This document is not yet final — information to be completed
The following details are still outstanding and must be filled in before this document is relied upon:
- Final review by qualified legal counsel
AgencyOS is a business platform used by agencies to run sales, delivery, finance and HR. Most of the personal data in it is put there by our customers about their staff, clients and prospects. If you received a call, email or survey from a company using AgencyOS and want your data corrected or deleted, contact that company directly — they decide what happens to it. We will help them respond.
1. Our role: controller and processor
We operate AgencyOS. Our data protection role depends on which data we are talking about.
We are a processor for Customer Data
When a customer organisation loads leads, contacts, client records, call recordings, invoices, time entries or survey responses into its workspace, that organisation is the controller. We process that data as a processor, on its documented instructions, under a data processing agreement. We do not decide what goes into a workspace, how long the customer keeps it, or who the customer contacts.
We are a controller for our own data
We are the controller for data we determine the purposes of ourselves: account and billing records, our correspondence with you, support requests and bug reports, security and audit logs, and diagnostics needed to keep the Service running.
2. Data we process
Account and identity data
- name, work email address, phone number, profile photo, job title and department;
- role, permissions and workspace membership;
- authentication data — password hashes (we never store passwords in readable form), session tokens, password-reset tokens, and login timestamps.
Customer Data your organisation puts into the platform
- Leads, contacts and clients: names, company, phone numbers, email addresses, addresses, notes, campaign and disposition history, do-not-call status.
- Communications: emails sent and received through connected mailboxes, SMS, in-app chat messages and attachments, call notes and comments.
- Voice and meetings: call metadata, call recordings, transcripts, meeting recordings and debriefs, AI voice-agent conversations, screen recordings attached to bug reports.
- Commercial records: quotes, contracts and their signature and acceptance records (including signer name, timestamp and IP address where captured), products, invoices, payments and collection activity.
- Work and performance records: tasks, timers, clock-in/clock-out events, capacity and workload, KPI and commission calculations, leave applications.
- Survey data: employee satisfaction responses and client satisfaction / NPS responses.
- Files: documents, images and attachments uploaded to the workspace.
Technical and usage data
- IP address, browser and device type, and pages or features used;
- application and security logs, error reports and performance diagnostics;
- audit records of significant actions taken in a workspace.
Billing data
Billing contact details, plan, subscription and payment status. Card details are entered directly with our payment processor and are never stored on our systems.
3. Purposes and legal bases
Where we act as controller and the GDPR applies, we rely on the following legal bases:
- Performance of a contract — creating and managing accounts, providing the Service, support, billing and collecting payment.
- Legitimate interests — securing the Service and preventing abuse, debugging and improving reliability, keeping audit and security logs, and communicating with customers about the Service. We balance these against your rights and interests.
- Legal obligation — accounting and tax records, responding to lawful requests.
- Consent — where we ask for it, such as certain optional integrations or marketing emails. You can withdraw consent at any time.
In summary, for the data we control:
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account and identity data | Creating accounts, authenticating users, providing the Service | Performance of a contract | Life of the account, then deleted with the workspace |
| Billing and payment records | Invoicing, collecting payment, accounting | Contract; legal obligation | As required by Danish bookkeeping law (currently 5 years) |
| Support and bug reports | Answering requests, reproducing and fixing issues | Contract; legitimate interests | Up to 24 months after the case is closed |
| Security, audit and application logs | Detecting abuse, investigating incidents, reliability | Legitimate interests; legal obligation | Limited period proportionate to the purpose |
| Service and product communications | Notifying customers about changes, incidents and releases | Legitimate interests (consent for marketing) | Until you object or withdraw consent |
Account and identity data
Purpose
Creating accounts, authenticating users, providing the Service
Legal basis
Performance of a contract
Retention
Life of the account, then deleted with the workspace
Billing and payment records
Purpose
Invoicing, collecting payment, accounting
Legal basis
Contract; legal obligation
Retention
As required by Danish bookkeeping law (currently 5 years)
Support and bug reports
Purpose
Answering requests, reproducing and fixing issues
Legal basis
Contract; legitimate interests
Retention
Up to 24 months after the case is closed
Security, audit and application logs
Purpose
Detecting abuse, investigating incidents, reliability
Legal basis
Legitimate interests; legal obligation
Retention
Limited period proportionate to the purpose
Service and product communications
Purpose
Notifying customers about changes, incidents and releases
Legal basis
Legitimate interests (consent for marketing)
Retention
Until you object or withdraw consent
Where we act as processor, the legal basis for the processing is determined by our customer, the controller.
