Privacy Policy
Version 2.0 | Effective date: September 14, 2026 | Last updated: September 14, 2026
1. Who we are and what this Policy covers
ActivePrime, Inc. (“ActivePrime”, “we”, “us”) is a Delaware corporation with its principal office at 800 West El Camino Real, Suite 180, Mountain View, California 94040, USA. We provide CRM data-quality software, including CleanData, to business customers. This Privacy Policy explains how we collect, use, share and protect personal information when we act for our own purposes, and the choices and rights you have.
This Policy applies to personal information we collect: (a) when you visit activeprime.com and its subdomains (the “Site”); (b) when you contact us, request information, register for a webinar or event or download materials; (c) when you or your employer buy or use our products, in respect of account, billing, support and usage contacts; (d) from business partners, event organizers, publicly available sources and third-party data providers; and (e) offline, for example at conferences. We refer to all of this as “Business Contact Data”.
This Policy does not cover the data our customers process with our products. When a customer uses ActivePrime software to clean, deduplicate, standardize or enrich records in its CRM, the customer is the controller (or “business”) for that data and ActivePrime processes it only as the customer’s processor (or “service provider”) on the customer’s instructions, under our customer agreement and Data Processing Agreement. If you are a contact in a customer’s CRM and have questions about that data, please contact the customer; if you contact us, we will refer your request to them.
This Policy does not apply to third-party websites we link to, including the Salesforce AppExchange. Please review their privacy policies before providing personal information to them.
2. Personal information we collect
Information you give us
Contact and professional details: name, job title, employer, business email address, telephone number and postal address, and the content of messages you send us.
Account and transaction details: order and billing information, payment information you provide when you buy, and records of the products you purchase. We do not issue login credentials for the Site.
Preferences: product interests, newsletter and communication preferences and similar choices you make.
Event information: registration and attendance at webinars, conferences and other events we host, sponsor or attend.
Support information: information you provide when you request support.
If you give us personal information about someone else (for example a colleague), you confirm that you are permitted to do so and that they have been referred to this Policy.
Information we collect automatically
When you use the Site or our products we and our service providers collect device and usage information such as IP address, approximate location derived from IP address, browser and device type, operating system, referring pages, pages viewed, time spent, links clicked and, for our products, feature usage, record counts and error logs. Some of this is collected through cookies and similar technologies, described in Section 5.
Information from other sources
We also receive personal information about business contacts from: our customers and partners (for example, when a customer names you as an account or support contact, or a partner refers you to us); event organizers and co-sponsors; and publicly available professional sources, such as your employer’s website. We do not buy business contact lists or use third-party data enrichment providers. We may combine information from these sources with information we collect directly. Where we obtain your information from a source other than you, we will provide you with the information required by applicable law within the time it requires.
3. How we use personal information and our legal bases
We use Business Contact Data for the purposes below. Where the EU or UK General Data Protection Regulation or similar laws apply, we rely on the legal basis shown for each purpose.
To provide, operate and secure the Site and our products, and to manage accounts, orders, invoicing and payment. Legal basis: where you are our contracting party, performance of a contract with you or steps at your request before one; otherwise, our legitimate interest in providing and securing services to our customers.
To provide customer support and product updates, patches and service communications. Legal basis: performance of a contract where you are the contracting party; otherwise, our legitimate interest in supporting our customers and their users.
To respond to your inquiries, requests for information or demos. Legal basis: legitimate interest in responding to you.
To send marketing communications about our products, services, events and content that we think are relevant to your role, and to measure their effectiveness. Legal basis: legitimate interest in business-to-business marketing; consent where the law requires it. You can opt out at any time (Section 6).
To organize and run events and webinars, including communicating with registrants. Legal basis: performance of a contract where you register with us directly; otherwise, our legitimate interest in running events; consent where the law requires it.
To analyze and improve the Site and our products, including through aggregated usage analytics. Legal basis: legitimate interest in improving our services; consent for non-essential cookies.
To detect, investigate and prevent fraud, abuse, security incidents and violations of our Terms of Use. Legal basis: legitimate interest in security; legal obligation.
To comply with legal obligations, respond to lawful requests from authorities, and establish, exercise or defend legal claims. Legal basis: legal obligation; legitimate interest.
