Legal

Privacy Policy

Last updated: July 5, 2026

This Privacy Policy explains how AgentGlob (“we”, “our”, or “us”) collects, uses, shares, and protects personal data when you visit our website or use the AgentGlob platform (the “Service”), and describes the rights you have over your data. It is designed to meet the requirements of the EU General Data Protection Regulation (GDPR) and the UK GDPR, and it applies to everyone who uses the Service, regardless of location.

1. Who We Are

For personal data collected through our marketing website and our account and billing systems, AgentGlob is the “controller” under the GDPR — meaning we determine why and how that data is processed. For personal data processed inside your Agent Workspace on your instructions, we act as a “processor” and you are the controller (see Section 14). You can reach us about privacy matters through our contact page.

2. Scope

This Policy covers the AgentGlob website, dashboard, and platform. It does not cover third-party websites, Channels, or services that you connect to or that link to us, which have their own privacy policies. We encourage you to review those separately.

3. Data We Collect

We collect the following categories of personal data:

  • Account data — name, email address, organization, password or authentication identifiers, and profile details you provide.
  • Billing data — billing name, address, tax identifiers, and payment details. Card details are collected and processed directly by our payment processor, Stripe; we do not store full card numbers.
  • Workspace & configuration data — Agent configurations, connected Channels, and tool settings you create.
  • Usage & metering data — records of Agent activity, requests, and resource consumption used to operate, secure, and bill the Service.
  • Support & communications data — messages you send us via the contact form, email, or support channels, and our responses.
  • Technical & device data — IP address, browser and device type, operating system, referring pages, timestamps, and log and diagnostic data collected automatically, including through cookies (Section 7).
  • Customer Data — content your Agents process on your behalf, which may contain personal data of third parties for which you are the controller (Section 14).

We collect this data directly from you, automatically as you use the Service, and — for billing — from our payment processor. We do not intentionally collect special categories of data (such as health, biometric, or political data); please do not submit such data except where strictly necessary and lawful.

4. How & Why We Use Data

We use personal data to:

  • Create, operate, and maintain your account and Workspace;
  • Provide, personalize, and improve the Service and develop new features;
  • Meter usage, process payments, issue invoices, and manage billing;
  • Secure the Service, prevent fraud and abuse, and enforce our Terms;
  • Provide customer support and respond to your requests;
  • Send service, security, and billing communications, and — where permitted — product updates;
  • Produce aggregated, de-identified analytics about how the Service is used; and
  • Comply with legal obligations and establish, exercise, or defend legal claims.

We do not sell your personal data, and we do not use Customer Data to train AI models without your explicit consent.

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract — to create your account, provide the Service, and process payments.
  • Legitimate interests — to secure and improve the Service, prevent fraud and abuse, and communicate about the Service, balanced against your rights and interests.
  • Legal obligation — to keep tax and accounting records and to respond to lawful requests.
  • Consent — for non-essential cookies and certain marketing communications, where required. You may withdraw consent at any time without affecting prior processing.

6. AI & Model Providers

To power Agents, the Service sends prompts and relevant context to AI model providers that you or we configure. Those providers process the data to return output and act as our sub-processors or, where you select them directly, as your own providers. We take steps to use providers that offer appropriate confidentiality and data-handling commitments, and we do not permit Customer Data to be used to train third-party models without your consent where we control that relationship. You are responsible for the data you or your Agents send to any provider you configure.

7. Cookies & Tracking

We use cookies and similar technologies that are strictly necessary to operate the website, authenticate you, and remember your preferences. Where applicable, we also use analytics cookies to understand site usage. Where the law requires, we ask for your consent before setting non-essential cookies, and you can withdraw it at any time. You can also control cookies through your browser settings, though disabling essential cookies may affect how the Service works. We honor recognized browser privacy signals where legally required.

8. Workspace Data Isolation

Each Workspace operates in a logically isolated environment. Data within a Workspace is not accessible to other Workspace operators or tenants. AgentGlob personnel access Workspace data only where necessary to provide support you request, to maintain security and integrity, or to comply with law, and subject to confidentiality obligations.

9. Sharing & Sub-processors

We share personal data only as needed, with the following categories of recipients:

  • Cloud & hosting providers (e.g., Google Cloud) that store and run the Service;
  • Payment processing (Stripe) to handle billing and payments;
  • AI model & Channel providers you configure your Agents to use, to operate those integrations;
  • Communications providers used to send account, billing, and contact-form emails;
  • Professional advisors and authorities where required by law or to establish, exercise, or defend legal claims; and
  • Successors in the event of a merger, acquisition, or sale of assets, subject to this Policy.

We require sub-processors to protect personal data under terms consistent with this Policy and applicable law. A current list of sub-processors is available on request via the contact page.

10. International Transfers

Some of our providers operate outside the European Economic Area. Where we transfer personal data internationally, we implement appropriate safeguards under the GDPR — such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or transfers to countries covered by an adequacy decision. You can request more information about these safeguards via the contact page.

11. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy:

  • Account and Workspace data — for the life of your account and a reasonable period after closure;
  • Billing and tax records — for the period required by applicable tax and accounting law (often 6–10 years);
  • Usage and log data — for a limited period for security, troubleshooting, and analytics; and
  • Support communications — for as long as needed to resolve your matter and maintain records.

When data is no longer needed, we delete or anonymize it. Customer Data is handled according to your instructions and our Terms.

12. Security

We implement technical and organizational measures designed to protect personal data, including encryption in transit, access controls and least-privilege practices, Workspace isolation, and monitoring. No system is perfectly secure; we cannot guarantee absolute security, but we work to protect your data and to notify you and regulators of qualifying breaches as required by law.

13. Your Rights

Subject to applicable law, and in particular if you are in the EEA or UK, you have the right to:

  • Access the personal data we hold about you and obtain a copy;
  • Rectify inaccurate or incomplete data;
  • Eraseyour data (“right to be forgotten”), subject to legal exceptions;
  • Restrict or object to certain processing, including processing based on legitimate interests and direct marketing;
  • Data portability — receive your data in a structured, commonly used, machine-readable format;
  • Withdraw consent at any time where processing is based on consent; and
  • Lodge a complaint with a supervisory authority (Section 18).

To exercise your rights, contact us through the contact page. We may need to verify your identity, and we will respond within the timeframe required by law (generally within one month). These rights are free to exercise, though we may charge a reasonable fee or decline manifestly unfounded or excessive requests as permitted by law. If your data is processed within a Workspace where another organization is the controller, please direct your request to that organization.

14. Controller vs. Processor Roles

When you use the Service as a Workspace operator, you decide what data your Agents process (for example, conversations with your customers, or records your Agents access). In that context you are the controller and AgentGlob is your processor, acting on your documented instructions. You are responsible for having a lawful basis for that processing and for providing any required notices to, and obtaining any required consents from, the individuals whose data flows through your Workspace. Where you require a Data Processing Agreement, we can make one available.

15. Automated Decision-Making

We do not use your personal data to make decisions that produce legal or similarly significant effects about you solely by automated means without a lawful basis and appropriate safeguards. Agents you configure may automate tasks within your Workspace; you are responsible for applying appropriate human oversight to those Agents as described in our Terms of Service.

16. Children’s Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.

17. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, provide reasonable notice (for example, by email or in-app notice). Your continued use of the Service after the effective date constitutes acknowledgment of the updated Policy.

18. Contact & Complaints

For privacy inquiries or to exercise your rights, contact us through the contact page. If you are in the EEA or UK and believe we have not resolved your concern, you have the right to lodge a complaint with your local data protection supervisory authority. We would appreciate the chance to address your concern first.