Legal

Privacy Policy

Effective date: 13 October 2025

Last updated: 23 September 2026. This update adds the Actyve app and its connected-calendar feature (section 10), and describes our single artificial-intelligence provider (section 16).

Lire cette politique en français

1. Introduction

This privacy policy explains how Actyve SRL, a company incorporated under Belgian law (“Actyve”, “we”, “us”, “our”), collects, uses, shares and protects the personal data of the users of its website (https://actyve.ai), its online audit tool (audit.actyve.ai), its application tool (jobs.actyve.ai), the Actyve app, its services and any other interaction with its activities.

The Actyve app is the customer relationship management (CRM) software used by our clients’ sales teams. In this document it is referred to as “Actyve” or, where it needs to be distinguished from the website, “the Actyve app”; “Actyve” is the name under which it appears on Google’s authorisation screen when a user connects their calendar to it (see section 10).

We attach the utmost importance to protecting your privacy and the confidentiality of your data. We are committed to collecting and processing personal data in compliance with the General Data Protection Regulation (GDPR, EU 2016/679) and applicable Belgian law. This document describes our practices as they stand on 23 September 2026: it does not constitute a declaration of compliance, and no certification attests to it.

By using our website or our services, or by interacting with Actyve, you accept the practices described in this policy. If you do not agree with it, we recommend that you do not use our website or our services.

2. Personal data we collect

Personal data is any information that makes it possible to identify you directly or indirectly. We collect such data when you:

  • use our website or our online forms,
  • take part in our events,
  • communicate with us (email, telephone, chat, social networks),
  • interact with our services or campaigns.

The categories of data we may collect are the following:

a. Identification and contact data: surname, first name, email address, telephone number, company.
b. Browsing data: IP address, device type, location data, pages visited, duration of visits.
c. Communications: messages exchanged with our team by email, chat, telephone or social networks.
d. Geolocation data: approximate or precise location of your device if you enable location services.

A note on the form on this website’s Contact page: when you submit it, the information entered (name, company, email address, telephone number and the content of your message) is sent to our website, then routed by our email delivery provider (see section 11) to our team’s mailboxes. Your email address is used as the reply address so that we can answer you directly. Your IP address is read at the time of sending, solely to limit the number of messages sent from a single connection and to filter out automated submissions; it is not recorded in any database and does not appear in the message. The form also contains a hidden anti-spam field, the content of which is never included in any message.

3. Purposes and legal bases of processing

We use your personal data for the following purposes:

a. Provision of services: performing a contract, responding to your requests, managing your account or project.
b. Communication: informing you about our services, events, offers and news, or responding to your requests.
c. Payment management: accounting, invoicing, fraud prevention.
d. Improvement of our services: statistical analysis, optimisation of the user experience, testing of new features.
e. Customer service: providing personalised follow-up, collecting your feedback and improving our support.
f. Legal obligations: complying with our tax, accounting or regulatory obligations.

We may also carry out profiling (analysing your data to better understand your needs and personalise our services) only with your explicit consent.

The legal basis for these processing operations depends on the purpose:

  • Performance of a contract (e.g. provision of services)
  • Consent (e.g. newsletters, profiling)
  • Legitimate interest (e.g. security, improvement of services)
  • Legal obligation (e.g. invoicing, compliance)

4. Data retention period

We keep your personal data only for as long as necessary to achieve the purposes described above, or to comply with our legal obligations.
At the end of that period, your data is deleted or anonymised. We may keep certain data in anonymised form for statistical or analytical purposes.

5. Data security

We implement appropriate technical and organisational measures to protect your data against loss, unauthorised access, disclosure, alteration or accidental destruction.
Only authorised persons within our company or our service providers may access your data, in strict confidence.

6. Sharing and transfer of data

We never sell your personal data.
We may however share it with the following categories of recipients, only where necessary:

a. Technical providers and partners: hosting providers, cloud solutions, marketing tools, messaging providers.
b. Legal advisers, authorities and courts: where required by law or to assert our rights.
c. Commercial subcontractors: solely in the context of performing our services on your behalf.

