◆ 1. Who We Are
Arctactic ("Arctactic," "we," "us," or "our") is a product of Zentrio (Pty) Ltd, a company incorporated in South Africa (Registration Number: 2026/489361/07). Zentrio operates an AI workforce automation platform providing businesses with AI employees (including Archie, Voice AI, Marketing AI, and Analytics AI) to automate CRM pipelines, outbound communications, and sales analytics.
Responsible Party / Data Controller: Zentrio (Pty) Ltd (operating as Arctactic)
Registered Office: [Registered Office Address], South Africa
Registration Number: 2026/489361/07
Information Officer (POPIA) / Data Protection Contact: legal@arctactic.com
This Privacy Policy applies to our marketing website (arctactic.com), our web application console, and all services delivered through our AI workforce platform. By accessing our services, you acknowledge this Policy.
This Policy is designed to meet the requirements of the following laws: South African POPIA (Protection of Personal Information Act 4 of 2013); the EU GDPR (Regulation 2016/679); the UK GDPR and Data Protection Act 2018; the US state privacy laws including CCPA/CPRA, VCDPA, CPA, CTDPA, TDPSA, and others; the UAE Federal Decree-Law No. 45 of 2021 (PDPL) and DIFC Data Protection Law 2020; and the Australian Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs).
◆ 2. Data We Collect
We collect data in four ways:
a) Data You Provide Directly
- Full name and business email address (account registration)
- Company name, industry, and team size
- Billing information (payment details collected and processed by Paddle as Merchant of Record — we never store raw card data)
- CRM contact records, deal stages, and notes you upload or configure
- Documentation, FAQs, and pipeline rules you create within your workspace
b) Data Generated by AI Agent Activity
- Telephony call recordings and transcripts processed by Voice AI
- SMS message logs sent or received by AI agents
- Email drafts, sequences, and engagement metadata managed by Marketing AI
- Sales analytics and forecast data generated by Analytics AI
- CRM opportunity routing decisions and pipeline event logs
c) Technical & Usage Data Collected Automatically
- IP address and approximate geographic location
- Browser type, operating system, and device identifiers
- Pages visited, session duration, and click-path data
- Authentication session tokens managed by WorkOS
- Performance and error telemetry from the application console
d) Data Scraped or Enriched via Third-Party APIs
- Data extracted using web scraping tools (e.g., Apify) or enrichment services integrated into your Arctactic workflows.
- Important: When you direct Arctactic AI agents to scrape public websites or utilise third-party data enrichment APIs, you act as the Data Controller for that data. You are strictly responsible for ensuring that the collection, use, and transfer of scraped data complies with applicable terms of service and data privacy regulations in each jurisdiction.
◆ 3. Legal Basis for Processing
We rely on the following legal bases depending on your jurisdiction:
🇿🇦 South Africa — POPIA (Section 11)
- Contract: Processing necessary to provide Arctactic services you have subscribed to (POPIA s.11(1)(b)).
- Legitimate interest: Platform security, fraud prevention, and product analytics (POPIA s.11(1)(f)).
- Legal obligation: Compliance with applicable laws including tax and anti-money laundering requirements (POPIA s.11(1)(c)).
- Consent: Non-essential cookies and marketing communications. You may withdraw consent at any time (POPIA s.11(1)(a)).
🇪🇺 EU — GDPR (Article 6)
- Contract: Art. 6(1)(b) — processing necessary for contract performance.
- Legitimate interest: Art. 6(1)(f) — security, fraud prevention, analytics.
- Legal obligation: Art. 6(1)(c) — compliance with EU law.
- Consent: Art. 6(1)(a) — non-essential cookies and marketing communications.
- For special category data (e.g., health-related call transcript content): explicit consent (Art. 9(2)(a)) or legal claims (Art. 9(2)(f)).
🇬🇧 UK — UK GDPR & DPA 2018
- We rely on the same legal bases as the EU GDPR. The UK GDPR mirrors Article 6 grounds following the UK's departure from the EU.
🇺🇸 United States
- We do not "sell" personal information as defined by US state privacy laws. We do not engage in cross-context behavioural advertising. Specific state-law rights are listed in Section 9.
🇦🇪 UAE — Federal PDPL (Art. 7) & DIFC DPL
- Contract: Processing necessary to fulfil your subscription agreement.
- Legitimate interest: Platform security and fraud prevention, balanced against data subject rights.
- Legal obligation: Compliance with UAE laws and regulations.
- Consent: Marketing communications and non-essential cookies.
