Privacy

Privacy notice

Action360 is an operational governance workspace used by organisations to track actions, risks, changes and readiness. We act as a processor, handling data on the documented instructions of the client that engaged us.

What we collect

CategoryFieldsPurpose
Account recordsAccount name, industry, logoIdentify the client workspace
User profilesName, work email, job title, department, active statusAuthenticate users and attribute records
Roles and groupsRole per account, group membershipDecide what each user may see and do
Governance recordsActions, risks, changes, sub-tasks, comments, readiness scoresDeliver the service the client engaged us for
AttachmentsFiles uploaded against a recordEvidence attached to governance items
NotificationsTitle, body, severity, delivery statusAlert owners and approvers
Activity and audit logsActor, event, target, timestampTraceability and security monitoring

We collect work-context data only. The platform is not designed for payment data, government identifiers, health data or other special category data, and clients are asked not to upload such data as attachments.

Retention

Client data — including governance records, attachments, notifications and audit logs — is retained for 13 months. User profiles are kept for the life of the engagement and deactivated immediately on a leaver notification.

Deletion

Your rights

Individuals may request access, rectification, erasure, restriction or objection. Because we act as a processor, requests are usually raised through the client organisation that provided your account. Your Action360 administrator will route the request to us, and we respond within 30 days.

Security

Encryption, access control, tenant isolation, logging and recovery arrangements are described on the security page. Third parties involved in processing are listed on the subprocessors page.

Questions about this notice: contact your Action360 administrator, who will route it to our privacy contact.