1. Scope and roles
This policy applies to the AGENEON website and service. AGENEON ("AGENEON", "we", "us", or "our") is the company and public identity responsible for the service. Its formal registered suffix, registration number, registered address, and jurisdiction will be inserted when registration details are finalized.
For account, security, and service-administration data, AGENEON determines why and how the data is processed. For customer, lead, and conversation data submitted to a workspace, the business customer generally determines the purposes and AGENEON processes that data on its behalf. The customer remains responsible for its notices, permissions, and lawful instructions.
2. Information about AGENEON users
We process information needed to create, secure, and operate accounts and workspaces.
- Account and authentication data, such as name, email address, password-authentication records managed by Supabase, authentication provider identifiers, session records, and account recovery activity.
- Workspace and business profile data, including workspace name, business name, business model, industry, market, locale, onboarding state, and configuration choices.
- Team and membership data, including user identifiers, workspace roles, operational roles, membership state, and actions taken by owners or administrators.
- Agent and service configuration, including display name, instructions, role, capabilities, guardrails, response style, handoff settings, catalog information, channel settings, and connected-resource approvals.
- Operational and security metadata, such as request identifiers, record timestamps, processing outcomes, bounded error classifications, connection status, token-expiry metadata, browser session cookies, and information ordinarily present in network requests, such as IP address, origin, user agent, and device/browser characteristics, where retained by the application or infrastructure provider.
3. Data processed for business customers
A workspace may process information about its own customers, prospects, and website visitors. AGENEON handles this content only to provide and secure the service under the workspace's instructions.
- Customer and lead records, which may include name, email, phone or another contact method, language, notes, interest, lead status, qualification details, and interaction timestamps.
- Conversation data, including incoming customer messages, AI-generated replies, channel and conversation state, handoff signals, limited runtime metadata, and internal test conversations. The implementation does not store hidden prompts, provider payloads, chain-of-thought, or credentials in conversation messages.
- Anonymous Website Chat data, including a random session-token hash, allowed site origin, locale, messages, rate-limit counters, and conversation state. A customer record is not required for an anonymous visitor.
- Information that a business user or visitor voluntarily puts into a conversation. Customers should configure agents not to request unnecessary sensitive information and should not submit data the service is not intended to handle.
4. Knowledge Base, files, websites, and vectors
Workspace owners and administrators can add manual text, upload currently supported UTF-8 TXT files, or ask AGENEON to ingest public website pages. Earlier interface foundations reference PDF and DOCX, but current processing accepts TXT only; unsupported files are not represented here as processed content.
For website sources, the service may retrieve selected same-site public pages, sitemap entries, page titles, URLs, canonical URLs, normalized text, content hashes, status/error codes, and processing timestamps. Requests are bounded and exclude common account, authentication, cart, checkout, admin, and search paths.
Knowledge text is divided into chunks and sent to OpenAI to create numerical embeddings. AGENEON stores the text chunks and vector representations in the workspace's Supabase database so relevant passages can be retrieved for an agent response. Reprocessing replaces the prior page and chunk set for that source.
5. Google OAuth and Calendar data
Google sign-in through Supabase Auth is separate from the Google Calendar connection. The Calendar connection currently requests only calendar.calendarlist.readonly, calendar.events.freebusy, and calendar.events.owned. AGENEON does not request Gmail or Google Contacts access.
AGENEON uses calendar list access to discover calendars subscribed to by the authorizing user and stores limited resource metadata such as the calendar identifier, display name, ownership/write eligibility, time zone, and approval state. Discovered calendars are disabled until an owner or administrator approves them.
For approved calendars, AGENEON may query free/busy windows. Event creation is optional, is available only for an approved calendar owned by the authorizing Google user, must be explicitly enabled, and requires a trusted approval context. Event data may include a bounded title, start/end time, time zone, description, location, and at most one guest.
