Loading...
ALT Sports Data, Inc. — AI, Data Privacy & Information Use Policy
ALT Sports Data, Inc.
Artificial Intelligence, Data Privacy & Information Use Policy
Effective Date: April 15, 2026 | Version 1.2
Applies to: All ASD Employees, Contractors, and Partner Users
1. Purpose and Scope
This policy establishes ALT Sports Data, Inc.'s ("ASD") rules governing the responsible use of artificial intelligence (AI) tools, the handling of personal information, the protection of proprietary company information and intellectual property (IP), and the treatment of communications in Slack (including Slack Connect channels shared with partner organizations). It reflects ASD's commitment to legal compliance across all applicable jurisdictions, including the United States (federal and state law), California, the European Union, the United Kingdom, and other international markets.
This policy also governs how ASD ingests partner or third-party documentation, maps source materials into ASD canonical schemas and internal data models, and ensures that documentation-to-model work is performed inside ASD-controlled platforms, including the ALT Sports Data Platform, wherever feasible.
This policy applies to:
All full-time and part-time ASD employees
Independent contractors and consultants with access to ASD systems
Part-time employees and advisors
Any third-party partner or vendor with access to ASD's Slack workspace, Confluence, Jira, Gmail, or Google Drive (including via Slack Connect)
2. Definitions
Personal Information (PI): Any information that identifies, relates to, or could reasonably be linked to an individual. Includes names, email addresses, phone numbers, employment details, financial data, health data, and online identifiers.
Sensitive Personal Information (SPI): A subset of PI including government IDs, financial account numbers, health or medical information, biometric data, racial or ethnic origin, religious beliefs, sexual orientation, and precise geolocation data.
Company IP: All proprietary information owned or licensed by ASD, including source code, odds models, data feeds, database schemas, algorithms, API specifications, trading strategies, market pricing methodologies, client lists, and business strategies.
AI Tool: Any software product using machine learning, large language models, generative AI, or automated reasoning to process, generate, summarize, classify, or act on inputs. Includes Claude, ChatGPT, Gemini, Copilot, Vertex AI, and similar tools.
Approved Enterprise AI Tool: An AI Tool that (a) appears on the published approved tools list maintained by the Technology team, (b) is used under an enterprise or business agreement with the provider that includes a Data Processing Agreement (DPA), confidentiality protections, and a "no training on ASD data" commitment, and (c) is accessed through ASD-managed accounts, SSO, or approved integrations. Examples include Claude for Work / Enterprise via ASD's contract, Anthropic API via ASD-controlled keys, Vertex AI in ASD's Google Cloud project, and approved Slack-integrated AI tooling.
Unapproved / Consumer AI Tool: Any AI Tool that is not on the approved tools list, is accessed via personal accounts, free tiers without an ASD DPA, or otherwise does not meet the Approved Enterprise AI Tool definition.
Slack Connect Channel: A Slack channel shared between ASD's workspace and a partner, client, vendor, or contractor organization where participants from both sides may see all messages and files.
ASD Collaboration Systems: ASD-managed communication and work platforms, including Slack, Atlassian, Confluence, Jira, Bitbucket, Gmail, Google Drive, and similar systems used for business operations.
Workspace-Public Content: Content intentionally posted, uploaded, commented on, or submitted within ASD Collaboration Systems. Workspace-Public Content is treated as non-private as between ASD and the submitting user, may be retained, reviewed, searched, summarized, and reused by ASD for legitimate business purposes, and forms part of ASD's business records and work product, except where restricted by applicable law or contract. For clarity, "Workspace-Public" means public within ASD — it does not mean externally published or publicly accessible outside ASD.
Workspace-Public Content specifically includes: (a) all Slack channels within ASD's Slack workspace, whether public, private, or Slack Connect (shared) channels, and (b) all content in ASD-managed Atlassian, Confluence, Jira, and Bitbucket spaces. Workspace-Public Content specifically does not include: (i) Slack direct messages (one-to-one DMs), (ii) Slack multi-person direct messages (group DMs that are not constituted as a channel), or (iii) content in personal Google Drive folders, personal Gmail drafts, or other non-shared personal workspaces.
Community Notes Submission: Any question, prompt, mention, command, or structured request intentionally submitted to an ASD-operated app, bot, agent, or app_mention workflow, including Community Notes-style workflows, by ASD personnel or by third-party leagues, vendors, or partners in ASD-managed environments.
Controller / Processor: GDPR-defined roles. ASD acts as Controller for employee and partner personal data it directs. ASD acts as Processor when handling personal data on behalf of a client or partner under contract.
3. AI Tool Use — Permitted and Prohibited
3.1 General Principles
AI tools are a core part of ASD's product development, data science, and operational strategy. This policy does not restrict AI use — it defines the conditions under which tools may be used responsibly, with particular attention to what information may and may not be shared as inputs.
