This Privacy Policy describes how personal data is processed in connection with the Actaa Service, distinguishing the Customer Content that the Customer controls from the account, billing, and security data for which Nomisma LLC acts as controller.
01 Overview and Scope
This Privacy Policy applies to the Actaa Service provided by Nomisma LLC. It shall be read together with the Platform Terms of Service and the Data Processing Addendum. Where an individual is an employee or other person whose personal data appears within a Customer's Actaa account, that Customer is responsible for its use of the Service, and such individuals should direct requests concerning their personal data to that organization in the first instance.
02 Controller and Processor Roles
Applicable data-protection law distinguishes the party that determines the purposes and means of processing (the controller) from the party that processes personal data on the controller's behalf (the processor). Nomisma's role is determined by the category of data:
- Customer Content — the Customer is controller; Nomisma is processor. With respect to the personal data contained in the content the Customer and its Authorized Users submit to the Service, the Customer is the controller and Nomisma acts as processor, processing such data only on the Customer's documented instructions under the DPA.
- Account, billing, and security data — Nomisma is controller. With respect to the data required to create and secure accounts, administer billing, provide support, and protect the platform, Nomisma is the controller and this Policy governs.
03 Categories of Data Processed
- Account data — Administrator and user identifiers such as name, work email, and role, together with authentication data handled through AWS Cognito, including TOTP multi-factor authentication.
- Authorized-user data — the users added by the Customer's Administrators and the permissions assigned to them.
- Usage and telemetry — logs of actions within the Service, including an audit log and AI audit trail, together with device and connection information and diagnostic data used to operate, secure, and improve the platform.
- Billing data — the information required to administer a subscription or Order. Payment processing is performed by Stripe, Inc.; full payment credentials, including card numbers, are collected and stored by Stripe and are never stored or transmitted by Nomisma. See the Sub-processors page.
- Customer Content processed on instruction — the documents, messages, records, and other content the Customer's organization creates within the Service, which may contain personal data. Such content is processed solely to provide the Service, as controller-directed processing under the DPA.
04 Processing by Artificial Intelligence Features
The private-AI features are designed to keep Customer Content within the Customer's control:
- Processing on AWS Bedrock. All model and embedding processing operates exclusively on AWS Bedrock within Actaa's own AWS account and region, using leading foundation models available through AWS Bedrock. Prompts and content are not transmitted to third-party model endpoints.
- No training on Customer Content. AWS Bedrock does not use your prompts or content to train its foundation models, and Nomisma does not use Customer Content to train general-purpose models.
- Three-layer PII scrubbing. Before content reaches the model, a three-layer scrubber redacts personal and sensitive data at ingestion, before the prompt, and on the output, and HR-sensitive content is hard-blocked.
- Per-company isolation. Data is isolated per company at the database layer, such that the AI is grounded solely in the Customer organization's own data.
05 Sub-processors
Nomisma engages a limited set of infrastructure sub-processors to provide the platform. The current list, together with each sub-processor's purpose and location, is published and maintained at Sub-processors. Notice of changes is given as described therein and in the DPA.
06 Security Measures
Nomisma maintains technical and organizational measures to protect personal data, including per-company data isolation, encryption in transit and of sensitive data at rest, authentication with multi-factor and role-based access control, and audit logging. The measures in force are described in full in the Security & Compliance Overview and in Annex II of the Data Processing Addendum.
07 Data Retention
Nomisma retains Customer Content for the duration of the Customer's subscription term. Following termination or upon the Customer's instruction to delete, content is deleted using an anonymized-deletion process with a 30-day recovery window, after which it is removed from active systems; the Customer may export its data at any time during the term using the one-click portability capability. Account, billing, and security data are retained for as long as necessary for the relationship and for legal, tax, and security purposes. Retention periods beyond the 30-day recovery window are as follows: routine backups cycle out within thirty-five (35) days; account and billing records are retained for the duration of the relationship and for up to twenty-four (24) months thereafter; and security and audit logs are retained for up to twelve (12) months, except where a longer period is required by applicable law.
