Only what the request needs.
This notice covers the ARIIA website and audit-request intake operated by ALMFC LLC. It explains the information collected, why it is needed, who handles it, and how long it is kept.
Information collected
The scorecard and fit builder keep your answers and email on your device until you explicitly choose “Send to ARIIA for review.” The scorecard sends at most two answer-free aggregate progress events per page load: that a result was completed and that a browser share or scorecard-link copy completed. Those events do not include the workflow name, score, answers, recipient, shared text, or whether a recipient received or opened the link. The fit builder sends at most two answer-free aggregate progress events per page load: that the form was started and that both required details are ready. All progress events include only the event name and a short allow-listed source label; they do not include an answer, email, raw IP address, cookie, device identifier, user agent, referrer, or persistent client identifier. If you send the request, ARIIA receives your email address, one workflow name, its selected friction, any optional decision-authority or timing context you provide, the consent notice version and time, a random submission identifier, and the allow-listed source label. If optional context is omitted, the request records that it was not provided yet. The source label is used only to understand which owned channel produced a consented request. A keyed one-way transform of the connection address is stored for submission-abuse prevention; the raw address is not stored in the audit-request record. Cloudflare may process ordinary network and security metadata as the hosting provider.
Purposes and consent
ALMFC LLC uses the submitted information only to review, scope, secure, and reply to that specific inbound audit request. Submission is not consent to a newsletter, advertising profile, automated outreach sequence, invoice, or payment. A separate choice and notice would be required for a new purpose.
Sharing
Information is handled by authorized ALMFC LLC personnel and Cloudflare as the infrastructure provider. It is not sold or shared for behavioural advertising. It may be disclosed when required by law or necessary to protect the service and its users. A payment provider receives information only after a separate purchase decision and its own terms are confirmed.
Retention
Unreviewed requests are scheduled for deletion after 90 days. If a request is used to make a fit or engagement decision, the limited decision record is retained for at least one year so the requester can seek access, subject to applicable law. Transaction, tax, fraud-prevention, or legal records may be retained separately for longer when required.
Access, correction, and withdrawal
You may request access or correction, ask a privacy question, or withdraw consent by contacting the Privacy Lead through @ariia.mobile. Withdrawal before a reply may prevent ALMFC LLC from responding. Some records may still be retained where a legal or contractual requirement applies.
Safeguards and boundaries
Connections use encryption in transit, administrative access is capability-gated, and credentials are kept outside source code. No internet service can promise absolute security. Do not submit passwords, one-time codes, payment numbers, wallet keys, identity documents, health information, or another person’s confidential data. The service is for adults acting in a business context.