we hold about them. Requests will be handled within the 40-day period prescribed by the Ordinance.

These rights extend to individuals whose publicly available data we process for simulation and research, not only to account holders. To exercise any of these rights, contact us at hello@decisionslab.io. We will respond within the timeframes required by applicable law.

6. International Data Transfers

Our core Services are hosted in Singapore via Vercel and Supabase. AI processing uses OpenAI and AWS, which may involve international data transfers. When you use our Services, your data may be processed in various international locations. We comply with applicable data protection laws for such transfers and maintain standard data processing agreements with our service providers.

7. Children's Privacy

Our Services are not intended for individuals under 16. We do not knowingly collect personal information from children. If you believe we have collected such information, please contact us to have it removed.

8. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes via email or a notice on the Site. Your continued use of the Services after such changes constitutes acceptance of the updated policy.

9. Contact Us

For questions or concerns about this Privacy Policy, contact us at: hello@decisionslab.io