Template pending legal review. This document is a working draft prepared by Octenta and has not yet been reviewed or approved by legal counsel.

Legal

Privacy Policy

Last updated: 1 July 2026

How Octenta collects, uses, stores and protects personal and corporate data.

1. Who we are

Octenta provides an enterprise platform for AI Employees that operate inside a customer's existing business systems. This policy explains how Octenta handles personal data when you visit octenta.com, contact us, or use the Octenta platform under a customer agreement.

Where Octenta processes personal data on behalf of a customer organisation, that customer is the data controller and Octenta acts as a processor under the terms of the relevant agreement. Where Octenta decides how and why data is used — for example website enquiries — Octenta is the controller.

2. Data we collect

  • Contact data you submit through the workforce audit form: name, work email, company, country, company size, roles of interest and the content of your message.
  • Model inputs you enter into the ROI calculator, where you choose to carry them into an enquiry. These are not stored unless submitted.
  • Platform account data for authorised users of a customer deployment: name, work email, role and permission assignments.
  • Operational data generated by the platform: audit-log entries, decision records, confidence scores and approval actions.
  • Technical data: IP address, browser and device type, and pages viewed, used for security and aggregate analytics.

3. Customer business data

AI Employees read and write records inside systems a customer connects to Octenta — finance, HR, logistics, procurement, IT and service platforms. That data belongs to the customer. Octenta accesses it only to perform the contracted processing, under the scopes the customer grants, and for as long as the connection remains active.

Octenta does not use customer business data to train general-purpose models for other customers.

4. How we use data

  • To respond to enquiries and prepare workforce audits.
  • To provide, secure, monitor and support the Octenta platform.
  • To maintain the immutable audit trail that records what each AI Employee decided and who approved it.
  • To meet legal, regulatory, accounting and contractual obligations.
  • To improve product performance using aggregated or de-identified information.

5. Legal bases

Depending on your location, Octenta relies on the performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where consent is required — for example for optional marketing communication, which you can withdraw at any time.

6. Sharing and subprocessors

Octenta shares personal data with service providers that support hosting, infrastructure, model inference, email delivery and customer support, each under written terms restricting their use of the data. A current list of subprocessors is made available to customers under their agreement.

Octenta does not sell personal data.

7. International transfers

Data may be processed outside the country in which it was collected. Where that occurs, Octenta applies appropriate safeguards, including contractual transfer mechanisms, and can support data-residency requirements agreed in a customer contract.

8. Retention

Enquiry data is retained while a commercial conversation is active and for a reasonable period afterwards. Platform data is retained for the term of the customer agreement and the deletion window described in it. Audit-log entries are append-only and retained for the period the customer specifies for compliance purposes.

9. Your rights

Subject to applicable law, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability, or object to processing based on legitimate interests. Where Octenta acts as a processor, requests are directed to the customer organisation that controls the data, and Octenta assists them in responding.

10. Security

Octenta applies role-based access control, encryption in transit and at rest, least-privilege integration scopes and full audit logging. Further detail is set out on the Octenta security page.

11. Cookies

The Octenta website uses cookies that are strictly necessary for the site to function, and may use aggregate analytics cookies. Where consent is required, it is requested before non-essential cookies are set.

12. Changes and contact

Octenta will update this policy as the platform and our obligations change, and will revise the last-updated date above. For any privacy question or request, contact Octenta through the contact page and mark your message for the attention of the privacy team.

Questions about this document?

Contact the Octenta team and we will route your question to the right person.

Contact Octenta