United States and Canada Privacy Policy
Last Updated: March 3, 2026. View the prior version of this Privacy Policy.
- IMPORTANT INFORMATION AND WHO WE ARE
Privacy policy
This privacy policy gives you information about how Actionstep collects and uses your personal data through your use of this website, including any data you may provide when you purchase a product or service. This policy is intended to satisfy the requirements of data protection laws in the United States and Canada.
This website is not intended for children, and we do not knowingly collect data relating to children.
Controller
The Actionstep Group is made up of different legal entities. This privacy policy is issued on behalf of the Group, so when we mention “Actionstep”, “we”, “us” or “our” in this privacy policy, we are referring to the relevant company in the Group responsible for processing your data. We will let you know which specific Actionstep entity will be the controller for your data when you purchase a product or service with us. If Actionstep, Inc. is the controller for your data in connection with this website.
2. THE TYPES OF PERSONAL DATA WE COLLECT ABOUT YOU
Personal data means any information about an individual from which that person can be identified.
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
- Identity Data: includes first name, last name, any previous names, username or similar identifier, marital status, title, date of birth and gender.
- Contact Data: includes billing address, delivery address, email address and telephone numbers.
- Financial Data: includes bank account and payment card details, which may be considered sensitive data under data protection laws.
- Transaction Data: includes details about payments to and from you and other details of products and services you have purchased from us.
- Technical Data: includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device ID and other technology on the devices you use to access this website.
- Profile Data: includes your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.
- Usage Data: includes information about how you interact with and use our website, products and services.
- Marketing and Communications Data: includes your preferences in receiving marketing from us and our third parties and your communication preferences.
We also collect, use and share aggregated data such as statistical or demographic data which is not personal data as it does not directly (or indirectly) reveal your identity. For example, we may aggregate individuals’ Usage Data to calculate the percentage of users accessing a specific website feature in order to analyse general trends in how users are interacting with our website to help improve the website and our service offering.
We do not use or disclose sensitive personal data about you except as necessary to provide you with our services, prevent fraud, or for other permissible uses under applicable data protection laws. You can request that we limit our processing of your personal data as detailed in paragraph 9, below.
3. HOW IS YOUR PERSONAL DATA COLLECTED?
We use different methods to collect data from and about you including through:
Your interactions with us. You may give us your personal data by filling in online forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
- apply for our products or services;
- create an account on our website;
- subscribe to our service or publications;
- request published resources or marketing materials to be sent to you; or
- give us feedback or contact us.
Automated technologies or interactions. As you interact with our website, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies and other similar technologies.
4. HOW WE USE YOUR PERSONAL DATA
Performance of a contract with you: Where we need to perform the contract we are about to enter into or have entered into with you.
To Conduct Our Business: We may use your personal data where it is necessary to conduct our business and pursue our legitimate interests, for example to enable us to give you the best and most secure customer experience. We make sure we consider and balance any potential impact on you and your rights (both positive and negative) before we process your personal data for our legitimate interests.
Legal obligation: We may use your personal data where it is necessary for compliance with a legal obligation that we are subject to. We will identify the relevant legal obligation when we rely on this legal basis.
Consent: We rely on consent only where we have obtained your active agreement to use your personal data for a specified purpose, for example if you subscribe to an email newsletter or other marketing communications.
Purposes for which we will use your personal data
We have set out below, in a table format, a description of all the types of data we have collected in the last 12 months, the ways we have used or plan to use the various categories of your personal data, and the sources of such information.
