Nakladanie

Privacy Policy (Actualog)

This Privacy Policy explains how Actualog (“we”, “us”, “our”) collects, uses, shares, and protects personal data when you use the Actualog website and the Actualog Product Information Management (PIM) platform (“Service”). Actualog is a B2B SaaS solution hosted in Microsoft Azure.

This text is provided as a product-ready policy template. Your legal team should review it for your jurisdiction, your subprocessors, and your exact business model.


1) Who we are

Controller (for Account & Website Data):
[Legal entity name]
[Registered address]
Contact: [privacy email]

Data Protection Officer (if applicable): [DPO contact or “Not appointed”]


2) What this policy covers

This policy covers personal data processed when you:

  • visit our public website,
  • create an account, sign in, and use the Service,
  • use collaboration features (profiles, communities, invitations),
  • contact support or receive service communications.

It applies to personal data relating to individual users, including users acting on behalf of a company.


3) Roles: Controller vs Processor (important for B2B)

Actualog processes different types of data in different roles:

3.1 Account & Platform Administration Data (we are the Controller)

We act as the data controller for data needed to:

  • create and manage user accounts,
  • administer authentication and security,
  • manage billing, subscription, and contractual relationships,
  • operate and improve the Service.

3.2 Customer Data in Workspaces (we are typically the Processor)

When a customer organization uses Actualog to store or manage product information, documents, catalogs, and related business content, the customer organization is typically the controller of that content (“Customer Data”), and Actualog acts as a processor on the customer’s instructions.

If you are using Actualog under a company subscription, your company’s agreement and any Data Processing Addendum (DPA) govern how Customer Data is processed.


4) Personal data we collect

4.1 Data you provide

  • Account data: name, email, password (hashed), sign-in provider identifiers (if you use SSO/social sign-in).
  • Profile data: avatar, biography/about text, social links, country, time zone, currency, optional phone.
  • Company/workspace data: company membership, invitations, roles/permissions assigned to you.
  • Support communications: messages and files you provide to support.

4.2 Data we collect automatically

  • Usage and log data: IP address, device/browser info, timestamps, pages/actions performed, error logs, audit logs (where enabled).
  • Security data: authentication events, suspicious activity signals, and related identifiers needed to protect accounts and the Service.

4.3 Cookies and similar technologies

We use cookies and similar technologies for essential functionality, preferences, and (where enabled) analytics. See Cookie Policy.


5) How we use personal data

We use personal data to:

  1. Provide the Service

    • create accounts and authenticate users
    • enable navigation, permissions, and workspace membership
    • deliver core platform functionality (PIM workflows, catalogs, communities)
  2. Operate security and prevent abuse

    • protect accounts, detect fraud and abuse
    • maintain secure sessions and platform integrity
  3. Customer support and communications

    • respond to support requests
    • send service notices (critical updates, security notifications, system changes)
  4. Billing and contractual administration

    • manage subscriptions, invoices, payments, and compliance obligations
  5. Product improvement

    • diagnose issues, improve performance and usability
    • analyze aggregated usage patterns (where applicable)
  6. Marketing communications (B2B)

    • send product updates and onboarding content where permitted by law or with consent
    • you can opt out of non-essential marketing communications at any time

Where GDPR or similar regimes apply, we process personal data based on:

  • Contract necessity (to provide the Service you request),
  • Legitimate interests (security, fraud prevention, service improvement, B2B relationship management),
  • Consent (where required, e.g., for non-essential cookies or certain marketing),
  • Legal obligation (accounting, compliance, responding to lawful requests).

Privacy notices typically must include purposes, legal bases, retention, recipients, and rights. :contentReference[oaicite:0]


7) How we share personal data

We do not sell personal data.

We may share personal data with:

7.1 Service providers (processors/subprocessors)

We use trusted vendors to host and operate the Service, provide security, support communications, and analytics (if enabled). Actualog is hosted in Microsoft Azure, and Microsoft acts as a provider for cloud infrastructure and related services.

Microsoft publishes a Data Protection Addendum (DPA) for its online services. :contentReference[oaicite:1]

7.2 Customer organizations (workspace administrators)

If you use Actualog as part of a company workspace, your profile and activity within that workspace (e.g., roles, audit events) may be visible to authorized workspace admins according to permissions.

We may disclose data where required by law, or to protect the rights, security, and integrity of Actualog, our customers, and users.


8) International transfers

If personal data is transferred outside your country/region (e.g., outside the EEA/UK), we use appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms where required.

Microsoft offers SCCs for transfers for in-scope services. :contentReference[oaicite:2]


9) Security

We implement technical and organizational measures designed to protect personal data, including access controls, least-privilege principles, monitoring, and encryption practices appropriate to a cloud SaaS platform.

Azure provides encryption capabilities for data at rest and in transit, with key management options. :contentReference[oaicite:3]

No system is 100% secure. We continually improve controls as threats evolve.


10) Data retention

We retain personal data only as long as necessary for the purposes described in this policy, including:

  • while your account is active,
  • as needed to provide the Service,
  • to comply with legal obligations (e.g., accounting),
  • to resolve disputes and enforce agreements.

Retention periods may differ by data type (e.g., security logs vs account profile) and by customer contract.


11) Your rights and choices

Depending on your location, you may have rights such as:

  • access to your personal data,
  • correction,
  • deletion,
  • restriction or objection to processing,
  • portability (where applicable),
  • withdrawal of consent (where processing is based on consent),
  • the right to lodge a complaint with a supervisory authority. :contentReference[oaicite:4]

How to exercise your rights

Contact us at [privacy email]. We may need to verify your identity. If you use Actualog through a company workspace, some requests regarding Customer Data may need to be handled by your organization (the controller).


12) California notice (CCPA/CPRA)

If you are a California resident, you may have rights such as:

  • the right to know what personal information is collected and why,
  • the right to request deletion (subject to exceptions),
  • the right to correct,
  • the right to opt out of “sale” or “sharing” (if applicable),
  • the right to non-discrimination for exercising privacy rights.

California’s guidance highlights that notices should describe categories of information collected and purposes. :contentReference[oaicite:5]

Actualog does not sell personal information. If we ever engage in activity that qualifies as “sale” or “sharing” under California law, we will provide appropriate notices and opt-out mechanisms.


13) Children

Actualog is intended for business users and is not directed to children. We do not knowingly collect personal data from children.


14) Changes to this policy

We may update this policy from time to time to reflect legal, technical, or operational changes. We will post the updated version with a new effective date.