Privacy Policy
For the Action Labs AI platform and related services
1. Purpose and scope
Action Labs Consultancy W.L.L. ("Action Labs", "we", "us" or "our") operates action-labs.ai and related web applications, integrations, APIs, dashboards, automation tools and support services (together, the "Services"). This Privacy Policy explains how we collect, use, disclose, retain and protect personal data when you access or use the Services, communicate with us, or act on behalf of an organisation that uses the Services.
The Services are primarily intended for business users. Where an organisation provides you access to the Services, that organisation may separately control certain personal data and may have its own privacy notice and instructions.
2. Who is responsible for your data
Unless a customer agreement states otherwise, Action Labs Consultancy W.L.L. is the data controller for account, website, billing, security and direct communications data collected for our own purposes. For content, files, records or personal data submitted by a customer for processing through the Services, Action Labs may act as a data processor or service provider on that customer’s documented instructions.
Registered office: Kingdom of Bahrain Privacy contact: o.rana@action-labs.co
3. Personal data we may collect
Account and identity data, such as name, business email address, phone number, job title, employer, username, authentication identifiers and profile details.
Customer and transaction data, such as organisation details, subscription or plan information, invoices, payment status and commercial correspondence. Full payment-card details should be handled by the applicable payment provider rather than stored by us.
User content and uploaded materials, including briefs, documents, images, artwork, design files, instructions, prompts, outputs, comments, approval records and other information submitted to the Services.
Usage and device data, such as IP address, browser and device type, operating system, timestamps, pages or features used, referring URLs, diagnostic logs, crash data and security events.
Integration data received when you connect an authorised third-party service, such as identity, cloud-storage, communications, analytics, file-hosting or productivity platforms. The exact data depends on the permissions you approve.
Communications and support data, including messages, meeting notes, support requests, feedback, call records and related attachments.
Cookies and similar technologies used for essential functionality, security, preferences and, where enabled with the appropriate notice or consent, analytics.
Please do not submit special-category, highly sensitive, confidential or regulated personal data unless it is necessary, authorised by your organisation, and supported by an appropriate written agreement with us.
4. How we use personal data
Provide, configure, operate and support the Services.
Authenticate users, manage permissions and maintain account security.
Process customer instructions, files and content, including generating, adapting, organising, exporting or otherwise transforming materials requested through the Services.
Maintain service reliability, prevent fraud or misuse, investigate incidents and enforce our Terms of Service.
Communicate about accounts, service changes, support matters, security and administrative notices.
Manage subscriptions, billing, procurement, audits and contractual relationships.
Improve features, usability and performance using aggregated, de-identified or appropriately controlled data. We will not use customer confidential content to train a generally available artificial-intelligence model unless the relevant customer has expressly agreed in writing.
Comply with law, regulatory requests, court orders and the establishment, exercise or defence of legal claims.
5. Legal bases
Depending on the circumstances and applicable law, we process personal data on one or more of the following bases: performance of a contract; steps requested before entering a contract; compliance with legal obligations; legitimate interests such as operating, securing and improving the Services; consent where required; and the establishment, exercise or defence of legal claims.
Where Bahrain law applies, we process personal data in accordance with Law No. (30) of 2018 with respect to Personal Data Protection and its implementing requirements. Where the EU or UK data-protection regime applies, we rely on an available lawful basis and provide the rights required by that regime.
6. Artificial intelligence and automated processing
Some features may use artificial intelligence, machine learning or rules-based automation to analyse instructions, create draft outputs, classify content, extract information or support workflows. Outputs may be inaccurate, incomplete or unsuitable and should be reviewed by an authorised human before use, publication or reliance. We do not intend the Services to make solely automated decisions that produce legal or similarly significant effects about individuals unless expressly agreed, lawfully configured and subject to appropriate safeguards.
7. How we share data
With the customer organisation that administers your account, including authorised administrators and collaborators.
With vetted service providers that support hosting, storage, authentication, file processing, communications, analytics, customer support, security, payments and professional services, subject to contractual confidentiality and data-protection obligations.
With third-party integrations at your or your organisation’s direction.
With professional advisers, auditors, insurers, regulators, law-enforcement bodies, courts or other authorities where reasonably necessary or legally required.
In connection with a merger, acquisition, financing, reorganisation, sale of assets or similar transaction, subject to appropriate safeguards.
With another party where you have authorised the disclosure.
We do not sell personal data for monetary consideration. We do not permit third parties to use customer content for their own independent advertising purposes.
8. International transfers
The Services may use infrastructure or service providers located outside Bahrain or the country where you are based. Where personal data is transferred internationally, we take steps intended to ensure an appropriate level of protection, including contractual safeguards, approved transfer mechanisms, transfer assessments, consent where legally appropriate, or another lawful basis. Customers remain responsible for ensuring that their instructions and use of integrations comply with any sector-specific localisation or transfer restrictions that apply to them.
9. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, comply with contracts and law, resolve disputes and maintain security records. Retention periods depend on the type of data, customer configuration, contractual commitments, legal requirements and the sensitivity of the information. Customer content is deleted or returned in accordance with the applicable agreement and operational backup cycles, subject to legal holds and security requirements.
10. Security
We use administrative, organisational and technical measures designed to protect personal data, such as access controls, authentication, encryption where appropriate, logging, backups, vulnerability management and service-provider due diligence. No system is completely secure, and we cannot guarantee absolute security. Users must protect credentials, use appropriate permissions and notify us promptly of suspected unauthorised access.
11. Your rights and choices
Subject to applicable law and relevant exceptions, you may have rights to request access to personal data, correction, deletion, restriction, objection, portability, withdrawal of consent and information about processing. You may also have the right to complain to a competent data-protection authority. Where we process data solely for a customer, we may direct your request to that customer or assist it in responding.
To exercise a right, contact o.rana@action-labs.co. We may need to verify your identity and authority before acting. You can also manage certain account, integration, cookie and communication preferences through the Services.
12. Children
The Services are not directed to children and are intended for users who are at least 18 years old or the age of legal majority in their jurisdiction. We do not knowingly collect personal data directly from children through the Services. If you believe a child has provided personal data, contact us so that we can assess and take appropriate action.
13. Third-party sites and services
The Services may link to or integrate with third-party products. Their privacy practices are governed by their own notices and agreements. Action Labs is not responsible for the independent practices of third parties, and you should review their terms before enabling an integration or disclosing data to them.
14. Changes to this Policy
We may update this Privacy Policy to reflect changes in the Services, law or our practices. We will post the revised version with a new effective date and provide additional notice where required. Continued use after the effective date is subject to the updated Policy, without limiting rights that require consent or another legal basis.
15. Contact and complaints
Questions, privacy requests and complaints may be sent to: Action Labs Consultancy W.L.L. Kingdom of Bahrain Email: o.rana@action-labs.co
You may also complain to the Personal Data Protection Authority in the Kingdom of Bahrain or another competent supervisory authority where applicable.