Data Protection Statement

Last updated: July 2026

This statement supplements our Privacy Policy with the technical and organizational detail relevant to GDPR, UK GDPR, and CCPA/CPRA compliance for Beacon, operated by Alpha2Zulu LLC.

1. Data Controller

Alpha2Zulu LLC is the data controller for personal data processed through Beacon. We have not appointed a formal Data Protection Officer given our current size; privacy inquiries are handled directly by the team at privacy@1humanleft.com.

2. Categories of Data Processed

  • Identity & contact data (name, email)
  • Account & authentication data (hashed password, login history)
  • Content data (posts, drafts, media, FingerPrintâ„¢ voice samples)
  • Connected-platform data (OAuth tokens, profile info, engagement metrics from LinkedIn, Facebook, Instagram, Bluesky, Threads, X)
  • Billing data (subscription tier, invoices — full card data held by Stripe, not by us)
  • Technical data (IP address, browser/device type, usage logs)

3. Subprocessors

We use the following subprocessors to operate the Service. Each is bound by contractual confidentiality and data-protection terms.

Subprocessor Purpose Data Involved
Stripe Payment processing & subscription billing Billing/payment details, email
Anthropic AI model provider for content generation Content inputs/outputs, voice profile data
LinkedIn, Facebook, Instagram, Bluesky, Threads, X Publishing & engagement data, via OAuth you authorize Access tokens, profile & post engagement data
Infrastructure/hosting provider Application hosting & data storage All account & content data

4. Retention Schedule

Data Type Retention Period
Account & content data Duration of active account, deleted within 30 days of account deletion
Connected-platform OAuth tokens Revoked immediately on disconnect or account deletion
Billing records 7 years (legal/tax requirement)
Server/security logs Up to 90 days

5. Security Measures

  • Encryption in transit (TLS) for all traffic between you and Beacon.
  • Encrypted storage of social media credentials and other sensitive tokens.
  • Role-based access controls and key-based (non-password) server access.
  • Firewalled infrastructure and monitoring for unauthorized access attempts.
  • Regular review of access and dependencies as part of ongoing security practice.

6. Your GDPR Rights

If GDPR/UK GDPR applies to you, you have the right to access, rectify, erase, restrict, or port your data, and to object to certain processing. You also have the right to lodge a complaint with your local supervisory authority. Contact privacy@1humanleft.com to exercise any of these rights.

7. Your CCPA / CPRA Rights

If you are a California resident, you have the right to know what personal information we collect, to request deletion, and to opt out of the "sale" or "sharing" of personal information. Alpha2Zulu LLC does not sell or share personal information as defined by CCPA/CPRA. You will not be discriminated against for exercising any of these rights.

8. International Transfers

Beacon is hosted and operated from the United States. Where we transfer personal data internationally, we rely on appropriate safeguards recognized under applicable law (such as Standard Contractual Clauses), to the extent required.

9. Data Breach Notification

In the event of a data breach affecting your personal data, we will notify affected users and, where legally required, relevant supervisory authorities, without undue delay and in accordance with applicable law.

10. Related Pages

See also our Privacy Policy, Terms of Service, and Data Deletion page.

11. Contact

Email: privacy@1humanleft.com
Company: Alpha2Zulu LLC (Beacon by H1L / One Human Left)