Privacy Policy

Privacy Policy

Last updated: 17 May 2026

This Privacy Policy explains how ALIGA may collect, use and manage information connected with ALIGA RCM.

Who we are

ALIGA Pty Ltd provides ALIGA Resource Capacity Management, also known as ALIGA RCM. ALIGA is committed to managing personal information responsibly and transparently.

Contact: info@aliga.com.au or 1300 1 ALIGA.

What ALIGA RCM is

ALIGA RCM is a resource capacity management and delivery planning platform for organisations managing projects, portfolios, teams, resources, allocations, rates, forecasts and executive reporting.

What personal information may be collected

The product may collect user account details, names, email addresses, phone numbers, organisation details, role or job title, login activity, organisation membership, access roles, support requests, public enquiry details and audit records.

Customer organisations may also enter names, roles, teams, resource capacity information, project assignments and other workforce planning data for approved operational use.

How information may be collected

Information may be collected through account registration, invitations, login, public contact and access request forms, service enquiry forms, file imports, application usage, support interactions and approved administration workflows.

Public forms include a honeypot field and rate limiting. Marketing consent checkboxes are not pre-ticked.

How information may be used

Information may be used to provide ALIGA RCM, respond to enquiries, manage user access, support customer setup, operate resource planning workflows, generate reports, investigate incidents, maintain review records, administer subscriptions and improve product reliability.

ALIGA RCM outputs are decision-support information. They do not replace approved commercial, workforce, project or legal decisions.

Project, resource, capacity and workforce data

Customer organisations may use ALIGA RCM to store project, schedule, milestone, team, role, FTE demand, allocation, rate assumption and reporting information. This data is treated as customer operational data and is scoped to the relevant organisation workspace.

Customer account and user data

User accounts are authenticated using signed application sessions. Access is role-based and organisation membership is checked before protected pages and APIs are used.

Cookies, analytics and usage data

The application uses an HttpOnly session cookie for authentication. ALIGA RCM may record usage events such as page visits, imports, exports, support actions and reporting activity for product operation and support.

Public pages may use a Microsoft-hosted chat/contact widget. Users should avoid submitting confidential project files, passwords or sensitive commercial information through public forms or chat.

Data storage and hosting location

Repository configuration verifies Azure App Service and Azure PostgreSQL as the production hosting architecture for capacity.aliga.com.au. ALIGA will confirm the specific hosting region and any data residency commitment in the relevant customer documentation or agreement.

Data security measures

Verified controls include signed HttpOnly session cookies, Secure cookies in production, SameSite=Lax, role-based access checks, organisation-scoped data queries, security headers, public form rate limiting, file import validation and reviewable records for key actions.

Encryption in transit is expected for the public HTTPS service and HSTS is applied when requests are served over HTTPS. Encryption at rest, backup encryption and hosting-region controls should be confirmed in customer documentation before they are relied on externally.

Access, correction, deletion and export requests

Customers and users can request access, correction, export or deletion assistance by contacting info@aliga.com.au. Requests may be subject to contractual, legal, audit, security and operational retention requirements.

Some exports exist in the product for approved users. Complete account deletion and organisation deletion processes require ALIGA operational review before production use.

Third-party services and sub-processors

Verified configuration references Azure, Microsoft Graph/Exchange Online email, Microsoft Entra sign-in pathways, Power BI export/integration pathways and optional Stripe hosted checkout. Final sub-processor, region and data-processing details should be confirmed by ALIGA for each customer arrangement.

Data retention

Retention settings exist for some audit, authentication, reporting and warehouse records. Final retention periods for customer production use are subject to customer agreement and ALIGA operational policy.

Contact ALIGA

Email info@aliga.com.au or call 1300 1 ALIGA for privacy, account, data export or deletion enquiries.