This page summarises how Actigy BPO processes personal data when delivering services. It reflects the terms of our Data Processing Agreement (DPA), which we are happy to sign as part of a services contract. For our website and business-contact processing, see the Privacy Policy.
Roles
For data processed in delivering services, the client is the controller and Actigy BPO is the processor. Actigy processes personal data only on the client’s documented instructions, including for transfers, unless required otherwise by law.
Subject matter and duration
Processing covers the personal data needed to perform the agreed services, for the duration of the engagement and any agreed wind-down period.
Nature and purpose
We process personal data to deliver the operations a client engages us for — for example finance, compliance (KYC/AML), insurance claims, medical billing, support, and back-office workflows.
Categories of data subjects and data
Depending on the service, data subjects may include the client’s customers, employees, patients, policyholders, or claimants. Personal data may include identity and contact details, financial and transaction data, KYC documentation, and, for healthcare work, health data. Special-category data is processed only where instructed and under additional safeguards.
Sub-processing
We engage sub-processors (for example hosting and tooling providers) under written terms that impose data-protection obligations no less protective than ours. A current list is available on request, and we give clients advance notice of intended changes so they can object.
International transfers
Delivery is from the EU (Bulgaria, Romania, Poland) and from Ukraine. EU/EEA personal data is kept within the EU/EEA where practical; transfers to Ukraine or other non-EEA locations rely on appropriate safeguards, including Standard Contractual Clauses. On request, EU personal data can be restricted to our EU-member hubs.
Security measures
We apply the technical and organisational measures described on our Security page, including access control, encryption in transit and at rest, segregation of duties, and a secure delivery model.
Assistance to the controller
We help clients respond to data-subject requests, carry out data-protection impact assessments, and meet their security and breach-notification obligations, taking into account the nature of the processing and the information available to us.
Personal-data breaches
We notify the affected client without undue delay after becoming aware of a personal-data breach involving their data, with the information needed for the client to meet its obligations.
Audits
We make available the information needed to demonstrate compliance and allow for and contribute to audits, including inspections, under the terms agreed in the DPA.
Return and deletion
On termination, we return or delete client personal data at the client’s choice, except where storage is required by law.
Sign a DPA
To put a signed Data Processing Agreement in place, contact hello@actigy.com or get in touch.
Questions about this policy? Email hello@actigy.com.