Effective September 5, 2026
Sourcing policy.
Actually Agentic is not a general people database. SparkGap LLC processes business-contact candidates only for a customer’s reviewed campaign, from bounded first-party public pages or a reviewed customer CSV, and keeps source evidence so inclusion can be explained and corrected.
Bounded first-party discovery
- The customer’s external agent supplies named company seeds, a canonical company domain, a first-party HTTPS entry URL, and a role-based ICP.
- Our crawler identifies itself as
ActuallyAgenticBot/1.0with a link to this policy and [email protected]. - It fetches only a small configured number of public HTML pages on the supplied company domain, follows that site’s robots.txt, delays requests, bounds response size and time, and rejects credentials, private/internal IP addresses, unsafe ports, cross-domain navigation, and unsafe redirects.
- It skips a page that asks not to receive unsolicited commercial email and keeps no address from it. A conspicuously published address is not an invitation when the publication says otherwise, and Canadian implied consent is unavailable in that case.
- It extracts narrowly relevant published business-contact evidence. Public page bodies are not retained. We keep the source URL, extraction method, confidence, collection time, expiration time, and a SHA-256 evidence hash.
- Pattern inference is off by default. When a customer expressly enables it, the system may generate one first.last candidate only for a named person in a target role found in structured first-party data; verification still gates use.
Reviewed CSV imports
Workspace owners and administrators may import a CSV only after providing a provenance note and attesting that it contains relevant business data they have the right to use. Required fields are email, title, and company name. The importer rejects personal-mail domains, duplicates, company-domain mismatches, excluded companies, and off-ICP titles. It records the file hash, actor, time, counts, and provenance note; it does not treat an upload as permission to ignore applicable notice, consent, objection, or suppression rules.
Verification and use
Candidate addresses remain pending until checked through the configured verification provider. Valid, catch-all, invalid, unknown, disposable, and suppressed results stay distinct. Catch-all addresses are excluded unless the customer’s reviewed plan expressly allows them. A campaign cannot cause a domain purchase until payment is committed and at least one business address returns valid; catch-all results alone are not enough. Verification does not establish a lawful basis or guarantee delivery.
Retention and separation
Uncontacted discovery and import records expire after the configured source-retention period, currently 90 days. Expired uncontacted candidates are deleted during refill/provisioning maintenance and are ineligible for sending. We do not reuse one customer’s contact pool for another. Sent-message, reply, billing, audit, bounce, complaint, and suppression evidence may be retained longer where needed to honor opt-outs, investigate abuse, resolve disputes, and meet legal obligations.
Access, correction, deletion, and objection
To ask where a business contact came from, correct it, request deletion, or object to processing or outreach, email [email protected]. Include the address involved and enough context for us to locate the record. We will verify the request, notify the responsible customer where appropriate, restrict the record while reviewing it, and place a durable suppression when needed so deletion does not accidentally permit renewed contact. Recipients can also use the unsubscribe mechanism in any message; replies and complaints create stop signals automatically.
Crawler issues
Site operators may report crawl behavior, request a correction, or object at [email protected]. Please include the affected domain, URL, approximate time, and relevant logs. We investigate abuse and robots-policy reports before resuming a disputed source.
