Sales Enact / Privacy

Privacy policy

How we handle information on our website and in your organisation’s Sales Enact workspace.

Last updated: 20 September 2026

1. Who we are

Sales Enact is operated by Quantaria Ltd, registered in England and Wales under company number 17004609. Our registered office is Star Lodge, Montpellier Drive, Cheltenham, United Kingdom, GL50 1TY. Contact us at graeme.elliott@salesenact.ai.

This policy covers this website, account administration and use of Sales Enact. We are the controller of information used for our own enquiries, account administration and service security. For business content processed in a customer’s workspace, the customer organisation normally acts as controller and we act as its processor, following its instructions. Its own privacy information also applies.

2. Information we handle

  • Account information: your name, email address, sign-in provider identifier, profile details supplied by that provider, organisation membership and permissions.
  • Workspace content: emails, attachments, documents, business contact details, order or invoice information, connected ERP records, prompts, conversations and drafts supplied by you or your organisation.
  • Service records: sign-in and activity records, job results, IP addresses, browser information and error or security logs.
  • Enquiries: information you choose to send when you contact us.

Business content may contain information about customers, suppliers and other people. It reaches us through authorised users, your organisation’s configured email integration or its connected business systems.

3. Google sign-in

If you choose Google sign-in, Sales Enact requests only the openid, profile and email permissions. These provide an account identifier, your email address and verification status, and basic profile information such as your name and profile picture, where available.

We use that information to authenticate you, associate your sign-in with your authorised Sales Enact account, display your identity and protect access to your workspace. We store the account and sign-in information needed for those purposes. Google sign-in does not grant Sales Enact access to your Gmail messages, Google Drive files or Google contacts. Workspace emails are received through your organisation’s separately configured integration.

We do not sell Google user data, use it for advertising or use it to train general-purpose AI models. It is shared only as needed to provide and secure the sign-in service, with authorised service providers or where required by law. Sales Enact’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

You can remove Sales Enact’s access in your Google Account connections. This stops future access through that connection; it does not automatically delete your Sales Enact account or your organisation’s business records. Contact your workspace administrator or us to request deletion.

4. How and why we use information

We use information to provide access, process the workflows your organisation configures, prepare drafts, support users, troubleshoot problems and protect the service. AI-assisted workflows can extract, classify, match and summarise content. Outputs can be inaccurate and are intended for review by authorised users before business actions are approved.

For information we control, our legal bases are our legitimate interests in operating a secure business service, managing business accounts and responding to enquiries; performance of a contract where that contract is with you; and compliance with legal obligations. Where we rely on consent, you can withdraw it. Authorising a sign-in provider does not give us permission to use your information for unrelated purposes.

We do not sell personal information or use workspace content for advertising. Sales Enact is a business service and is not intended for children.

5. Services and sharing

Information is available to users permitted by your organisation’s access settings and to service providers where needed to operate the relevant feature. Depending on your organisation’s configuration, these include:

  • Amazon Web Services: application hosting, databases, file storage, document text extraction and backups.
  • Microsoft or Google: the sign-in provider you choose.
  • Postmark: receiving and delivering configured service and workflow emails.
  • OpenAI, Anthropic and Cohere: processing relevant content for configured AI, embedding and search features.
  • NetSuite: retrieving or updating business records through your organisation’s authorised integration and workflow actions.

These providers may process information under their applicable service terms and data-protection arrangements. We may also disclose information to professional advisers or public authorities when necessary to meet legal obligations or protect rights and security. We do not make private workspace content publicly available through this website.

6. Storage, security and retention

Our primary application infrastructure is hosted on AWS in the UK. External providers may process information in other countries. Where an international transfer requires safeguards under UK data-protection law, appropriate safeguards are required, such as an adequacy regulation or approved contractual provisions. Contact us for information about the arrangements relevant to your organisation’s service.

We use access controls, encrypted connections, private storage and backups to help protect information. Access to a workspace depends on its organisation membership and permissions.

We retain account and business records for as long as needed to provide the service, follow the customer organisation’s instructions and meet applicable legal or security needs. Enquiries and technical records are kept only for as long as needed for their purpose. Customer database backups are retained on a 30-day cycle. That cycle does not set a 30-day limit for active workspace records or stored file versions; deletion of those is handled separately. Deleted information may remain in restricted backups until those backups expire.

Cookies and browser storage

This public website has no analytics or advertising trackers. The application uses essential session cookies and browser storage for sign-in, security and workspace preferences. Existing application cookies may also be sent when you visit a page on the same domain. The web server records basic request information for operation and security. Your chosen sign-in provider handles its own cookies under its privacy policy.

7. Your choices and rights

Depending on the circumstances, you can ask to access or correct your personal information, have it deleted, restrict or object to its use, or receive a portable copy. You can withdraw consent where processing relies on it. Some rights have legal exceptions, including where records must be retained.

For content controlled by your organisation, contact your workspace administrator first. We can help identify the appropriate contact and assist the organisation with its request. For information Quantaria Ltd controls, email graeme.elliott@salesenact.ai. We may need to verify your identity before acting.

You may complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint, or to your local data-protection authority where applicable.

8. Contact and changes

For privacy, support or account enquiries, contact graeme.elliott@salesenact.ai, or write to Quantaria Ltd at the registered office above.

We will update this page when our practices change and revise the date at the top. Where appropriate, we will also notify customer organisations of material changes.