GDPR Compliance
Last updated: January 1, 2026
1. General
1.1 AISOLO Technologies Private Limited [CIN: U62099MH2023PTC403351] operates Agentbeam and is committed to GDPR compliance for every EU and UK data subject, regardless of where they access the Platform from.
1.2 This document sets out our legal bases for processing, your rights as a data subject, and how we protect your personal data across the website, local runtime recorder, browser extension, command-line tools and cloud dashboard.
1.3 Agentbeam is architected privacy-first: the most sensitive data — the content of agent shell commands, file diffs and tool-call arguments — is recorded locally by default and is never transmitted to us unless you explicitly enable cloud sync. This data minimization by design substantially reduces what GDPR rights we need to act on, because for most users, most data never reaches us at all.
2. Legal basis for processing
2.1 Lawful bases under GDPR Article 6
- Consent (Article 6(1)(a)): marketing communications, optional website analytics, and browser extension permissions you grant
- Contract (Article 6(1)(b)): providing the Service to a registered account, including cloud dashboard sync, billing, and support
- Legal obligation (Article 6(1)(c)): tax and financial record-keeping, and responding to lawful regulatory requests
- Legitimate interest (Article 6(1)(f)): security monitoring, fraud prevention, and improving the reliability of the Platform
2.2 Special category data
- We do not seek to process special category data under GDPR Article 9
- Synced agent activity is technical and operational in nature (commands, file paths, rule matches) — it is not designed to capture special category data, and your organization controls what fields are synced
- Browser extension access to page content requires explicit browser permission and never leaves your device
3. Your GDPR rights
3.1 Privacy-by-design implementation
Because most Platform data is local by default, several GDPR rights are effectively pre-satisfied for the local recorder and browser extension: data minimization (we only receive what you sync), storage limitation (retention windows below), and purpose limitation (synced fields are scoped to your organization's own policy).
3.2 Right of access (Article 15)
- View account and billing information from your cloud dashboard settings
- Request a full export of the personal data we hold via [email protected]
- Response time: within one month, typically within 5 business days
3.3 Right to rectification (Article 16)
- Update account details directly in dashboard settings
- Request correction of any other inaccurate data via [email protected]
3.4 Right to erasure (Article 17)
- Request full account and synced-data deletion via [email protected]
- Locally recorded data can be deleted immediately and directly by you using the Platform's local tooling — no request to us required
- Cloud-side deletion is completed within 14 working days, and residual backups are purged within 45 days, subject to legal retention requirements (e.g. billing records)
3.5 Right to restrict or object to processing (Articles 18 & 21)
You may ask us to restrict processing of your data, or object to processing based on legitimate interest, by writing to [email protected]. We will honor the request unless we have compelling legitimate grounds that override your interests, or need the data for a legal claim.
3.6 Right to data portability (Article 20)
Request an export of your data in a structured, commonly used, machine-readable format (JSON or CSV) via [email protected]. Export requests are processed within 30 days.
4. Data protection by design and by default
- Local-first architecture: sensitive agent activity stays on-device unless you opt into cloud sync
- Granular sync policy: organizations choose exactly which fields are synced to the cloud dashboard
- No training of third-party foundation models on your data
- Access to cloud-stored data is limited to authorized personnel on a least-privilege basis
- Encryption in transit for all data sent to our cloud infrastructure
5. International data transfers
Where personal data is transferred outside the EEA or UK — for example, to infrastructure providers with data centers in the United States — we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, and require our sub-processors to maintain equivalent protections.
6. Data breach notification
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, as required by GDPR Article 33, and will notify affected individuals directly without undue delay where the breach is likely to result in a high risk, as required by Article 34.
7. Children's privacy
The Platform is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect personal data from children. If we learn that we have inadvertently collected a child's personal data, we will delete it promptly.
8. Automated decision-making
Agentbeam's scanners and risk-flagging rules are heuristic pattern matches, not automated decisions that produce legal or similarly significant effects on you within the meaning of GDPR Article 22 — a flagged action is a recommendation for human review, never an automatic account or access decision. We do not use profiling to make decisions about individuals.
9. Sub-processors and Data Protection Officer contact
We use a limited set of sub-processors to operate the cloud dashboard and website:
| Sub-processor | Purpose |
|---|---|
| Cloud infrastructure provider | Hosting for the cloud dashboard and account data |
| Payment processor | Subscription billing |
| Google Analytics | Aggregate website usage measurement |
| PostHog | Product analytics on the marketing website |
| Email delivery provider | Transactional and account emails |
An up-to-date, named sub-processor list, and a signed Data Processing Addendum for enterprise and team customers, is available on request. GDPR inquiries can be sent to:
- Email: [email protected]
- Subject line: “GDPR Request — [Type of Request]”
- Response time: within one month, typically within 5 business days
- Company: AISOLO Technologies Private Limited, CIN: U62099MH2023PTC403351
- Registered office: 1003, Kamdhenu Commerz, Sector 14, Kharghar 410210, Navi Mumbai, Maharashtra, India
10. Exercise your GDPR rights
To exercise any of your GDPR rights:
- Email [email protected]
- Subject: “GDPR Request — [Right to Access / Erasure / Rectification / Portability / Restriction / Objection]”
- Include your account email and the specific request details
- We may request identity verification before actioning a request
- Response: within one month, extendable by two further months for complex requests, with notice
If you are not satisfied with our response, you may lodge a complaint with your local EU/UK supervisory authority. See also our Data Rights page for rights under other jurisdictions.