Legal

Privacy Policy

Effective June 24, 2026

Welcome to Agentive Concepts (referred to as "AC STUDIO", "Company", "we", "us", or "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our platform, dashboard, APIs, webhooks, and white-label AI sales agent infrastructure accessible via our domains and subdomains.

We believe in absolute transparency. This policy is written in plain English without the standard corporate obfuscation (PostHog style). If you are an agency reselling our services or a direct customer, this document maps out exactly what happens to your data and your end-users' data.

01

Core Architecture & Data Roles

Depending on how you interact with AC STUDIO, we act as either a Data Controller or a Data Processor under the General Data Protection Regulation (GDPR) and other global privacy frameworks:

  • We act as a Data Controller for personal data related to your direct agency account, billing configurations, payment tokens, support requests, and platform telemetry.
  • We act as a Data Processor for the business data, contacts, and communication content that you, your sub-accounts, and your end-users process through our active communication channels (including WhatsApp, Instagram, Messenger, Telegram, Email, web chat, and SMS).

For White-Label / Sub-Account End Users

If you are an end-user interacting with an agency's custom-branded white-label deployment of AC STUDIO, the Agency is the Data Controller for your personal data. We act strictly as the back-end technical Data Processor operating under the documentation and instructions provided by that specific Agency. End-users in these scenarios should consult the respective Agency's own privacy policy.

02

Information We Collect

We do not sell your data, and we do not participate in cross-context behavioral advertising. We collect data across the following categories:

A. Information You Give Us Directly

  • Account Configuration: Name, email address, phone number, company name, primary business role, billing address, and tax identifiers.
  • Profile Customization: Logos, brand names, custom domain pairings, primary and accent colors, and transactional email signatures used to rebrand the dashboard.
  • Workspace & Context Setup: Ingested client websites, scraped product listings, custom FAQs, custom function configurations, webhook targets, and manual bot instruction guidelines.
  • Communications: Helpdesk tickets, emails sent to hello@agentiveconcepts.com, and any diagnostic screenshots or logs you explicitly share.

B. Business Data Processed Through the Services

  • CRM & Contacts: Contact information automatically ingested or imported (names, phone numbers, emails, social profile IDs, and custom tags).
  • Omnichannel Conversations: Full text strings, voice notes, static images, videos, and document attachments sent or received by your end-users across connected channels.
  • Custom Function Inputs/Outputs: Transient payloads moving through our API endpoints or custom third-party platform functions.

C. Payment & Transactional Billing

When you purchase subscription tiers or top up automated message credits, all payment parameters are processed directly through our secure billing partner, Stripe. We never store raw credit card numbers on our physical servers. We maintain only secure reference tokens, card brand identification, the last four digits of the active card, and the associated billing history.

D. Third-Party OAuth & Connected Platform Data

  • Google & Meta Authentication: Tokenized OAuth profile data used to verify identity, enable Calendar appointment bookings, or sync assets.
  • Channel Meta-Data: Unique page identifiers, target phone numbers, or administrative configuration details supplied by Meta Platforms or Twilio when connecting live messaging environments.

E. Telemetry & Automated Log Collection

  • Usage Telemetry: Active pages visited within the dashboard, UI actions triggered, error tracking logs, and performance statistics.
  • Network & Device Context: IP addresses, browser engine configurations, operating system footprints, tracking referral URLs, and approximate geolocation data derived via IP analysis.
03

How We Use Information

We process information strictly to execute core business features, honor contractual obligations, or maintain our legitimate security interests:

  • Service Provisioning: Running, maintaining, metering, and enhancing the white-label AI sales agent ecosystem.
  • AI Conversational Processing: Submitting text strings to advanced language models (Anthropic Claude) and processing rich multimedia files (voice note transcription, image screening, video analysis) using Google Gemini.
  • Omnichannel Message Delivery: Formatting and routing messages across live production endpoints (WhatsApp Cloud API, Instagram Graph API, Messenger, Telegram API, SMTP Email relays, Web Chat gateways, and SMS infrastructure).
  • Administrative Operations: Managing automated billing tiers, calculating custom credit markup distribution, and identifying systemic subscription fraud.
  • Security Enforcement: Diagnosing rate-limit triggers, monitoring malicious workspace activity, and blocking coordinated bot attacks.
04

AI Processing Transparency & Model Training

We reject the practice of treating user data as free R&D material. We do not use your Customer Data, your client accounts' configurations, or your end-users' private conversations to train AI models unless you explicitly request a custom enterprise fine-tuning workflow under a separate written agreement.