🇦🇺 Australia — Privacy Act 1988 (APPs)
- We collect personal information only where it is reasonably necessary for our functions or activities (APP 3). We collect it directly from you where reasonably practicable and handle it in accordance with the Australian Privacy Principles.
◆ 4. How We Use Your Data
- Deliver and operate the AI workforce platform and CRM automation services
- Authenticate user identity and manage workspace permissions via WorkOS
- Process subscription billing and generate invoices through Paddle
- Execute outbound calls, SMS, and email sequences as configured by your pipeline rules
- Route CRM leads, generate opportunity cards, and produce sales forecasts
- Provide customer support, debugging, and account troubleshooting
- Send transactional notifications (billing receipts, agent alerts)
- Monitor platform security and prevent fraudulent access
- Comply with legal obligations and enforce our Terms of Service
We do not:
- Sell your personal data or CRM records to third parties (including as defined under CCPA, VCDPA, or any applicable US state law)
- Use your call transcripts, documents, or proprietary data to train public or shared AI/ML models
- Share your data with advertisers or data brokers
- Engage in cross-context behavioural advertising
◆ 6. International Data Transfers
Our primary infrastructure is hosted in the United States. When you access Arctactic from outside the United States, your personal data may be transferred internationally. We ensure appropriate safeguards are in place for each jurisdiction:
🇪🇺 EEA → United States
We rely on Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914), specifically Module 2 (Controller-to-Processor), to lawfully transfer EEA personal data to US-based subprocessors. Copies are available upon request.
🇬🇧 UK → United States
We use the UK International Data Transfer Addendum (IDTA) to the SCCs, as approved by the UK Information Commissioner's Office, for transfers from the UK to our US-based subprocessors.
🇿🇦 South Africa → United States
Transfers of personal information outside South Africa are conducted in accordance with POPIA Section 72. We ensure recipient countries provide an adequate level of protection, or we use binding contractual provisions that impose the equivalent of the POPIA conditions on the recipient. By agreeing to our Terms of Service, you acknowledge and consent to the transfer of your data to the United States as necessary to provide the services.
🇦🇪 UAE
For users in the UAE, data transfers to third countries comply with the requirements of the UAE Federal PDPL (Art. 22) and, where applicable, the DIFC Data Protection Law 2020. We ensure that international transfers are made to countries recognised as providing adequate protection, or under appropriate safeguards including contractual clauses. Note that certain data categories may be subject to UAE data residency requirements; we will inform you of any such limitations relevant to your account.
🇦🇺 Australia → United States
Where we disclose personal information to overseas recipients (including our US-based subprocessors), we take reasonable steps to ensure those recipients do not breach the Australian Privacy Principles (APP 8). By using our services, you may consent to this disclosure. We take contractual steps to ensure overseas subprocessors handle your data consistently with the APPs.
You may request a copy of our applicable transfer mechanisms by contacting legal@arctactic.com.
◆ 7. Data Retention
- Account & CRM data: Retained for the duration of your active subscription plus 90 days after cancellation to allow data export, then deleted.
- Call recordings & transcripts: Retained for 12 months from the date of recording, or as required by applicable law.
- Billing records: Retained for 7 years to comply with tax and financial regulations (including South African Income Tax Act requirements, and equivalent requirements in other jurisdictions).
- Analytics & aggregated logs: May be retained indefinitely in anonymised form.
- Support communications: Retained for 3 years following resolution of the support request.
Upon account deletion, we will purge or anonymise your personal data within 30 days, unless retention is required by applicable law.
◆ 8. Your Privacy Rights (All Jurisdictions)
Depending on your jurisdiction, you have the following rights regarding your personal data. We will respond to verified requests within the timescales required by applicable law (generally 30 days, extendable where permitted).
| Right | 🇿🇦 POPIA | 🇪🇺 GDPR | 🇬🇧 UK GDPR | 🇺🇸 CCPA/CPRA | 🇦🇪 UAE PDPL | 🇦🇺 APPs |
|---|---|---|---|---|---|---|
| Access / Know | s.23 | Art. 15 | Art. 15 | ✓ | Art. 13 | APP 12 |
| Correction / Rectification | s.24 | Art. 16 | Art. 16 | ✓ | Art. 13 | APP 13 |
| Erasure / Deletion | s.24 | Art. 17 | Art. 17 | ✓ | Art. 13 | APP 11 |
| Restriction of Processing | — | Art. 18 | Art. 18 | — | — | — |
| Data Portability | — | Art. 20 | Art. 20 | ✓ | — | — |
| Object to Processing | s.11(3) | Art. 21 | Art. 21 | ✓ | Art. 13 | — |
| Withdraw Consent | s.11 | Art. 7(3) | Art. 7(3) | ✓ | Art. 10 | ✓ |
| Lodge Complaint | s.74 | Art. 77 | Art. 77 | ✓ | Art. 19 | s.36 |
To exercise any of these rights, contact us at legal@arctactic.com with the subject line "Privacy Rights Request — [Your Jurisdiction]." We will respond within the timeframe required by your applicable law (typically 30 days).
