These terms form part of your subscription agreement and meet the requirements of Article 28 GDPR. They apply whenever we process personal data on your behalf.
Last updated: 21 July 2026
For the personal data of your customers and contacts, you are the controller and we are the processor. You decide why the data is collected and what happens to it; we act on your instructions. For our own website and our own business contacts, we are the controller and our Privacy Policy applies instead.
We process personal data only to provide the service you subscribed to: running your digital employee, your workspace, your mail and your automations. Typically that means contact details, order and transaction records, support conversations and any documents you or your customers put into the system. The categories of people involved are your customers, your leads, and your own staff who use the workspace. We do not seek special-category data. Because we host mailboxes, correspondence may incidentally contain some — a customer describing a health problem, for instance — and where that happens we do not process it for any purpose beyond delivering and storing the message.
We process personal data only on your documented instructions, which include this agreement and your normal use of the platform. If we ever believe an instruction breaches data protection law, we will tell you rather than quietly comply. Everyone with access is bound by confidentiality.
We use sub-processors to run the service, and each is bound by terms at least as strict as these. The current list is published at /agent/subprocessors.json and in your workspace. We will give you at least 30 days' notice before adding or replacing one, and you may object; if we cannot resolve your objection you may terminate without penalty for the remainder of the paid period.
By default we process on providers covered by an adequacy decision or equivalent safeguards, and we send only the operational context required for service continuity — not your whole memory. You may elect a different model provider for your own agents: your election is recorded in your subscription agreement and that provider becomes an authorised sub-processor for your data alone. Where an elected provider is not covered by an adequacy decision, we will tell you so in writing before it is activated, together with the safeguards available and their limits, so that you decide with the facts in front of you. Your election never changes what runs anywhere else on the platform.
Data is encrypted in transit and at rest. Each client's data lives in a separate tenant, isolated from every other client. Access is limited to those who need it, over authenticated channels, and is logged. Our own agents monitor the platform continuously and raise faults before they become incidents. We test and update these measures as the service changes.
If one of your customers exercises a right — access, correction, erasure, portability, objection — we will help you answer it, and we give you the tools to do most of it yourself from the workspace. We will also help with impact assessments and with any regulator who comes asking.
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any event within 48 hours, with what we know, what we are doing, and what we think you should do. You make the regulator notification, because you are the controller; we give you what you need to make it.
Your digital employee has a memory, and that memory is what makes it useful. It also means erasure needs to be handled more carefully than deleting a row from a table, so this clause says exactly how it works.
We hold the memory in two separate layers. The first records specific events involving identifiable people — that a named customer ordered twice and is waiting on a refund. That layer is personal data. It is kept for as long as it is useful for the service and in any event no longer than 24 months, unless you instruct otherwise in writing, and it is erased on request.
The second layer holds what the employee has learned, with the people taken out — that customers who order twice and then ask for a refund usually want an exchange offered first. That layer carries no personal data, cannot be traced back to an individual, and is therefore not subject to erasure. It is the same distinction a human colleague lives with: after five years they remember how to handle a refund dispute, not the name of every customer from 2021.
When you exercise erasure, we delete the identifiable layer, including the derived vector representations of it — deleting the text but keeping the embedding does not count as erasure and we do not treat it as such. What survives is the general lesson, and your employee keeps doing its job.
When the subscription ends we make your data available to export for 30 days, then delete your entire tenant — both layers, and the backups on their normal rotation. We retain only what the law requires us to keep, such as invoices.
Mail is treated differently from agent memory. We do not delete your mailboxes on a timer: each has a storage allowance, and when it fills we ask you to clear space rather than removing anything ourselves. Mail is also forwarded to your own server, so a copy exists outside our systems at all times.
We will give you the information you reasonably need to show that we meet these obligations, and we will accommodate an audit at reasonable notice and frequency, either by you or by an auditor you appoint who is not our competitor.
Está hablando con una IA. Aria es una empleada digital automatizada, no una persona.
Una vista previa de un empleado digital real. En tu web, este es tuyo: formado en tu negocio, tus productos y tus clientes.