Privacy
Last updated 29 September 2026. This policy covers this website, our sales correspondence and our billing. It also states exactly what the self-hosted software can send to us, which is close to nothing and is off by default.
This website
This site loads no third-party assets. No analytics, no tag manager, no font CDN, no embedded media. It sets no cookies. The only external addresses linked from it are github.com and verify.actaseal.com, and those are links you choose to follow, not resources the page loads.
The site is served by GitHub Pages, which as a matter of ordinary web hosting receives the IP address and user agent of anyone who requests a page. We do not receive, store or analyse those logs.
If you write to us
If you email sales@actaseal.com we hold your message and your email address so we can reply and keep a record of the conversation. Our mailboxes are hosted by Zoho. We do not add you to a marketing list and we do not sell or share the address.
If you buy
Billing is handled by Paddle, which acts as merchant of record and collects the payment and tax details it needs to do that. We receive your company name, billing contact and subscription status. We do not receive or store your card number.
What the self-hosted software sends
The software runs inside your infrastructure. It makes no outbound network call by default. Three features can be turned on by you, and each is described here in full.
Licence revocation check. If you set
ACTASEAL_LICENCE_REVOCATION_URL, your installation
periodically fetches a revocation list. The request carries nothing
about your evidence; it is a fetch of a public list. You can avoid the
network entirely by pointing
ACTASEAL_LICENCE_REVOCATION_FILE at a local file you
update yourself. If the fetch fails, the installation keeps using the
last list it successfully retrieved and records how stale it is, rather
than failing open or shutting you down.
Transparency-log anchoring. If you set
ACTASEAL_REKOR_URL, receipts can be anchored to an external
transparency log you choose. If it is unset, no network call is
attempted at all. What is anchored is a hash, not content.
Usage export. If your tier is metered and you choose to send us a usage summary, that summary contains counts only: usage counts per agent identifier and per capability, and their totals. It contains no ledger event, no action identifier, no actor identifier, no tenant identifier and no payload field. That is not a policy description, it is enforced by an automated test in our codebase which asserts the payload's keys are a subset of an allowed list and that no value anywhere in it is a ledger event. The summary is signed by your own signing key before it leaves, and uploading it is a deliberate act, never automatic.
What we therefore do not have
We do not hold your evidence, your ledger, your policies, your receipts, your workpapers, your approvals or the personal data of your customers or employees. Not because we promise not to look, but because in a self-hosted deployment it is never transmitted to us.
Retention and your rights
We keep sales correspondence for as long as the commercial relationship is live and for three years afterwards. Billing records are kept as long as tax law requires. You can ask us what we hold about you, ask for it to be corrected, or ask us to delete it, by writing to sales@actaseal.com. We will respond within thirty days.
Our sub-processors are listed at /legal/subprocessors.html.