Skip to content
iAgentify

Guide

Privacy: where data is stored and who can see it

Your data is hosted in the European Union and only your team sees it. What is sent to the AI to write a reply, which providers are involved and how to exercise your rights.

Reviewed on
5 min read
In this article

Your account’s data is stored on servers located in the European Union and is only seen by the people on your team, each according to their role. An AI provider takes part in writing the replies, and it receives what is needed to answer and nothing else. This article explains it in plain words.

Where the data is stored

The database, the documents you upload to the knowledge, the conversations and the leads are stored on servers located in the European Union.

Who can see it

Each business works in its own account. Your agents, your knowledge sources, your conversations and your leads are only accessible to the users of your account: on every request, iAgentify checks which account you belong to and what role you hold.

  • You decide who gets in and with which role. There are four roles. Billing belongs to the Owner, and Read only can only look. Bear in mind that every role, including that one, can read conversations and see and export leads. The detail is in team roles.
  • Whoever leaves the team loses access. When you remove a person from Team, they lose access to the account and their sessions end at once.
  • There is a record of what is done. Admins and owners have the Activity log under Settings › Company: sign-ins, team changes, billing and configuration, with who and when.
  • The iAgentify team. Any access to an account by the iAgentify support team is recorded. You can see it in that same log: in the filter, which starts on All activity, choose iAgentify team.
  • Your own sign-in. iAgentify verifies your email when you sign up and locks the account for a while after several failed sign-in attempts. If you use the iAgentify assistant on WhatsApp, it asks for your support PIN before showing anything from your account.

What is sent to the AI to write a reply

To write each reply, iAgentify sends the language-model provider (OpenAI) the customer’s message, the conversation context, your agent’s instructions and the relevant passages from your knowledge. Nothing else. The same provider is involved when knowledge is indexed, that is, when a source is added or re-indexed.

iAgentify does not use your conversations or your documents to train AI models. Under OpenAI’s terms for its API, data sent that way is not used to train its models by default either.

Which providers are involved, and when

These third parties take part so that the service works.

ProviderPurposeWhen it is involved
OpenAILanguage-model processingOn every agent reply and when indexing knowledge
MetaDelivery of WhatsApp and Instagram messagesOnly if you connect those channels
TwilioDelivery of WhatsApp messagesOnly if you connect WhatsApp with a Twilio number: one from your own Twilio account or one iAgentify sets up for you
Redsys and the bankCard paymentsWhen you subscribe, renew or buy credits
Hosting provider in the European UnionHosting of the platform and the dataAlways

The full detail is in the privacy policy.

What is stored encrypted and what never reaches iAgentify

  • Channel credentials. What is needed to connect WhatsApp and Instagram is stored encrypted and is never shown again, in the app or through the API. You can disconnect a channel at any time from Channels.
  • Card. Card details are entered on the bank’s page: iAgentify neither receives nor stores them. It keeps, encrypted, a reference to charge renewals, and the last four digits so that you can recognise the card.
  • Password and support PIN. They are not stored in readable form: only what is needed to check them is kept.
  • API keys. Each key is shown in full only once, when it is created.

The chat code carries a public key, which anyone can see on your website. That is why it is worth listing your domains: from then on, the chat only works on them. See limit the chat to your domains.

When the chat shows the contact form, it includes a consent checkbox that your customer has to tick before sending their details.

Your role and iAgentify’s (GDPR)

  • Your customers’ data. You are the data controller and iAgentify acts as the processor: it processes the data only to provide the service to you and on your instructions.
  • Your account’s data. For your own data (your name, your email, your invoices), the controller is iAgentify. The company behind it is named in the privacy policy.

In practice, if one of your customers asks about their data or asks you to erase it, the request comes to you. What you can delete yourself and what you need to write to us for is in deleting data.

Exercise your rights and ask for more information

You can ask for access to, correction of or deletion of your data at any time by writing to [email protected].

If you need to pass this information on to your data protection lead, write to us at that same address with their questions and we will answer in writing. You can also read the security page and the privacy policy of this site.