Who is responsible
ACTIUM LABS LTD, company number 17278431, is the site operator and data controller. Its registered office is 12 Cliff Road, Cowes, United Kingdom, PO31 8BN.
For privacy enquiries or to exercise data-protection rights, email legal@actium.cloud.
Information associated with this site
If you create an account using verified email/password, Google, Microsoft or GitHub through the managed Auth0 broker, Actium records an internal Cognito account identifier, provider identity mapping, verified email, name, profession, optional organisation and account timestamps. Cognito processes native passwords and verification/recovery codes; Actium application APIs do not receive or store them. Email and provider identifiers are not entitlement keys.
If you request a protected release, Actium records the product/version, controlled reason, exact licence acceptance, entitlement state, download timestamp/count and revocation state against the internal account identifier. Legacy development access-request records are retained separately under their approved audit schedule. Actium does not use account or request data to subscribe you to marketing.
During delivery and security operations, infrastructure providers may process limited technical data such as IP address, browser or device information, requested paths, timestamps and security logs. OAuth tokens and plaintext temporary access secrets are not written to application logs or DynamoDB.
Purposes and lawful bases
- To deliver and secure the website, rate-limit misuse, verify access requests, issue short-lived private downloads and support entitlement revocation, relying on legitimate interests in controlled software delivery.
- To provide a release under the licence you accept or take steps at your request before entering a contract.
- To respond to email enquiries, relying on legitimate interests in communicating about Actium Labs’ work.
- To comply with legal or record-keeping obligations where required.
Infrastructure providers
Amazon Web Services provides hosting, Cognito authentication, request storage, transactional email and private release delivery in the London region. Google, Microsoft, GitHub and Auth0 process authentication information when you choose the corresponding sign-in method. Microsoft 365 also provides general email services.
Retention
Unredeemed verification tokens and per-click download grants expire automatically after their short configured lifetime. Rate-limit records expire automatically. Access request, entitlement, download and revocation records are retained only for controlled delivery, licence administration, security and necessary audit, then deleted under the approved retention schedule. General enquiry correspondence is normally retained for up to 24 months after the last substantive contact. Application logs are configured for 14 days in development and 30 days in production unless an incident or legal obligation requires longer preservation.
Your rights
Depending on the circumstances, UK data-protection law may give you rights to access, correct or erase personal information; restrict or object to processing; and receive certain information in a portable format. These rights are not absolute.
You may complain to the Information Commissioner’s Office. Guidance is available at ico.org.uk/make-a-complaint.
Authentication storage and analytics
This site uses no analytics, advertising tracking or non-essential cookies. Cognito and the browser authentication library use strictly necessary sign-in state and token storage so sessions survive refreshes and can be renewed or signed out. This information is used only for account security and access control.
