1. Controller and processor roles
- For our website and our own account holders, Agenton Oy is the data controller.
- When we run the Service for a business customer, that customer is the controller and Agenton is the processor, acting on their documented instructions under a Data Processing Agreement.
Agenton Oy, Business ID 3490327-5, Helsinki, Finland. Contact: [email protected].
2. Lawful basis for processing
Where Agenton is the controller, we process personal data under:
- Article 6(1)(b), contract: account management, service delivery, and support
- Article 6(1)(f), legitimate interests: service improvement, security, and fraud prevention
- Article 6(1)(a), consent: optional cookies, analytics, and marketing
3. Your rights
- Access (Art. 15): a copy of the personal data we hold about you
- Rectification (Art. 16): correction of inaccurate data
- Erasure (Art. 17): deletion of your data
- Restriction (Art. 18): limits on how we process your data
- Portability (Art. 20): your data in a structured, machine-readable format
- Objection (Art. 21): objecting to processing based on legitimate interests
If your data was processed through a business customer's use of the Service, that customer is the controller. We forward any request to them and help them respond.
4. Storage, security, and transfers
- Personal data is stored and processed within the EU/EEA.
- Encryption in transit and at rest, with least-privilege access and multi-factor authentication on production-critical systems.
- Some sub-processors have parent companies outside the EEA. Those transfers are covered by EU Standard Contractual Clauses, the Microsoft EU Data Boundary, or an adequacy decision.
5. Data retention
We keep personal data only as long as needed to run the Service or meet legal requirements. Call recordings, transcripts, metadata, analytics, and logs are kept for up to 6 months. Full details are in our Privacy Policy.
6. Personal data breaches
We maintain a defined breach-response process and notify affected controllers without undue delay, so they can meet their obligations under Articles 33 and 34 GDPR.