In connection with a merger, acquisition, financing, reorganization or sale of all or part of our business, including due diligence. Legal basis: legitimate interest in conducting such transactions.
We do not use Business Contact Data to make decisions based solely on automated processing that produce legal or similarly significant effects on you. We may use analytics tools to segment marketing audiences and measure engagement; you can object to this under Section 11 if applicable.
4. How we share personal information
We share Business Contact Data only as follows:
Service providers that process it on our behalf and under contract, for hosting, CRM and marketing automation, email delivery, analytics, customer support, payment processing, event management, security and similar functions.
Salesforce and partners: if you engage with us through the Salesforce AppExchange, a reseller or marketplace, or a joint event or promotion with a partner, we and the partner named at the point of collection may each receive your contact information and use it under our own privacy policies. We do not give your contact information to partners for their own marketing, and we do not receive payment or other consideration in exchange for contact information.
Professional advisers, auditors and insurers, under confidentiality obligations.
Authorities, courts and other parties where required by law, to respond to lawful requests, to protect our rights, property or safety or those of others, or to enforce our Terms of Use. We will limit disclosures to what is required.
A successor or acquirer in connection with a merger, acquisition, financing or sale of assets; we will post notice on the Site of any resulting change in who is responsible for your information or in how it is used.
With your direction or consent, for example when you ask us to share information with a third party.
5. Cookies, tracking technologies and Global Privacy Control
We and our service providers use cookies, pixels, tags, local storage and similar technologies on the Site and in our emails. They fall into three groups: strictly necessary technologies that make the Site work and keep it secure; analytics and performance technologies that help us understand how the Site is used; and marketing technologies that measure the effectiveness of our campaigns. Our separate Cookie Notice at activeprime.com/cookies lists each cookie and similar technology we use, its provider, purpose and duration, and is incorporated into this Policy.
Where the law requires consent for non-essential cookies, we ask for your consent through our cookie banner before those technologies are set, and you can change or withdraw your choices at any time through the cookie settings link on the Site. Elsewhere, you can opt out of analytics and marketing cookies through the same settings and through your browser controls. Blocking some cookies may affect how the Site works.
Emails we send may contain a small image (a pixel) that tells us whether the email was opened and which links were clicked, so that we can measure campaign performance. You can limit this by disabling images in your email client, and you can opt out of marketing emails altogether (Section 6).
Global Privacy Control. If your browser or extension sends a Global Privacy Control (GPC) signal, we treat it as a request to opt out of the sale or sharing of your personal information and of targeted advertising to the extent required by the law of your state, for the browser and device sending the signal and, where the law requires and you are known to us, for the personal information associated with you. We do not respond to “Do Not Track” signals, which have no common standard.
6. Your marketing choices
You can opt out of marketing emails at any time by using the unsubscribe link in any marketing email or by contacting privacy@activeprime.com. We will process opt-outs within the time required by law. You will still receive transactional and service messages about your account, orders, support requests, security and product updates, and events you have registered for.
7. Artificial intelligence and automated processing
This Section describes how we use analytics and machine learning for our own purposes and, for information only, how our products use them when processing customers’ CRM data. As Section 1 explains, customers’ CRM data is governed by our customer agreement and Data Processing Addendum, not by this Policy.
On the Site and in our marketing we may use analytics and machine-learning tools to understand aggregate visitor behavior, optimize content and measure campaign performance. These tools operate on aggregated or de-identified information. We do not use lead scoring or intent data to make decisions about individuals.
Our products use rules-based techniques and may use machine-learning techniques to identify duplicates, standardize fields and validate addresses in our customers’ CRM data. Any learning from a customer’s own data is used only to provide the service to that customer. We may also use de-identified data derived from customer CRM data, which cannot reasonably be linked to a customer or to any individual, to operate, secure, benchmark and improve our products, to develop new features, and to train and improve machine-learning models that we use to serve our customers generally. Some of the models we train are large language models, and we train them only on de-identified data. We maintain measures designed to prevent re-identification, we commit to maintain and use the data only in de-identified form and not to attempt to re-identify it, and we require any recipient of the data to do the same. We do not use protected health information or other data subject to heightened legal requirements for any of these purposes. A customer may opt out of the use of de-identified data derived from its CRM data for cross-customer model training; opt-out requests are handled under the customer’s agreement with us and we give effect to them for future training within 30 days.
