Legal · Last updated: 12 July 2026
Privacy Policy
1. Controller
AGICY(“AGICY”, “we”, “us”) is the brand / project operator of agicy.ai. Planned Cyprus Cap. 113 vehicles, including the target HoldCo AGICY Holdings Ltd, are not yet incorporated — no company registration (HE) number is published. Contact via /contact or the emails below; a registered office address will be published only after incorporation evidence is available.
Data Protection Contact: agi@agicy.ai
Data Protection Officer (DPO) — appointment pending pre-Financial Close. Until a named DPO is published:
- Interim contact: agi@agicy.ai
- Response SLA: 30 calendar days (GDPR Art. 12(3))
- Publication: named DPO and direct contact will be added to this page upon Cyprus Commissioner registration
2. Data We Collect
We process the following categories of personal data:
- Account data— name, email, organisation (when you register or apply for compute access)
- Transaction data— billing details processed by Stripe; we do not store card numbers
- Usage data— pages visited, search queries, API calls (anonymised for analytics)
- Communication data— contact form submissions, email correspondence
- Newsletter data— email address submitted via “The Ledger” signup (double opt-in)
3. Legal Basis (GDPR Art. 6)
- Contract performance— processing your SRA application, providing compute services
- Legitimate interest— analytics, security monitoring, fraud prevention
- Consent— newsletter subscription, optional cookies
- Legal obligation— tax, AML/KYC where applicable
4. Sub-processors
We engage the following categories of sub-processors under GDPR Article 28 Data Processing Agreements (DPAs). A live register will be published at agicy.ai/trust-center before Financial Close:
| Processor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing (PCI DSS) | EU / US¹ |
| Vercel, Inc. | Application hosting & edge | EU region |
| Supabase, Inc. | Authentication & database | EU region |
| Neon, Inc. | PostgreSQL (Playground, audit logs) | EU region |
| Cloudflare, Inc. | Turnstile bot protection (Playground and AI Readiness Audit, when enabled) | EU / US¹ |
| Transactional email provider | Account & service notifications | EU region (TBD)² |
| Overclock Labs / Akash Network | On-demand GPU (Bridge Compute only — not Vasilikos campus) | EU placement filters; US parent¹ |
¹ Where processing may occur outside the EEA, we rely on EU Standard Contractual Clauses (2021/914) and supplementary technical measures.
² Final email provider to be confirmed; DPA executed before production launch.
We do not sell personal data. Transfers outside the EU/EEA occur only with adequate safeguards (SCCs, adequacy decision, or explicit instruction). See Section 4.1.
4.1 International transfers
Primary processing is in the Republic of Cyprus and EU regions. Playground and platform subprocessors above may process limited metadata (IP address, email) in the United States. We assess transfer impact under Schrems II and implement encryption in transit, access controls, and processor contractual commitments before any transfer becomes operational.
5. Retention
We retain personal data only as long as necessary:
| Category | Retention | Basis |
|---|---|---|
| Account & contract data | Duration of relationship + 6 years | Cyprus commercial & tax law |
| Billing & invoice records | 7 years | EU tax compliance |
| Authentication / security logs | 90 days | Legitimate interest (security) |
| Analytics (aggregated) | 26 months, then anonymised | Legitimate interest |
| Newsletter subscriptions | Until unsubscribe + 30 days | Consent |
| Playground email (contest) | 12 months after contest end or erasure request | Contract / consent |
| NDA & data-room access logs | 5 years after NDA term | Legal obligation / legitimate interest |
| audit_log (downloads / vault actions) | 24 months (IP/UA stored as truncated SHA-256) | Legitimate interest (security / diligence) |
| affiliate_clicks | 24 months (IP/UA hashed) | Consent (Functional) + contract with partners |
| Contact / voucher / leasing form submissions | Duration of enquiry + 24 months (or erasure) | Contract / legitimate interest / consent |
| Support correspondence | Contract term + 12 months | Contract performance |
6. Your Rights
Under GDPR Articles 15–22, you have the right to:
- Access your personal data
- Rectification of inaccurate data
- Erasure (“right to be forgotten”)
- Restriction of processing
- Data portability
- Object to processing
- Withdraw consent at any time
To exercise any right, email agi@agicy.ai. We respond within 30 days.
7. Cookies
We use a consent banner for non-essential cookies. Strictly necessary cookies (login, NDA gate, consent memory, bot protection) run without optional consent. Affiliate / UTM cookies and optional product analytics require your opt-in. See our Cookie Policy for the full inventory. No Google Analytics, Meta Pixel, or ad retargeting is deployed. No GTM container is loaded until counsel-approved and consent-gated.
8. Security
We implement appropriate technical and organisational measures including encryption in transit (TLS 1.3), at-rest encryption for stored data, access controls, and regular security assessments. The planned datacenter is designed to NIS2-aligned security standards.
9. Supervisory Authority
You have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (dataprotection.gov.cy).
10. Changes
We may update this policy. Material changes will be communicated via email to registered users and a notice on this page. The “last updated” date above reflects the current revision.