  • Anthropic Claude & Google Gemini: Our platform hooks into these foundational models using verified enterprise API accounts. Under these strict enterprise parameters, both Anthropic and Google are legally barred from logging or utilizing our API request payloads to train their baseline commercial models.
  • Bring Your Own Key (BYOK): If you configure your workspace to operate using your personal Anthropic API key, all AI pipeline requests are routed and billed directly under your standalone legal agreement with Anthropic.
  • Human-in-the-Loop Safeguards: Our AI agents excel at autonomous call scheduling, lead qualification, and close management. However, they do not execute legally binding decisions on their own. We incorporate an optional Assist/Human Mode that allows human operators to seize manual control of any sub-account conversation thread instantly.
05

Sub-Processors & Infrastructure Map

To deliver a scalable architecture, we partner with specialized sub-processors. Every technical sub-processor is bound to robust Data Protection Agreements (DPAs) meeting or exceeding GDPR Article 28 expectations.

Sub-ProcessorOperational FocusData Center Jurisdiction
AnthropicCore Large Language Model processing (Claude engine)United States
GoogleGemini API (Media/Voice translation), Calendar & Drive OAuth integrationsUnited States / European Union
Meta PlatformsWhatsApp Business Cloud API, Instagram Graph API, Messenger routesUnited States / European Union
TwilioTelco SMS processing and system number routingUnited States
StripePayment gateway execution, subscription meters, and merchant processingUnited States / European Union
HetznerDedicated bare-metal cloud infrastructure (WhatsApp Web sessions & local tool sets)Germany (EU)
Google Cloud PlatformRegional cloud function compilation and dynamic micro-servicesEuropean Union
Firebase (Google)Secure user authentication databases and real-time Firestore layersEuropean Union
ComposioApp integration infrastructure maps for modular Custom FunctionsUnited States
BrightDataNetwork proxies utilized exclusively for localized WhatsApp connectivityUnited States / Israel
AlgoliaEnterprise indexing for immediate workspace dashboard searchesEuropean Union
06

International Data Transfers & Safeguards

While AC STUDIO's primary operations are managed within the European Economic Area (specifically utilizing dedicated infrastructure in the Netherlands and Germany), executing global messaging pipelines requires routing data to global sub-processors.

When data is transferred outside the European Economic Area (EEA) or the United Kingdom, we rely upon established compliance mechanisms:

  1. 01.Standard Contractual Clauses (SCCs): We implement the European Commission's standard clauses (Decision 2021/914) with all non-EU infrastructure partners.
  2. 02.UK International Data Transfer Addendum: Applied to ensure equivalent protections for records technical to the UK market.
  3. 03.Adequacy Decisions: Utilized for data processing partners operating in recognized safe jurisdictions (such as Israel).
07

Data Retention Protocols

We clean up data according to clear schedules rather than hoarding records indefinitely:

  • Active Platform Contexts: Account data, brand settings, and instruction sets remain active for the natural lifecycle of your active subscription.
  • Conversations & Logs: Threads, message payloads, and interaction histories are retained for three (3) years from the date of the last contact interaction by default. Workspace administrators can adjust this to a shorter automated deletion timeframe directly inside the dashboard.
  • Financial Records: Invoices, Stripe reference logs, and ledger items are legally archived for seven (7) years to satisfy Dutch tax and audit laws.
  • System Backups: Production server snapshot backups are fully rotated and permanently overwritten within a rolling 90-day window.
  • Account Termination: Following an explicit request to cancel your subscription, you are granted a 30-day export window to retrieve workspace configurations. Once that window closes, automated extraction and hard deletion scripts scrub the production databases.
08

Your Global Privacy Rights (GDPR / UK GDPR / CPRA)

No matter your geographic jurisdiction, we support comprehensive control over your personal data. If you are located in the EEA, UK, Switzerland, or California, you maintain the following actionable rights:

  • Right of Access & Portability: Request a structured, machine-readable export of all direct personal data we store linked to your identity.
  • Right of Rectification: Instantly update inaccurate, obsolete, or broken profile parameters inside your dashboard.
  • Right of Deletion ("Right to be Forgotten"): Request the permanent erasure of direct account records, subject to overriding statutory tax archiving constraints.
  • Right to Object & Restrict: Deny consent for processing built around our legitimate interests or restrict specific platform features.
  • Right to Limit Sensitive Data: We do not process sensitive personal markers (health, political leanings, genetics) or track high-risk user profiles.

To trigger an official request regarding your rights, submit an email with verifiable identity parameters to: hello@agentiveconcepts.com. We review and process valid compliance requests within 30 days.

