Data Processing Addendum
Actovian is operated by Miloš Topić, an individual service provider based in the Republic of Serbia. Contact: office@actovian.com. This English version is the controlling version.
This Data Processing Addendum (“DPA”) forms part of the Actovian Terms whenever Actovian processes personal data in Customer Content on behalf of a Customer.
1. Roles and instructions
The Customer is controller and Actovian is processor for Customer Content. Each party remains an independent controller for personal data it processes for its own account, legal, security or billing purposes. Actovian will process Customer Content only on documented instructions contained in the Terms, configured product actions and lawful written directions, unless law requires otherwise.
2. Processing details
- Subject: governed AI planning, collaboration, approvals, connected-service synchronization and customer-directed actions.
- Duration: the active service period plus the deletion and legal-retention periods in the Privacy Policy.
- Data: business identities, roles, communications, calendar records, company information, goals, instructions, approvals, logs and audit evidence.
- People: Customer users, employees, contractors, prospects, customers, suppliers and meeting participants whose data the Customer submits.
- Purpose: providing, securing, supporting and measuring the service under Customer instructions.
3. Confidentiality and security
Persons authorised to process Customer Content are bound by confidentiality. Actovian maintains proportionate technical and organisational measures including tenant-scoped access control, role permissions, encryption in transit, encrypted integration credentials, restricted production secrets, audit trails, approval-bound external actions, rate limits, backup procedures and incident controls.
4. Subprocessors
The Customer gives general authorisation for the providers on the published Subprocessor List. Actovian will require materially equivalent data-protection obligations and remains responsible for their processing to the extent required by law. Material additions will be published before use where reasonably practicable. A Customer may object on reasonable data-protection grounds by emailing us promptly; if no reasonable alternative exists, either party may terminate the affected service.
5. Assistance
Taking account of the nature of processing and information available, Actovian will reasonably assist with data-subject requests, security, breach assessment, impact assessments and regulator consultations. The Customer remains responsible for responding to its data subjects and ensuring its instructions are lawful.
6. Security incidents
Actovian will notify the Customer without undue delay after confirming a personal-data breach affecting Customer Content and will provide available information reasonably necessary for the Customer’s obligations. Notice is not an admission of fault.
7. Return and deletion
During an active account, Customers may use available export controls. Following a verified deletion request or termination, Actovian will delete or anonymise Customer Content within a reasonable technical period unless law requires retention. Legally retained data remains protected and is used only for the retention purpose.
8. International transfers
Where restricted transfers require a safeguard, the parties incorporate the applicable European Commission Standard Contractual Clauses by reference, using the controller-to-processor module and the processing details in this DPA, unless another lawful transfer mechanism applies. Actovian will provide reasonable information about provider transfer safeguards on request.
9. Audit information
Actovian will make information reasonably necessary to demonstrate compliance available no more than once annually, unless a confirmed incident or regulator requires more. Audits must protect other customers, security and confidentiality, avoid production disruption, and use existing reports and remote review where sufficient. Customer-specific on-site work may be charged at reasonable cost unless it identifies a material Actovian breach.
10. Order of precedence
This DPA controls over conflicting Terms for processing Customer Content. Mandatory law controls over both. Contact office@actovian.comfor a countersigned copy or customer-specific annex.