Effective September 5, 2026
Privacy notice.
This notice explains how SparkGap LLC handles information when you use Actually Agentic. Contact [email protected] for privacy requests.
Information we process
- Account data: email address, password hash, organization, role, verification state, sessions, and audit history.
- Campaign data: agent-generated plans and templates, approved domains, budgets, compliance attestations, and operational events.
- Prospect data: business contact details, company details, source provenance, verification results, suppression state, and sequencer identifiers.
- Technical data: request identifiers, timestamps, errors, rate-limit counters, and security events. We do not place advertising cookies.
- Billing data: checkout and subscription identifiers and payment status. Stripe handles full payment-card details.
Why we use it
We process data to provide and secure the service, provision approved infrastructure, source and verify contacts, honor suppressions, support users, bill customers, prevent abuse, maintain audit records, and meet legal obligations. Where applicable, our bases include performing our contract, legitimate interests in operating and protecting the service, consent, and legal obligations.
Your role and ours
For workspace user data, we generally act as controller. For prospect data uploaded, requested, or selected for your campaigns, your organization is the controller and we act as its processor/service provider. You decide whether the contacts and outreach are lawful and must provide any required notices or rights handling.
Service providers
We disclose only the data needed to operate each function. Current categories include hosting/database/queue vendors; Stripe for billing; MillionVerifier for email verification; and Cloudflare for domain registration, operator registrant-contact processing, and authoritative DNS. Managed domains use our operator contact rather than customer registrant data. We operate first-party public-site discovery, provenance storage, mail cells, mailbox storage, sequencing, delivery-event processing, and suppression. Public page bodies are discarded after extraction; uncontacted source records expire under the configured retention period. Your external agent receives only what you paste into it; we do not send your campaign context to an AI provider. See our current subprocessor list and sourcing policy.
Retention
We retain account and campaign records while the workspace is active and as needed for billing, disputes, security, suppression, and legal compliance. Email-verification and password-reset tokens expire and are stored only as one-way hashes. Mailbox credentials and message bodies retained by the application are encrypted with an operator-managed key. Suppression records may be retained longer so an opt-out is not accidentally reversed.
Security and tenancy
We use encrypted transport, opaque hashed sessions and tokens, role permissions, append-only audit records, bounded provider responses, and PostgreSQL row-level security. No system is perfectly secure; contact us immediately if you believe an account or token was exposed.
Where we operate
We offer Actually Agentic only to organizations in the United States and Canada, and only for outreach to recipients in those countries. We process information in the United States. One provider, MillionVerifier, verifies addresses in the European Economic Area; that transfer is covered by the mechanisms in our Data Processing Addendum. Ask us for current subprocessor and location information.
California privacy rights
The California Consumer Privacy Act applies to business contact information — the partial exemption for it expired on January 1, 2023 — so this section covers the business contacts we process for our customers as well as our own workspace users.
What we collect. Identifiers (name, business email address, employer, job title, and where published, business phone); professional and employment information; commercial information (subscription and payment status); and internet activity limited to our own service (request identifiers, timestamps, errors, and security events). We collect it from you, from your organization’s workspace, from bounded first-party public company pages as described in our sourcing policy, from reviewed customer imports, and from our billing and verification providers. We use it for the purposes in “Why we use it” above, and disclose it for those business purposes to the providers on our subprocessor list. We keep each category for the period in our retention schedule and no longer than the purpose requires.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months, including for anyone under 16. We do not use or disclose sensitive personal information for any purpose that would give you a right to limit it.
Your rights. You may request the specific pieces and categories of personal information we hold about you, ask us to correct it, ask us to delete it, and receive a portable copy. You may use an authorized agent, and we will not discriminate against you for exercising any of these rights. Email [email protected] with the address involved and enough context to locate the record; we will verify the request before acting. If we decline, you may appeal by replying to our response and saying you are appealing.
Where the record is a business contact sourced for a customer’s campaign, that customer is the business and we act as its service provider. We will restrict the record while we review, route the request to the responsible customer, and keep a minimized suppression entry so deleting the rest of the record cannot cause renewed contact.
Canada
For recipients in Canada we handle personal information under PIPEDA and send commercial electronic messages under CASL. Where we rely on implied consent from a business address that a person or their employer published conspicuously, we record the source page, the extraction method, and the collection date, and we do not rely on it when the page refuses unsolicited commercial email. Every message identifies the sender, carries the sender’s postal address, and offers an unsubscribe mechanism that stays valid well beyond the required 60 days. To withdraw consent, use the unsubscribe link in any message or email [email protected].
Your choices and rights
Depending on where you live, you may request access, correction, deletion, portability, restriction, or objection, and may appeal or complain to a regulator. Email [email protected]. We will verify the request and may preserve records we are legally required or permitted to retain.
Children and changes
The service is for businesses and is not directed to children. We may update this notice as the service changes and will identify the new effective date.