| Type of Data | Purpose/Use | Source of Information |
| Identity Data | To provide you with our services and to market to you | Directly from you when you register as a customer, complete a transaction, or otherwise provide us with this information and from third-party data enrichment services |
| Contact Data | To provide you with our services and to market to you | Directly from you when you register as a customer, complete a transaction, or otherwise provide us with this information and from third-party data enrichment services |
| Financial Data | To complete transactions with you and for legal and compliance purposes | Directly from you when you engage in a transaction with us |
| Transaction Data | To complete transactions with you and for legal and compliance purposes | Directly from you when you engage in a transaction with us |
| Technical Data | To provide our services to you, improve our website and service offerings, and to market to you | Automatically when you use our website |
| Profile Data | To provide our services to you, improve our website and service offerings, and to market to you | Directly from you when you create a profile on our website or otherwise use our services |
| Usage Data | To provide our services to you, improve our website and service offerings, and to market to you | Automatically when you use our website |
| Marketing and Communication Data | To provide our services to you and to market to you | Directly from you and from third parties with whom you have shared this information |
Compliance, Fraud Prevention and Safety
In addition to the above, we may use and disclose some or all of your personal data as we believe appropriate to: (a) investigate or prevent violation of the law or your agreements with us; (b) protect our, your or others’ rights, privacy, safety or property (including by prosecuting and defending legal claims); (c) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity; (d) comply with applicable laws, lawful requests and legal process, such as to respond to subpoenas or requests from government authorities; and (e) where permitted by law in connection with a legal investigation. For example, we may share information with law enforcement to reduce the risk of fraud or if someone uses or attempts to use our website or services for illegal reasons.
Direct marketing
When your personal data is collected via forms or other data collection tools, you will be asked to indicate your preferences for receiving marketing communications from Actionstep.
We may also analyse your Identity, Contact, Technical, Usage and Profile Data to form a view about which products, services and offers may be of interest to you and/or send you relevant marketing communications.
Third-party marketing
We will get your express consent before we share your personal data with any third party for their own direct marketing purposes or otherwise use your personal data for cross-contextual behavioral or targeted advertising. If you have provided your consent, you may opt-out via the method specified below.
Opting out of marketing
You can ask us to stop sending you marketing communications at any time by following the opt-out links within any marketing communication sent to you or by contacting us privacy@actionstep.com.
If you opt out of receiving marketing communications, you will still receive service-related communications that are essential for administrative or customer service purposes for example relating to updates to our Terms and Conditions, product changes or checking that your contact details are correct.
Cookies
A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server. Cookies may be either “persistent” cookies or “session” cookies: a persistent cookie will be stored by a web browser and will remain valid until its set expiry date, unless deleted by the user before the expiry date; a session cookie, on the other hand, will expire at the end of the user session, when the web browser is closed. Cookies do not typically contain any information that personally identifies a user, but personal data that we store about you may be linked to the information stored in and obtained from cookies.
We use cookies for the following purposes:
- authentication: to identify you when you visit our website and as you navigate our website;
- personalisation: to store information about your preferences and to personalise the website for you;
- analysis: to help us to analyse the use and performance of our website and services; and
- cookie consent: to store your preferences in relation to the use of cookies more generally.
Cookies used by our service providers
Our service providers use cookies and those cookies may be stored on your computer when you visit our website. Click on the links below to read more about how they use cookies.
- We use Google Analytics to analyze the use of our website. Google Analytics gathers information about website use by means of cookies. The information gathered relating to our website is used to create reports about the use of our website. To opt out of the Google Analytics, we encourage you to check out Google Analytics’ currently available opt-outs for the web.
- We use Freshdesk to provide in-product customer support.
- We use Pendo to analyse how our product is used and to gather feedback so that we can make improvements to the product.
- We use CookieYes to manage consent and the use of cookies on our website.
- We use Ortto to appropriately use and manage contact details, preferences and activity history for the purposes of marketing and company communications.
Opt-out signals
This website recognizes do not track and opt out preference signals. These are privacy preference that users can set in their web browsers. When a user turns on these signals, the browser sends a message to websites requesting that they do not track the user across sites. This website responds to these browser settings and signals and, if you have enabled these signals, this website will prevent our third party advertising partners from continuing to collect information about you and your activity on our website through the use of third party cookies, tracking pixels, and other tools. However, even with these signals enabled, we will continue to collect other information about you and your activity through the use of cookies, tracking pixels, and other tools as described in this policy. For information about do not track signals, visit www.allaboutdnt.org.
5. DISCLOSURES OF YOUR PERSONAL DATA
We do not share your personal data with third parties for cross-context behavioral or targeted advertising purposes or otherwise sell your personal data, but in the past 12 months we may have disclosed your personal data for the business purposes discussed above to the third parties listed here: Trust Center – Actionstep.