All third parties are bound by strict confidentiality and security obligations and use your data only for the agreed purposes.

7. Transfers outside the European Union

In some cases, your data may be transferred to countries outside the European Economic Area. In that case, we ensure that appropriate safeguards are in place (standard contractual clauses of the European Commission or an adequacy decision).

8. Your data protection rights

Under the GDPR, you have the following rights:

  • Right of access: obtain a copy of your data.
  • Right to rectification: correct any inaccurate data.
  • Right to erasure: request the deletion of your data under certain conditions.
  • Right to restriction: temporarily restrict processing.
  • Right to object: object to processing based on legitimate interest.
  • Right to data portability: receive your data in a structured format.
  • Right to withdraw your consent at any time.

To exercise your rights, contact us at: contact@actyve.ai

8.1. Response time

We undertake to respond within one month of receiving your request.

This period may be extended by two months where your request is complex or where we receive several requests at the same time. In that case, we will inform you of the extension and of its reasons within one month of receiving your request, in accordance with Article 12(3) of the GDPR.

8.2. Right to lodge a complaint with a supervisory authority

If you consider that the processing of your personal data does not comply with the regulations, you have the right to lodge a complaint with a supervisory authority, in accordance with Article 77 of the GDPR. In Belgium, the competent authority is the Data Protection Authority.

Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit)
Rue de la Presse 35, 1000 Brussels, Belgium
Email: contact@apd-gba.be
Website: www.dataprotectionauthority.be

This authority can be approached in three ways: a request for information, a request for mediation, or a complaint. It does however ask that you first contact the controller, that is to say us, and wait one month before referring the matter to it. We therefore invite you to write to us first at contact@actyve.ai: it is the fastest way to have anything that needs correcting corrected, and it does not deprive you of any of your remedies.

You may also lodge your complaint with the supervisory authority of the Member State in which you have your habitual residence, your place of work, or where the alleged infringement took place.

Finally, you have the right to an effective judicial remedy, both against a decision of a supervisory authority (Article 78 of the GDPR) and against us as controller (Article 79 of the GDPR).

9. Cookie policy

9.1. What is a cookie?

A cookie is a small text file placed on your device (computer, smartphone, tablet) when you visit our website. It stores information about your browsing in order to improve your experience, analyse the use of the website and display relevant advertising.

9.2. Cookies set by this website

This website sets no cookies. This was verified page by page on 1 August 2026, by inspecting cookies as well as the browser’s local storage and session storage: no cookie, and no data kept on your device by the website.

We use no audience measurement tool and no advertising tool on this website: neither Google Analytics, nor Matomo, nor Meta Pixel, nor Google Ads, nor any equivalent. We therefore do not measure your browsing and we build no advertising profile from your visit.

The fonts used by the website are hosted on our own servers. Displaying them triggers no call to a third-party font service.

9.3. Third-party content embedded in certain pages

Three pages load content hosted on a domain other than actyve.ai, either in an embedded frame or as a video file. In each of these cases, your browser contacts that domain directly, which necessarily receives your IP address and the usual technical information of a connection (browser, operating system).

  • Home page (actyve.ai): the presentation video is hosted by Bunny.net (BunnyWay d.o.o., Slovenia). It is only requested when you start playback: as long as you do not click the play button, no data is sent to that service, the animated preview shown by default being a file hosted on our own servers. No cookie was observed during our checks of 1 August 2026.
  • Become a partner page (actyve.ai/audit): our audit tool, hosted on audit.actyve.ai. It records the answers and contact details you enter as well as your IP address, and it keeps the state of your audit in your browser’s local storage.
  • Jobs page (actyve.ai/jobs): our application tool, hosted on jobs.actyve.ai. It uses a Meta measurement tool, subject to its own consent banner displayed inside the embedded frame. If you accept in that banner, Meta cookies (_fbp, _fbc) are set by jobs.actyve.ai; if you refuse or do not respond, no cookie is set.

Details of this third-party content, of the data it receives and of its recipients can be found in our Cookie policy (in French).

