Legal

Privacy Policy

Version 2.6 As of 6 October 2026

The German version is authoritative.

roleALPHA — platform for organisational and role management

Language note: This is a translation for information purposes. In the event of any discrepancy, the German version prevails.


In short: what this policy covers — and what it does not

roleALPHA is offered exclusively to businesses. That entails a distinction without which this policy cannot be understood:

What it concerns Who decides about it? Where is it set out?
Use of the website and of the platform itself — account, sign-in, logs, statistics, support roleALPHA GmbH is the controller in this policy
Content a customer organisation enters — employee data, organisational structures, roles, effort, documents The customer organisation is the controller, we are the processor in the Data Processing Agreement; section 8 of this policy summarises it

What this means for you: if you are an employee or a contact of an organisation that uses roleALPHA and wish to request access to, correction or deletion of your data stored in the platform, please approach that organisation — not us. We may process those data only on its instructions and cannot give you information without them. We assist the organisation in answering you.


1. Controller and data protection officer

roleALPHA GmbH
Aschergasse 34, 1130 Vienna, Austria
Commercial register number FN 685262p, registry court Commercial Court of Vienna
VAT number ATU83606108
Management: Oskar Dohrau, Joseph Dinh
E-mail: office@rolealpha.app

Further details in the Imprint.

We have appointed a data protection officer: ⟨TODO: name or company, address and e-mail address of the data protection officer⟩. You may address data protection enquiries to them or to datenschutz@rolealpha.app.


2. What we process, for what purpose and for how long

The table below lists the processing operations for which we are the controller. The GDPR, the Austrian Data Protection Act (DSG) and the Telecommunications Act 2021 (TKG 2021) apply.

Processing Data categories Purpose Legal basis Duration
User account name, sign-in address (e-mail), internal user name, role per tenant, tenant memberships, password hash (only for older accounts; since October 2026 a password is used to sign in only by platform administrators), language setting, display and dashboard settings authentication, permissions, communication; one account per person: access to several tenants under the same sign-in address is held in one account, without any tenant learning that or where else the account is used. Where several accounts still exist for the same sign-in address (from before this rule), platform operations merge them into one account after a dry run; the others remain locked as references for logs and history, and the merge is logged per tenant Art. 6(1)(b) until the account is deleted
Sign-in (sign-in code, passkey, two-factor, single sign-on; password only for platform administrators) e-mail address, hash values of codes and recovery codes, public key and accompanying details of a passkey, encrypted TOTP secret, identifiers supplied by the customer's identity provider — no biometric data secure sign-in Art. 6(1)(b) and (f) until removed by you, at the latest until the account is deleted; one-time codes at the latest one day after expiry
Sign-in attempts and rate limiting IP address, user identifier, timestamp, success or failure protection against brute-force and abuse Art. 6(1)(f) 15 minutes (lockout window)
Server logs IP address, timestamp, requested resource, status code, browser and operating system, referrer operation, security, error analysis Art. 6(1)(f) 30 days
Error logs error message, stack trace, program version, page address without the query part, browser and operating system, the type of the last interactions without element text; for signed-in users the user and tenant identifier detection and remediation of program errors Art. 6(1)(f) 30 days
Usage statistics pseudonymous identifiers (salted hash values), page views, events, browser and operating system, referrer — on rolealpha.com without identifiers; no cookies, no IP address in clear text product improvement, reach measurement Art. 6(1)(f) ⟨TODO: configured retention of the analytics instance⟩
System and notification e-mails e-mail address, name, content of the message access notices (without a password or any other secret), operational messages, domain notifications Art. 6(1)(b) and (f) until the purpose is fulfilled
E-mail delivery log recipient address, time, occasion, dispatch path, result, error message of the remote server; subject only for operational messages — no message text proof of delivery, troubleshooting Art. 6(1)(f) 90 days
In-app feedback and support requests type of report (bug, improvement, question), title, description, screenshot, page structure export and file attachments (where the person attaches them), technical context (page, browser, screen size), login address (e-mail), user name, user and tenant identifier, history of replies; automatic classification of the report and, where applicable, an automatically drafted reply handling the request, error remediation, product improvement Art. 6(1)(b) and (f) ⟨TODO: set the retention period for support tickets⟩; the link between ticket and user on the platform is deleted with the tenant
Contract and billing data company name, address, VAT number, commercial register number, contact persons, billing address including the e-mail address for invoices (maintained by the Customer's administrator in the platform), scope of services, usage volumes per tenant (counted daily: number of persons and AI agents, number of objects in Data Nodes on rA Cloud, cost of AI use via the platform's key; the monthly peak is billed — plain counts and amounts without reference to individual persons); for the data processing agreement additionally the agreed operating model, the named persons authorised to issue instructions and the contact for personal data breaches (name and, for the contact, e-mail address) contract performance, invoicing, drawing up and evidencing the data processing agreement Art. 6(1)(b) and (c) 7 years (§ 132 BAO)
Support and remote maintenance access logs; data viewed in the course of remedying a malfunction troubleshooting, maintenance Art. 6(1)(b); for customer content Art. 28 logged, purpose-bound

