Draft pending legal review — not yet finalized. This describes, accurately, what data Agentic Zero actually collects and why. Sections marked [PENDING] need confirmation from legal counsel (in particular, our EU representative/DPO details and the exact lawful basis citations) before this page is treated as our final, binding policy.
Agentic Zero ([PENDING: legal entity name, registered address]) is the data controller for the account/contact information described below. For your own operational and business data processed while delivering the Service, Agentic Zero acts as a data processor on your behalf — that relationship is governed by a separate Data Processing Agreement (DPA), not by this page.
| Data | Purpose | Source |
|---|---|---|
| Company name, sector, process description | Generate your feasibility preview and tier classification | You, via the AUDIT form |
| Contact name and email | Send your preview, respond to your inquiry, send account credentials | You, via the AUDIT form or checkout |
| Payment confirmation (not the card itself) | Activate your Essential subscription | Stripe, our payment processor |
| Portal login (email + password hash) | Authenticate you to your own dashboard | Created automatically at onboarding |
| Operational data from your connected systems (e.g. SAP) | Perform the certified business process | Your own systems, per the DPA |
| Usage/audit logs of autonomous actions | Give you an auditable record of every autonomous decision | Generated by the Service |
Essential subscriptions are paid through Stripe. We never see, store, or transmit your card number — Stripe's own hosted checkout collects it directly. Stripe acts as an independent controller for payment data; see Stripe's privacy policy.
Account and billing records are kept for as long as your account is active, plus the period required by tax/accounting law thereafter ([PENDING: confirm exact statutory retention period]). Operational data processed under a DPA is retained and deleted according to the terms of that specific agreement.
Subject to applicable law (including the GDPR, where it applies to you), you may request access to, correction of, or deletion of your personal data, and object to or restrict certain processing. To exercise any of these rights, contact alberto@agentic-zero.com. [PENDING: confirm designated DPO / EU representative contact, if legally required for our size/activity].
We apply access controls, secrets management, and automated PII-detection review to how we handle data internally. If we become aware of a data incident affecting your personal data, we will assess and notify affected parties and any applicable authority as required by law.
We may update this policy as the Service evolves. Material changes will be reflected in the version and date at the top of this page.
Questions about this policy: alberto@agentic-zero.com.