Privacy Policy
Last updated: 4 August 2026
This policy explains what happens to your information when you use Agentic, an AI workspace that turns your documents and instructions into finished work.
It is written to be read. If anything here is unclear, or if you want something done with your data, email support@agentic.pm.
Who is responsible for your data
Agentic is operated as Agentic, by an individual established in Romania, acting as the data controller. You can reach us at support@agentic.pm for any question about your data, and we will provide further contact details on request.
Agentic is currently a free private beta. Please read our Terms of Service alongside this policy, particularly the parts about the accuracy of AI-generated output.
What we collect
Information you give us when you sign up
We use passwordless sign-in, so we never ask for or store a password. We hold your email address, your name if you provide one, and the projects and teams you belong to.
Your content
This is the heart of the service and the most important category to understand. It includes the documents you upload or import, the instructions and messages you write, the projects and plans you create, and the deliverables the system produces for you.
From your documents we also derive and store summaries, search indexes that let agents find relevant passages, and notes that agents keep so they remember context across a project. These derived records contain material drawn from your documents.
Information about other people
The product is built for client work, so you will often add information about people who are not our users: clients, colleagues, contacts and the people described in the documents you upload.
We process that information on your instruction. You are responsible for having a proper reason to give it to us, and for telling those people if they need to know. If you are one of those people and you want to know what we hold about you, email us and we will help — though in most cases we will need to involve the customer who provided it, because it is their project.
Voice and likeness, only if you choose
Some features need more sensitive material, and none of them are on by default:
- Voice cloning uses voice samples you record and explicitly consent to.
- Avatar video uses a likeness you upload and explicitly consent to.
- Calls and interviews are recorded and transcribed when you and the other participants consent.
A voice model and a facial likeness can identify you uniquely, so we treat these as sensitive information and rely on your explicit consent for them. You can withdraw that consent at any time by emailing us, and we will delete the material. If you invite other people to a recorded call, you are responsible for making sure they know it is being recorded.
Technical information
We record your IP address, your browser's user agent, and sign-in and security events. Our engineering logs include your email address and IP address so we can investigate problems and abuse.
Why we use it, and our legal basis
| What we do | Why | Legal basis |
|---|---|---|
| Run the service: store your documents, generate deliverables, let your team collaborate | It is what you signed up for | Performance of our contract with you |
| Send you sign-in links and messages about your account | You cannot use the service otherwise | Performance of our contract |
| Keep the service secure, investigate faults and prevent abuse | To keep the service working and safe | Our legitimate interests |
| Understand which features fail so we can fix them | To improve the product | Our legitimate interests |
| Voice cloning, avatar likeness, and recording calls | Only because you asked for these features | Your explicit consent |
| Comply with legal obligations | Because we must | Legal obligation |
We do not use your content to train our own AI models, and we do not sell it or use it for advertising.
Who we share it with
To turn your documents and instructions into finished work, we send content to specialist providers who process it on our behalf. The full list, what each one receives and where it is based is on our service providers page.
In summary: AI model providers generate the work; research tools handle search queries that may reflect your documents' contents; presentation, voice and video services build particular deliverables; an email provider delivers messages you send; a connection broker holds the authorisation for accounts you link; and hosting, storage and diagnostics providers run the service.
Our administrators can access project content when needed to operate, support and troubleshoot the service. We keep this to what is necessary, but you should know it is possible.
We will also disclose information if the law requires it.
Where your data goes
We keep our own infrastructure in Europe. The application, its database and its logs run in the Netherlands, and your files are stored in Cloudflare's Eastern Europe region.
Most of the specialist providers listed above are in the United States, and one AI provider is in China. When they process your content it is transferred outside the European Economic Area. There is no realistic European alternative for AI models of the quality this product needs, so these transfers are a genuine feature of how the service works rather than something we can avoid. We rely on the transfer protections in each provider's terms, such as the European Commission's standard contractual clauses or the EU–US Data Privacy Framework.
Our diagnostic records, which include document content contained in the requests we send to AI providers, are held by LangSmith in the United States.
How long we keep it
We keep your content until you delete it, or until you ask us to close your account. Nothing is deleted automatically, so if you want something gone, tell us or delete it yourself.
Some technical records expire on their own: sign-in links after 30 minutes, sessions after 90 days of inactivity, and internal processing state after 14 days. Database backups are kept for up to 35 days, so deleted content can persist in a backup for that long before it is overwritten.
What deletion reaches. When you delete a document we destroy the file itself, the text extracted from it, its search index entries, its summaries, and the notes agents kept about it. Deleting a project removes its records and stored files the same way.
What deletion cannot reach. We cannot retrieve or delete copies already processed by the providers listed above. Those are governed by each provider's own retention terms. Once a document has been sent to an AI provider to produce your work, that transfer has happened and we cannot undo it.
Your rights
If you are in the EEA or the UK, you have the right to access your data, correct it, have it deleted, restrict or object to how we use it, receive it in a portable form, and withdraw any consent you gave.
How to use them, honestly described. Agentic is a beta and does not yet have self-service controls for all of this. You can delete documents and projects yourself in the product. For anything else — including closing your account, getting a copy of your data, or correcting your name or email — email support@agentic.pm and we will do it by hand. We will respond within one month. It is a manual process today rather than a button, and we would rather say so than imply otherwise.
Withdrawing consent for voice cloning, avatar likeness or recordings does not affect anything we did before you withdrew it.
If you think we have handled your data badly, please tell us first so we can fix it. You also have the right to complain to a data protection authority. Ours is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP, dataprotection.ro), and you may also complain to the authority in the country where you live.
Cookies
We use one cookie, called cc_session. It keeps you signed in. It cannot be read by scripts, is
only sent over an encrypted connection, and expires after 90 days of inactivity.
That is the whole story: we have no analytics cookies, no advertising cookies and no third-party trackers. Because this single cookie is strictly necessary to provide a service you asked for, we do not need to show you a consent banner, and we would rather keep it that way than add tracking.
Automated decisions
The product generates content automatically — that is the point of it. But we do not make automated decisions about you that have legal or similarly significant effects. A human, usually you, decides what to do with what the system produces.
Children
Agentic is not intended for anyone under 18, and we do not knowingly collect information about children.
Security
Sign-in is passwordless, so there is no password to steal. Sessions can be revoked. Access to your files uses short-lived links that expire after 30 minutes, and our storage credentials are limited to the single bucket holding your files. No system is perfectly secure, and we will tell you promptly if something happens that affects your data.
Changes to this policy
If we change something significant — a new category of provider receiving your content, for example — we will update the date at the top and let you know by email or in the product.