Guide
Privacy: where data is stored and who can see it
Your data is hosted in the European Union and only your team sees it. What is sent to the AI to write a reply, which providers are involved and how to exercise your rights.
- Reviewed on
- 5 min read
In this article
Your account’s data is stored on servers located in the European Union and is only seen by the people on your team, each according to their role. An AI provider takes part in writing the replies, and it receives what is needed to answer and nothing else. This article explains it in plain words.
Where the data is stored
The database, the documents you upload to the knowledge, the conversations and the leads are stored on servers located in the European Union.
Who can see it
Each business works in its own account. Your agents, your knowledge sources, your conversations and your leads are only accessible to the users of your account: on every request, iAgentify checks which account you belong to and what role you hold.
- You decide who gets in and with which role. There are four roles. Billing belongs to the Owner, and Read only can only look. Bear in mind that every role, including that one, can read conversations and see and export leads. The detail is in team roles.
- Whoever leaves the team loses access. When you remove a person from Team, they lose access to the account and their sessions end at once.
- There is a record of what is done. Admins and owners have the Activity log under Settings › Company: sign-ins, team changes, billing and configuration, with who and when.
- The iAgentify team. Any access to an account by the iAgentify support team is recorded. You can see it in that same log: in the filter, which starts on All activity, choose iAgentify team.
- Your own sign-in. iAgentify verifies your email when you sign up and locks the account for a while after several failed sign-in attempts. If you use the iAgentify assistant on WhatsApp, it asks for your support PIN before showing anything from your account.
What is sent to the AI to write a reply
To write each reply, iAgentify sends the language-model provider (OpenAI) the customer’s message, the conversation context, your agent’s instructions and the relevant passages from your knowledge. Nothing else. The same provider is involved when knowledge is indexed, that is, when a source is added or re-indexed.
iAgentify does not use your conversations or your documents to train AI models. Under OpenAI’s terms for its API, data sent that way is not used to train its models by default either.
Which providers are involved, and when
These third parties take part so that the service works.
| Provider | Purpose | When it is involved |
|---|---|---|
| OpenAI | Language-model processing | On every agent reply and when indexing knowledge |
| Meta | Delivery of WhatsApp and Instagram messages | Only if you connect those channels |
| Twilio | Delivery of WhatsApp messages | Only if you connect WhatsApp with a Twilio number: one from your own Twilio account or one iAgentify sets up for you |
| Redsys and the bank | Card payments | When you subscribe, renew or buy credits |
| Hosting provider in the European Union | Hosting of the platform and the data | Always |
The full detail is in the privacy policy.
What is stored encrypted and what never reaches iAgentify
- Channel credentials. What is needed to connect WhatsApp and Instagram is stored encrypted and is never shown again, in the app or through the API. You can disconnect a channel at any time from Channels.
- Card. Card details are entered on the bank’s page: iAgentify neither receives nor stores them. It keeps, encrypted, a reference to charge renewals, and the last four digits so that you can recognise the card.
- Password and support PIN. They are not stored in readable form: only what is needed to check them is kept.
- API keys. Each key is shown in full only once, when it is created.
The website chat and consent
The chat code carries a public key, which anyone can see on your website. That is why it is worth listing your domains: from then on, the chat only works on them. See limit the chat to your domains.
When the chat shows the contact form, it includes a consent checkbox that your customer has to tick before sending their details.
Your role and iAgentify’s (GDPR)
- Your customers’ data. You are the data controller and iAgentify acts as the processor: it processes the data only to provide the service to you and on your instructions.
- Your account’s data. For your own data (your name, your email, your invoices), the controller is iAgentify. The company behind it is named in the privacy policy.
In practice, if one of your customers asks about their data or asks you to erase it, the request comes to you. What you can delete yourself and what you need to write to us for is in deleting data.
Exercise your rights and ask for more information
You can ask for access to, correction of or deletion of your data at any time by writing to [email protected].
If you need to pass this information on to your data protection lead, write to us at that same address with their questions and we will answer in writing. You can also read the security page and the privacy policy of this site.
Related articles
- Deleting data: sources, leads, agents and the accountWhat you can delete yourself from the app and what happens each time, what you need to ask Support for, and how to close the account or handle a customer’s erasure request.
- Limit the chat to your domains, and whyWhile the allowed domains list is empty, any website can show your chat and use up your credits. How to fill it in, what each entry covers and what it does not protect.
- Team roles: what each one can doThe four iAgentify roles and what each one allows, area by area. Who can pay, how to change a role and how to remove a person from the team.
- The support PIN for WhatsAppWhat the 6-digit PIN the iAgentify assistant asks for on WhatsApp is, how to set it together with your number, and what the assistant can do once it is verified.