Privacy Policy

What personal data we process, why, and on what basis.

Effective 27 August 2026 · Last updated 27 August 2026

This document is not yet final — information to be completed

The following details are still outstanding and must be filled in before this document is relied upon:

  • Final review by qualified legal counsel

AgencyOS is a business platform used by agencies to run sales, delivery, finance and HR. Most of the personal data in it is put there by our customers about their staff, clients and prospects. If you received a call, email or survey from a company using AgencyOS and want your data corrected or deleted, contact that company directly — they decide what happens to it. We will help them respond.

1. Our role: controller and processor

We operate AgencyOS. Our data protection role depends on which data we are talking about.

We are a processor for Customer Data

When a customer organisation loads leads, contacts, client records, call recordings, invoices, time entries or survey responses into its workspace, that organisation is the controller. We process that data as a processor, on its documented instructions, under a data processing agreement. We do not decide what goes into a workspace, how long the customer keeps it, or who the customer contacts.

We are a controller for our own data

We are the controller for data we determine the purposes of ourselves: account and billing records, our correspondence with you, support requests and bug reports, security and audit logs, and diagnostics needed to keep the Service running.

2. Data we process

Account and identity data

  • name, work email address, phone number, profile photo, job title and department;
  • role, permissions and workspace membership;
  • authentication data — password hashes (we never store passwords in readable form), session tokens, password-reset tokens, and login timestamps.

Customer Data your organisation puts into the platform

  • Leads, contacts and clients: names, company, phone numbers, email addresses, addresses, notes, campaign and disposition history, do-not-call status.
  • Communications: emails sent and received through connected mailboxes, SMS, in-app chat messages and attachments, call notes and comments.
  • Voice and meetings: call metadata, call recordings, transcripts, meeting recordings and debriefs, AI voice-agent conversations, screen recordings attached to bug reports.
  • Commercial records: quotes, contracts and their signature and acceptance records (including signer name, timestamp and IP address where captured), products, invoices, payments and collection activity.
  • Work and performance records: tasks, timers, clock-in/clock-out events, capacity and workload, KPI and commission calculations, leave applications.
  • Survey data: employee satisfaction responses and client satisfaction / NPS responses.
  • Files: documents, images and attachments uploaded to the workspace.

Technical and usage data

  • IP address, browser and device type, and pages or features used;
  • application and security logs, error reports and performance diagnostics;
  • audit records of significant actions taken in a workspace.

Billing data

Billing contact details, plan, subscription and payment status. Card details are entered directly with our payment processor and are never stored on our systems.

3. Purposes and legal bases

Where we act as controller and the GDPR applies, we rely on the following legal bases:

  • Performance of a contract — creating and managing accounts, providing the Service, support, billing and collecting payment.
  • Legitimate interests — securing the Service and preventing abuse, debugging and improving reliability, keeping audit and security logs, and communicating with customers about the Service. We balance these against your rights and interests.
  • Legal obligation — accounting and tax records, responding to lawful requests.
  • Consent — where we ask for it, such as certain optional integrations or marketing emails. You can withdraw consent at any time.

In summary, for the data we control:

Account and identity data

Purpose

Creating accounts, authenticating users, providing the Service

Legal basis

Performance of a contract

Retention

Life of the account, then deleted with the workspace

Billing and payment records

Purpose

Invoicing, collecting payment, accounting

Legal basis

Contract; legal obligation

Retention

As required by Danish bookkeeping law (currently 5 years)

Support and bug reports

Purpose

Answering requests, reproducing and fixing issues

Legal basis

Contract; legitimate interests

Retention

Up to 24 months after the case is closed

Security, audit and application logs

Purpose

Detecting abuse, investigating incidents, reliability

Legal basis

Legitimate interests; legal obligation

Retention

Limited period proportionate to the purpose

Service and product communications

Purpose

Notifying customers about changes, incidents and releases

Legal basis

Legitimate interests (consent for marketing)

Retention

Until you object or withdraw consent

Where we act as processor, the legal basis for the processing is determined by our customer, the controller.

We do not sell personal data, and we do not use Customer Data for advertising or for training AI models of our own.

4. Calls, recordings and transcripts

The platform can place and receive calls, record them, transcribe them and analyse them. Call audio is carried by telephony providers, recordings are stored in the workspace, and transcription and analysis are performed by AI providers listed below.

The customer organisation running the calls decides whether to record, whom to call, and how to notify participants. It is responsible for giving notice and obtaining consent where the law requires it, for honouring do-not-call requests, and for respecting calling-hours restrictions. Do-not-call lists, quiet hours and consent tracking are available in the platform for that purpose.

5. AI processing

Several features send content to third-party AI providers to produce a result:

  • transcription of call and meeting audio;
  • meeting summaries, call debriefs and conversation analysis;
  • drafting and rewriting text, generating presentation and script content;
  • AI voice agents that conduct calls and surveys;
  • voice synthesis and, where a user configures it, voice or presenter likeness cloning.

Content is sent only when a feature is used, and only to the provider needed for that feature. AI output is generated automatically and may be inaccurate — it is meant to be reviewed by a person, and it is not used by us to make automated decisions that produce legal or similarly significant effects on anyone. Where a customer uses AI-derived scores or analysis in employment or performance contexts, that customer is responsible for ensuring meaningful human review and for informing the people concerned.

6. Employee and HR data

AgencyOS records working time, task activity, call performance, KPI attainment, commissions, leave and satisfaction survey responses. Where you are an employee of a customer organisation, that organisation is the controller of this data and its own HR privacy notice applies. Customer organisations are responsible for informing staff about monitoring and for meeting any consultation or works-council obligations before enabling these features.