◆ 9. US State Privacy Rights
The following US state privacy laws may apply to residents of those states. In each case, we do not sell personal information or engage in cross-context behavioural advertising.
California — CCPA/CPRA (Cal. Civ. Code §§ 1798.100 et seq.)
- Right to Know: The categories and specific pieces of personal information collected in the past 12 months.
- Right to Delete: Request deletion of personal information, subject to statutory exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: We do not sell or share personal information for cross-context behavioural advertising.
- Right to Limit Use of Sensitive Personal Information: Limit our use to what is necessary to provide the service.
- Right to Non-Discrimination: We will not discriminate against you for exercising CCPA rights.
- Automated Decision-Making (ADMT): You may request information about the logic of our AI systems and opt-out of ADMT for significant decisions (effective January 1, 2025 under CPRA regulations).
- Categories Collected (last 12 months): Identifiers, commercial information, internet/network activity, audio/electronic data (call recordings), professional information.
Submit a verifiable consumer request to legal@arctactic.com with subject line "CCPA Request." Response within 45 days (extendable by 45 additional days with notice).
Virginia — VCDPA (Va. Code Ann. §§ 59.1-571 et seq.)
- Rights to access, correct, delete, and obtain a portable copy of your personal data; right to opt-out of targeted advertising, sale, and profiling for significant decisions. Response within 45 days.
Colorado — CPA (Colo. Rev. Stat. §§ 6-1-1301 et seq.)
- Rights to access, correct, delete, and data portability; right to opt-out of targeted advertising, sale, and profiling. Response within 45 days (extendable by 45 days).
Connecticut — CTDPA (Conn. Gen. Stat. §§ 42-515 et seq.)
- Rights to access, correct, delete, and portability; right to opt-out of targeted advertising, sale, and profiling for significant decisions. Response within 45 days.
Texas — TDPSA (Tex. Bus. & Com. Code §§ 541.001 et seq.)
- Rights to access, correct, delete, and portability; right to opt-out of targeted advertising, sale, and profiling. Response within 45 business days.
Montana — MCDPA (Mont. Code Ann. §§ 30-14-3401 et seq.)
- Rights to access, correct, delete, and portability; opt-out of targeted advertising, sale, and profiling. Response within 45 days.
Oregon — OCPA (Or. Rev. Stat. §§ 646A.570 et seq.)
- Rights to access (list of specific third parties), correction, deletion, and portability; opt-out of targeted advertising, sale, and profiling. Response within 45 days.
Florida — FDBR (Fla. Stat. §§ 501.701 et seq.) — Applicable to controllers processing data of 100,000+ consumers
- Rights to access, correct, delete, and portability; opt-out of targeted advertising, sale, and profiling. Response within 45 days.
Illinois — BIPA (740 ILCS 14/)
- If Voice AI processes any biometric identifiers (e.g., voice print data) from Illinois residents, we will comply with BIPA requirements, including obtaining written consent prior to collection and maintaining a publicly available retention policy.
New York — SHIELD Act (N.Y. Gen. Bus. Law § 899-bb)
- We maintain reasonable administrative, technical, and physical safeguards to protect personal information of New York residents from unauthorised access, use, or disclosure.
To exercise any US state right, contact legal@arctactic.com with subject "Privacy Rights Request — [Your State]." You may also appeal a denied request to the same email with "Privacy Rights Appeal" in the subject line.
◆ 10. UAE Residents — Federal PDPL & DIFC
If you are located in the United Arab Emirates, the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and/or the DIFC Data Protection Law 2020 (Law No. 5 of 2020, as amended) may apply to you.
Under the UAE PDPL, you have the right to:
- Be informed about how your personal data is processed (Art. 9)
- Access a copy of your personal data we hold (Art. 13)
- Request correction of inaccurate or incomplete data (Art. 13)
- Request deletion of your personal data in certain circumstances (Art. 13)
- Object to the processing of your personal data (Art. 13)
- Withdraw consent at any time, where consent is the basis for processing (Art. 10)
- Lodge a complaint with the UAE Data Office
We process personal data of UAE residents only for the purposes of performing our services contract, complying with UAE legal obligations, or with your consent. We do not transfer personal data to a country that does not provide adequate protection without appropriate safeguards.