We may also share your personal data with government or law enforcement officials or other third parties for compliance, fraud prevention and safety purposes as more fully described above. In addition, we may share your personal data with third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy policy.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
You may be able to opt-out of the sharing of your information as detailed in paragraph 9, below.
6. INTERNATIONAL TRANSFERS
We share your personal data within the Actionstep Group. This may involve transferring your data to our offices in Australia, Canada, New Zealand, the United Kingdom, and the United States. We may also transfer your personal data to our service providers that may be located outside of your home country. Details about the locations of our service providers are available in our Trust Center. Your use of this website or provision or use of our constitutes your consent for the transfer your personal data outside of your home country as detailed above for the purposes identified in this Privacy Policy.
Laws in the locations where we handle your personal information may not be as protective as the laws in your home country; however, we will still handle your personal data in accordance with this Privacy Policy and assure suitable mechanisms are in place to protect your personal data. Where required by law, you may request a copy of these mechanisms by emailing us at privacy@actionstep.com.
For more information about the use or storage of personal information outside of your home country, or if you have any questions about cross-border transfers, please email us at privacy@actionstep.com.
7. DATA SECURITY
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
8. DATA RETENTION
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
In some circumstances, you can ask us to delete your data. See paragraph 9 below for further information. By law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for six years after they cease being customers. If you ask us to delete your personal data or otherwise cease using your personal data for a particular purpose, we may need to retain certain of your details in our database to ensure that we do not use your data for such purpose and as otherwise required by law.
In some circumstances we will anonymize your personal data (so that it can no longer be associated with you), including for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
9. YOUR LEGAL RIGHTS
You have a number of rights under data protection laws in relation to your personal data.
You have the right to:
Request access to your personal data. This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it, as well as a list of the third parties with which we share or have shared your personal data. However, under applicable data protections law, we may be unable provide you with certain sensitive information, despite your request (for example, we will not send you copies of your social security number even if it is something we collected).
Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
Request deletion of your personal data in certain circumstances. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
Request to opt out of the continued use and disclosure of your personal data (subject to legal limitations and reasonable notice).
Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
Request confirmation of whether we have shared your personal data with third parties for direct marketing purposes (also referred to as a “Shine the Light” request).
If you wish to exercise any of the rights set out above, please contact us privacy@actionstep.com. As part of your request, please specify which right you are exercising. We will not discriminate against you if you choose to exercise your rights.
Who may make a request
Only you or an individual empowered by law to act on your behalf may make a request related to your personal data.
No fee usually required
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, if allowed by applicable data protection laws, we could refuse to comply with your request in these circumstances.
What we may need from you
As part of your request, please be prepared to provide your name and email address or phone number. After receiving your request, we will use the information you provided to authenticate your identity or your authority as an authorized agent. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
Time limit to respond
We will try to respond to your request within 45 days and notify you if your request has been granted or declined, or if an exception applies to your request. If we need additional time, we will contact you with the reason and the extension period. We will deliver our written response by mail or electronically, at your option. Our response will also explain the reasons we cannot comply with any request, if applicable.
Right to appeal
You have the right to appeal our refusal to take action on a rights request after receiving our decision as detailed in our response or by contacting us as detailed at the end of this Policy. If you are a Nebraska resident, you also have the right to appeal this refusal to the office of the Attorney General. We will try to inform you of our decision in writing within 45 days after receipt of your appeal, with a written explanation of our decision. If we need more time, we will contact you with the reason and the extension period. If your appeal is denied or if you have concerns about the results of an appeal, you may contact your state’s attorney general. We will provide their contact information with the results of the appeal.
10. CONTACT DETAILS
If you have any questions about this privacy policy or about the use of your personal data or you want to exercise your privacy rights, please contact privacy@actionstep.com.
11. CHANGES TO THE PRIVACY POLICY AND YOUR DUTY TO INFORM US OF CHANGES
We keep our privacy policy under regular review. This version was last updated on March 3, 2026. Historic versions can be obtained by contacting us.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us, for example a new address or email address.
12. THIRD-PARTY LINKS
This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.