Privacy Policy
Public Beta
Last updated: · Effective:
1. Controller
The controller responsible for the processing of your personal data is agentis GmbH, Torstraße 201, 10115 Berlin, Germany (registered with the District Court Berlin (Charlottenburg) under HRB 285323 B).
For data protection enquiries, contact us at [email protected]. For all other matters, [email protected].
2. Scope
This Privacy Policy explains how agentis processes personal data when you visit agentis.capital, register for and use the agentis platform, or connect a bank account through our Service. It applies to the Public Beta.
3. What we process
We process the following categories of personal data:
- Account data — your name, email address, organisation (if applicable), and authentication data managed by our identity provider.
- Bank connection metadata — when you connect a bank account, we store the information needed to identify the account and maintain the connection: account holder name, IBAN, account name and type, currency, the bank’s name and country, and an Open Banking session reference.
- Bank transaction data (balances, transactions, card data, direct debits, standing orders) — see Section 4 for our pass-through approach to this data.
- Usage and audit data — API request logs, audit trail entries for connection events and configuration changes, IP address.
4. Pass-through architecture for bank data
By design, agentis does not store your bank transaction history, balances, card data, direct debits, or standing orders. When you or an AI agent under your Policy requests this information, it is fetched live from your bank through our Open Banking provider, filtered against your Policy, and returned in the API response. It is not cached, not written to disk, and not retained after the request completes.
We do not use bank data for advertising, profiling, credit scoring, or training machine-learning models. The only bank-related data we retain is the connection metadata described in Section 3.
5. Purposes and legal bases
We process personal data only on the legal bases set out in Article 6 of the GDPR.
Contract performance (Art. 6(1)(b)) — to create and authenticate your account, to maintain bank connections, and to deliver the core functionality of the Service when you or an authorised AI agent requests financial information.
Consent (Art. 6(1)(a)) — you give explicit consent to your bank when you authorise an Open Banking connection, in accordance with PSD2. You may withdraw this consent at any time. Waitlist registrations on agentis.capital are also processed on the basis of your consent.
Legitimate interest (Art. 6(1)(f)) — to secure the Service, prevent abuse, enforce Policy controls, maintain audit trails for compliance purposes, and protect our infrastructure. We have balanced these interests against your rights and consider them proportionate.
6. Recipients
We share personal data only with processors acting on our behalf under Article 28 GDPR, in the following categories:
- Open Banking aggregator (licensed AISP, EU-based)
- Identity and authentication provider
- Cloud infrastructure provider (EU region)
- CDN, DNS, and edge security provider
We do not sell personal data and we do not share it with third parties for advertising purposes. The current list of named sub-processors is available at agentis.capital/subprocessors.
7. International data transfers
All bank data and the substantive data stored by agentis is hosted in the European Union. Where a sub-processor processes data outside the EU/EEA — for example, components of our identity provider or global edge networks — transfers are based on an adequacy decision of the European Commission or on Standard Contractual Clauses (Art. 46 GDPR), with additional safeguards where required.
8. Retention
We retain personal data only for as long as necessary for the purposes for which it was collected:
- Account data and bank connection metadata — for the duration of your account; deleted within 30 days of an erasure request, subject to legal retention obligations.
- Bank transaction data — not retained (see Section 4).
- Audit logs — up to 7 years, where retention is required by accounting, tax, or financial compliance obligations.
- Operational logs — up to 90 days.
- Usage analytics — aggregated and pseudonymised API usage data (such as request frequency and endpoint activity) — for the duration of your account.
9. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection to processing (Art. 21). Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal (Art. 7(3)).
To exercise any of these rights, contact [email protected]. We will respond within one month. To withdraw Open Banking consent, disconnect the bank account in the agentis dashboard or revoke access directly with your bank.
10. Security
We implement appropriate technical and organisational measures (Art. 32 GDPR), including encryption of data in transit and at rest, hashed credentials, EU-only data residency, restricted production access, and a pass-through architecture for bank data that minimises what is stored at all. The most effective protection for sensitive data is not collecting or retaining it in the first place.
11. Automated decision-making
agentis evaluates AI agent data-access requests against rules you define. This is deterministic rule evaluation, not profiling or AI-based decision-making, and does not produce legal or similarly significant effects on you within the meaning of Art. 22 GDPR. You retain full control over the rules at all times.
12. Cookies
Our marketing website uses a privacy-friendly analytics tool that does not set cookies and does not collect personal data. The agentis dashboard uses strictly necessary cookies for authentication session management, which are exempt from consent requirements under Art. 5(3) of the ePrivacy Directive. We do not use any analytics, advertising, or tracking cookies in the dashboard.
13. Children
The Service is intended for business and professional use and is not directed at individuals under 18. We do not knowingly collect personal data from minors.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email at least 14 days before the changes take effect, and update the “Last updated” date at the top of this page.
15. Right to lodge a complaint
If you believe our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your residence, place of work, or place of the alleged infringement. The supervisory authority for agentis GmbH is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Friedrichstraße 219, 10969 Berlin, Germany). We encourage you to contact us first so that we can try to resolve your concern directly.