Privacy Policy
Effective date: 1 January 2026
Last updated: 17 July 2026
This Privacy Policy explains how ACTServ Technology Ltd ("ACTServ", "we", "us") processes personal data in connection with our website, sales and enquiries, customer and supplier relationships, the ACTServ GRC Platform, support, billing, events, marketing and other direct business interactions.
Where our customers use the ACTServ GRC Platform to process information about their own personnel, vendors and other individuals, those customers remain responsible for their own privacy notices. This Privacy Policy does not replace the privacy notices of ACTServ customers.
1. Who we are
ACTServ Technology Ltd is a company established in the Republic of Cyprus under registration number HE428639.
Registered address: 17 Armodiou, 2335 Lakatamia, Cyprus
Privacy contact: privacy@actserv.tech
2. Our roles: Controller and Processor
ACTServ acts as Data Controller for personal data relating to:
- Website enquiries
- Sales and prospective customer information
- Customer contacts and account administration
- Billing and contract administration
- Security and fraud prevention
- Support administration
- Supplier and partner contacts
- Marketing communications
- ACTServ's own legal and corporate obligations
ACTServ acts as Processor, or as Subprocessor where the customer itself acts as Processor, for Customer Data processed through the ACTServ GRC Platform on behalf of customer organisations.
Processing of Customer Data is governed by the customer agreement, the ACTServ GRC Master Subscription Agreement, the Data Processing Agreement and the Subprocessor Schedule.
If your personal data is processed in the Platform on behalf of a customer organisation, requests concerning that data should usually be directed to that organisation, which acts as Controller.
3. People covered by this Policy
This Policy covers:
- Website visitors
- Prospective customers
- Customer representatives
- Customer employees and authorised Platform users
- Suppliers and business partners
- Professional advisers
- Event participants
- Job applicants, where applicable
- People contacting ACTServ for support or other business purposes
4. Personal data we collect
Contact and business data
We may process:
- Name
- Job title
- Company and department
- Business email address
- Business telephone number
- Business address
- Customer, supplier or partner role
- Communications and correspondence
Contract and billing data
We may process:
- Subscribed services
- Contract and order details
- Invoice and payment status
- VAT and accounting information
- Procurement contacts
- Renewal and customer-administration information
Platform account data
We may process:
- Name, business email address and organisation
- User identifier, assigned role and account status
- Authentication and MFA-related status
- Session and account activity metadata
ACTServ does not directly receive or store Platform user passwords. Authentication credentials are handled by the Platform's identity provider.
Technical and security data
We may process:
- IP address, browser and device information
- Timestamps, login and authentication activity
- Audit events and security alerts
- Application diagnostics, error and performance information
- Records required to detect and investigate misuse or incidents
Enquiry, sales and marketing data
We may process:
- Service interest, demo and contact requests
- Meeting notes and communication preferences
- Event participation and source of enquiry
Support information
We may process:
- Support-ticket content, screenshots and attachments
- Technical logs voluntarily provided
- Troubleshooting records and communications with ACTServ support
Please do not submit passwords, secret keys or unnecessary sensitive personal data through support channels.
Customer Data processed on behalf of customers
Customers may use the ACTServ GRC Platform to process employee and user information, roles and departments, control, risk and policy owners, vendor and professional contacts, audit and assessment records, compliance evidence, uploaded files, Microsoft 365 inventory or integration metadata, and other information selected by the customer. The customer determines the purpose and content of this processing.
5. How we obtain personal data
We obtain personal data:
- Directly from you
- From your employer or organisation
- From customer administrators
- Automatically through website or Platform use
- From customer-controlled integrations
- From support interactions
- From suppliers and business partners
- From publicly available professional sources
- From referral or event partners, where lawful
6. Why we use personal data and legal bases
Enquiries and demonstrations. We respond to requests, schedule meetings and assess potential business relationships. Legal basis: steps requested before entering into a contract, and our legitimate interests in developing business relationships.
Customer and supplier administration. We enter into and administer contracts, maintain contacts, deliver services and manage renewals and procurement. Legal basis: performance of a contract, legitimate interests and legal obligations.
Platform accounts. We provision accounts, authenticate users, administer permissions and provide the Platform. Legal basis: performance of contracts with customer organisations, and our legitimate interests in delivering and securing the service. Individual Platform users do not need a personal contract with ACTServ.
Security, monitoring and fraud prevention. We protect systems, detect abuse, investigate incidents, enforce contractual restrictions and maintain auditability. Legal basis: our legitimate interests in protecting ACTServ, its customers and users from security threats, misuse and fraud, and legal obligations where applicable.
Support. We respond to tickets, troubleshoot, maintain service quality and investigate technical issues. Legal basis: contractual performance and our legitimate interests in providing effective support.
Billing and accounting. We invoice, collect payment, keep financial records and comply with tax and accounting requirements. Legal basis: contract, legal obligation and our legitimate interests in managing the business.
Marketing. We communicate relevant ACTServ services, invite contacts to events and maintain business relationships. Legal basis: consent where required, and our legitimate interests in proportionate business-to-business marketing, subject to your right to opt out at any time.
Legal and regulatory compliance. We comply with law, respond to authorities, establish or defend legal claims and meet audit, insurance and governance requirements. Legal basis: legal obligation and our legitimate interests in protecting ACTServ's legal position.
Website operation and measurement. We operate the website, maintain its security and understand aggregate usage. Legal basis: our legitimate interests in operating and securing the website, and consent where non-essential cookies are used.