We do not sell personal data, and we do not use Customer Data for advertising or for training AI models of our own.
4. Calls, recordings and transcripts
The platform can place and receive calls, record them, transcribe them and analyse them. Call audio is carried by telephony providers, recordings are stored in the workspace, and transcription and analysis are performed by AI providers listed below.
The customer organisation running the calls decides whether to record, whom to call, and how to notify participants. It is responsible for giving notice and obtaining consent where the law requires it, for honouring do-not-call requests, and for respecting calling-hours restrictions. Do-not-call lists, quiet hours and consent tracking are available in the platform for that purpose.
5. AI processing
Several features send content to third-party AI providers to produce a result:
- transcription of call and meeting audio;
- meeting summaries, call debriefs and conversation analysis;
- drafting and rewriting text, generating presentation and script content;
- AI voice agents that conduct calls and surveys;
- voice synthesis and, where a user configures it, voice or presenter likeness cloning.
Content is sent only when a feature is used, and only to the provider needed for that feature. AI output is generated automatically and may be inaccurate — it is meant to be reviewed by a person, and it is not used by us to make automated decisions that produce legal or similarly significant effects on anyone. Where a customer uses AI-derived scores or analysis in employment or performance contexts, that customer is responsible for ensuring meaningful human review and for informing the people concerned.
6. Employee and HR data
AgencyOS records working time, task activity, call performance, KPI attainment, commissions, leave and satisfaction survey responses. Where you are an employee of a customer organisation, that organisation is the controller of this data and its own HR privacy notice applies. Customer organisations are responsible for informing staff about monitoring and for meeting any consultation or works-council obligations before enabling these features.
Employee satisfaction surveys may be configured as identifiable or aggregated; the customer chooses which, and should tell participants which applies before they respond.
8. Sub-processors
We use the providers below to deliver the Service. Which ones apply to you depends on the modules and integrations your workspace enables. Each is bound by a written agreement containing data protection obligations.
| Provider | Purpose | Data involved | Hosting |
|---|---|---|---|
| Supabase | Application hosting, database, file storage and authentication | All Customer Data and account data | EU / as configured |
| Twilio | Outbound and inbound voice calling, SMS, phone number provisioning | Phone numbers, call metadata, call recordings, SMS content | EU / US |
| Telnyx | Alternative voice carrier and SIP connectivity for the dialer | Phone numbers, call metadata, call audio | EU / US |
| Vapi | AI voice agents for outbound calls and surveys | Call audio, transcripts, contact identifiers | US |
| OpenAI | Transcription, meeting summaries, call analysis, text generation | Text and audio submitted to AI features | US |
| ElevenLabs | Voice synthesis and voice cloning for AI agents | Voice samples, generated audio | US |
| HeyGen | Generated presenter video for sales presentations | Scripts, likeness and voice configuration for participating users | US |
| Mailgun | Transactional and outbound email delivery | Recipient email addresses, email content | EU / US |
| Google (Gmail API) | Optional mailbox connection for lead correspondence | Email content and metadata from the connected mailbox | EU / US |
| Stripe | Subscription checkout and payment processing | Billing contact details, payment status (card data goes directly to Stripe) | EU / US |
| QuickBooks (Intuit) | Optional accounting and invoice synchronisation | Invoice, customer and payment records | US |
| Zoom | Meeting recordings and transcripts ingested via webhook | Meeting metadata, recordings, transcripts | EU / US |
| Cal.com | Meeting scheduling and booking confirmation | Names, email addresses, meeting times | EU / US |
| Loom | Screen recording attached to bug reports and internal notes | Screen recordings and their metadata | US |
Supabase
Purpose
Application hosting, database, file storage and authentication
Data involved
All Customer Data and account data
Hosting
EU / as configured
Twilio
Purpose
Outbound and inbound voice calling, SMS, phone number provisioning
Data involved
Phone numbers, call metadata, call recordings, SMS content
Hosting
EU / US
Telnyx
Purpose
Alternative voice carrier and SIP connectivity for the dialer
Data involved
Phone numbers, call metadata, call audio
Hosting
EU / US
Vapi
Purpose
AI voice agents for outbound calls and surveys
Data involved
Call audio, transcripts, contact identifiers
Hosting
US
OpenAI
Purpose
Transcription, meeting summaries, call analysis, text generation
Data involved
Text and audio submitted to AI features