9.4. How to object

As the website itself sets no cookies, no action is required on your part to browse it. For the third-party content described above, you can:

  • refuse in the consent banner displayed by our application tool on jobs.actyve.ai: no Meta cookie is then set;
  • set your browser to block or delete cookies, including those of embedded content; the instructions can be found in your browser’s help;
  • not start playback of the video on the home page: as long as you do not click the play button, its host is not contacted;
  • not open the other pages listed above: apart from these, no page of the website loads content hosted on another domain.

Should an audience measurement tool or an advertising tool ever be added to this website, a mechanism to collect your consent would be put in place before any non-essential cookie is set.

Non-essential cookies are set on the basis of your explicit consent, in accordance with Article 6(1)(a) of the GDPR.

10. Actyve app: Google user data

This section concerns only the Actyve app, the CRM used by our clients’ sales teams, and only those of its users who choose to connect their Google Calendar to it. It describes what the app does with the data obtained from Google.

10.1. What is connected, and for what purpose

A user of the Actyve app can voluntarily connect their Google Calendar from Settings, then Connected calendar. The app then asks Google for permission to access that user’s calendar events (the calendar.events scope, https://www.googleapis.com/auth/calendar.events). This access is used for two purposes only:

  • importing the user’s events in order to block their busy slots when appointments are booked. The data imported is the dates and times, title, location, description and link of each event. Attendees and the organiser are never imported. The details of these events are visible only to the user themselves and, if the client account enables this option, to the administrators of their team; the other members of the team see only a “Busy” slot;
  • writing into the user’s Google Calendar the appointments they book in the app. The prospect is never added as an attendee of the event and receives no invitation.

The app uses this data for no other purpose.

10.2. What we do not do with this data

  • It is neither sold, nor used for advertising purposes, nor transferred to third parties, except for what is strictly necessary to operate these two features, for the security of the app or to comply with a legal obligation.
  • It is never used to create, train or improve an artificial-intelligence or machine-learning model, whether general-purpose or not, neither by Actyve nor by a service provider.
  • No member of Actyve’s team reads this data, except with the user’s explicit consent, for security purposes, or to comply with a legal obligation.

10.3. Storage and security

The imported events and the Google access tokens are stored in the European Union, in the app’s database hosted by Scaleway in Paris. The Google access tokens are stored encrypted.

10.4. Disconnecting and deletion

The user can unlink their calendar at any time from Settings, then Connected calendar. Access is then revoked with Google, the tokens are deleted and the imported events are erased from the app. The user can also remove the Actyve app’s access from their Google account settings, at https://myaccount.google.com/permissions. When a user is removed from their company’s account, their Google access is purged automatically.

10.5. Statement regarding Google’s policy

Actyve's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

11. Who receives your data

In addition to section 6, here are the recipients to whom your data may be communicated, and the service concerned in each case (the actyve.ai website, the online audit, the application tool, the Actyve app).

  • Hosting and execution of our applications: Vercel, for the website, the online audit, the application tool and the Actyve app. The Actyve app is served from Vercel’s Paris region.
  • Artificial-intelligence provider: Scaleway (Generative APIs, France), for all our services: the online audit, the screening of applications, the Actyve app and the Actyve AI assistant. It is our only artificial-intelligence provider (see section 16).
  • Database of the Actyve app: Scaleway (France, Paris).
  • Databases of the online audit and of the application tool: Neon.
  • Delivery of our automated emails: Resend, for the website’s contact form, the online audit, the application tool and the Actyve app’s sign-in codes.
  • Google: only when a user of the Actyve app connects their Google Calendar, under the conditions described in section 10.
  • Customer relationship management and appointment scheduling: our customer relationship management and appointment scheduling provider, for the website and the online audit, which receives the contact details of people wishing to be called back as well as the appointments booked.
  • Advertising platform: Meta, for measuring the campaigns linked to our application form, and only if you consent to it in the banner displayed by that tool.

With the exception of the advertising platform, which also pursues its own purposes, and of Google, whose connected calendar belongs to the user’s own Google account, these providers act on our behalf, as processors, under the contracts concluded with them.
To these are added the recipients already mentioned in section 6: our legal advisers, the authorities and the courts, where required by law or to assert our rights.
The content loaded from another domain when you visit certain pages of the website, and the data it receives as a result, are described in section 9.