7. ACTServ GRC Platform and Customer Data
Customers control Platform configuration and Customer Data. Customers determine their authorised users and choose which integrations to enable and with what permission scopes.
ACTServ processes Customer Data only for providing, securing, supporting and administering the Platform, as set out in the Data Processing Agreement. ACTServ separately processes account, billing, security and support administration data as Controller.
The Platform is a management tool and does not independently determine the customer's compliance decisions. The customer is responsible for its own privacy notices, lawful bases, user communications and processing instructions. The providers involved in delivering the Platform are listed in the Subprocessor Schedule.
8. Integrations
Customers may enable integrations between the Platform and third-party or customer-controlled systems. The customer selects the integration and controls its permissions and scope. ACTServ processes the information made available through the configured integration. Third-party providers may separately process information under their own agreements with the customer. Revoking an integration does not necessarily delete information already collected and retained under the customer agreement.
For Microsoft 365, inventory integrations may collect directory, identity, licensing, device or security information according to the permissions granted by the customer. Email functionality, where enabled, sends notifications through a customer-controlled designated mailbox and does not provide ACTServ with general mailbox-reading access.
9. Cookies and similar technologies
We aim to keep the use of cookies and similar technologies to a minimum.
The website currently uses only essential storage required for basic functionality, security and remembering acknowledgement of the cookie notice. The ACTServ GRC Platform may use necessary authentication and session technologies provided by its identity provider.
The website does not currently use marketing or advertising cookies. If optional analytics or similar technologies are introduced, they will be activated only after consent where consent is required by law.
10. Sharing and recipients
We may disclose personal data to:
- Cloud, hosting and application providers
- Identity and authentication providers
- Communication and email providers
- CRM, sales and customer-management providers, where used
- Support and operational providers
- Analytics providers, where used
- Accountants, auditors, legal advisers, insurers and other professional advisers
- Banks and payment providers
- Competent authorities
- Parties involved in a merger, acquisition, reorganisation or asset sale, subject to appropriate safeguards
For Customer Data processed through the Platform, the relevant providers are listed in the Subprocessor Schedule.
ACTServ does not sell personal data.
11. International transfers
Where personal data is transferred outside the European Economic Area to a country that has not been recognised by the European Commission as providing an adequate level of protection, ACTServ relies on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, together with supplementary measures where appropriate. Information about these safeguards may be requested through privacy@actserv.tech.
12. Retention
We retain personal data only as long as needed for the purposes described in this Policy:
- Enquiry and prospect information: for a reasonable period after the last meaningful interaction
- Customer and supplier contracts: for the contract term and applicable legal, tax, accounting and limitation periods
- Billing records: as required under Cyprus accounting and tax law
- Platform account data: for the duration of the account and a proportionate period required for security, dispute and compliance purposes
- Security and audit logs: according to ACTServ's documented security and operational retention schedules
- Support records: as necessary to resolve the request and support legal, contractual and security needs
- Marketing preferences: until withdrawal or objection, with a limited suppression record retained to respect the request
- Customer Data: according to the customer agreement, the Data Processing Agreement, the export period and the backup-deletion cycle
- Recruitment records: according to the applicable recruitment retention process, where collected
Data may be retained longer where required by law, a legal hold, a dispute, an investigation or a security need.
13. Security
ACTServ maintains appropriate technical and organisational measures designed to protect personal data, including access controls, multi-factor authentication where applicable, role-based access, logging and monitoring, personnel confidentiality, secure development practices, incident-response procedures, backups and supplier management. Further information about ACTServ's security arrangements is available in the Security Overview.
ACTServ Technology Ltd maintains an Information Security Management System certified to ISO/IEC 27001:2022 within the certified scope.
While we seek to protect personal data, no method of transmission or storage can be guaranteed to be completely secure.
14. Automated decision-making
ACTServ does not use personal data covered by this Privacy Policy to make decisions based solely on automated processing that produce legal or similarly significant effects, unless specifically disclosed at the relevant time.
15. Direct marketing
ACTServ may send proportionate business-to-business marketing about relevant ACTServ services and events. Where required, we ask for consent. You may opt out at any time by using the unsubscribe option in the relevant communication or by contacting privacy@actserv.tech. Opting out does not affect operational, security, billing or contractual communications.
16. Your rights
Subject to applicable law, you may have rights including:
- The right to request access to your personal data
- The right to request correction of inaccurate data
- The right to request deletion of your personal data
- The right to request restriction of processing
- The right to object to processing in certain circumstances
- The right to data portability, where applicable
- The right to withdraw consent, where processing is based on consent
- Rights regarding qualifying automated decision-making
- The right to lodge a complaint with the competent supervisory authority
We may need to verify your identity before responding to a request.
If ACTServ processes the relevant personal data solely on behalf of a customer, the request should normally be directed to that customer. ACTServ will assist the customer in accordance with the applicable Data Processing Agreement.
17. Complaints
You may lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus or another competent supervisory authority.
18. Children
The website and the ACTServ GRC Platform are intended for business and professional use and are not directed to children. ACTServ does not knowingly provide Platform accounts directly to children.
19. Third-party websites
This website may contain links to third-party websites and services. Those sites and services have their own privacy notices, and ACTServ Technology Ltd is not responsible for their privacy practices or content.
20. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The current version and its date appear on this page. Material changes may be communicated by email or by prominent notice where appropriate.
21. Contact
For questions relating to this Privacy Policy or the processing of personal data, please contact:
ACTServ Technology Ltd
Registration number: HE428639
Registered address: 17 Armodiou, 2335 Lakatamia, Cyprus
Email: privacy@actserv.tech
