ACTAEby Diviga
DemoArchitectureDocsSecurityComparePricingStatus
Log inGet started
LEGAL / PRIVACY

Privacy Policy

How Diviga handles account, billing, support, website, and Actae Cloud data—and what stays in your self-hosted environment.

Effective 18 August 2026Operator: Diviga
Dębowa, 55-010 Radwanice, PolandRegistration: NIP 8943089331
LEGALTerms of ServicePrivacy PolicyRefund PolicyContact

1. Controller and scope

Diviga, operator of Actae (“Actae”, “we”, “us”), is the controller for personal data processed through actae.dev, marketing communications, evaluations, the customer portal, licensing control plane, support, and our commercial relationship. Our legal identity is also displayed at checkout and on order documentation. Privacy questions and rights requests can be sent to hello@actae.dev.

This Policy does not make us controller of personal data processed solely inside a customer-operated self-hosted Actae runtime. For that data, the customer determines the purposes and means of processing. Where we process Actae Cloud execution data on a business customer’s instructions, that customer is generally controller and we act as processor, subject to the applicable agreement.

2. Data we collect

Account and identity

Name, email address, organization, authentication provider identifiers, password hashes, verification status, session records, security events, and account preferences.

Commercial and billing

Plan, installation, subscription and entitlement identifiers, order status, billing country, tax and invoice metadata, and limited payment information received from Polar. Polar processes full payment-card details; Actae does not store full card numbers or card security codes.

Product and technical data

Installation identifiers, runtime version and platform, enrollment and key lifecycle metadata, subscription synchronization, usage totals and quota status, IP address, request timestamps, user agent, audit records, errors, and security/availability telemetry.

Actae Cloud Customer Data

If you use Actae Cloud, the dedicated runtime stores the events, state snapshots, tool results, lineage, metadata, and other content your application sends. Self-hosted execution payloads remain in the PostgreSQL environment you operate and are not uploaded to the SaaS control plane as part of normal operation.

Communications

Support requests, evaluation applications, survey responses, meeting notes, and other information you choose to send us.

3. Sources

We collect data directly from you, your organization’s administrators and users, your Actae installation or SDK, and the devices and browsers used to access our Services. We also receive relevant data from providers you choose or that support the Services, including Polar for orders and subscriptions, Google or GitHub when used for sign-in, and email, hosting, security, and infrastructure providers.

4. Why we process data and our legal bases

PurposeLegal basis
Provide accounts, licensing, Cloud runtimes, support, billing coordination, exports, and requested ServicesPerformance of a contract; steps requested before entering a contract
Authenticate users, prevent fraud and abuse, secure systems, debug incidents, and maintain auditabilityLegitimate interests in operating secure and reliable Services; legal obligations where applicable
Process tax, accounting, sanctions, consumer, and regulatory requirementsCompliance with legal obligations
Improve usability, reliability, capacity, and product design using limited operational dataLegitimate interests, balanced against your rights
Send requested or service-related communicationsContract and legitimate interests
Send optional marketing communications or use non-essential trackingConsent where required; you may withdraw it at any time

We do not use Customer Data to train general-purpose AI models. We do not sell personal data or use it for cross-context behavioral advertising.

5. Cookies and local storage

We use strictly necessary cookies and browser storage for sessions, authentication, security, checkout continuity, and saved interface preferences. Optional analytics or marketing technologies, if introduced, will be documented and presented with consent controls where required. Browser settings can remove stored data, but blocking necessary storage may prevent login or portal use.

6. Who receives data

We disclose data only as needed to operate the Services: to Polar as merchant of record and payment/reseller provider; hosting, database, backup, content-delivery, email, authentication, monitoring, security, and support vendors; professional advisers; and competent authorities where legally required. Organization administrators may access information associated with their workspace.

Providers process data under contractual and confidentiality obligations appropriate to their role. Polar independently controls buyer, payment, tax, invoice, fraud, and regulatory data under its own privacy terms. We may disclose data in a merger, financing, reorganization, or sale, subject to appropriate protection and notice where required.

7. International transfers

Some providers may process data outside your country or the European Economic Area. Where required, we use a lawful transfer mechanism such as an adequacy decision or approved standard contractual clauses, together with supplementary safeguards where appropriate. Contact us for information relevant to your data.

8. Retention

We keep personal data only as long as necessary for the purposes described: account data while the account is active; subscription and entitlement data through the commercial relationship; security and operational logs for a limited period appropriate to investigation and reliability; Actae Cloud Customer Data for the retention period of the selected plan and deletion lifecycle; and tax, invoice, transaction, dispute, and legal records for periods required by law.

When you delete an account, active data is removed or anonymized unless retention is required for legal obligations, fraud prevention, dispute resolution, or security. Deleted Cloud data may remain in encrypted backups until those backups expire under their rotation schedule. Self-hosted data deletion is controlled by the customer operating that runtime.

9. Security

We use measures designed for the nature of the data and current scope, including TLS, access controls, credential hashing, scoped secrets, audit logging, tenant isolation for Cloud runtimes, encrypted off-host backups, dependency and configuration controls, and incident monitoring. No system is perfectly secure. Keep credentials confidential and contact us immediately if you suspect compromise.

Our public Security page describes current controls and limitations. Actae does not claim certifications or security guarantees that are not expressly stated.

10. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing; receive portable data; withdraw consent without affecting earlier processing; and complain to a competent data protection authority. Where processing relies on legitimate interests, you may object based on your situation. We do not make solely automated decisions producing legal or similarly significant effects about Actae users.

Use portal export and deletion tools where available or contact hello@actae.dev. We may verify identity and authority before acting. If the request concerns data controlled by your employer or another Actae customer, contact that organization first; we will assist it as required.

11. Children

The Services are business software and are not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided data, contact us so we can investigate and delete it where appropriate.

12. Changes

We may update this Policy as the Services, providers, or law change. The effective date identifies the current version. We will provide reasonable notice of material changes, especially where they affect how existing account or Customer Data is used.

ACTAEby Diviga

Durable execution infrastructure for long-running AI agents.

DocsArchitectureSecurityStatusChangelogPortalTermsPrivacyRefunds
© 2026 Diviga