12. Hosting and transfers outside the European Union

Section 7 sets out the principle. Here is the actual situation as it stands on 23 September 2026.

  • The Actyve app’s database is hosted by Scaleway in France (Paris). The Google Calendar data described in section 10 is stored there.
  • Our artificial-intelligence provider, Scaleway, processes our requests in France, within the European Union. These requests are not transferred outside the European Union.
  • The databases of the online audit and of the application tool are hosted by Neon, on Amazon Web Services infrastructure located in the European Union, in the Europe region (Frankfurt, Germany).
  • Our hosting provider Vercel is a company established in the United States, as are some of our other providers (email delivery, advertising platform). The Actyve app is served from Vercel’s Paris region; the website, the online audit and the application tool are executed outside the European Union, and the attachments sent with an application are kept in a storage space located in the United States.
  • When a user of the Actyve app connects their Google Calendar, the appointments they book in the app are written into that calendar and therefore sent to Google, whose calendar service they already use. That transfer results from their choice to connect that calendar, and stops when they unlink it (section 10).

Each of these transfers relies on a mechanism provided for by the GDPR. All our providers established outside the European Union are bound by the standard contractual clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), incorporated into the processing agreements we have concluded with them: this is the appropriate safeguard provided for in Article 46 of the Regulation. Our hosting provider Vercel is furthermore certified under the EU-US Data Privacy Framework.

13. Security measures in place

Section 5 sets out the principle. Here are the measures actually in place on 23 September 2026.

  • Our pages are served exclusively over HTTPS: any request received over HTTP is redirected by our hosting provider, and our responses carry an HSTS header with a two-year duration, which asks your browser never to connect in clear text again.
  • Connections are established using TLS 1.3 in production, with cipher suites providing forward secrecy.
  • Connections to our databases require TLS as well as channel binding, which ties authentication to the encrypted channel used.
  • Encryption of data at rest, using AES-256, is provided and documented by our hosting providers Vercel and Neon. That encryption is theirs: we add no application-level encryption on our side, with one exception: the Google access tokens of the Actyve app are encrypted by the app before being stored (section 10).
  • Access to the administration consoles of our audit and application tools is restricted to a named list of email addresses. Identification is by Google account or by a single-use link valid for ten minutes, and no account can be created outside that list.

Our hosting providers have their own frameworks: Vercel is SOC 2 Type 2 and ISO 27001:2022 certified; Neon states that it aligns with SOC 2, ISO 27001 and ISO 27701, with annual audits carried out by two independent firms. These certifications are those of our hosting providers. Actyve itself holds no security certification, nor any certification within the meaning of Article 42 of the GDPR.

No measure makes a system invulnerable. Should a personal data breach be likely to result in a high risk to your rights and freedoms, we would inform you in accordance with Article 34 of the GDPR.

14. Data retention criteria

Section 4 sets out the rule. In accordance with Article 13(2)(a) of the GDPR, which allows either a period or the criteria used to determine it to be stated, here are the criteria we apply.

  • Contact requests and commercial exchanges: the time needed to handle your request, then for the duration of the ongoing exchanges or business relationship.
  • Answers and reports from the online audit: the time needed to examine your situation and, where applicable, for the commercial follow-up that results from it.
  • Applications: the time needed to examine the application and for the duration of the recruitment process concerned.
  • Contractual, accounting and invoicing documents: the retention period imposed by Belgian accounting and tax law.
  • Evidence that consent was obtained: the time needed to be able to prove it.
  • Google Calendar data (Actyve app): for as long as the calendar remains connected; it is erased when the user unlinks their calendar or is removed from their company’s account (section 10).

You can request the deletion of your data at any time by writing to contact@actyve.ai. We act on such requests under the conditions and within the time limits set out in section 8, except for data that the law requires us to keep.

15. Automated processing and decision-making

Two of our tools involve automated processing that influences what happens next with your request. Rather than stating that there is none, we prefer to describe them, together with the logic applied, its consequences and your rights, in accordance with Articles 13(2)(f) and 22 of the GDPR.

