Agentyk.me is built from the ground up for GDPR compliance — not bolted on as an afterthought.
Three foundational principles that make Agentyk.me GDPR-compliant by architecture.
A complete overview of what data we store, where, the legal basis, and retention period.
| Data Category | Storage Location | Legal Basis | Retention |
|---|---|---|---|
| Account profile | Firestore EU (eur3) | Art. 6(1)(b) Contract | Until account deletion |
| Consent records | Firestore EU (eur3) | Art. 6(1)(c) Legal obligation | Until account deletion |
| Usage metrics | Firestore EU (eur3) | Art. 6(1)(f) Legitimate interest | 12 months |
| Audit logs | Firestore EU (eur3) | Art. 6(1)(f) Legitimate interest | Team: 30 days / Enterprise: 1 year |
| Payment data | Stripe (SCCs) | Art. 6(1)(b) Contract | Per Stripe retention policy |
| Chat conversations | Browser memory only | N/A | Auto-deleted on tab close |
| Fraud prevention | Firestore EU (eur3) | Art. 6(1)(f) Legitimate interest | As necessary |
Every GDPR data subject right is implemented and available today.
Safeguards in place for any data processing outside the EEA.
Standard Contractual Clauses (SCCs)
SCCs in place with Microsoft Azure for any processing outside the EEA.
Transfer Impact Assessment (TIA)
Completed TIA evaluating the level of data protection in third countries.
Supplementary Measures
Encryption in transit (TLS 1.3) and at rest (AES-256), plus strict access controls.
Note: Firebase Auth and Stripe involve global infrastructure with appropriate safeguards (SCCs and supplementary measures) in place.
The legal entity responsible for your data and how to reach us.
Treubstraat 21 U314
2288 EH Rijswijk
The Netherlands
Autoriteit Persoonsgegevens
(Dutch Data Protection Authority)
Data Processing Agreement (DPA) available on request.
Review our full privacy policy, explore our security architecture, or request a DPA.
Need a DPA? Contact support@agentyk.me