08 Data-Subject Rights
Where the GDPR or comparable laws apply, individuals have rights over their personal data, including rights of access, rectification, erasure, restriction, portability, and objection (Articles 15–22). As the Customer organization is the controller of Customer Content, Nomisma assists controllers in fulfilling such requests. The platform implements Article 17 (erasure) and Article 20 (portability) directly, through one-click export and anonymized deletion.
- Where an individual's personal data resides in a Customer's Actaa account, the individual should contact that Customer as controller.
- For data in respect of which Nomisma is the controller (account, billing, security), the individual may contact Nomisma at info@actaa.ai.
09 International Data Transfers
The platform is hosted on AWS in the United States. Where personal data is transferred from the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, Nomisma relies on appropriate safeguards. Specifically, Nomisma relies on the European Commission's Standard Contractual Clauses (2021/914), the UK International Data Transfer Addendum, and, for Switzerland, the Swiss addendum, together with supplementary technical and organizational measures; the Service is hosted in the United States on Amazon Web Services (region us-east-1). Where Nomisma is required to designate a representative under Article 27 of the GDPR or the UK GDPR, it will do so and identify that representative in this Policy.
10 Legal Bases for Processing
Where Nomisma acts as controller, it relies on the following legal bases:
- Performance of a contract — to create and operate accounts and to provide the Service to the Customer's organization.
- Legitimate interests — to secure the platform, prevent abuse, and improve the Service, balanced against the rights of individuals.
- Legal obligation — to satisfy tax, accounting, and other legal requirements.
- Consent — where requested, for example in respect of certain optional communications, which the individual may withdraw at any time.
With respect to Customer Content, the Customer's organization is the controller and determines the legal basis for processing, as reflected in the DPA.
11 California Privacy Rights (CCPA/CPRA)
With respect to Customer Content processed on the Customer organization's behalf, Nomisma acts as a service provider under the California Consumer Privacy Act as amended by the CPRA. Nomisma does not sell or share Customer Data, and does not retain, use, or disclose it except to provide the Service under this Agreement and as permitted by law. California residents may exercise their rights with the business (the controller) that submitted their data to the Service; where Nomisma is the business with respect to account or billing data, individuals may contact Nomisma at info@actaa.ai.
12 Personal-Data Breach Notification
Nomisma maintains processes to detect and respond to security incidents. Where Nomisma becomes aware of a personal-data breach affecting Customer Content, it shall notify affected customers without undue delay and provide the information reasonably available to assist the Customer in meeting its own notification obligations, as further set out in the DPA.
13 Data Processing Addendum
Nomisma's processing of Customer Content on the Customer's instructions is governed by the Data Processing Addendum, which incorporates Article 28 of the GDPR and forms part of the Platform Terms of Service. Where this Policy and the DPA differ in respect of processor obligations, the DPA controls.
14 Mobile Applications
Where the Service is accessed through the Actaa mobile application for iOS or Android, the following additional positions apply. The full terms governing the App are set out in the Mobile Application Terms.
- Device permissions — the App requests camera, microphone, photo-library, biometric, local-storage, and notification permissions. Each is requested at the point of use, may be declined, and may be revoked in device settings; declining disables only the dependent feature.
- Biometric data — where biometric app-lock is enabled, authentication is performed by the device operating system, which returns only a success or failure result. Fingerprint, face-geometry, and equivalent biometric data never leave the device and are never transmitted to, stored by, or accessible to Nomisma.
- Credentials on the device — session credentials are held in the iOS Keychain or Android Keystore under operating-system encryption, and are cleared on logout.
- Notifications — the App presently delivers local notifications only. No remote push token is collected or stored, and no notification content is routed through Apple's or Google's push infrastructure. This Policy will be updated before any remote-push processing begins.
- No third-party SDKs — the App embeds no third-party analytics, advertising, or crash-reporting software development kits.
15 Contact
Privacy enquiries may be directed to info@actaa.ai. Nomisma has not appointed a separate data protection officer; all privacy enquiries are handled through that address. Nomisma LLC is formed under the laws of the State of Wyoming, USA.