3.2 Permitted Uses
Drafting, summarizing, and editing internal documents, proposals, and communications
Analyzing publicly available sports data, market research, and third-party datasets
Generating and reviewing code, where no proprietary trading logic or customer credentials are included
Automating league onboarding analysis, contract drafting templates, and data classification tasks
Building internal AI pipelines using ASD-controlled infrastructure (e.g., Vertex AI with ASD-owned data)
Mapping partner questionnaires, technical specifications, onboarding packets, and other documentation into ASD-approved schemas and internal models when performed inside ASD-controlled systems
Processing anonymized or aggregated data for model training and validation
3.3 Prohibited Inputs to Unapproved / Consumer AI Tools
The following must never be provided to any Unapproved / Consumer AI Tool. These prohibitions do not apply to Approved Enterprise AI Tools operating under an ASD DPA, or to ASD-controlled AI infrastructure:
Full names, email addresses, phone numbers, or other personal information of any individual
Source code containing proprietary trading logic, odds algorithms, normalization pipelines, or simulation models
API keys, credentials, tokens, database passwords, or any authentication secrets
Confidential content from Slack messages or threads, including Slack Connect channels
Email content including confidential business negotiations, pricing terms, or attorney-client communications
Unpublished financial data, investor materials, cap tables, or M&A information
Personal health, disability, or family-related information about any individual
Content from partner companies shared via Slack Connect or email that is marked or understood to be confidential
Raw or semi-structured partner documentation, onboarding packs, data dictionaries, or technical specifications that have not been approved for processing by the relevant Technology or Product owner
3.4 ASD-Controlled AI Infrastructure and Platform-First Processing
When AI processing occurs within ASD-controlled infrastructure (e.g., Vertex AI pipelines owned and operated by ASD, or models deployed within ASD's AWS environment), the third-party sharing restrictions in Section 3.3 do not apply. However:
All data processed in ASD-controlled AI infrastructure remains subject to ASD's data classification and access control policies
Personally identifiable information processed in ASD AI systems must be logged in a data processing register
Model outputs containing personal information must be secured with the same protections as the source data
Documentation ingestion, schema mapping, and documentation-to-model translation for partner, client, or league workflows should be performed within ASD-controlled platforms, including ALTP, wherever feasible
Existing approved mappings, schemas, and documentation models must be reused or extended rather than recreated in ad hoc external tools
3.5 No Passive Scraping or Covert Collection
ASD does not passively scrape, harvest, or silently monitor communications from leagues, vendors, individuals, or partner organizations. This policy only authorizes ASD to process and retain content that participants intentionally post, upload, or submit into ASD-managed systems.
3.6 Approved Tools and Experimentation
For work involving ASD data, partner data, or production workflows, employees must only use Approved Enterprise AI Tools or ASD-controlled AI infrastructure. Employees and contractors may evaluate new or unapproved AI tools for potential adoption provided they use only synthetic data, publicly available data, or ASD data classified as Public.
4. Slack — Internal and Slack Connect Channels
4.1 Internal Slack Channels
All Slack messages and files in ASD-managed Slack channels — whether public, private, or Slack Connect — are treated as Workspace-Public Content: company communications that are part of ASD property and business records, and may be retained, accessed, reviewed, searched, summarized, and reused by ASD in accordance with applicable law.
4.2 Slack Connect Channels — Partner Protections
Slack Connect channels are shared with partner organizations. ASD employees participating in Slack Connect channels must:
Treat information shared by partner personnel as confidential unless clearly operational
Not forward, screenshot, or reproduce partner communications outside ASD without express consent
Not input partner communications or files from Slack Connect into any Unapproved / Consumer AI Tool
Not disclose the identity, role, or contact details of partner personnel to parties outside ASD without authorization
In derived datasets, FAQ systems, Community Notes outputs, or knowledge artifacts created from league-facing shared channels, ASD may normalize third-party participant statements at the organization level rather than naming the individual external speaker.
4.3 Slack AI Features
Before enabling any native Slack AI features at the workspace level, the Technology team must review Slack's current data processing terms. ASD will notify Slack Connect partner organizations of any AI features that process shared channel content.
4.4 Atlassian, Confluence, Jira, and Bitbucket
All content intentionally created or stored in ASD-managed Atlassian, Confluence, Jira, and Bitbucket environments is treated as Workspace-Public Content within ASD.
4.5 Notice to Third-Party Participants
Any third-party individual or organization granted access to ASD Collaboration Systems must receive notice that content contributed to ASD-managed systems is treated as Workspace-Public Content and may be retained, searched, and reused by ASD.
4.6 Direct Messages and Group Direct Messages — Off Limits
Slack direct messages and Slack multi-person direct messages are not Workspace-Public Content and are not within the operational scope of ASD's retention, review, search, summarization, reuse, AI indexing, or derived-dataset rights under this policy. DMs are treated as private communications between their participants.