The retention periods for customer content are set by the customer organisation itself; they appear in Annex 1.4 of the Data Processing Agreement.


3. Recipients

We disclose personal data only where this is necessary to perform the contract, where a legal obligation exists, where a legitimate interest supports it or where you have consented. The categories of recipients are: hosting and infrastructure providers, the e-mail dispatch provider, the operator of our issue repository (only technical error descriptions from which names, e-mail addresses, identifiers and customer addresses are removed before transfer — no in-app feedback), providers of AI services where a customer organisation has released them, tax advisers and auditors where legally required, and authorities and courts where we are legally obliged.

To convert AI costs from US dollars into euros we retrieve the public reference rate of the European Central Bank once a day. No personal data is transmitted in the process — the request carries neither tenant nor user identifiers.

Every provider that processes personal data on our behalf is bound under Art. 28 GDPR. The complete, versioned list with address, service, place of processing and transfer mechanism is at Subprocessors.


4. Transfers to third countries

Some of the providers engaged — in particular providers of AI services and the operator of the issue repository — are established outside the EU and the EEA, mostly in the USA. We base these transfers on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR) and, where the recipient is certified, on the EU-U.S. Data Privacy Framework (adequacy decision of 10 July 2023, Art. 45 GDPR). Which mechanism applies to which recipient is set out in the list of Subprocessors.

Despite these safeguards, residual risks may remain, such as access by authorities under local law against which there may be no equivalent remedies. This can be avoided: the AI functions are disabled by default and must be released per tenant and per data area. Without such a release no content leaves the platform towards an AI provider. A customer organisation can run roleALPHA entirely without third-country transfers.


5. Storage on your device

The platform sets no cookies — neither for sign-in nor for statistics nor for advertising. There is no third-party tracking. Instead the application stores the following entries in your browser's local storage (localStorage) or session storage (sessionStorage); session storage is cleared when the browser tab is closed.

Key Content Purpose Duration
ra_token your sign-in token keeping you signed in until sign-out or expiry
pa_token sign-in token of the platform administration as above as above
ra_theme chosen appearance (light/dark) display setting until you change it
flow-positions-… node positions of a diagram view you have moved keeping your layout between visits until you reset it
ra_help_sidebar_expanded which chapters of the help navigation you expanded or collapsed keeping your view of the manual until you change it
ra-graph-… your view settings of the relationship graph keeping your graph view until you change them
ra_project_kanban_bahn the chosen swimlane grouping of the kanban board keeping the board view until you change it
ra-explorer-positionen:… (session storage) card positions of an explorer view you have moved so your arrangement survives a trip to a detail page and back until the tab is closed
ra_handoff_rueckkehr (session storage) the address you were sent to the shared sign-in page from so you land where you came from after signing in until the tab is closed
ra_entwurf_puffer:… (session storage) the details you entered into a form and have not yet saved so your input is not lost if the tab crashes or is reloaded; the application offers them back and never replays them itself until the tab is closed, at the latest when the record is saved

This storage is strictly necessary for the service you have requested and is therefore permitted without consent under § 165(3) TKG 2021. You can delete the entries in your browser at any time; you will then be signed out. That is why the platform needs and shows no cookie banner.


6. What we expressly do not do

These commitments limit the processing set out in section 2 and apply for as long as this policy applies.

