How actain handles data — for end-users of a site running the agent, and for the businesses that embed it. Built to the EU/US legal floor (EU AI Act · GDPR · DPA).
End-users always see: “You're chatting with an AI assistant.” (en). actain never impersonates a human. The disclosure is a non-disableable property of the product — server-enforced in every widget render path, not a setting a tenant can turn off.
The agent reads only the structure of a page — which elements exist and what they do — never the values your end-users type, and the snapshots it reads at runtime are kept only as long as a request is being handled. What we retain is small by design: usage metadata, the requirements you provide during setup, and your agent's configuration. We keep no copy of your site's source code, and no end-user personal data beyond the active session without consent.
Every request is scoped to the customer it belongs to, and our systems offer no way to list or read across customers — so one customer can never access another's data or configuration. Sensitive parts of the service stay on our servers and are never sent to the browser; only your own agent's configuration is delivered to your site, encrypted in transit.
| Name | Role | Location |
|---|---|---|
| LLM provider (online tier) | Inference for escalated requests | US / EU |
| Hosting / CDN | Serves the site and the encrypted configuration | US / EU |
| n8n (workflow orchestration) | Routes escalated requests to the specialist | Self-hosted |
| Postgres (managed) | Tenant configuration, configuration history, audit log | US / EU |
Actain acts as a data processor for the tenant (the controller). We process end-user interaction data solely to operate the embedded agent, apply per-tenant isolation, and engage the sub-processors listed below. A full counter-signed Data Processing Agreement is available on request.
For data-subject requests (export or erase) or a counter-signed DPA, contact privacy@actain.co.