Privacy Policy
This policy explains what data Agata handles, why it is used, who it may be shared with, and how you can exercise your rights. It applies to Agata's website, accounts, and workspaces.1. Controller and scope
The controller is the individual or legal entity identified above. This policy covers the public website, account creation, and the use of Agata workspaces and applications.
When a customer organisation determines what information its team adds to Agata, that organisation may act as controller and Agata as processor for that data. The applicable terms will be set out in a data processing agreement where required.
2. Data we process
The specific information depends on the features you use. Agata aims to limit collection to what is needed to provide and protect the service.
- Account and identity: name, email address, avatar, language, preferences, and authentication data. Passwords are stored as hashes, not readable text.
- Workspace and content: tasks, projects, notes, files, library items, finances, goals, collaborative activity, and any content you choose to enter.
- Optional features: health, nutrition, or habit information you enter voluntarily. This may be special-category data and requires additional controls before commercial use.
- Agent and AI: messages, selected context, responses, tool actions, technical identifiers, and the model used.
- Billing: plan, subscription status, country, Stripe identifiers, invoices, and credit usage. Agata does not store your full card number.
- Technical data: IP address where processed by the infrastructure, device, browser, security logs, errors, access times, and aggregated usage metrics.
3. Purposes and legal bases
We process data to create and maintain accounts, provide requested features, synchronise workspaces, process payments, offer support, prevent abuse, maintain security, and comply with legal obligations.
The legal bases may include performance of a contract or pre-contractual steps, compliance with legal obligations, legitimate interests in protecting and improving the service, and your consent where appropriate. You may withdraw consent without affecting earlier processing.
4. Artificial intelligence
When you use Agent or a generative feature, Agata sends the message, instructions, and necessary context to the AI infrastructure to produce the result. The context may include workspace content where the feature requires it.
AI responses can be wrong. Do not enter secrets, third-party data, or special-category data unless necessary. Agata will document active providers and configurations before commercial launch and restrict their use of content to providing and securing the service.
5. Providers and recipients
Agata uses specialist providers to host the application, store data, authenticate users, send email, process payments, meter usage, and run AI features. The current architecture includes Vercel, PostgreSQL infrastructure, Vercel Blob, Upstash, Resend, Google, Stripe, Metronome, and model providers accessed through the AI infrastructure.
These providers should only process the data needed for their role and under their contracts. We may also disclose information where required by law, to protect rights, or as part of a corporate transaction subject to appropriate safeguards.
6. International transfers
Some providers may process data outside the European Economic Area. Where applicable, Agata will rely on adequacy decisions, standard contractual clauses, or other safeguards recognised by law.
Before commercial launch, the inventory of locations, subprocessors, and transfer mechanisms for every active provider will be completed.
7. Retention and deletion
Account and workspace data is kept while the account or workspace is active. When deletion is requested, it will be removed or anonymised from active systems unless a legal obligation, pending claim, or limited technical backup period applies.
Billing records are retained for applicable statutory periods. Security and operational records are kept for a period proportionate to their purpose. Agata will define and publish specific operational periods before accepting payments.
8. Your rights
You may request access, correction, deletion, objection, restriction, and portability, and you may withdraw consent. We may need to verify your identity before responding.
If you believe processing breaches the law, you may complain to the Spanish Data Protection Agency at aepd.es. We welcome the opportunity to review your request first.
9. Security, children, and changes
Agata applies technical and organisational controls proportionate to the risk, including workspace permissions, authentication, encryption in transit, operational logging, and secret separation. No system can guarantee absolute security.
The service is not directed to anyone under 18. This policy may change as the product, providers, or law evolves. Material changes will be communicated by reasonable means and a new effective date will be shown.