1. Data controller
The controller of personal data processed via agentsgo.eu and agent.agentsgo.eu is KODUARVE OÜ, registry code 16936830, registered in the Republic of Estonia (European Union). You can contact us at timofei@koduarve.ee for any privacy-related question, data subject request, or to lodge a complaint about how we handle your data.
2. Scope
This Policy applies to all services provided under the AgentGo Cloud brand, including:
• agentsgo.eu — public website, account dashboard, billing • agent.agentsgo.eu — AgentGo agent management UI (multi-tenant SaaS) • voice.agentsgo.eu — voice-call infrastructure (Telnyx webhooks + media) • AI agents you create and operate inside our infrastructure, including any social-media integrations (Instagram, Facebook Page, Telegram, VKontakte) you choose to connect.
It does NOT apply to third-party services to which you link an account (Facebook, Instagram, Telegram, VKontakte, Telnyx, Stripe, etc.); those operate under their own privacy policies.
3. Data we collect
Account data: email address, optional display name, hashed password (bcrypt), language preference, theme preference, tenant identifiers.
Usage data: API requests, agent configurations, dashboard events, IP address, browser User-Agent, timestamps. Used for security and to debug incidents.
Voice data: phone numbers involved in calls (from / to), call direction, call duration, call recordings (μ-law WAV when retention is enabled), text transcripts, end reason, billing rate snapshots, agent identifiers.
Contact-book data: names, phone numbers (E.164), notes, owner agent IDs that you or your agent enters or imports via vCard (.vcf).
Social-media account data — when you connect a Facebook Page, Instagram Business account, Telegram channel, or VKontakte account, we receive and store: • Platform-side account/page ID and username • Long-lived OAuth access tokens (encrypted at rest) • Display name and basic profile metadata returned by the platform • Scopes that you granted us • For Telegram channels: the bot API token (stored encrypted) and the channel ID • Inbound webhook events delivered by the platform (DMs, comments, mentions, reactions) — only events directed at the connected account • Outbound posts your agents publish, including caption, media URL, scheduled time, and the resulting platform post ID
Knowledge-graph data: entities and relationships derived from your agent's conversations (people, places, events, tasks) — used to give the agent persistent memory.
Billing data: top-up amount, payment method (card last 4 / SEPA reference / 'manual' adjustment / 'voice' / 'subscription' / 'number'), transaction status, wallet balance, invoice metadata.
We do NOT collect: full payment card numbers (Stripe handles them), biometric voice templates, location data beyond country implied by phone country code or by your IP, browsing history outside our domains, content of social-media accounts you have NOT connected.
4. How Meta-platform data is handled
When you click 'Connect Instagram' or 'Connect Facebook Page' you grant our Meta App a long-lived access token. This token is stored in our database, encrypted at rest, and is used ONLY to:
• Read the list of Facebook Pages you administer and the Instagram Business accounts linked to those Pages • Read inbound DMs, comments, and mentions delivered to those accounts via Meta's webhook subscription • Publish posts, replies, comments, and DMs that you or your authorised agent explicitly trigger • Read media metadata that you uploaded as part of a post you initiated
We DO NOT use Meta data for ad targeting, profile enrichment, training generative models, or to build a profile about you beyond what is necessary to operate the connected agent. We do not share Meta data with any third party except the AI provider you have selected (see (6)) to generate the response that your agent then posts on your behalf.
Tokens are revoked automatically when you click 'Disconnect' in /social, when you remove the AgentGo Cloud app from your Facebook settings (https://www.facebook.com/settings → Apps and Websites), or when Meta notifies us that the token has been revoked. Token revocation triggers immediate deletion of the associated row in social_accounts and the cessation of webhook event processing for that account.
5. Purposes of processing
(a) Provide the Service: route calls, generate AI responses, store transcripts, publish to social media on your instruction, debit wallet, render dashboards. (b) Bill correctly: compute usage charges, generate invoices, comply with VAT and accounting law (Estonian Accounting Act § 12). (c) Prevent fraud and abuse: detect anomalies, enforce acceptable-use policy, prevent automated abuse of social-media platforms. (d) Improve the Service: aggregate, non-identifying statistics; debug specific failures with your explicit consent. (e) Communicate: send important account / service / security / billing notices. (f) Comply with platform policies: respect Meta Platform Terms, Telnyx acceptable use, etc.
6. Legal bases (GDPR Art. 6)
(b) Contract — to provide the Service you have subscribed to. (c) Legal obligation — accounting, VAT, anti-money-laundering (AML), responses to lawful authority requests. (f) Legitimate interest — fraud prevention, network security, debugging, internal record-keeping; in each case the legitimate interest is balanced against your privacy interest and you may object via timofei@koduarve.ee. (a) Consent — for optional marketing communications, for connecting external accounts (Meta, VKontakte, Telegram), and for any feature that requires recording calls in jurisdictions where consent is the applicable basis.
7. Third-party processors
We rely on the following processors to deliver the Service. Each acts under a Data Processing Agreement compatible with the GDPR:
• Stripe Payments Europe, Ireland — card payment processing. • Telnyx LLC, Ireland / USA — telephony connectivity (DID rental, voice routing, recording storage). • Google Cloud, Ireland / USA — Gemini Live voice provider, infrastructure. • OpenAI Ireland Limited — Realtime voice provider, GPT models. • xAI Corp, USA — Grok voice and language model provider. • Anthropic PBC, USA — Claude language model. • MiniMax, Singapore — Text-to-speech provider. • Meta Platforms Ireland — Facebook + Instagram Graph API (only when you have connected an account). • VK Company, Russia — VKontakte API (only when you have connected an account). • Telegram Messenger Inc., UK — Telegram Bot API (only when you have connected a channel). • Hetzner Online GmbH, Germany — physical hosting of the production cluster.
