This notice covers the personal data Cloudscockpit.io collects through this website — specifically the cohort application form on the Women SME AI Labs page and the Connect page. It describes exactly what is collected, why, where it lives, how long we keep it, and how you get it back, corrected, or deleted.
The data controller for the personal data described in this notice is CloudsCockpit Inc., a Delaware C Corporation, registered at 20816 Top Ridge Drive, Boyds, MD 20841, USA.
Questions about this notice, or about data we hold on you, go to legal@actionboard.ai. You can also reach us through the Connect page.
The cohort application form asks for the following. Only name, email and your consent are required; everything else is optional and the form will submit without it.
| Field | Required | Why we ask |
|---|---|---|
| Name | Required | To address you, and to match you to a pod seat. |
| Required | To send the confirmation email and to reply to your application. It is the only channel we use. | |
| Company (business name) | Optional | To understand the business the pod would serve. |
| Role | Optional | To judge whether you can set the pod's goal and act on its output. |
| Sector | Optional | To match solo and pair applicants into a pod with enough task overlap. |
| Stage (applying as) | Optional | To know whether you arrive as a formed group of five, a pair, or alone. |
| Notes (weekly tasks and goal) | Optional | Free text you write. It becomes the basis of your first skill files if you join. |
| Consent | Required | Recorded, with a timestamp, as the record of your permission. |
We do not ask for customer data, financial data, health data, government identifiers, or any other special-category data. Please do not put any of that in the free-text notes field. If you do send us special-category data unprompted, we will delete it.
We do not sell your data. We do not share it with advertisers. There is no advertising or analytics tracker embedded in the application form.
The site is served from Cloudflare's edge network. In the course of serving and protecting the site, Cloudflare processes standard request metadata — IP address, user agent, timestamp, requested URL — for security, abuse prevention and rate limiting. The application endpoint is rate limited using this metadata. [REVIEW: confirm the exact Cloudflare log retention window in force on the account, and whether any analytics product is enabled]
This site loads fonts from Google Fonts, and the home page loads JavaScript libraries from the unpkg CDN. Your browser's request to those third parties exposes your IP address to them. [REVIEW: decide whether to self-host fonts and libraries to remove this third-party exposure]
One purpose: to process your cohort application. Concretely, that means reading your submission, deciding whether your tasks have enough overlap to form a pod, matching you with other applicants if you applied solo or as a pair, and writing back to you with the outcome.
We also send you a confirmation email immediately on submission, containing your application reference so you can quote it back to us.
We rely on your consent, which you give by ticking the box on the form, and on taking steps at your request prior to entering into a contract for the application handling itself. Rate limiting and abuse prevention rely on our legitimate interest in keeping the service available.
We operate from the United States and offer the cohort to residents of the United States, Bangladesh, Saudi Arabia and the Netherlands. We have no establishment in the EU or the UK, so where the EU or UK GDPR reaches us it does so under Article 3(2) — because we offer services to data subjects in those territories — and not under Article 3(1). The regimes in scope are therefore the EU and UK GDPR (via Article 3(2)), US state privacy laws including California’s CCPA/CPRA, the Saudi Personal Data Protection Law, and applicable law in Bangladesh. [REVIEW: counsel to confirm the lawful basis relied on under each of these four regimes — naming the regimes in scope is not the same as confirming the basis under each]
Applications are read by a person. We do not make an accept or reject decision about you by automated means, and we do not profile you.
Submissions are sent over HTTPS to our application endpoint at agent.actionsboard.ai, which runs on Cloudflare Workers, and are stored in Cloudflare R2 object storage. Requests are served and processed at Cloudflare edge locations in the EU and the US, so your data may be processed in either region and transferred between them.
For transfers out of the UK/EEA we rely on [REVIEW: confirm the transfer mechanism actually in place with Cloudflare — Standard Contractual Clauses, UK IDTA, or adequacy — and reference the signed Cloudflare DPA].
That is the complete list. [REVIEW: if a CRM, spreadsheet, or scheduling tool is later used to triage applications, it must be added here as a processor]
Data is encrypted in transit (TLS) and at rest by Cloudflare R2. The site sends X-Frame-Options, X-Content-Type-Options, Referrer-Policy and a restrictive Permissions-Policy. No API keys or credentials are present in any page you load. [REVIEW: document who holds access credentials to the R2 bucket and how that access is reviewed]
You can ask us to delete your application earlier at any time. See the next section.
You can ask us to do any of the following, and we will act on it:
Email legal@actionboard.ai with the word PRIVACY in the subject line and, if you have it, your application reference (the SME-… code from your confirmation email) — it lets us find your record without asking you for further identifying details. If you no longer have the reference, the email address you applied with is enough. You can also reach us through the Connect page.
Where the EU or UK GDPR applies, we respond within one month. Where California’s CCPA/CPRA applies, we respond within 45 days. There is no charge.
If you are unhappy with how we handled your data, tell us first — we would rather fix it. You also have the right to complain to a supervisory authority. Because CloudsCockpit Inc. has no establishment in the EU, the GDPR one-stop-shop mechanism does not apply to us and there is no single lead supervisory authority — you may lodge a complaint with the data protection authority of the country where you live.
If we change what we collect, why, or who processes it, we will update this page and change the date at the top. If the change is material and we hold your data, we will email you.
The factual sections of this notice — who we are, what we collect, why, where it is stored, who processes it, how long we keep it and how to reach us — are final. The items still flagged for review above are either with counsel or awaiting an operational confirmation. See also the Terms.