  • Server logs are not combined with other sources to build user profiles.
  • Error logs contain no form contents, no text of clicked elements, no query parts of addresses, no request bodies, no cookies and no headers. Values that look like a secret are replaced automatically before forwarding. There is no session replay, no per-user performance measurement and no collection from visitors without an error. The error tracker stores nothing on your device.
  • Error tracking and usage statistics we operate ourselves, on our own infrastructure. No transmission to an error-tracking or analytics provider takes place.
  • The usage statistics are cookieless, respect "Do Not Track" and transmit identifiers exclusively as a salted hash value — those evaluating them cannot map an entry to a person known by name.
  • Passwords are stored solely as a bcrypt hash, never in clear text.
  • Biometric data of a passkey are processed exclusively by your device; they are neither transmitted to us nor stored by us. No processing of special categories under Art. 9 GDPR takes place on our side.
  • The e-mail delivery log stores no message text.
  • Advertising e-mails are sent only with consent or within the limits of § 174 TKG 2021; you can unsubscribe at any time.

How support requests are handled: reports from the platform and e-mails to support arrive in our self-operated helpdesk (Zammad, on our own infrastructure at netcup). Every request is classified automatically as a bug, an improvement or a question; for questions, an automatically drafted reply based on our public help may be sent, marked as such. The language model used for this is operated by us on rented infrastructure (Hetzner); the request goes to no AI provider. If a bug has to be handed over to our development team, a staff member writes a technical task — name, e-mail address, screenshot and your text stay in the helpdesk. A tenant's administration can switch the feedback function off for that tenant.

One request: a screenshot in the in-app feedback contains whatever was visible on your screen at the moment it was taken — which may be personal data of third parties. Please review the preview before sending and remove what is not needed; or send the feedback without a screenshot to support@rolealpha.app.


7. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You may object to processing based on a legitimate interest on grounds relating to your particular situation (Art. 21) — this concerns in particular server and activity logs as well as the usage statistics. Consent once given may be withdrawn at any time with effect for the future (Art. 7(3)).

A message to datenschutz@rolealpha.app is enough.

No automated decision-making including profiling within the meaning of Art. 22 GDPR takes place.

Note the allocation of roles: if your rights concern content a customer organisation has entered, that organisation is your point of contact (see section 8). If you nevertheless reach us, we forward your request without delay or refer you on, without dealing with it on the merits.


8. Content of our customer organisations

For everything a customer organisation enters into the platform — persons, roles, org charts, value creation, objectives, projects, competences, effort, demand, document references and the drafts, logs and analyses arising from them — that organisation is the controller. We process these data solely on its documented instructions, under the Data Processing Agreement pursuant to Art. 28 GDPR.

The details are set out there, not here: which data categories arise in which Data Node (Annex 1.1), from which source systems data are taken and to which AI providers they are transmitted, how the operating models allocate responsibility (Annex 1.2), which processing carries an elevated risk and where co-determination is to be checked (Annex 1.3), and which retention periods apply (Annex 1.4). The agreement is publicly available; the duty to inform the employees concerned rests with their employer under Art. 13 and 14 GDPR.

Two commitments bind us in doing so and therefore also appear here: customer content is not used to train AI models, and without an express release of a data area by the customer organisation no AI service gains access to it (fail-closed default).


9. Right to lodge a complaint

You may lodge a complaint with a supervisory authority at any time; the authority responsible for us is the

Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42, 1030 Vienna, Austria
Telephone: +43 1 52 152-0 · E-mail: dsb@dsb.gv.at · www.dsb.gv.at


10. Security and personal data breaches

We take the technical and organisational measures required under Art. 32 GDPR; they are described in the document Technical and Organisational Measures. If we become aware of a personal data breach, we document it, report it to the supervisory authority within 72 hours where we are the controller, and notify the data subjects where there is a high risk. Where the breach concerns customer content, we inform the customer organisation concerned within 48 hours; the notification to the authority is then made by that organisation.


11. Contact and changes

Data protection enquiries: datenschutz@rolealpha.app · General enquiries: office@rolealpha.app · Support: support@rolealpha.app

We adapt this policy when the legal situation, our services or the processing change. The version in force is marked with a version number and a date; we inform customer organisations of material changes in advance. Engaging a new subprocessor follows the procedure with a right of objection set out in the list of Subprocessors.


Deutsche Fassung (maßgeblich): Datenschutzerklärung

© 2026 roleALPHA GmbH