Privacy Policy

Last updated: 12 September 2026

1. Who we are and what this covers

Almita Limited, trading as Decisions Lab ("we," "us," or "our"), operates a behavioural simulation platform. Customers describe an audience, we typically build the personas for the individuals in it, and simulations run against those personas.

This Privacy Policy explains how we collect, use, store, and protect personal data when you visit decisionslab.io or use the platform (together, the "Services"). It covers account holders, other people in a customer organisation, and persona subjects, the individuals whose professional information is used to build a persona.

2. Who controls what

Persona subject data

Decisions Lab is the data controller for persona subject data, whether we identified the individual or a customer named them. We decide what information is collected, from which sources, and how long it is kept. Requests from a persona subject come to us at privacy@decisionslab.io and we action them directly.

Customer content

For everything you submit, including your brief, your materials, simulation configuration, and your account and billing data, you are the controller and Almita Limited is the processor. We process it only on your documented instructions.

3. Data we collect from customers and their users

When you create an account, join an organisation, or contact us, we collect:

  • Contact and account details, such as name, work email address, and company name.
  • Organisation identity and authentication data handled through WorkOS, including session metadata.
  • Billing and subscription metadata stored in our application database. Customers are invoiced. We do not collect or store payment card details.
  • Content you submit to run the Services, including briefs, materials, and simulation configuration.
  • Usage data, including IP address, browser and device information, pages visited, and product events.

Cookies and analytics

We use cookies and similar technologies to operate the site, keep you signed in, and measure product usage through PostHog. You can manage cookies through your browser settings. Some cookies are required for the Services to function.

4. Persona subjects

In most engagements we build the audience. You describe the audience you want to understand, and we identify individuals who fit and build personas from publicly available professional information about them. Some customers supply their own records instead, typically name, job title, company, company website, and public professional profile URL. In both cases we collect the public source material ourselves. It is held internally rather than shown in the product or included in exports. You receive the personas and the simulation results.

Persona subject data is used to build personas and run simulations, and for nothing else. We do not contact persona subjects. We do not sell persona subject data, use it for our own marketing, or use it to train models.

5. How we use data

We use personal data to:

  • Provide, operate, and maintain the Services, including accounts and organisations.
  • Build personas and run simulations on a customer's instructions.
  • Collect public source material needed to build those personas.
  • Analyse aggregated product usage to operate and improve the Services.
  • Communicate about the Services, including support and, where relevant, marketing.
  • Bill for the Services and keep accounting records.
  • Comply with law and enforce our Terms of Service.

7. AI processing

Persona profiling and simulation use OpenAI and AWS Bedrock. Our OpenAI account is configured for zero data retention, so prompts are not stored. Persona and prompt content is processed in memory and is not retained by those providers after the request completes. Bedrock memory is not enabled. We do not use your data or persona subject data to train AI models, our own or those of any third party.

Decisions Lab makes no automated decisions producing legal or similarly significant effects about individuals. Simulation outputs describe a modelled persona rather than assessing a real person.

8. Who we share data with

We share personal data with the subprocessors that host and operate the platform. This list is maintained on our Trust page and mirrored here.

  • Vercel: Application hosting services (United States)
  • Convex: Database services (United States)
  • WorkOS: Authentication and user management services (United States)
  • Railway: Cloud hosting services (United States)
  • Supabase: Database services (United States)
  • Amazon S3: Storage services (United States (Virginia))
  • OpenAI: Generative AI and AI model inference services (United States)
  • AWS Bedrock: Generative AI and AI model inference services (United States (Virginia))
  • Axiom: Log aggregation and monitoring services (United States)
  • PostHog: Analytics services (United States)

We may also disclose information if required by law, or as part of a merger, acquisition, or sale of assets, with notice where the law requires it.

9. Where data is processed

Almita Limited is incorporated in Hong Kong. Our infrastructure and subprocessors are located in the United States, so personal data submitted to the platform is transferred to and processed there. Transfer mechanisms are set out in our Data Processing Agreement, which is available on request.

10. How long we keep it

Audience records, personas, and simulation results are kept until you delete them or close your account. When you delete data or close your account, it is removed from active use immediately and permanently purged within 30 days across our databases and object storage. We will confirm deletion in writing on request. Prompts sent to our AI providers are not retained by them. Operational logs hold request metadata only and follow our logging provider's standard retention.

11. Security

All traffic between your browser, our services, and our subprocessors uses TLS 1.2 or higher. Customer data is encrypted at rest using AES-256 across our databases and object storage. Production credentials are held in a dedicated secrets manager and are never stored in source code or version control. Access to production systems and logs is limited to named personnel.

12. Your rights

Depending on your location, including the EU and UK under GDPR, California under CCPA / CPRA, and Hong Kong under the Personal Data (Privacy) Ordinance, you may have rights to access, correct, or delete personal data, to opt out of marketing, to request portability, or to restrict or object to certain processing.

Hong Kong residents may exercise rights under the Personal Data (Privacy) Ordinance (Cap. 486), including access and correction. Requests will be handled within the 40-day period prescribed by the Ordinance.

To exercise these rights, contact us at privacy@decisionslab.io. We will respond within the timeframes required by applicable law.

13. Business use only

The Services are offered to businesses and their authorised users. They are not intended for consumers or for anyone under 18.

14. Changes and contact

This Privacy Policy is effective from 9 September 2026. We may update it to reflect changes in our practices or legal requirements. We will notify you of material changes by email or a notice on the site. Continued use of the Services after those changes take effect constitutes acceptance of the updated policy.

For privacy questions and data subject requests, contact privacy@decisionslab.io.