UAE Data Office: uaedataoffice.ae
DIFC Commissioner of Data Protection: difc.ae
To exercise your UAE privacy rights, contact legal@arctactic.com with subject line "UAE PDPL Request."
◆ 11. Australian Residents — Privacy Act 1988 & APPs
If you are located in Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to your personal information.
Collection: We collect personal information only where reasonably necessary for our business functions (APP 3). Where practicable, we collect directly from you and notify you of the purpose at collection.
Use and Disclosure: We use personal information only for the primary purpose of collection, or with your consent, or where otherwise permitted under the APPs (APP 6).
Cross-Border Disclosure: We may disclose your personal information to our US-based subprocessors. Where we do so, we take reasonable steps to ensure those parties comply with the APPs (APP 8). By using our services, you acknowledge and agree to such overseas disclosure.
Access and Correction: You have the right to access the personal information we hold about you and to request corrections (APPs 12 and 13). We will respond within 30 days.
Notifiable Data Breaches (NDB) Scheme: If a data breach is likely to result in serious harm to you, we will notify both you and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, and no later than 30 days after becoming aware of the breach (Privacy Act s.26WH).
Spam Act 2003: Any commercial electronic messages we send comply with the Spam Act 2003, including the requirement for consent, clear sender identification, and a functional unsubscribe mechanism.
Office of the Australian Information Commissioner (OAIC):
Website: oaic.gov.au
Phone: 1300 363 992 (within Australia)
To exercise your Australian privacy rights, contact legal@arctactic.com with subject line "Australian Privacy Request." If you are not satisfied with our response, you may complain to the OAIC.
◆ 12. Children's Privacy
Arctactic is a B2B platform intended exclusively for business users aged 18 and older. We do not knowingly collect personal information from individuals under the age of 18 (or under 16 for EU/UK users, consistent with applicable local laws). We do not target our services at children and do not knowingly collect data from children. If we discover we have inadvertently collected data from a minor, we will delete it promptly. If you believe a minor has provided us data, contact legal@arctactic.com.
◆ 13. Security Measures
We implement industry-standard technical and organisational measures to protect your data:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for all data at rest in Convex database environments
- Multi-Factor Authentication (MFA) and SSO via WorkOS
- Role-based access controls limiting internal employee access
- Regular security audits of AI routing logic and infrastructure
Breach Notification Timelines (by jurisdiction):
- 🇪🇺 EU (GDPR Art. 33): Authority notification within 72 hours; affected data subjects without undue delay where high risk (Art. 34).
- 🇬🇧 UK (UK GDPR Art. 33): ICO notification within 72 hours of becoming aware.
- 🇿🇦 South Africa (POPIA s.22): The Information Regulator and affected data subjects must be notified as soon as reasonably possible after discovery of a breach.
- 🇺🇸 US States: Varies by state — most require notification within 30–90 days (e.g., California: expediently and without unreasonable delay; New York SHIELD Act: expedient notice).
- 🇦🇪 UAE (PDPL Art. 14): UAE Data Office notification without undue delay, and within 72 hours where feasible.
- 🇦🇺 Australia (NDB Scheme): OAIC and affected individuals notified as soon as practicable, and no later than 30 days after becoming aware of an eligible data breach.
No system is completely secure. In the event of a data breach affecting your rights, we will notify you as required by applicable law.
◆ 14. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements across any applicable jurisdiction. We will post the revised policy on this page with an updated "Last Updated" date. For material changes, we will notify active subscribers by email at least 14 days in advance.
Your continued use of the service after the effective date constitutes acceptance of the updated policy.
◆ 15. Contact & Supervisory Authorities
For privacy inquiries, rights requests, or data protection concerns:
- Email: legal@arctactic.com
- Subject line: "Privacy Request — [Your Jurisdiction]"
- Response time: Within 30 days (or as required by applicable law)
If you are not satisfied with our response, you may lodge a complaint with the relevant supervisory authority for your jurisdiction:
| Jurisdiction | Authority | Website |
|---|---|---|
| 🇿🇦 South Africa | Information Regulator | inforegulator.org.za enquiries@inforegulator.org.za |
| 🇪🇺 European Union | Lead DPA in your EU member state | edpb.europa.eu |
| 🇬🇧 United Kingdom | Information Commissioner's Office (ICO) | ico.org.uk |
| 🇦🇪 UAE | UAE Data Office | uaedataoffice.ae |
| 🇦🇺 Australia | Office of the Australian Information Commissioner (OAIC) | oaic.gov.au |
| 🇺🇸 United States (CA) | California Privacy Protection Agency (CPPA) | cppa.ca.gov |