Privacy Policy
Last updated: July 8, 2025
1. Introduction
Welcome to Actionful (“Actionful,” “we,” “us,” or “our”). Actionful is an AI-agent platform that enables businesses to design, deploy, and manage conversational and task-automation agents across channels, including but not limited to WhatsApp, web, and other messaging or productivity platforms owned by Meta, Google, Microsoft, and their affiliates.
This Privacy Policy explains how we collect, use, disclose, and protect personal data when you (“Customer”) use our services, visit our websites, or otherwise interact with us. It also describes your choices and rights. By using our services, you acknowledge that you have read and understood this policy.
2. Definitions
- “Services” – The Actionful SaaS platform, APIs, SDKs, websites, dashboards, mobile or desktop applications, documentation, and related support.
- “Customer Data” – Any data, content, or information (including personal data) submitted to the services by or on behalf of a customer or its end users.
- “Personal Data” – Any information that relates to an identified or identifiable natural person.
- “Processing” – Any operation performed on personal data, whether or not by automated means.
- “Controller” / “Processor” – As defined by the EU GDPR. Unless otherwise stated, customers are the controllers of customer data, and Actionful acts as a processor or service provider.
3. Scope
This policy applies to personal data that we process:
- When you browse or interact with our websites or marketing communications (Actionful as Controller), and
- When we host or process customer data on behalf of a customer (Actionful as Processor or service provider).
Separate terms, such as a data processing addendum, may govern where we act solely as a processor.
4. Information We Collect
| Category | Types of data | Source |
|---|---|---|
| Account & Profile | Name, email address, phone number, company name, role or title, billing address, authentication credentials | Provided by customer or its users |
| Usage & Log | IP address, device identifiers, browser type, operating system, timestamps, API calls, error logs, feature usage, session metadata | Collected automatically |
| Communications | Support tickets, chat messages, recordings (with notice), survey responses, marketing preferences | Provided by you or generated in interactions |
| Customer Content | Message transcripts, prompts, AI-agent configurations, training data, files, end user contact information | Submitted or generated by customer via the services |
| Third-Party Integrations | IDs or tokens for Meta or WhatsApp, Google, Microsoft, or other connected services; metadata about chats or meetings | Provided by integration or customer |
5. How We Use Personal Data
- Provide and operate the services – authenticate users, route messages, generate or train AI models, deliver notifications, and maintain platform functionality.
- Improve and develop – troubleshoot, debug, run analytics, perform research, and train models using de-identified or aggregated data where feasible.
- Security and abuse prevention – detect, prevent, and respond to fraud, spam, security incidents, and service misuse.
- Billing and account management – issue invoices, process payments, and communicate about account status.
- Compliance and legal – satisfy contractual or legal requirements, respond to lawful requests, or enforce our agreements.
- Marketing (controller context) – send product updates or promotional materials, subject to your opt-out rights.
Our legal bases under GDPR are performance of a contract, legitimate interests, consent where obtained, and compliance with legal obligations.
6. Sharing and Disclosure
We do not sell personal data. We disclose it only:
- With authorized service providers and sub-processors – hosting, analytics, email, support, payment, or communications vendors bound by confidentiality and data protection obligations.
- With connected platforms – when you link Meta or WhatsApp, Google, Microsoft, or other third-party accounts, we share the data necessary to enable requested functionality under their developer policies.
- Within our corporate group – to affiliates that support the services, subject to this policy.
- For legal reasons – to competent authorities when required, or to protect rights, property, or safety.
- Business transfers – in connection with mergers, acquisitions, or asset sales, with appropriate safeguards.
7. International Transfers
We are headquartered in the Netherlands, with infrastructure in the EU, US, and other regions. When personal data is transferred outside the European Economic Area, we rely on approved mechanisms such as adequacy decisions, Standard Contractual Clauses, or Binding Corporate Rules, and implement supplementary safeguards where required.
8. Data Retention
We retain personal data for as long as necessary to (i) provide the services, (ii) comply with legal obligations, (iii) resolve disputes, or (iv) enforce agreements. Customer data is deleted or returned within 30 days of account termination unless otherwise agreed or required by law. Aggregated or anonymized data may be retained indefinitely.
9. Security
We employ administrative, technical, and physical safeguards, including encryption in transit and at rest, network segmentation, role-based access controls, and regular penetration testing, to protect personal data. No system is 100% secure, but we follow industry best practices and frameworks such as ISO 27001 and SOC 2 Type II.
10. Your Rights and Choices
Depending on your jurisdiction, you may have the right to:
- Access, correct, or delete personal data
- Object to or restrict processing
- Port data to another service
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
Requests can be submitted to [email protected]. Where we act as processor, we will forward requests to the relevant customer (controller).
For marketing communications, you may opt out via the unsubscribe link or through your account settings.
11. California and U.S. State Notices
Actionful acts as a service provider or processor under the California Consumer Privacy Act (CCPA) and similar state laws. We do not sell or share personal data as defined by such laws, nor do we use it for cross-context behavioral advertising without consent.
12. Children
The services are not directed to children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us so we can delete it.
13. Changes to This Privacy Policy
We may update this policy from time to time. Material changes will be notified via email or through the services at least 30 days before they take effect. Continued use of the services after the effective date constitutes acceptance of the revised policy.
14. Contact Us
QuantumDot V.O.F.
Zandbreeweg 12A, 7577 BZ Oldenzaal, The Netherlands
Email: [email protected]
For data-protection queries, please specify “Privacy Request” in the subject line.