Audio sent to AI providers and text/media sent to social-media platforms is processed under their respective terms; we do not control internal retention beyond what those agreements promise. Where a processor is established outside the EEA, transfers rely on Standard Contractual Clauses adopted by the European Commission and on technical safeguards (encryption in transit and at rest).
8. Retention
Account data: retained while the account is active; deleted 30 days after account closure, subject to (10).
Call recordings and transcripts: 90 days by default, or until you delete them in /dashboard/calls, whichever comes first. Configurable per agent.
Contact-book entries: retained until you delete them, until you delete the owning agent, or until the account is closed.
Social-media tokens and account rows: retained for as long as the connection is active; deleted immediately when you click 'Disconnect' in /social, when Meta/VK signals token revocation, or as part of a User Data Deletion request (see /legal/user-data-deletion).
Social-media webhook events (DMs, comments, mentions): 180 days, then automatically purged. You may delete individual events earlier from the agent dashboard.
Social-media posts published through us (history): retained until you delete them, the connected account is disconnected, or the account is closed.
Billing transactions and tax invoices: retained for 7 years to comply with Estonian Accounting Act.
Anonymised aggregate statistics: retained indefinitely.
Server access logs: 30 days (security purposes).
9. Your rights (GDPR)
You have the right to: • Access your personal data (Art. 15) • Request correction (Art. 16) • Request erasure / 'right to be forgotten' (Art. 17) — see also /legal/user-data-deletion for the dedicated Meta-data-deletion procedure • Restrict processing (Art. 18) • Object to processing based on legitimate interest (Art. 21) • Data portability — receive a machine-readable export of the personal data you provided to us (Art. 20) • Withdraw consent at any time without affecting the lawfulness of past processing (Art. 7(3))
Where processing is necessary to comply with a legal obligation (e.g. accounting records retained for 7 years) we cannot erase the affected records before the legal retention period expires. We will, however, restrict access to the minimum personnel necessary and delete promptly once the obligation ends.
To exercise any right write to timofei@koduarve.ee. We respond within 30 days. You may also lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or with the supervisory authority in your country of residence.
10. User Data Deletion
If you want to delete data we hold about you that originated from a Meta-platform connection (Facebook Page, Instagram Business account), follow the dedicated procedure at /legal/user-data-deletion.
For any other personal data we process, write to timofei@koduarve.ee with the subject 'Data deletion request'. Include the email address on your AgentGo Cloud account and (if applicable) the tenant slug. We will: • Acknowledge receipt within 5 business days • Confirm identity (we may ask security questions to prevent account hijack) • Execute deletion within 30 days, except for data we are legally required to keep (see (9)) • Send a written confirmation when complete
You can also self-serve some deletions: disconnect social accounts in /social, delete contacts in /dashboard/contacts, delete call recordings in /dashboard/calls.
11. International transfers
Several of our processors are established outside the European Economic Area, notably in the United States and Singapore. Transfers rely on Standard Contractual Clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914) and, where applicable, on supplementary technical measures (encryption in transit using TLS 1.2+ and at rest using AES-256). Where we send data to a Meta service, that transfer relies on Meta's standard data-protection terms.
12. Cookies and similar technologies
agentsgo.eu uses strictly necessary cookies for session authentication, locale preference, theme preference, and CSRF protection. agent.agentsgo.eu uses an OAuth-state cookie scoped to /v1/social during a social-media connection flow.
We do not use third-party analytics or advertising cookies. The saas-web and agentgo-web containers do not embed Google Analytics, Hotjar, Meta Pixel, or similar trackers. If a future version introduces them, we will update this Policy and seek your consent first.
13. Security
Production traffic is served over TLS 1.3. Passwords are hashed with bcrypt (cost 10). Database connections require TLS. OAuth access tokens (Meta, VK), Telegram bot tokens, and other sensitive credentials are encrypted at rest using AGENTGO_ENCRYPTION_KEY-derived keys stored separately from the encrypted blobs.
Backup snapshots are encrypted at rest. Access to production is restricted to the platform operator and is audited. Webhook calls from Meta are authenticated using X-Hub-Signature-256 HMAC-SHA-256 verification.
If we discover a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the Estonian Data Protection Inspectorate within 72 hours and affected users without undue delay (GDPR Art. 33, 34).
14. Automated decisions and AI
AgentGo Cloud uses AI providers (Anthropic Claude, OpenAI GPT, Google Gemini, xAI Grok) to generate agent responses, suggest social-media replies, transcribe calls, and provide voice synthesis. These are NOT 'solely automated decisions producing legal effects' within GDPR Art. 22 — humans (you, the agent operator) retain control over what is published, dialed, or sent.
Where your agent autonomously publishes content to a social-media account you connected, that content is generated by an AI model under instructions you have configured. You remain the legal author and publisher of that content.
15. Children
The Service is intended for business users aged 18 or older. We do not knowingly collect data from individuals under 16. If we learn that we have collected personal data of a person under 16 without verified parental consent, we will delete it. If you believe we may hold such data, contact timofei@koduarve.ee.
16. Changes to this Policy
We may update this Policy from time to time. Material changes will be announced via a banner in /dashboard and via email to the account owner at least 14 days before they take effect. The 'updatedAt' date at the top reflects the most recent revision. The current and prior versions remain accessible via Git history at our infrastructure repository.
17. Contact
KODUARVE OÜ Registry code: 16936830 Country: Estonia (EU)
Data Protection contact: timofei@koduarve.ee Supervisory authority: Andmekaitse Inspektsioon (https://aki.ee)
For Meta-platform-specific data deletion: /legal/user-data-deletion