Privacy Policy
Actovian is operated by Miloš Topić, an individual service provider based in the Republic of Serbia. Contact: office@actovian.com. This English version is the controlling version.
1. Who controls your data
For account administration, security, product analytics, support and direct service communications, the data controller is Miloš Topić, operating Actovian from the Republic of Serbia. For Customer Content submitted by an organisation, the customer normally acts as controller and Actovian acts as its processor under the Data Processing Addendum. Paddle independently controls payment and transaction data as merchant of record.
2. Data we process
- Identity and account data: name, email, authentication identifiers, locale and role.
- Workspace data: company profile, team membership, goals, policies, approvals and audit records.
- Connected-service data: Google account identity, encrypted OAuth credentials, Gmail and Calendar content selected or synchronized for the service.
- AI data: prompts derived from workspace instructions, model outputs, token usage, safety identifiers and approval decisions.
- Technical data: IP-derived security evidence, device and browser information, logs, error records and abuse signals.
- Billing data: plan, subscription status, Paddle customer and transaction identifiers. Actovian does not store full payment-card details.
- Support data: messages and materials you send to support.
3. Why and on what basis we process data
- To provide the service, authenticate users, execute customer instructions and administer subscriptions: performance of the service contract.
- To protect accounts, prevent abuse, preserve audit evidence and improve reliability: legitimate interests in operating a secure B2B service.
- To meet tax, accounting, fraud-prevention and legal obligations: compliance with law.
- To send optional marketing communications: consent, where consent is required. You may withdraw it at any time.
Actovian does not sell personal data or use Customer Content to build advertising profiles.
4. AI and automated processing
Actovian uses AI providers to create plans, drafts and internal work artifacts. Material external actions remain subject to configured policy and human approval. Actovian does not make solely automated legal, employment, credit or similarly significant decisions about individuals. Customers must not use the service for such decisions.
5. Sharing and subprocessors
Data is shared only as needed with infrastructure, authentication, AI, integration, email, payment and security providers listed on our Subprocessors page, with professional advisers, or where required by law. Customers control which Google account is connected and may disconnect it at any time.
6. International transfers
We prefer European hosting regions where available. Some providers may process data outside Serbia or the EEA. We rely on applicable adequacy decisions, contractual safeguards such as Standard Contractual Clauses, and provider security measures where required.
7. Retention
- OAuth credentials are kept only while the integration is connected and are removed when disconnection completes.
- Synced Gmail and Calendar resource data is retained for up to 90 days on a rolling basis unless the customer removes it earlier.
- Operational and security logs are normally retained for up to 90 days.
- Support correspondence may be retained for up to 24 months after closure.
- Workspace content is retained while the account is active and deleted or anonymised after a verified deletion request, subject to technical completion and legal retention duties.
- Billing, fraud-prevention, consent and audit evidence may be retained for the period required by applicable law or necessary to establish or defend legal claims.
8. Security
We use tenant isolation, role-based access, encrypted provider credentials, least-privilege integration scopes, payload-bound approvals, audit trails, rate limits and protected production secrets. No internet service is perfectly secure; customers must also protect their credentials and promptly report suspected misuse.
9. Your rights
Depending on applicable law, you may request access, correction, export, deletion, restriction or objection, and may withdraw consent. Use the account data controls or email office@actovian.com. We may verify identity before acting. You may also complain to the Serbian Commissioner for Information of Public Importance and Personal Data Protection or another competent supervisory authority.
10. Children, cookies and changes
Actovian is a business service and is not intended for anyone under 18. We currently use only essential authentication, security and language-preference storage as described in the Cookie Notice. Material policy changes will be versioned and, where required, presented for renewed acceptance.