Privacy Policy
Last updated: April 2026
Agenturo is operated by its founder. For privacy matters, contact privacy@agenturo.app.
Agenturo is GDPR-compliant. We process personal data lawfully under Article 6 GDPR, honour all data subject rights, maintain a public sub-processor list, and act as your data processor for lead capture under a formal Data Processing Agreement.
1. Data Collected
Account data: email, name. Agent config: content you provide during setup. Conversations: messages (30-day retention). Leads: name, email, phone, company — encrypted at rest (AES-256), 90-day retention. IP addresses: hashed with SHA-256, never stored in plain text. Analytics: anonymised, no PII.
2. How We Use Your Data
- Account data: to provide and manage your account, send service communications.
- Agent configuration: to build, personalise, and serve your AI agent.
- Conversations: to deliver AI responses and maintain conversation context.
- Leads: to provide lead capture functionality to agent owners.
- IP addresses (hashed): for rate limiting, abuse prevention, and security.
- Analytics (anonymised): to understand usage patterns and improve the Service.
3. Legal Basis
Account: contract performance (Art. 6(1)(b)). Conversations: legitimate interest (Art. 6(1)(f)). Leads: explicit consent (Art. 6(1)(a)). Analytics: legitimate interest.
4. Third Parties
Creem (payments/MoR), OpenRouter (LLM inference), Vercel (hosting), Resend (email), Neon (database). Calendar booking links redirect to third-party scheduling services. See subprocessors.
5. International Data Transfers
Your data may be transferred to and processed in the United States, where our primary infrastructure providers (Vercel, Neon, OpenRouter, Resend, Sentry) operate. Our payment processor Creem operates within the EU. For transfers from the EEA/UK to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46 GDPR. See our subprocessors list for each provider's transfer mechanism.
6. Your Rights (GDPR — EEA / UK)
Under GDPR and applicable data protection law, you have the following rights:
- Access: Request a copy of your personal data — email privacy@agenturo.app.
- Rectification: Correct inaccurate data — email privacy@agenturo.app or update in your admin panel.
- Erasure: Delete your agent from the admin panel — permanently and immediately removes all associated data (conversations, messages, leads, soul versions, analytics, token records). To close your login account, email privacy@agenturo.app.
- Data portability: Your agent soul is available as plain text in the soul editor at any time. For other data export requests, email privacy@agenturo.app.
- Restriction & objection: Email privacy@agenturo.app.
- Withdraw consent: For email marketing — use the unsubscribe link in any marketing email. For lead data as a visitor — contact the agent owner whose page you used, or email privacy@agenturo.app. For account data — email privacy@agenturo.app. Withdrawal does not affect lawfulness of prior processing.
- Lodge a complaint: Contact your local data protection authority (e.g., ICO for UK, your national DPA for EEA).
We respond to all requests within 30 days. We may request identity verification before processing your request.
6A. Your Rights (CCPA / CPRA — California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you the following rights:
- Right to Know: What categories of personal information we collect, the sources, the business purpose, and the categories of third parties we share it with.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions.
- Right to Correct: Request correction of inaccurate personal information we hold about you.
- Right to Opt-Out of Sale or Sharing: We do not sell or share personal information for monetary or other consideration. No opt-out link is required, but you may confirm this by emailing privacy@agenturo.app.
- Right to Limit Use of Sensitive Personal Information: Limit use of sensitive PI to what is necessary to perform the service.
- Right to Non-Discrimination: We will not treat you differently for exercising any of these rights.
Categories of personal information collected in the past 12 months:
- Identifiers: Email address, name, hashed IP address — collected for account management and security. Not sold.
- Internet / electronic activity: Conversation messages, session data, error logs — collected for service delivery and debugging. Not sold.
- Commercial information: Subscription plan, payment status — collected for billing. Not sold.
- Inferences: Agent configuration and usage patterns — collected to personalise and serve your agent. Not sold.
To exercise CCPA rights: email privacy@agenturo.app. We respond within 45 days (extendable by a further 45 days with notice for complex requests). You may designate an authorised agent to submit requests on your behalf with written verification.
7. Automated Decision-Making
Agenturo uses AI models to generate conversational responses. This processing is core to the Service you have requested (Art. 22(2)(a) GDPR). No decisions with legal or similarly significant effects are made solely by automated means. AI-generated responses may be inaccurate and should not be relied upon as professional advice.
8. Security
Encryption at rest (AES-256 for leads), encryption in transit (TLS 1.3), hashed IPs (SHA-256), parameterised queries, CSP headers, HSTS, rate limiting, and real-time error monitoring (Sentry).
Breach notification. In the event of a personal data breach likely to result in high risk to your rights and freedoms, we will notify affected users without undue delay by email, and report to the relevant supervisory authority within 72 hours, as required by GDPR Art. 33–34.
9. Cookies
We use two cookies only. No tracking cookies. No advertising cookies. No third-party cookies.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
| next-auth.session-token | Authentication session (HttpOnly, Secure) | Essential | 30 days |
| theme | Light/dark theme preference | Functional | Persistent |
Essential cookies are required for the Service to function and cannot be disabled. The theme preference cookie enables a personalised interface and contains no personal data.
10. Data Retention
Conversations: 30 days. Leads: 90 days (extendable to 1 year with your consent). Account data: subscription period + 90 days. Anonymised aggregates: indefinite. Deleting your agent immediately removes all associated data regardless of these windows.
11. Children's Privacy
Agenturo is not directed at children under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact privacy@agenturo.app and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email at least 14 days before they take effect. The "Last updated" date at the top reflects the most recent revision.
Contact
privacy@agenturo.app · support@agenturo.app