Privacy Policy
Last updated 25 September 2026
1. Who we are
Agentra provides an AI Business Agent platform for businesses. This policy explains what personal data we handle, why, and what rights you have. It covers both visitors to this website and customers using the platform.
2. Two different roles
The distinction matters for who is responsible for what:
- Where we are the controller. For your own account and business data — the email you sign up with, your workspace settings, your billing records, and how you use the product.
- Where we are the processor. For the personal data of your customers that flows through your assistant — call transcripts, chat messages, contact details given while booking. You decide what is collected and why; we process it on your instructions in order to run the Service.
If you are one of our customers' customers and want your data removed, contact that business directly — they control it, and we act on their instructions.
3. What we collect
- Account data: email address, name, business name, and authentication credentials (passwords are stored only as salted hashes).
- Workspace content: the documents you upload, your assistant configuration, and the derived search index (embeddings) generated from your documents.
- Conversation data: messages, call transcripts, and metadata such as channel, timestamps and appointment details.
- Billing data: plan, subscription status and usage counts. Card details are handled by our payment processor and are not stored on our systems.
- Technical data: IP address, browser and device information, and log data generated when you use the Service.
4. Why we process it
To provide and operate the Service; to authenticate you and secure your workspace; to generate assistant replies grounded in your documents; to bill you and meter usage against your plan; to provide support; to detect abuse and protect the Service; and to comply with legal obligations. Where we rely on legitimate interests, we have considered the impact on you and you may object.
5. AI model providers
Generating a reply requires sending conversation content and relevant passages from your documents to a third-party AI model provider. Generating the search index requires sending document text to an embeddings provider. We select providers that contractually commit not to use customer content to train their general models, and we pass your content to them only to produce output for you.
6. Sub-processors
We use third parties to run the Service, including cloud hosting and database infrastructure, AI model and embeddings providers, telephony and messaging providers, payment processing, email delivery, and error monitoring. Each is bound by a data-processing agreement. A current list is available on request.
7. What we do not do
- We do not sell personal data.
- We do not use one customer's workspace content to improve another customer's assistant.
- We do not use your content or your customers' conversations to train our own general-purpose models.
8. Retention
Account and workspace data is retained for as long as your account is active. After you close your account, data is retained for a limited wind-down period so it can be exported or recovered, and is then deleted or anonymised. Billing records are kept for the period required by tax and accounting law. Deleting a document from your knowledge base also removes the passages and embeddings derived from it.
You can request deletion sooner, subject to legal retention requirements.
9. Security
Data is encrypted in transit. Access to production systems is restricted to personnel who need it, and each workspace is isolated so that queries are scoped to the owning business. No system is perfectly secure, but we will notify you and any relevant regulator of a qualifying personal-data breach as required by law.
10. International transfers
Our providers may process data outside your country. Where that involves a transfer out of the UK or EEA, it is made under an appropriate safeguard such as an adequacy decision or standard contractual clauses.
11. Your rights
Depending on where you are, you may have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent where processing is based on consent. You also have the right to complain to your data-protection authority. To exercise any of these, use our contact page.
12. Cookies
We use cookies that are necessary for the Service to function — keeping you signed in, maintaining your session, and protecting forms against cross-site request forgery. We also store your light/dark theme preference locally in your browser. Necessary cookies cannot be switched off without breaking sign-in.
13. Children
The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from children.
14. Changes
We may update this policy. Material changes will be communicated by email or an in-product notice, and the "last updated" date above will change.
15. Contact
Privacy questions and rights requests can be sent through our contact page. See also our Terms of Service.