1. Scope & role
Agentico ("Agentico," "we," "us," or "our") operates agentico.llc and related APIs, MCP servers, and SDKs (the "Service"). This Privacy Policy describes how we handle personal information about visitors, account holders, and API users ("you").
For purposes of applicable privacy laws, Agentico is the business responsible for processing personal information described here. Where we process personal information solely on behalf of a business customer under a separate data processing agreement, that agreement controls for that processing.
2. Information we collect
Information you provide
- Account data: name, email address, and profile image when you sign in via Google Identity Services or other supported providers.
- Contact data: phone numbers submitted on the landing page or forms, including MFA provisioning metadata.
-
Formation data: series names, purposes, responsible-party attestations
(
human_approval), contract hashes, and related metadata submitted through Formation verbs. - Support & legal communications: messages you send to our privacy team or our legal team.
Information collected automatically
- Usage & audit data: MCP verb invocations, timestamps, request identifiers, error codes, and SDK/API activity needed to operate and secure the Service.
- Device & network data: IP address, browser type, operating system, and approximate location derived from IP.
- Session data: signed session cookies for authenticated areas.
Information from third parties
- Identity providers: Google token claims used to verify your identity at signup (subject to Google's policies).
- Payment processors (if enabled): billing status and limited payment metadata — we do not store full payment card numbers on our servers.
Phone capture may provision TOTP authentication secrets for MFA enrollment. We do not intentionally collect government ID images or full bank account numbers through v0.1. Do not submit information you are not required to provide.
3. How we use information
We use personal information to:
- provide, operate, and maintain the Service;
- authenticate users and prevent fraud, abuse, and security incidents;
- generate formation artifacts and audit trails you request;
- communicate about the Service, including security and legal notices;
- comply with law, enforce our Terms, and protect rights;
- analyze aggregated, de-identified usage to improve reliability; and
- process payments and account billing where applicable.
NO SALE OF PERSONAL INFORMATION. We do not sell or share personal information for cross-context behavioral advertising. We do not use phone numbers collected on the landing page for unrelated telemarketing or promotional SMS without separate opt-in.
4. Subprocessors
We use infrastructure and service providers listed at /legal/subprocessors. Each processes data only as necessary to provide the Service under contractual confidentiality obligations.
7. Retention
We retain personal information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type:
- account and formation audit data: duration of account plus a reasonable backup period;
- phone leads: until you request deletion or accounts are inactive for 24 months;
- TCPA/SMS consent records: at least seven (7) years;
- security logs: typically up to 12 months unless longer retention is required by law.
We may retain de-identified or aggregated data indefinitely.
8. Security
We implement administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, access controls, and signed session tokens. No method of transmission or storage is 100% secure.
YOU ARE RESPONSIBLE FOR PROTECTING API KEYS AND CREDENTIALS. Compromise of your keys may expose formation data and permit unauthorized verb invocation.
9. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or port certain personal information, and to opt out of certain processing. To exercise rights, email our privacy team with the address associated with your account. We may verify your identity before responding.
California residents (CCPA/CPRA)
California residents may request: (1) categories and specific pieces of personal information collected; (2) deletion, subject to exceptions; and (3) correction of inaccurate information. We do not sell or share personal information for cross-context behavioral advertising as defined by California law. You may designate an authorized agent with written permission. We will not discriminate against you for exercising privacy rights.
Other U.S. state privacy laws
Where state comprehensive privacy laws apply, we honor applicable rights to access, delete, correct, and appeal denials as required.
EEA/UK (if applicable)
The Service is directed at U.S. entity formation. If you are in the EEA/UK and we process your personal information, you may have additional rights under GDPR/UK GDPR. Contact our privacy team.
10. Children
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child provided information, contact us to request deletion.
11. International users
Agentico is operated from the United States. If you access the Service from outside the U.S., you understand that personal information may be processed in the U.S. and other countries where we or our providers operate, which may have different data protection laws.
12. Changes
We may update this Privacy Policy by posting a revised version with a new effective date. Material changes will be highlighted on the Service. Continued use after the effective date constitutes acknowledgment of the update.
13. Contact
Agentico
Principal contact: email below; physical service-of-process address available on request at
our legal team per
Legal Entity & Notices.
Email: our privacy team
Legal: our legal team
Web: https://www.agentico.llc