Privacy Policy

Version v1-2026-07-21 · Last updated 21 July 2026

Draft pending legal review — not yet finalized. This describes, accurately, what data Agentic Zero actually collects and why. Sections marked [PENDING] need confirmation from legal counsel (in particular, our EU representative/DPO details and the exact lawful basis citations) before this page is treated as our final, binding policy.

1. Who controls this data

Agentic Zero ([PENDING: legal entity name, registered address]) is the data controller for the account/contact information described below. For your own operational and business data processed while delivering the Service, Agentic Zero acts as a data processor on your behalf — that relationship is governed by a separate Data Processing Agreement (DPA), not by this page.

2. What we collect, and why

DataPurposeSource
Company name, sector, process descriptionGenerate your feasibility preview and tier classificationYou, via the AUDIT form
Contact name and emailSend your preview, respond to your inquiry, send account credentialsYou, via the AUDIT form or checkout
Payment confirmation (not the card itself)Activate your Essential subscriptionStripe, our payment processor
Portal login (email + password hash)Authenticate you to your own dashboardCreated automatically at onboarding
Operational data from your connected systems (e.g. SAP)Perform the certified business processYour own systems, per the DPA
Usage/audit logs of autonomous actionsGive you an auditable record of every autonomous decisionGenerated by the Service

3. Payment processing

Essential subscriptions are paid through Stripe. We never see, store, or transmit your card number — Stripe's own hosted checkout collects it directly. Stripe acts as an independent controller for payment data; see Stripe's privacy policy.

4. How long we keep it

Account and billing records are kept for as long as your account is active, plus the period required by tax/accounting law thereafter ([PENDING: confirm exact statutory retention period]). Operational data processed under a DPA is retained and deleted according to the terms of that specific agreement.

5. Who we share it with

6. Your rights

Subject to applicable law (including the GDPR, where it applies to you), you may request access to, correction of, or deletion of your personal data, and object to or restrict certain processing. To exercise any of these rights, contact alberto@agentic-zero.com. [PENDING: confirm designated DPO / EU representative contact, if legally required for our size/activity].

7. Security

We apply access controls, secrets management, and automated PII-detection review to how we handle data internally. If we become aware of a data incident affecting your personal data, we will assess and notify affected parties and any applicable authority as required by law.

8. Changes to this policy

We may update this policy as the Service evolves. Material changes will be reflected in the version and date at the top of this page.

9. Contact

Questions about this policy: alberto@agentic-zero.com.