09

Security Framework

We secure data through modern, layered technical controls:

  • Encryption in Transit: Every network payload, API call, and dashboard session is protected via TLS 1.2 or TLS 1.3 configurations.
  • Encryption at Rest: Sensitive storage parameters, database fields, API configurations, and Meta/Anthropic integration tokens are encrypted using AES-256 standard protocols.
  • Access Isolation: Internal platform administration relies on strict role-based access controls following the principle of least privilege.
  • Incident Response Framework: In the event of a security anomaly or suspected data compromise, we execute a documented response protocol. If a breach poses a significant risk to user rights, we notify relevant supervisory authorities (such as the Dutch Autoriteit Persoonsgegevens) within 72 hours, alongside a direct disclosure to impacted account holders without undue delay.
10

Policy Evolution

We update this documentation to reflect changing regulatory requirements and infrastructure upgrades. If an amendment fundamentally impacts your processing rights, we will notify you via a direct system alert or dashboard notification at least 30 days before the updated policy takes effect. Non-material alignment updates are published here immediately with a revised date at the top of the page.

11

Onboarding & Account Management Terms

The following terms describe what is included with each subscription plan and billing cadence regarding onboarding services, dedicated account management, and ongoing strategy meetings. These terms form part of our Terms of Service and supplement the Privacy Policy above (which governs how any personal data shared during these engagements is processed).

A. CSM-Guided Onboarding (€999 value)

Our flagship onboarding is a structured, Customer Success Manager (CSM)-guided implementation program covering workspace configuration, channel connection, knowledge base ingestion, prompt tuning, and a live launch checklist. Its standalone retail value is €999. It is included free of charge under the conditions described below.

  • Pro plan (monthly or annual): CSM-guided onboarding is always included free. Pro is the only tier where the program is bundled regardless of billing cadence.
  • Starter & Growth: Annual billing. CSM-guided onboarding is included free as part of the annual commitment.
  • Starter & Growth: Monthly billing. CSM-guided onboarding is not included. Customers instead receive a single (1×) onboarding call to validate setup. The full CSM program can be purchased separately at the standard €999 fee, or unlocked by upgrading to an annual plan or to Pro.

B. Dedicated Account Manager & Monthly Strategy Meetings

  • Pro plan (monthly or annual): A dedicated Account Manager / CSM and recurring monthly strategy meetings are always included.
  • Starter & Growth: Annual billing. A dedicated Account Manager and monthly strategy meetings are included for the duration of the annual term.
  • Starter & Growth: Monthly billing. No dedicated Account Manager and no recurring strategy meetings. Support is delivered through shared support channels (email and helpdesk).

C. Annual Commitment, Downgrades & Refunds

Annual plans are billed upfront for a 12-month term. The CSM-guided onboarding and the dedicated AM / monthly meetings are delivered against that annual commitment. If an annual subscription is cancelled or downgraded to a monthly plan before the term ends, the €999 onboarding value and any account-management hours already consumed become payable and may be deducted from any pro-rated refund, in line with our Terms of Service.

D. Scheduling, Delivery & Scope

  • Sessions are delivered remotely via video conferencing and are scheduled through the booking link shared by your CSM.
  • The 1× onboarding call (monthly Starter/Growth) is a single working session, typically 45–60 minutes, focused on initial setup.
  • Monthly strategy meetings (annual & Pro) are recurring working sessions, typically 30–60 minutes, focused on performance review, optimization, and roadmap alignment.
  • Missed sessions without prior notice are not automatically rescheduled; please cancel at least 24 hours in advance through the provided booking link.

E. Confidentiality & Data Handling During Onboarding

Any business data, credentials, prompts, or documents shared with a CSM or Account Manager during onboarding or recurring meetings are processed under the same roles, sub-processors, retention schedules, and security controls defined in sections 01–09 of this Privacy Policy. CSMs and Account Managers are bound by internal confidentiality obligations and access data strictly on a need-to-know basis to deliver the service.

F. Changes to Included Services

We may adjust the scope, format, or value of CSM-guided onboarding and account-management services for new subscriptions. Plans already active at the time of a change keep the inclusions of their current billing term; any modification takes effect at the next renewal and is communicated in advance per section 10.

12

Contact & Legal Identity

For any questions regarding this Privacy Policy, your data pathways, or model isolation workflows, please reach out to us:

Agentive Concepts (AC STUDIO)

Email: hello@agentiveconcepts.com

WhatsApp Contact: https://wa.me/31600000000