8. International transfers
We are based in the United States and process Business Contact Data in the United States, the European Economic Area and Canada, and in other countries where our service providers operate. If you are in the European Economic Area, the United Kingdom or Switzerland, this means your information may be transferred to a country that may not provide the same level of data protection as your home jurisdiction. Where we transfer your information to a recipient in such a country, we rely on the European Commission’s Standard Contractual Clauses and, for the United Kingdom, the UK International Data Transfer Addendum, together with additional safeguards where needed. You may request a copy of the relevant transfer mechanism by contacting privacy@activeprime.com.
9. How long we keep personal information
We keep Business Contact Data only for as long as needed for the purposes in Section 3, taking into account the nature of our relationship with you, legal, tax and accounting requirements, limitation periods, and our need to resolve disputes and enforce our agreements. As a guide:
Marketing and prospect records: three years after our last meaningful interaction with you, unless you opt out earlier, in which case we keep your contact details on a suppression list so that we can honor your opt-out.
Customer account, contract and billing records: the term of the customer relationship plus seven years, to meet tax, accounting and contractual requirements.
Support records: three years after the case is closed.
Site analytics and log data: up to 26 months, after which it is deleted or aggregated.
Event records: two years after the event, unless you become a customer or prospect.
Data in backups is deleted in the ordinary backup cycle. Customers’ CRM data is retained and deleted as set out in the Data Processing Agreement.
10. Security
We maintain administrative, physical and technical safeguards designed to protect Business Contact Data against unauthorized access, use, alteration and loss, including encryption in transit and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a security incident affecting your personal information requires notification under applicable law, we will notify you and any relevant authority within the timeframes the law requires, by email or, where required, by mail.
11. Your privacy rights and how to exercise them
Depending on where you live, you may have some or all of the following rights in relation to Business Contact Data: to access it and receive a copy; to correct inaccurate information; to have it deleted; to receive it in a portable format; to restrict or object to certain processing, including processing based on legitimate interests and direct marketing; to withdraw consent at any time, without affecting processing already carried out; to opt out of the sale or sharing of personal information, targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects; not to be discriminated against for exercising your rights; and to appeal a decision we make on your request. Sections 12 and 13 describe additional rights for California residents and for residents of other U.S. states, and Section 14 for individuals in the EEA, UK and Switzerland.
How to make a request. You can exercise your rights by emailing privacy@activeprime.com or by using our request form at activeprime.com/privacy-request. We operate exclusively online and have a direct relationship with the individuals whose information we hold, so these are the methods by which we accept privacy requests. Please tell us which right you are exercising and, if you are a contact in a customer’s CRM rather than a contact of ActivePrime, please contact that customer instead (Section 1).
Verification. For requests to access, correct, delete or port your information, we will take reasonable steps to verify your identity before acting, usually by matching the information in your request with what we hold, or by sending a confirmation to the email address on file. We may ask for more information if needed. You may authorize an agent to make a request for you; we will ask for evidence of the authorization and may still verify your identity directly. We do not require verification for requests to opt out of sale, sharing or targeted advertising or to limit the use of sensitive personal information, although we may ask for information we need to act on them.
Timing. We will respond within one month if the GDPR or UK GDPR applies (extendable by up to two further months for complex or numerous requests), and within 45 days if a U.S. state privacy law applies (extendable once by a further 45 days), and we will tell you if we need more time. For California residents, we will confirm receipt of a request to know, delete or correct within 10 business days and will act on a request to opt out or to limit the use of sensitive personal information within 15 business days. We do not charge a fee unless a request is manifestly unfounded or excessive.
Appeals. If we decline your request, we will explain why and how to appeal. You can appeal by replying to our decision or emailing privacy@activeprime.com with “Privacy appeal” in the subject line; we will respond within the period required by the law of your state. You may also contact your state Attorney General or, in the EEA or UK, your data protection authority.
12. California privacy rights
This Section applies to California residents and supplements the rest of this Policy. It describes our practices for the 12 months before the effective date of this Policy and our current practices.
