Skip to content
Agentify

Privacy Policy

This Privacy Policy explains how Houdart CommV, a limited partnership registered at Kerkstraat 20, 9900 Eeklo, Belgium, VAT/enterprise number BE0782.382.501 ("Agentify", "we", "us"), collects and uses personal data when you visit agentify.so (the "Website"), use the Agentify dashboard and API that we operate (the "Hosted Service"), run Agentify in your own infrastructure (a "Self-Hosted Deployment"), contact us, or purchase a subscription or license.

1. Our role: controller or processor

Data we collect directly from you. For account, billing, contact, and license data, we are the data controller.

Content you put into the Hosted Service. Agent configurations, OpenAPI specifications, service credentials, model-provider credentials, and the conversations your agents have with their end users ("Customer Content") are processed by us on your behalf and on your instructions. For that data, you are the controller and we are your processor. If you need a data processing agreement, contact us.

Self-Hosted Deployments. When you run Agentify in your own infrastructure, we have no access to your deployment or the data in it, and we are neither controller nor processor for it. There are two exceptions: the license issuance data described in section 2, and the optional message monitoring feature described in section 3, which sends conversation data to us when you turn it on.

2. Data we collect directly from you

Website visitors. The Website does not use analytics or tracking, and does not set cookies. Our hosting provider may keep standard server logs (such as IP address and requested page) for a short period for security and operational purposes.

Accounts on the Hosted Service. When you create an account, we collect your first and last name, email address, password (stored hashed), and optionally a profile image. If your organization signs in with Microsoft single sign-on, we receive the identifiers and profile details Microsoft provides for your account. For each session we record the IP address and browser user agent, together with your role and permissions in the dashboard.

Prospective customers and support requests. If you contact us (for example, via contact@agentify.so or the email links on our pricing page), we collect the information you provide, such as your name, email address, company name, and the contents of your message.

Customers, subscriptions, and licenses. When you subscribe or purchase a license, we collect the information necessary to provide, invoice, and administer it, such as your name, company name, billing address, email address, and payment details, and we keep a record of each license we issue (the licensee's name, email address, entitlements, and contract reference). Once available, payments will be processed by our payments provider, Polar, which will collect and process payment information on our behalf under its own terms.

3. Customer Content we process on your behalf

On the Hosted Service we store what you configure and what your agents produce: agent settings and prompts, OpenAPI specifications, credentials and API keys for the services and model providers your agents use (encrypted at rest), conversation threads and messages, an identifier for each end user talking to your agent, feedback on responses, and usage statistics (token counts per agent and per end user).

Message monitoring. In both the Hosted Service and Self-Hosted Deployments, message monitoring is an opt-in feature that sends every conversation thread and message of an agent to our event collector at collect.agentify.so, so you can review them in the dashboard. We retain monitored messages for 30 days. Enabling it requires an explicit confirmation in the dashboard, and you can point the feature at your own event collector instead, in which case no conversation data reaches us.

Model providers. Your agents send prompts and conversation content to the model provider configured for them. If you configure your own provider and credentials, that data goes from your agent to that provider under your own account and terms, and we are not a party to that processing. On the Hosted Service, every new agent starts with a default model that runs on our own OpenAI or Microsoft Azure OpenAI account, and platform features such as classification and model routing use that default model as well. Until you replace the default model, conversation content for those agents therefore passes to that provider under our account, acting as our sub-processor.

End users of your agents. If you are an end user of an agent built with Agentify, the organization that operates that agent is responsible for how your data is used. Please contact them first; we will assist them in responding to your request.

4. Why we process this data, and our legal basis

  • Providing the Hosted Service and the message monitoring feature: performance of a contract with you, and processing on your instructions as your processor.
  • Operating and securing the Website and the Hosted Service: legitimate interest in keeping our systems secure and available.
  • Responding to inquiries and providing support: legitimate interest, or steps taken at your request prior to entering into a contract.
  • Subscriptions, license issuance, invoicing, and billing: performance of a contract, and compliance with legal tax and accounting obligations.

5. Who we share data with

We share personal data with the following recipients, each acting as our processor or sub-processor, or as an independent controller for their own purposes:

  • Hetzner Online GmbH (Germany) provides the servers on which the Hosted Service and our event collector run.
  • OpenAI or Microsoft Azure OpenAI provide the default model on the Hosted Service, as described in section 3.
  • Microsoft processes your sign-in when your organization uses Microsoft single sign-on.
  • Polar will process payments once enabled for Agentify subscriptions.
  • Service providers who support our hosting, email, and business operations, bound by contract to protect your data.

We do not sell personal data. Model providers you configure yourself, and any services your agents call through your OpenAPI specifications, receive data under your own agreements with them.

6. International transfers

The Hosted Service and our event collector are hosted in the European Union. Some of the providers listed above may process data outside the European Economic Area. Where this is the case, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, to ensure your data remains protected.

7. Data retention

  • Account data and Customer Content: for as long as your account or subscription is active. After termination, or on your request, we delete it within 30 days, except where we must keep it to comply with a legal obligation.
  • Monitored messages: 30 days from the moment we receive them.
  • Usage statistics: for the duration of your subscription, for billing and entitlement enforcement.
  • Contact and support data: for as long as needed to resolve your inquiry and for a reasonable period afterward.
  • Billing and license-issuance data: for as long as required by applicable tax and accounting law.

8. Security

We apply technical and organizational measures appropriate to the data we process: passwords are stored hashed, credentials and API keys are encrypted at rest, access to production systems is restricted to authorized personnel, and servers are hardened and kept up to date. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your rights

If you are located in the European Economic Area, you have the right to: access the personal data we hold about you; request rectification or erasure; restrict or object to processing; request data portability; and withdraw consent at any time where processing is based on consent. To exercise any of these rights, contact us at contact@agentify.so. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), or with the supervisory authority in your own EU member state.

10. Children's privacy

The Website and the Hosted Service are not directed at individuals under the age of 16, and we do not knowingly collect personal data from them.

11. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "last updated" date below and, where appropriate, notify you directly.

12. Contact

For questions about this Privacy Policy or to exercise your rights, contact us at contact@agentify.so, or by post to Houdart CommV, Kerkstraat 20, 9900 Eeklo, Belgium.