15.1. Online audit

When you answer our audit questionnaire, your answers are analysed by artificial-intelligence models hosted by Scaleway (see section 16). They produce a report as well as a score of fit between the needs expressed and our offer. That score determines whether a sales appointment is offered to you at the end of the audit.

The logic of the assessment: it is based on the answers you enter, which describe your business, your sales organisation and your needs, as well as on publicly available information about your company, searched for on the web by one of these models.

The consequences for you are commercial: depending on the result, appointment booking is offered to you, or it is not. That score measures a company’s fit with our offer. It in no way constitutes an assessment of the solvency, reliability or behaviour of a person, and it is used for no other purpose.

15.2. Application form

Our application form includes an automatic knock-out criterion: the answer to the question about on-site presence is checked by a computer rule, applied before any analysis and without any artificial-intelligence model. An answer incompatible with that criterion ends the application process.

Applications that pass that step are then analysed by an artificial-intelligence model hosted by Scaleway, which produces a score, a level and a recommendation from the information you have provided, in particular your background, your technical skills and, where you share it, your public GitHub profile.

The decision to shortlist, reject or hire a candidate is taken by a person on our team, not by the system. That person sees the score, the level and the summary produced automatically: they use them to sort and prioritise applications, and the decision is recorded separately, by an explicit action on their part. Below a score threshold, the application remains recorded and viewable in our recruitment tool, but it is not flagged to the team.

This automated assessment falls under point 4(a) of Annex III to Regulation (EU) 2024/1689 on artificial intelligence, which covers systems intended for recruitment, in particular to analyse and filter applications and to evaluate candidates. We do not claim to escape it: it is a high-risk system within the meaning of that Regulation, and the fact that a person decides in the last resort changes nothing.

The obligations attached to the high-risk systems of that Annex III were due to apply on 2 August 2026. Regulation (EU) 2026/1744, in force since 27 July 2026, postponed them to 2 December 2027. We are preparing for that deadline.

Details of this classification, of what it covers and of the applicable timetable can be found on our page AI and transparency (in French).

15.3. Your rights regarding these processing operations

For both of these processing operations, you can write to us at contact@actyve.ai to obtain human intervention, express your point of view and contest the result obtained. You can also ask for an explanation of the result concerning you. We then re-examine your file and respond under the conditions and within the time limits set out in section 8.

16. Use of artificial intelligence

We use artificial-intelligence models to conduct and deliver our online audit, to analyse the applications we receive and to run the assistance features of the Actyve app and of the Actyve AI assistant. These models are called through programming interfaces; Actyve trains no model and does not use your data to train any.

A single artificial-intelligence provider is involved for all our services (website, online audit, application tool, Actyve app and Actyve AI assistant): Scaleway, through its Generative APIs offering. Scaleway is a company established in France, in the European Union, and the models we call are hosted and operated by Scaleway on its own infrastructure. We go through no aggregator or intermediary, and we make no direct call to the creator of a model.

According to its documentation, Scaleway does not store the content of our requests, does not read it and does not use it to train, retrain or improve models; that content is accessible neither to the creators of the models nor to third parties. The same documentation provides for one exception: in the event of a technical incident or abusive use, the content of a request may be kept for at most two weeks, solely to analyse and fix the problem. Reference: Data privacy, Scaleway Generative APIs.

No data received from Google APIs (section 10) is sent to an artificial-intelligence model in order to train it.

Details of the models used, of what happens to the data sent to them and of our position with regard to the European regulation on artificial intelligence can be found on our page AI and transparency (in French).

Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites and encourage you to read their respective privacy policies.

18. Changes to the privacy policy

We may update this privacy policy to reflect legal, technical or commercial developments. Any change will be published on this page with the updated effective date. Your continued use of the website will constitute acceptance of the changes.

19. Contact

For any question about this policy or to exercise your rights, you can contact us at:

Actyve SRL
Company number: 1015.964.340
Address: Rue Delwaide 60/5, 4681 Oupeye, Belgium
Email: contact@actyve.ai