Agentbeam
Legal

GDPR Compliance

Last updated: January 1, 2026

This page explains how Agentbeam meets its obligations under the EU and UK General Data Protection Regulation (“GDPR”) for users and customers in the European Economic Area and United Kingdom, across the local runtime recorder, browser extension, and cloud dashboard.

1. General

1.1 AISOLO Technologies Private Limited [CIN: U62099MH2023PTC403351] operates Agentbeam and is committed to GDPR compliance for every EU and UK data subject, regardless of where they access the Platform from.

1.2 This document sets out our legal bases for processing, your rights as a data subject, and how we protect your personal data across the website, local runtime recorder, browser extension, command-line tools and cloud dashboard.

1.3 Agentbeam is architected privacy-first: the most sensitive data — the content of agent shell commands, file diffs and tool-call arguments — is recorded locally by default and is never transmitted to us unless you explicitly enable cloud sync. This data minimization by design substantially reduces what GDPR rights we need to act on, because for most users, most data never reaches us at all.

3. Your GDPR rights

3.1 Privacy-by-design implementation

Because most Platform data is local by default, several GDPR rights are effectively pre-satisfied for the local recorder and browser extension: data minimization (we only receive what you sync), storage limitation (retention windows below), and purpose limitation (synced fields are scoped to your organization's own policy).

3.2 Right of access (Article 15)

  • View account and billing information from your cloud dashboard settings
  • Request a full export of the personal data we hold via [email protected]
  • Response time: within one month, typically within 5 business days

3.3 Right to rectification (Article 16)

  • Update account details directly in dashboard settings
  • Request correction of any other inaccurate data via [email protected]

3.4 Right to erasure (Article 17)

  • Request full account and synced-data deletion via [email protected]
  • Locally recorded data can be deleted immediately and directly by you using the Platform's local tooling — no request to us required
  • Cloud-side deletion is completed within 14 working days, and residual backups are purged within 45 days, subject to legal retention requirements (e.g. billing records)

3.5 Right to restrict or object to processing (Articles 18 & 21)

You may ask us to restrict processing of your data, or object to processing based on legitimate interest, by writing to [email protected]. We will honor the request unless we have compelling legitimate grounds that override your interests, or need the data for a legal claim.

3.6 Right to data portability (Article 20)

Request an export of your data in a structured, commonly used, machine-readable format (JSON or CSV) via [email protected]. Export requests are processed within 30 days.

4. Data protection by design and by default

  • Local-first architecture: sensitive agent activity stays on-device unless you opt into cloud sync
  • Granular sync policy: organizations choose exactly which fields are synced to the cloud dashboard
  • No training of third-party foundation models on your data
  • Access to cloud-stored data is limited to authorized personnel on a least-privilege basis
  • Encryption in transit for all data sent to our cloud infrastructure

5. International data transfers

Where personal data is transferred outside the EEA or UK — for example, to infrastructure providers with data centers in the United States — we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, and require our sub-processors to maintain equivalent protections.

6. Data breach notification

If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, as required by GDPR Article 33, and will notify affected individuals directly without undue delay where the breach is likely to result in a high risk, as required by Article 34.

7. Children's privacy

The Platform is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect personal data from children. If we learn that we have inadvertently collected a child's personal data, we will delete it promptly.

8. Automated decision-making

Agentbeam's scanners and risk-flagging rules are heuristic pattern matches, not automated decisions that produce legal or similarly significant effects on you within the meaning of GDPR Article 22 — a flagged action is a recommendation for human review, never an automatic account or access decision. We do not use profiling to make decisions about individuals.

9. Sub-processors and Data Protection Officer contact

We use a limited set of sub-processors to operate the cloud dashboard and website:

Sub-processorPurpose
Cloud infrastructure providerHosting for the cloud dashboard and account data
Payment processorSubscription billing
Google AnalyticsAggregate website usage measurement
PostHogProduct analytics on the marketing website
Email delivery providerTransactional and account emails

An up-to-date, named sub-processor list, and a signed Data Processing Addendum for enterprise and team customers, is available on request. GDPR inquiries can be sent to:

  • Email: [email protected]
  • Subject line: “GDPR Request — [Type of Request]”
  • Response time: within one month, typically within 5 business days
  • Company: AISOLO Technologies Private Limited, CIN: U62099MH2023PTC403351
  • Registered office: 1003, Kamdhenu Commerz, Sector 14, Kharghar 410210, Navi Mumbai, Maharashtra, India

10. Exercise your GDPR rights

To exercise any of your GDPR rights:

  • Email [email protected]
  • Subject: “GDPR Request — [Right to Access / Erasure / Rectification / Portability / Restriction / Objection]”
  • Include your account email and the specific request details
  • We may request identity verification before actioning a request
  • Response: within one month, extendable by two further months for complex requests, with notice

If you are not satisfied with our response, you may lodge a complaint with your local EU/UK supervisory authority. See also our Data Rights page for rights under other jurisdictions.