Employee satisfaction surveys may be configured as identifiable or aggregated; the customer chooses which, and should tell participants which applies before they respond.

7. Cookies and local storage

AgencyOS is an application, not an ad-supported website. We use only what the application needs to work:

  • Authentication — session and refresh tokens kept in your browser so you stay logged in. Sessions expire after inactivity (default 30 minutes, configurable by your administrator).
  • Preferences — interface settings such as theme, language, filters and column layouts.
  • Operational state — cached data and offline/service-worker state so the application loads quickly.

These are strictly necessary or functional and are not used to track you across other websites. We do not run third-party advertising or cross-site tracking cookies. Some embedded third-party components (for example scheduling or screen recording) may set their own cookies when you use them; their providers' policies apply.

8. Sub-processors

We use the providers below to deliver the Service. Which ones apply to you depends on the modules and integrations your workspace enables. Each is bound by a written agreement containing data protection obligations.

Supabase

Purpose

Application hosting, database, file storage and authentication

Data involved

All Customer Data and account data

Hosting

EU / as configured

Twilio

Purpose

Outbound and inbound voice calling, SMS, phone number provisioning

Data involved

Phone numbers, call metadata, call recordings, SMS content

Hosting

EU / US

Telnyx

Purpose

Alternative voice carrier and SIP connectivity for the dialer

Data involved

Phone numbers, call metadata, call audio

Hosting

EU / US

Vapi

Purpose

AI voice agents for outbound calls and surveys

Data involved

Call audio, transcripts, contact identifiers

Hosting

US

OpenAI

Purpose

Transcription, meeting summaries, call analysis, text generation

Data involved

Text and audio submitted to AI features

Hosting

US

ElevenLabs

Purpose

Voice synthesis and voice cloning for AI agents

Data involved

Voice samples, generated audio

Hosting

US

HeyGen

Purpose

Generated presenter video for sales presentations

Data involved

Scripts, likeness and voice configuration for participating users

Hosting

US

Mailgun

Purpose

Transactional and outbound email delivery

Data involved

Recipient email addresses, email content

Hosting

EU / US

Google (Gmail API)

Purpose

Optional mailbox connection for lead correspondence

Data involved

Email content and metadata from the connected mailbox

Hosting

EU / US

Stripe

Purpose

Subscription checkout and payment processing

Data involved

Billing contact details, payment status (card data goes directly to Stripe)

Hosting

EU / US

QuickBooks (Intuit)

Purpose

Optional accounting and invoice synchronisation

Data involved

Invoice, customer and payment records

Hosting

US

Zoom

Purpose

Meeting recordings and transcripts ingested via webhook

Data involved

Meeting metadata, recordings, transcripts

Hosting

EU / US

Cal.com

Purpose

Meeting scheduling and booking confirmation

Data involved

Names, email addresses, meeting times

Hosting

EU / US

Loom

Purpose

Screen recording attached to bug reports and internal notes

Data involved

Screen recordings and their metadata

Hosting

US

We may also disclose data to professional advisers, to authorities where legally required, and to a successor entity in a merger or acquisition (with notice to affected customers). To be notified of changes to this list, write to taras@agencyos.tech.

9. International transfers

Some sub-processors are located outside the European Economic Area, principally in the United States. Where personal data is transferred outside the EEA or the UK, we rely on an adequacy decision where one applies, and otherwise on the European Commission's Standard Contractual Clauses together with supplementary measures such as encryption in transit and at rest and access controls. A copy of the relevant transfer mechanism is available on request.

10. Retention

  • Customer Data is retained for as long as the customer keeps it in the workspace. Customers control deletion within the application.
  • After a subscription ends, Customer Data is available for export for 30 days and then deleted or anonymised within 90 days, except where retention is legally required.
  • Backups are kept on a rolling cycle of about 30 days and are overwritten in the ordinary course.
  • Billing and accounting records are kept for the period required by tax law in our jurisdiction.
  • Security and audit logs are kept for a limited period proportionate to their security purpose.

11. Security

We apply technical and organisational measures appropriate to the risk, including workspace isolation enforced in the database, role-based access control, encryption in transit and at rest, encrypted storage of third-party credentials, session expiry and audit logging. Our Security Overview describes these in detail, including how to report a vulnerability.

If a personal data breach affects data we process for you, we will notify you without undue delay and in any event within 72 hours of becoming aware of it, with the information you need to meet your own notification duties.

12. Your rights

Where the GDPR or similar law applies, you have the right to access your personal data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

If your data is in a customer's workspace — for example you are an employee, client or prospect of an agency using AgencyOS — please contact that organisation. It is the controller. If you contact us instead, we will forward your request to it and support it in responding; we are not permitted to change or delete a customer's data on our own initiative.

If we are the controller — for example for our account and billing records — write to taras@agencyos.tech. We respond within one month and may ask you to verify your identity before we act.

13. Children

The Service is a workplace tool intended for people aged 18 and over. We do not knowingly collect personal data from children. If you believe a child's data has been submitted, contact us and we will work with the relevant controller to remove it.

14. Changes to this policy

We may update this policy as the Service evolves. The date at the top shows when it was last changed, and we will give notice of material changes by email or in-app before they take effect.

15. Contact and complaints

Data protection enquiries: SY Consultancy ApS (CVR no. 41963972), taras@agencyos.tech, C/O VXC, Amaliegade 45, 1., 1256 København K, Denmark.

We have not appointed a statutory Data Protection Officer; data protection questions are handled by the address above. A Data Processing Agreement, including the current sub-processor list and the EU Standard Contractual Clauses, is available on request.

If you are in the EEA or UK and believe we have handled your personal data unlawfully, you may lodge a complaint with your local supervisory authority. In Denmark this is Datatilsynet (the Danish Data Protection Agency), Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk.