Privacy Policy

This policy explains what personal data ActionsLedger processes, why, and what choices you have. It is a launch-phase draft: the bracketed placeholders must be completed by the operating entity before publication.

LAST UPDATED 25 AUG 2026

1Controller and contact

The data controller is [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. For privacy requests write to privacy@actionsledger.com. Our data protection contact is [DPO OR CONTACT NAME]. EU/UK representative, where required: [REPRESENTATIVE].

2What we collect

  • Account data — name, work email, organisation, role, password hash or identity-provider identifier.
  • Waitlist data — the email address and optional system of record you submit on the onboarding queue page.
  • Customer data — the records, proposed changes and evidence your agents and integrations send us, which may contain personal data about your contacts.
  • Audit data — who approved which change, when, and on what basis.
  • Technical data — IP address, device and browser information, request logs and error reports.
  • Billing data — company details and payment metadata held by [PAYMENT PROVIDER]; we do not store full card numbers.

3Why we process it

To provide and secure the service (contract), to prevent abuse and keep an accurate audit trail (legitimate interests and legal obligation), to bill you (contract), and to send launch and product updates (consent, withdrawable at any time). We do not sell personal data and we do not use your customer data to train third-party models.

4Roles: controller and processor

For account, waitlist, billing and technical data we act as controller. For the customer data in your workspace you are the controller and we act as processor under the terms of the Terms of Service and the data processing addendum at [DPA LINK].

5Sub-processors

We use a short list of vendors to run the service: hosting [HOSTING PROVIDER], database and authentication [DATABASE PROVIDER], email delivery [EMAIL PROVIDER], payments [PAYMENT PROVIDER], analytics [ANALYTICS PROVIDER], error monitoring [MONITORING PROVIDER]. The current list, with locations and roles, is maintained at [SUB-PROCESSOR LIST LINK]; we give [SUB-PROCESSOR NOTICE] notice before adding one.

6International transfers

Data is primarily hosted in [PRIMARY REGION]. Where data leaves that region we rely on EU Standard Contractual Clauses and the UK addendum, plus supplementary measures where needed. Copies are available on request.

7Retention

Account data: for the life of the account plus [ACCOUNT RETENTION]. Waitlist data: until onboarding or [WAITLIST RETENTION], whichever comes first. Audit entries: [AUDIT RETENTION], because their value is being tamper-evident over time. Technical logs: [LOG RETENTION]. Backups are cycled within [BACKUP RETENTION].

8Security

Encryption in transit and at rest, tenant isolation with row-level security, scoped integration credentials held only by the merge engine, least-privilege internal access, and an append-only hash-chained audit trail. We will notify affected customers of a personal-data breach without undue delay and within [BREACH NOTICE WINDOW]. Report a vulnerability to disclosure@actionsledger.com.

9Cookies and analytics

We use strictly necessary cookies for sign-in and preferences such as your light/dark theme. Analytics and any non-essential cookies run only with consent, as described at [COOKIE NOTICE LINK].

10Your rights

Depending on where you live you can request access, correction, deletion, portability, restriction, or object to processing, and withdraw consent. Contact privacy@actionsledger.com; we respond within [RESPONSE WINDOW]. You may also complain to your supervisory authority ([SUPERVISORY AUTHORITY]). If you are an end user of a customer's workspace, please contact that customer first.

11Changes

We will update this page when our practices change and note the date above. Material changes are communicated to account owners at least [CHANGE NOTICE] in advance.