5. Email Communications (Gmail)
Email communications are company property and may be retained and reviewed by ASD in accordance with applicable law. When AI tools are used to draft or summarize email content, employees must ensure no content prohibited under Section 3.3 is included as input for Unapproved / Consumer AI Tools.
For derived datasets, FAQ systems, or knowledge artifacts created from email communications, ASD treats external correspondents the same way it treats third-party participants in league-facing shared channels — anonymized at the organization level rather than identified by personal name.
6. Company IP and Proprietary Information
6.1 Classification
ASD information is classified into four tiers:
Public: Cleared for external distribution
Internal: For ASD use only
Confidential: Sensitive business information
Restricted: Highest sensitivity (investor materials, M&A discussions, encryption keys, employee compensation)
6.2 Handling Rules
Confidential and Restricted information must not be input into any Unapproved / Consumer AI Tool, shared in Slack Connect channels beyond the specific partner requirement, transmitted unencrypted outside ASD systems, or retained by former employees beyond their departure date.
All work product created using ASD data or in the course of employment — including AI-generated outputs — is the intellectual property of ASD.
6.3 Documentation Models and Schema Governance
Where ASD receives external documentation that must be translated into product, onboarding, analytics, or operational models, the resulting mappings must be maintained as governed artifacts within ASD-controlled systems.
7. Regulatory Compliance
7.1 California — CCPA / CPRA
For employees and contractors in California, and for personal information ASD collects from California residents:
ASD collects personal information only for disclosed, lawful purposes
California employees have the right to know, delete, and opt out of the sale/sharing of their PI — ASD does not sell employee PI
Sensitive personal information is used only for purposes permitted under CPRA Section 1798.121
7.2 US Federal
ASD's AI and data practices comply with the FTC Act (Section 5), the Electronic Communications Privacy Act (ECPA), the Computer Fraud and Abuse Act (CFAA), and applicable sector-specific laws.
7.3 European Union — GDPR
ASD processes personal data only where a lawful basis exists under GDPR Article 6: performance of a contract, compliance with a legal obligation, legitimate interests, or explicit consent where required.
EU data subjects have rights to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), and not to be subject to solely automated decision-making with significant effects (Art. 22).
ASD will not deploy AI systems making solely automated decisions with legal or similarly significant effects on EU data subjects without implementing Art. 22 safeguards.
Transfers of EU personal data to the United States or other third countries will rely on Standard Contractual Clauses (SCCs) or other mechanisms recognized by the European Commission.
ASD will conduct a DPIA under GDPR Article 35 before deploying any new AI system that processes personal data at scale.
7.4 United Kingdom — UK GDPR
ASD applies the same standards as EU GDPR for UK data subjects, consistent with the UK GDPR and Data Protection Act 2018.
7.5 Other Jurisdictions
Canada: PIPEDA, provincial laws, and the forthcoming Bill C-27 / AIDA framework
Australia: Privacy Act 1988 and Australian Privacy Principles
Any jurisdiction-specific gambling or sports data regulations imposing additional data handling requirements
8. Data Minimization and Retention
ASD collects and retains only the minimum personal information necessary for the specified purpose. Production data (AWS RDS, S3) is retained per ASD's Data Protection Policy. Slack and Gmail retention is governed by workspace and Google Workspace retention settings configured by the Technology team.
9. Security and Incident Response
Data at rest is encrypted using AWS KMS; data in transit uses TLS. Access to systems containing personal information is governed by AWS IAM with least-privilege principles and MFA. Suspected incidents must be reported immediately to the Technology leadership team.
Confirmed breaches involving EU personal data will be reported to the relevant supervisory authority within 72 hours per GDPR Articles 33-34.
10. Responsibilities
Technology / Product Leadership: Maintains approved AI tools list, oversees data classification, and manages Slack workspace security
All Employees and Contractors: Read, understand, and comply with this policy. Use good judgment when adopting new AI tools. Report incidents promptly
People Operations / HR: Incorporates this policy into onboarding. Manages employee data subject rights requests
Legal / Compliance: Reviews policy annually and upon material regulatory changes
11. Policy Review and Updates
This policy will be reviewed annually, following any material data incident, and following significant new AI or privacy legislation. The current version is maintained in ASD's Google Drive and Confluence workspace.
12. Good Faith and Transition Provisions
This policy is intended as a working operational standard, not a tripwire. ASD personnel who operate in good faith toward the purposes of this policy are treated as compliant.
For privacy questions, data subject rights requests, or incident reports, contact privacy@altsportsdata.com.
ALT Sports Data, Inc. | AI, Data Privacy & Information Use Policy | Version 1.2 | April 15, 2026Last updated: April 15, 2026 — Version 1.2
Questions? Contact privacy@altsportsdata.com