AgentIO

Data Processing Agreement

DRAFT. This text has been written but has not yet been reviewed by a lawyer. The same banner is shown inside the app. It will be removed once legal review is complete.

This agreement applies when you connect your own server, accounts or data to Agent IO.

1. PARTIES AND ROLES

You (or the organisation you represent) are the DATA CONTROLLER: you decide which data is processed. Agent IO is the DATA PROCESSOR: it acts only on your instructions and within the scope you set. This split falls under GDPR art. 4(7)-(8) and 28, Turkish KVKK art. 3 and 12, UK GDPR and LGPD art. 5.

2. NO STORAGE

Content read from the servers you connect is processed on your device and is NOT stored on our servers. We keep no records, write no content to our logs, and use nothing for model training. Our logs hold technical data only: status code, duration, token count, tool name.

3. EXCEPTION — SERVER-SIDE EXECUTION

If you SEPARATELY sign the "keep running while the app is closed" option, work runs on our servers. Because the model call happens there, the content is visible in memory while the job runs; but what is written to our database is ENCRYPTED (AES-256-GCM, key held separately) and deleted within 24 hours. This option is OFF by default and requires its own consent.

4. SUB-PROCESSORS

The AI models that produce answers are supplied by third parties, and it is unavoidable that they see what is sent:

We have not yet secured zero-data-retention terms with these providers. Our own servers keep no copy of your content; what a provider retains is governed by that provider's own policy. If the sub-processor list changes you are notified in the app; your right to object is reserved (GDPR art. 28(2)).

5. INTERNATIONAL TRANSFERS

Our infrastructure is hosted in the European Union (europe-west1). Where a transfer to a model provider requires it, we use appropriate transfer safeguards; the applicable safeguard is identified for each provider (GDPR art. 44-49, KVKK art. 9). Where local law imposes localisation or additional requirements (e.g. China PIPL, Russia 152-FZ, India DPDPA), those obligations are assessed separately; not storing data does not by itself remove them.

6. SECURITY MEASURES

Your credentials are kept in the Keychain on your device and are not sent to our servers. All connections are encrypted with TLS. Only publicly reachable addresses are accepted; private network addresses are refused for security. Tool permissions are OFF by default (GDPR art. 32).

7. YOUR OBLIGATIONS

You confirm that you are legally entitled to process the data you connect and that you have obtained the necessary notices and consents. Special category data (health, biometrics, beliefs, political opinion, sex life) and payment card data carry additional obligations that are yours; consult your own legal adviser before connecting such data.

8. DATA SUBJECT REQUESTS

Meeting access, rectification, erasure, portability and objection requests is yours as the controller. Because we store nothing, we hold no copy to delete; we provide reasonable technical support on request (GDPR art. 15-22, KVKK art. 11, CCPA/CPRA §1798.100 et seq.).

9. BREACH NOTIFICATION

If a security breach is detected in our infrastructure you are informed without undue delay and within 72 hours at the latest (GDPR art. 33).

10. TERMINATION

When you remove a connection your credentials are deleted from your device. If server-side execution is on, pending records are deleted automatically within 24 hours.