agenthost

Privacy Policy

In effect from [[EFFECTIVE_DATE]] · version 1.0

agenthost asks for as little as it can: an email address to sign you in, a name for your organization, and the files you choose to deploy. Here is exactly what we hold, why we are allowed to, and how to get it back or get rid of it.

1. Who is responsible

[[LEGAL_NAME]], company registration number [[ORG_NR]], [[ADDRESS]], Sweden, is the controller for the personal data described here. Contact us at[[PRIVACY_EMAIL]]. [[If a data protection officer is appointed, name them here; most organizations of this size are not required to have one.]]

Two different roles. For your account we are the controller — this policy covers that. For personal data inside the applications you deploy, you are the controller and we are only your processor: we handle it on your instructions under a data processing agreement, and this policy does not decide what happens to it. Ask us for a copy of that agreement at [[PRIVACY_EMAIL]].

2. What we collect, and why

DataWhyLegal basis
Email address, your name, organization nameTo create and run your account, and to identify you when you sign inPerformance of a contract (Art. 6(1)(b))
Sign-in codes, access and refresh tokens, API tokens, session records — all stored only as hashesTo authenticate you and the clients you authorizePerformance of a contract (Art. 6(1)(b))
Which clients you authorized, and when tokens were last usedSo you can see and revoke access, and so we can detect misuseLegitimate interest in securing the service (Art. 6(1)(f))
Server logs: IP address, timestamps, requested URLs, error detailTo operate the service, investigate faults, and prevent abuseLegitimate interest in a working, secure service (Art. 6(1)(f))
Projects, applications, hostnames, deployment history, and the files you deployTo provide the hosting you asked forPerformance of a contract (Art. 6(1)(b))
Billing details and invoicesTo charge for the service and to keep our booksContract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
Support correspondenceTo answer you and keep track of the issueLegitimate interest in supporting our customers (Art. 6(1)(f))

We do not buy personal data, we do not run advertising, and we do not profile you. There is no automated decision-making with legal or similarly significant effects in the sense of Art. 22.

3. Who else sees it

We use a small number of providers, each of them a processor bound by a data processing agreement:

ProviderWhat forWhere
Postmark (ActiveCampaign, Inc.)Sending sign-in codes and account emailUSA — see section 4
[[HOSTING_PROVIDER]]Servers, databases, and backups[[REGION, e.g. EU (Frankfurt)]]
[[ADDITIONAL_PROCESSORS — payment provider, error monitoring, and anything else in production]][[Purpose]][[Region]]

Beyond that we disclose personal data only where the law requires it, or to advisers and acquirers in connection with a sale of the business, under confidentiality.

4. Transfers outside the EU/EEA

Our email provider is established in the United States, so sending you a sign-in code involves a transfer of your email address there. That transfer is covered by [[TRANSFER_MECHANISM — the EU-US Data Privacy Framework where the provider is certified, and/or the European Commission's standard contractual clauses, together with a transfer impact assessment]]. You may request a copy of the safeguards from us. Everything else is kept within the EU/EEA.

5. How long we keep it

6. Cookies

agenthost sets two cookies, both strictly necessary to sign you in. Because they are strictly necessary, they need no consent under the Electronic Communications Act — which is why you are not being asked to click a banner. There is no analytics, no advertising, and no third-party tracking on this site.

CookiePurposeLifetime
ah_sessionKeeps you signed in so authorizing another client is one click30 days
ah_csrfEnsures an authorization was approved by you and not forged by another site30 days

7. How we protect it

Traffic runs over TLS. No password exists to be stolen: you sign in with a one-time code, and every credential we store — sign-in codes, session identifiers, access, refresh, and API tokens — is kept only as a salted hash, so a copy of our database does not let anyone into your account. Access to production is limited to those who need it. If a breach occurs that is likely to put your rights at risk, we notify the supervisory authority within 72 hours and tell you without undue delay.

8. Your rights

You can ask us at any time to:

Write to [[PRIVACY_EMAIL]] and we will answer within one month. If you think we are handling your data wrongly, you can complain to the Swedish Authority for Privacy Protection —Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, [email protected] — or to the authority where you live.

9. Changes

If we change this policy we will post the new version here with a new date, and email you before anything material takes effect.