Last updated: 30 July 2026
Actoki is a software service developed, owned and operated by Oxiti Ltd. In this privacy notice, “Actoki” means the service and “we”, “us” or “our” means Oxiti Ltd as its operator. This notice explains how we collect and use personal data when you visit https://actoki.com, create or use an account, use our application programming interfaces (APIs), protected maps, billing features, support services or administration tools.
1. Who is responsible for your personal data
The data controller for the account, website and commercial relationship is Oxiti Ltd. Registered in England and Wales · Company number 15228422 · Registered office: 5 Canon Court, Institute Street, Bolton, England, BL1 1PZ. You can contact our privacy team at privacy@actoki.com.
Where a customer sends personal data to an Actoki API for processing on that customer's instructions, the customer will usually be the controller and Oxiti Ltd will usually act as its processor. The customer's own privacy information and lawful basis remain its responsibility. Additional data-processing terms may apply to that use.
2. The personal data we collect
Account and team data
- Name, business email address, preferred language and account role.
- Password hash, two-factor authentication method, recovery and session-security records.
- Invitations, membership, permission, account-status and administrative history.
Business and billing data
- Business and legal name, company and VAT numbers, billing address, billing contact details and purchase-order reference.
- Credit purchases, invoices, refunds, tax information, transaction identifiers and payment status. Card details are handled by Stripe and are not stored by Oxiti Ltd.
API, map and service-use data
- API-key identifier, scopes, allow-list settings, request time, endpoint, response status, units or credits used, source IP address and security signals.
- Protected-map identifier, approved origin, map configuration, usage, rate-limit and delivery events.
- Inputs submitted to a service and outputs returned by it where this is necessary to perform the request, troubleshoot it, prevent abuse or meet an agreed retention period. Customers should not send more personal data than the selected service requires.
Support and administration data
- Support messages, attachments, internal account notes and actions taken to resolve a request.
- Time-limited super-administrator support access, including the administrator, selected user and account, reason, ticket reference, start/end time, IP address, browser and actions performed.
Website, device and cookie data
- IP address, browser and device information, pages or features used, security events and necessary cookie values.
- Analytics and advertising data only where the relevant optional consent has been granted and the corresponding tags have been configured.
Data from other sources
We may receive account information from an inviting organisation, payment and tax status from Stripe, email-delivery events from our mail provider, security or abuse indicators from infrastructure providers, and data returned by upstream API or public-data providers used to fulfil a request.
3. Why we use personal data and our lawful bases
| Purpose | Typical lawful basis |
|---|---|
| Create and operate accounts, authenticate users, provide APIs, maps, credits, invoices and support. | Performance of a contract; steps requested before entering a contract. |
| Secure the platform, detect abuse, contain leaked keys, investigate incidents, keep audit trails and enforce limits. | Legitimate interests in protecting users, customers and the service; legal obligations where applicable. |
| Process payments, refunds, tax records, accounting evidence and statutory requests. | Contract; legal obligation; legitimate interests in financial administration. |
| Communicate service, security, billing and policy information. | Contract; legal obligation; legitimate interests in operating the service. |
| Measure optional analytics or advertising performance. | Consent for non-essential cookies or similar technologies and, where relevant, consent or legitimate interests for the related personal-data processing. |
| Improve reliability, capacity, documentation and service design using aggregated or appropriately minimised usage information. | Legitimate interests in developing and improving Actoki. |
Where we rely on legitimate interests, we consider the necessity and impact of the processing and apply safeguards such as access controls, minimisation, retention limits and audit records. You can object to processing based on legitimate interests.
4. Automated security and account controls
Oxiti Ltd uses automated rules to protect the Actoki service. These can rate-limit requests, reject a request outside an API key's approved network or scope, suspend an individual key after suspicious activity, block a seriously overdue or negative-balance account, or require additional authentication. Security and billing decisions can be reviewed through support. We do not intend to use these controls to make decisions that produce legal effects unrelated to access to the Actoki service.
5. Who we share data with
We share personal data only where needed for the purposes above. Recipients may include:
- Hosting, database, content-delivery, security, logging and backup providers.
- Email delivery, support and operational communication providers.
- Stripe and related payment or tax services for checkout, payment, refund, fraud and tax processing.
- Google services loaded through Google Tag Manager where optional consent and configuration permit them.
- Map, registry, travel, communications or other upstream providers required to perform a selected API request.
- Professional advisers, insurers, auditors, regulators, law-enforcement bodies or courts where disclosure is lawful and necessary.
- A purchaser, investor or successor in connection with a genuine corporate transaction, subject to confidentiality and data-protection safeguards.
Customers should review the documentation for an endpoint before sending personal data, because different services may use different upstream providers.
6. International transfers
Some suppliers or upstream providers may process data outside the United Kingdom. Where restricted-transfer rules apply, we use an available lawful transfer mechanism, such as adequacy regulations, the UK International Data Transfer Agreement or Addendum, and supplementary safeguards where appropriate. Contact us for information about the safeguards relevant to a particular service.
7. How long we keep data
| Record | Typical retention approach |
|---|---|
| Account profile and membership | For the account relationship and a limited period afterwards, unless earlier deletion is appropriate or longer retention is required. |
| Invoices, payments, refunds and tax records | For the period required by applicable accounting, tax, fraud-prevention and dispute rules. |
| Authentication, security and audit events | For a proportionate security period based on risk, investigation and accountability needs. |
| API request content | Normally transient or retained only as stated for the relevant endpoint, cache, support case or security event. |
| Cookie-consent evidence | Normally 180 days, subject to the configured retention setting and legal requirements. |
| Blocked account scheduled for deletion | Access may be blocked immediately and account data scheduled for deletion or anonymisation after 90 days. Financial, security and legal records may be retained where required. |
| Support records and internal notes | For the support relationship, quality control, security and the defence of legal claims. |
We may retain anonymised statistics that no longer identify an individual.
8. Security
We use measures designed to protect data, including encrypted transport, password hashing, two-factor authentication, scoped and hashed server keys, origin-restricted map keys, session revocation, rate limiting, suspicious-activity detection, audit logs, access controls and separate secrets. No service can guarantee absolute security. Keep server keys and account credentials confidential, use narrow scopes and network allow-lists, and tell us promptly if you suspect compromise.
9. Your rights
Depending on the circumstances, you may have rights to be informed, access your personal data, correct it, erase it, restrict its use, object to processing, receive portable data and withdraw consent. You may also complain to the UK Information Commissioner's Office. Some rights are limited where we must retain information for legal, security or contractual reasons.
Submit a request through Actoki support or email privacy@actoki.com. We may need to verify identity and authority before acting.
10. Cookies
Necessary cookies support authentication, security, language and privacy preferences. Optional analytics and advertising technologies are controlled through the cookie banner. Read the Cookie policy and use the persistent Cookie settings control to change your choice.
11. Children
Actoki is a developer and business platform and is not directed to children. Do not create an account or submit a child's personal data unless you are legally authorised and the selected service is appropriate for that use.
12. Changes to this notice
We publish each material update as a new, dated version. Where appropriate, we will provide an in-product or email notice and ask again for optional cookie consent. Previous published versions are retained internally for accountability.
13. Contact and complaints
Privacy contact: privacy@actoki.com. Support: support@actoki.com.
You can complain to the Information Commissioner's Office if you are unhappy with how we use personal data. We would appreciate the opportunity to address your concern first.