Google access and refresh tokens are exchanged and used only on the server, encrypted at rest with AES-256-GCM using a server-held key, and excluded from browser payloads and ordinary logs. Connection metadata and granted scopes are stored separately from credentials. Owners and administrators can disconnect the connection, which attempts Google token revocation and removes the connection and its dependent stored credentials/resources. Users may also revoke AGENEON in their Google Account security settings.
AGENEON's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Why we process information
We use information to authenticate users; create and administer workspaces; provide conversations, customer records, knowledge retrieval, AI responses, handoff state, channels, and approved integrations; prevent abuse; diagnose failures; maintain availability and security; respond to support, privacy, and deletion requests; comply with law; and improve service reliability.
We minimize collection through bounded request sizes, limited runtime history, narrow OAuth scopes, approved calendar resources, metadata-only operational logs, and provider requests configured not to store Responses API output where supported by the implementation.
7. Service providers and disclosures
AGENEON uses service providers to deliver the service, including Supabase for authentication, database, and file storage; OpenAI for AI responses and embeddings; and Google APIs for user-authorized Calendar operations and authentication as configured. See the Subprocessors page for the current code-evidenced list.
We may disclose information when reasonably necessary to comply with law, protect rights and security, investigate abuse, or complete a business transaction subject to appropriate safeguards. We do not describe GitHub as a production customer-data processor based on the current repository evidence.
8. International processing
AGENEON is intended for international use. Service providers may process data in countries other than the user's or customer's country. Exact production project regions and legal transfer arrangements depend on provider and deployment configuration and require owner confirmation; we do not state an unverified data-residency location.
9. Retention and deletion
We retain account and workspace data while needed to provide the service, meet security and legal obligations, resolve disputes, and enforce agreements. The product currently supports deletion of individual Knowledge Base sources and disconnection of Google Calendar, but it does not expose a complete automated account or workspace deletion workflow.
Authorized requests for account, workspace, customer, contact, or conversation deletion are handled through a verified support process. Data may remain temporarily in backups, security records, or provider systems until ordinary rotation or legal requirements permit deletion. Exact production retention periods have not been formally confirmed, so this policy does not promise a fixed number of days. See Data Deletion for instructions.
10. Security
We use safeguards evidenced by the implementation, including workspace-scoped database access, Supabase row-level security, authenticated role checks, server-only secrets and privileged clients, encrypted Google Calendar tokens, hashed OAuth state and Website Chat session tokens, origin restrictions, bounded inputs and logs, and network protections for website ingestion. No system is completely secure, and AGENEON does not claim a certification or guarantee against every incident.
11. Access, correction, and privacy rights
Depending on applicable law, an individual may ask to access, correct, export, restrict, object to processing of, or delete personal information, or withdraw consent. AGENEON may verify identity and authority before acting.
If the request concerns data controlled by an AGENEON business customer, contact that business first. We will support the customer where required and will not override its lawful instructions without a valid basis.
12. Workspace responsibilities
Business customers must provide required privacy notices, obtain appropriate permissions, honor data-subject requests, configure access and agents responsibly, approve only necessary integrations and calendar resources, and avoid uploading or soliciting unlawful or unnecessary sensitive data. Workspace owners control membership and should remove access when no longer needed.
13. Children
The intended minimum age and any child-directed restrictions require owner and jurisdiction confirmation. Until then, the service is not designed for children, and customers must not knowingly use it to collect children's personal data without a lawful basis and appropriate safeguards.
14. Updates and contact
We may update this policy as the service, providers, or law changes. Material changes will be reflected by a new last-updated date and, where appropriate, additional notice.
AGENEON's registered suffix, registration number, registered address, and jurisdiction will be added when finalized. Dedicated privacy contact details also remain to be established. Until published, submit privacy questions or requests through the verified support channel included in your AGENEON onboarding or account correspondence and identify the workspace and request type. Do not send passwords, tokens, or unnecessary sensitive information.