Categories of personal information we collect, and sources. In the past 12 months we have collected the following categories of personal information, from the sources described in Section 2: identifiers (name, email address, telephone number, postal address, IP address, account credentials); customer records (billing and order information); professional or employment-related information (employer, job title); commercial information (products purchased or considered); internet or other electronic network activity (interactions with the Site, our products and our emails); and approximate geolocation derived from IP address. We collect these categories for the business purposes listed in Section 3.
Sensitive personal information. We do not collect sensitive personal information as defined by California law.
Disclosure, sale and sharing. In the past 12 months we have disclosed personal information for business purposes as follows: identifiers, customer records, professional information, commercial information and internet activity information to our service providers (hosting, CRM and marketing automation, email delivery, analytics, customer support, payment processing, event management and security); and, where the circumstances in Section 4 arose, the relevant categories to professional advisers, authorities or a successor. We do not knowingly sell or share the personal information of consumers under 16 years of age.
Your rights. You have the right to: know what personal information we collect, use, disclose, sell or share about you, and to access it; delete personal information we collected from you, subject to legal exceptions; correct inaccurate personal information; opt out of the sale or sharing of your personal information; limit the use of sensitive personal information where we use it beyond the purposes permitted by law; and not receive discriminatory treatment for exercising these rights. To exercise them, use the methods in Section 11; response times are stated there.
Do Not Sell or Share. To opt out of sharing, use the “Do Not Sell or Share My Personal Information” link on the Site, adjust your cookie settings, enable Global Privacy Control in your browser, or email privacy@activeprime.com. We honor opt-out requests for the browser or device from which they are made and, where you provide your contact details, for the personal information associated with them.
Retention. We keep each category of personal information for the periods described in Section 9.
Financial incentives. We do not offer financial incentives or price or service differences in exchange for personal information.
Shine the Light. California Civil Code Section 1798.83 lets California residents ask for information about disclosures of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes; if that changes, you may make a request using the contact details in Section 17.
13. Other U.S. state privacy rights
If you live in a U.S. state whose privacy law gives you these rights, you may have the rights to access, correct, delete and obtain a portable copy of your personal data, to opt out of targeted advertising, the sale of personal data and profiling in furtherance of decisions that produce legal or similarly significant effects, and to appeal our decision on a request. Most of these laws do not apply to information about individuals acting in a business or employment context, which is most of the information we hold, but we will honor requests from any resident who is entitled to make them. We do not process sensitive data as defined in those laws without the consent they require, and we do not sell personal data. To exercise these rights, use the methods in Section 11; we will respond within 45 days, extendable once by 45 days, and you may appeal as described there.
14. Additional information for the EEA, UK and Switzerland
Controller. ActivePrime, Inc. is the controller of Business Contact Data.
Legal bases. Section 3 sets out the legal basis for each purpose. Where we rely on legitimate interests, those interests are stated there; you may object at any time (Section 11). If you object to direct marketing, including related profiling, we will stop. For other processing we will stop unless we have compelling legitimate grounds that override your interests or need the data for legal claims. Where we rely on consent, you may withdraw it at any time.
Complaints. You have the right to lodge a complaint with your data protection supervisory authority. In the UK this is the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address your concerns first, so please contact us at privacy@activeprime.com.
Whether you must provide data. You are not required to provide personal information to us, but we may be unable to respond to you or enter into a contract without it.
15. Children
We do not knowingly collect personal information directly from children under 18 for our own purposes. If you believe that we have collected personal information directly from a child under 18, contact privacy@activeprime.com; we will investigate it and delete the information where the law requires.
16. Changes to this Policy
We review this Policy periodically and will update it to reflect changes in our practices, technology and the law. We will post the updated Policy on the Site with a new effective date. If a change materially affects how we use personal information we have already collected, we will notify you in advance by a notice on the Site and, where we have your email address, by email, and we will obtain your consent where the law requires it.
17. Contact us
Privacy questions and requests: privacy@activeprime.com or activeprime.com/privacy-request. Post:
ActivePrime, Inc.,
Attn: Privacy,
800 West El Camino Real,
Suite 180,
Mountain View, CA 94040, USA.
Telephone: +1-617-247-9908.