Hosting
US
ElevenLabs
Purpose
Voice synthesis and voice cloning for AI agents
Data involved
Voice samples, generated audio
Hosting
US
HeyGen
Purpose
Generated presenter video for sales presentations
Data involved
Scripts, likeness and voice configuration for participating users
Hosting
US
Mailgun
Purpose
Transactional and outbound email delivery
Data involved
Recipient email addresses, email content
Hosting
EU / US
Google (Gmail API)
Purpose
Optional mailbox connection for lead correspondence
Data involved
Email content and metadata from the connected mailbox
Hosting
EU / US
Stripe
Purpose
Subscription checkout and payment processing
Data involved
Billing contact details, payment status (card data goes directly to Stripe)
Hosting
EU / US
QuickBooks (Intuit)
Purpose
Optional accounting and invoice synchronisation
Data involved
Invoice, customer and payment records
Hosting
US
Zoom
Purpose
Meeting recordings and transcripts ingested via webhook
Data involved
Meeting metadata, recordings, transcripts
Hosting
EU / US
Cal.com
Purpose
Meeting scheduling and booking confirmation
Data involved
Names, email addresses, meeting times
Hosting
EU / US
Loom
Purpose
Screen recording attached to bug reports and internal notes
Data involved
Screen recordings and their metadata
Hosting
US
We may also disclose data to professional advisers, to authorities where legally required, and to a successor entity in a merger or acquisition (with notice to affected customers). To be notified of changes to this list, write to taras@agencyos.tech.
9. International transfers
Some sub-processors are located outside the European Economic Area, principally in the United States. Where personal data is transferred outside the EEA or the UK, we rely on an adequacy decision where one applies, and otherwise on the European Commission's Standard Contractual Clauses together with supplementary measures such as encryption in transit and at rest and access controls. A copy of the relevant transfer mechanism is available on request.
10. Retention
- Customer Data is retained for as long as the customer keeps it in the workspace. Customers control deletion within the application.
- After a subscription ends, Customer Data is available for export for 30 days and then deleted or anonymised within 90 days, except where retention is legally required.
- Backups are kept on a rolling cycle of about 30 days and are overwritten in the ordinary course.
- Billing and accounting records are kept for the period required by tax law in our jurisdiction.
- Security and audit logs are kept for a limited period proportionate to their security purpose.
11. Security
We apply technical and organisational measures appropriate to the risk, including workspace isolation enforced in the database, role-based access control, encryption in transit and at rest, encrypted storage of third-party credentials, session expiry and audit logging. Our Security Overview describes these in detail, including how to report a vulnerability.
If a personal data breach affects data we process for you, we will notify you without undue delay and in any event within 72 hours of becoming aware of it, with the information you need to meet your own notification duties.
12. Your rights
Where the GDPR or similar law applies, you have the right to access your personal data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
If your data is in a customer's workspace — for example you are an employee, client or prospect of an agency using AgencyOS — please contact that organisation. It is the controller. If you contact us instead, we will forward your request to it and support it in responding; we are not permitted to change or delete a customer's data on our own initiative.
If we are the controller — for example for our account and billing records — write to taras@agencyos.tech. We respond within one month and may ask you to verify your identity before we act.
13. Children
The Service is a workplace tool intended for people aged 18 and over. We do not knowingly collect personal data from children. If you believe a child's data has been submitted, contact us and we will work with the relevant controller to remove it.
14. Changes to this policy
We may update this policy as the Service evolves. The date at the top shows when it was last changed, and we will give notice of material changes by email or in-app before they take effect.
15. Contact and complaints
Data protection enquiries: SY Consultancy ApS (CVR no. 41963972), taras@agencyos.tech, C/O VXC, Amaliegade 45, 1., 1256 København K, Denmark.
We have not appointed a statutory Data Protection Officer; data protection questions are handled by the address above. A Data Processing Agreement, including the current sub-processor list and the EU Standard Contractual Clauses, is available on request.
If you are in the EEA or UK and believe we have handled your personal data unlawfully, you may lodge a complaint with your local supervisory authority. In Denmark this is Datatilsynet (the Danish Data Protection Agency), Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk.